|
194251
|
6.5 |
MEDIUM
Network
|
grafana
|
grafana
|
The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any aut…
|
CWE-863
Incorrect Authorization
|
CVE-2021-28146
|
2024-11-21 14:59 |
2021-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194252
|
7.5 |
HIGH
Network
|
kde
|
discover
|
libdiscover/backends/KNSBackend/KNSResource.cpp in KDE Discover before 5.21.3 automatically creates links to potentially dangerous URLs (that are neither https:// nor http://) based on the content of…
|
NVD-CWE-noinfo
|
CVE-2021-28117
|
2024-11-21 14:59 |
2021-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194253
|
5.3 |
MEDIUM
Network
|
torproject fedoraproject
|
tor fedora
|
Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka TROVE-2021-002.
|
CWE-617
Reachable Assertion
|
CVE-2021-28090
|
2024-11-21 14:59 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194254
|
7.5 |
HIGH
Network
|
torproject fedoraproject
|
tor fedora
|
Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2021-28089
|
2024-11-21 14:59 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194255
|
6.1 |
MEDIUM
Network
|
compassplus
|
tranzware_e-commerce_payment_gateway
|
index.jsp in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a Stored cross-site scripting (XSS) vulnerability
|
CWE-79
Cross-site Scripting
|
CVE-2021-28126
|
2024-11-21 14:59 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194256
|
7.5 |
HIGH
Network
|
compassplus
|
tranzware_e-commerce_payment_gateway
|
/exec in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a vulnerability in its XML parser.
|
CWE-611
XXE
|
CVE-2021-28110
|
2024-11-21 14:59 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194257
|
6.1 |
MEDIUM
Network
|
compassplus
|
tranzware_fimi
|
TranzWare (POI) FIMI before 4.2.20.4.2 allows login_tw.php reflected Cross-Site Scripting (XSS).
|
CWE-79
Cross-site Scripting
|
CVE-2021-28109
|
2024-11-21 14:59 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194258
|
6.1 |
MEDIUM
Network
|
acexy_wireless-n_wifi_repeater_project
|
acexy_wireless-n_wifi_repeater_firmware
|
Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) suffers from a reflected XSS vulnerability due to unsanitized SSID value when the latter is displayed in the /repeater.html page ("Repeater Wizard" homep…
|
CWE-79
Cross-site Scripting
|
CVE-2021-28160
|
2024-11-21 14:59 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194259
|
5.4 |
MEDIUM
Network
|
concretecms
|
concrete_cms
|
Concrete CMS (formerly concrete5) before 8.5.5 allows remote authenticated users to conduct XSS attacks via a crafted survey block. This requires at least Editor privileges.
|
CWE-79
Cross-site Scripting
|
CVE-2021-28145
|
2024-11-21 14:59 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194260
|
4.3 |
MEDIUM
Network
|
zoom
|
zoom
|
Zoom through 5.5.4 sometimes allows attackers to read private information on a participant's screen, even though the participant never attempted to share the private part of their screen. When a user…
|
CWE-200
Information Exposure
|
CVE-2021-28133
|
2024-11-21 14:59 |
2021-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|