|
194271
|
8.8 |
HIGH
Network
|
myvestacp vestacp
|
myvesta vesta_control_panel
|
web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different origin.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-28379
|
2024-11-21 14:59 |
2021-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194272
|
5.4 |
MEDIUM
Network
|
gitea
|
gitea
|
Gitea 1.12.x and 1.13.x before 1.13.4 allows XSS via certain issue data in some situations.
|
CWE-79
Cross-site Scripting
|
CVE-2021-28378
|
2024-11-21 14:59 |
2021-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194273
|
7.8 |
HIGH
Local
|
linux fedoraproject netapp
|
linux_kernel fedora cloud_backup solidfire_baseboard_management_controller_firmware
|
An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not prevent user applications from sending kernel RPC messages, aka CID-20c40794eb85…
|
CWE-862
Missing Authorization
|
CVE-2021-28375
|
2024-11-21 14:59 |
2021-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194274
|
7.5 |
HIGH
Network
|
debian
|
courier-authlib debian_linux
|
The Debian courier-authlib package before 0.71.1-2 for Courier Authentication Library creates a /run/courier/authdaemon directory with weak permissions, allowing an attacker to read user information.…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2021-28374
|
2024-11-21 14:59 |
2021-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194275
|
7.5 |
HIGH
Network
|
tt-rss
|
tiny_tiny_rss
|
The auth_internal plugin in Tiny Tiny RSS (aka tt-rss) before 2021-03-12 allows an attacker to log in via the OTP code without a valid password. NOTE: this issue only affected the git master branch f…
|
CWE-863
Incorrect Authorization
|
CVE-2021-28373
|
2024-11-21 14:59 |
2021-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194276
|
7.5 |
HIGH
Network
|
spdk
|
storage_performance_development_kit
|
An issue was discovered in Storage Performance Development Kit (SPDK) before 20.01.01. If a PDU is sent to the iSCSI target with a zero length (but data is expected), the iSCSI target can crash with …
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-28361
|
2024-11-21 14:59 |
2021-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194277
|
6.1 |
MEDIUM
Network
|
eclipse
|
theia
|
In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2021-28162
|
2024-11-21 14:59 |
2021-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194278
|
6.1 |
MEDIUM
Network
|
eclipse
|
theia
|
In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript code can be injected.
|
CWE-79
Cross-site Scripting
|
CVE-2021-28161
|
2024-11-21 14:59 |
2021-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194279
|
7.5 |
HIGH
Network
|
is-svg_project
|
is-svg
|
The is-svg package 2.1.0 through 4.2.1 for Node.js uses a regular expression that is vulnerable to Regular Expression Denial of Service (ReDoS). If an attacker provides a malicious string, is-svg wil…
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2021-28092
|
2024-11-21 14:59 |
2021-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194280
|
7.5 |
HIGH
Network
|
pupnp_project
|
pupnp
|
A stack overflow in pupnp before version 1.14.5 can cause the denial of service through the Parser_parseDocument() function. ixmlNode_free() will release a child node recursively, which will consume …
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2021-28302
|
2024-11-21 14:59 |
2021-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|