|
194601
|
6.1 |
MEDIUM
Network
|
symbiote
|
silverstripe_queued_jobs
|
A vulnerability has been identified in the Silverstripe CMS 3 and 4 version of the symbiote/silverstripe-queuedjobs module. A Cross Site Scripting vulnerability allows an attacker to inject an arbitr…
|
CWE-79
Cross-site Scripting
|
CVE-2021-27938
|
2024-11-21 14:58 |
2021-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194602
|
6.1 |
MEDIUM
Network
|
mybb
|
mybb
|
Cross-site Scripting vulnerability in MyBB before 1.8.26 via Custom moderator tools.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27949
|
2024-11-21 14:58 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194603
|
7.2 |
HIGH
Network
|
mybb
|
mybb
|
SQL Injection vulnerability in MyBB before 1.8.26 via User Groups. (issue 3 of 3).
|
CWE-89
SQL Injection
|
CVE-2021-27948
|
2024-11-21 14:58 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194604
|
7.2 |
HIGH
Network
|
mybb
|
mybb
|
SQL Injection vulnerability in MyBB before 1.8.26 via the Copy Forum feature in Forum Management. (issue 2 of 3).
|
CWE-89
SQL Injection
|
CVE-2021-27947
|
2024-11-21 14:58 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194605
|
8.8 |
HIGH
Network
|
mybb
|
mybb
|
SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. (issue 1 of 3).
|
CWE-89
SQL Injection
|
CVE-2021-27946
|
2024-11-21 14:58 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194606
|
8.8 |
HIGH
Network
|
mybb
|
mybb
|
SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.
|
CWE-89
SQL Injection
|
CVE-2021-27890
|
2024-11-21 14:58 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194607
|
6.1 |
MEDIUM
Network
|
mybb
|
mybb
|
Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27889
|
2024-11-21 14:58 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194608
|
9.8 |
CRITICAL
Network
|
shopxo
|
shopxo
|
A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar where the suffix is JPG, which is uploaded after modifying the phar suffix.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-27817
|
2024-11-21 14:58 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194609
|
6.1 |
MEDIUM
Network
|
openmaint
|
openmaint
|
Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbitrary web script or HTML via any "Add" sections, such as Add Card Building & Flo…
|
CWE-79
Cross-site Scripting
|
CVE-2021-27695
|
2024-11-21 14:58 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194610
|
7.0 |
HIGH
Local
|
ssh
|
tectia_client tectia_connectsecure tectia_server
|
SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation in nonstandard conditions. ConnectSecure on Windows is affected.
|
NVD-CWE-noinfo
|
CVE-2021-27893
|
2024-11-21 14:58 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|