|
194761
|
6.1 |
MEDIUM
Network
|
acquia
|
mautic
|
Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack through the contact's first or last name and triggered when viewing a contact's details page then clicking on the action d…
|
CWE-79
Cross-site Scripting
|
CVE-2021-27911
|
2024-11-21 14:58 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194762
|
6.1 |
MEDIUM
Network
|
acquia
|
mautic
|
Insufficient sanitization / filtering allows for arbitrary JavaScript Injection in Mautic using the bounce management callback function. The values submitted in the "error" and "error_related_to" par…
|
CWE-79
Cross-site Scripting
|
CVE-2021-27910
|
2024-11-21 14:58 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194763
|
6.1 |
MEDIUM
Network
|
acquia
|
mautic
|
For Mautic versions prior to 3.3.4/4.0.0, there is an XSS vulnerability on Mautic's password reset page where a vulnerable parameter, "bundle," in the URL could allow an attacker to execute Javascrip…
|
CWE-79
Cross-site Scripting
|
CVE-2021-27909
|
2024-11-21 14:58 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194764
|
9.8 |
CRITICAL
Network
|
vizio
|
p65-f1_firmware e50x-e1_firmware
|
Several high privileged APIs on the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs do not enforce access controls, allowing an unauthenticated threat actor to access privileged functionali…
|
CWE-78
OS Command
|
CVE-2021-27944
|
2024-11-21 14:58 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194765
|
5.4 |
MEDIUM
Network
|
textpattern
|
textpattern
|
A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which allows remote attackers to execute arbitrary code via a crafted payload entered …
|
CWE-79
Cross-site Scripting
|
CVE-2021-28002
|
2024-11-21 14:58 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194766
|
5.4 |
MEDIUM
Network
|
textpattern
|
textpattern
|
A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to execute arbitrary code via a crafted payload entered into the U…
|
CWE-79
Cross-site Scripting
|
CVE-2021-28001
|
2024-11-21 14:58 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194767
|
4.8 |
MEDIUM
Network
|
local_services_search_engine_management_system_project
|
local_services_search_engine_management_system
|
A persistent cross-site scripting vulnerability was discovered in Local Services Search Engine Management System Project 1.0 which allows remote attackers to execute arbitrary code via crafted payloa…
|
CWE-79
Cross-site Scripting
|
CVE-2021-28000
|
2024-11-21 14:58 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194768
|
4.9 |
MEDIUM
Network
|
local_services_search_engine_management_system_project
|
local_services_search_engine_management_system
|
A SQL injection vulnerability was discovered in the editid parameter in Local Services Search Engine Management System Project 1.0. This vulnerability gives admin users the ability to dump all data f…
|
CWE-89
SQL Injection
|
CVE-2021-27999
|
2024-11-21 14:58 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194769
|
4.8 |
MEDIUM
Network
|
phpgurukul
|
vehicle_parking_management_system
|
A persistent cross site scripting (XSS) vulnerability in the Add Categories module of Vehicle Parking Management System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted pay…
|
CWE-79
Cross-site Scripting
|
CVE-2021-27822
|
2024-11-21 14:58 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194770
|
7.5 |
HIGH
Network
|
hcc-embedded
|
nichestack
|
The web server in InterNiche NicheStack through 4.0.1 allows remote attackers to cause a denial of service (infinite loop and networking outage) via an unexpected valid HTTP request such as OPTIONS. …
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2021-27565
|
2024-11-21 14:58 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|