|
194971
|
3.3 |
LOW
Local
|
sap
|
3d_visual_enterprise_viewer
|
When a user opens manipulated PhotoShop Document (.PSD) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unav…
|
NVD-CWE-noinfo
|
CVE-2021-27584
|
2024-11-21 14:58 |
2021-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194972
|
6.1 |
MEDIUM
Network
|
web_based_quiz_system_project
|
web_based_quiz_system
|
Web Based Quiz System 1.0 is affected by cross-site scripting (XSS) in admin.php through the options parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-28006
|
2024-11-21 14:58 |
2021-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194973
|
9.8 |
CRITICAL
Network
|
kentico
|
kentico_cms
|
The Blog module in Kentico CMS 5.5 R2 build 5.5.3996 allows SQL injection via the tagname parameter.
|
CWE-89
SQL Injection
|
CVE-2021-27581
|
2024-11-21 14:58 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194974
|
7.8 |
HIGH
Local
|
jpeg
|
jpeg-xl
|
jpeg-xl v0.3.2 is affected by a heap buffer overflow in /lib/jxl/coeff_order.cc ReadPermutation. When decoding a malicous jxl file using djxl, an attacker can trigger arbitrary code execution or a de…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-28026
|
2024-11-21 14:58 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194975
|
5.4 |
MEDIUM
Network
|
apache
|
superset
|
Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describing chart's related information. Abusing this functionality, a malicious user co…
|
CWE-79
Cross-site Scripting
|
CVE-2021-27907
|
2024-11-21 14:58 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194976
|
9.8 |
CRITICAL
Network
|
bam_project
|
bam
|
An issue was discovered in the bam crate before 0.1.3 for Rust. There is an integer underflow and out-of-bounds write during the loading of a bgzip block.
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2021-28027
|
2024-11-21 14:58 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194977
|
9.8 |
CRITICAL
Network
|
msi
|
dragon_center
|
The MsIo64.sys driver before 1.1.19.1016 in MSI Dragon Center before 2.0.98.0 has a buffer overflow that allows privilege escalation via a crafted 0x80102040, 0x80102044, 0x80102050, or 0x80102054 IO…
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-27965
|
2024-11-21 14:58 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194978
|
9.8 |
CRITICAL
Network
|
sfcyazilim
|
sonlogger
|
SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Config/SaveUploadedHotspotLogoFile without any authentication or session header. T…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-27964
|
2024-11-21 14:58 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194979
|
8.2 |
HIGH
Network
|
sfcyazilim
|
sonlogger
|
SonLogger before 6.4.1 is affected by user creation with any user permissions profile (e.g., SuperAdmin). An anonymous user can send a POST request to /User/saveUser without any authentication or ses…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-27963
|
2024-11-21 14:58 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194980
|
6.1 |
MEDIUM
Network
|
openark
|
orchestrator
|
resources/public/js/orchestrator.js in openark orchestrator before 3.2.4 allows XSS via the orchestrator-msg parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27940
|
2024-11-21 14:58 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|