|
196031
|
7.5 |
HIGH
Network
|
fortinet
|
fortimail
|
A missing cryptographic step in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an unauthenticated attacker who intercepts the encrypted messages to manipulate them in such …
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2021-26100
|
2024-11-21 14:55 |
2021-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196032
|
9.8 |
CRITICAL
Network
|
just-safe-set_project
|
just-safe-set
|
Prototype pollution vulnerability in ‘just-safe-set’ versions 1.0.0 through 2.2.1 allows an attacker to cause a denial of service and may lead to remote code execution.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-25952
|
2024-11-21 14:55 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196033
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the imagelist view of com_media leads to a XSS vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2021-26039
|
2024-11-21 14:55 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196034
|
7.5 |
HIGH
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 2.5.0 through 3.9.27. Install action in com_installer lack the required hardcoded ACL checks for superusers. A default system is not affected cause the default ACL …
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2021-26038
|
2024-11-21 14:55 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196035
|
5.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 2.5.0 through 3.9.27. CMS functions did not properly termine existing user sessions when a user's password was changed or the user was blocked.
|
CWE-613
Insufficient Session Expiration
|
CVE-2021-26037
|
2024-11-21 14:55 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196036
|
7.5 |
HIGH
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 2.5.0 through 3.9.27. Missing validation of input could lead to a broken usergroups table.
|
CWE-20
Improper Input Validation
|
CVE-2021-26036
|
2024-11-21 14:55 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196037
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the rules field of the JForm API leads to a XSS vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2021-26035
|
2024-11-21 14:55 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196038
|
7.5 |
HIGH
Network
|
xml2dict_project
|
xml2dict
|
XXE vulnerability in 'XML2Dict' version 0.2.2 allows an attacker to cause a denial of service.
|
CWE-611
XXE
|
CVE-2021-25951
|
2024-11-21 14:55 |
2021-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196039
|
7.8 |
HIGH
Local
|
avaya
|
aura_device_services
|
An arbitrary code execution vulnerability was discovered in Avaya Aura Device Services that may potentially allow a local user to execute specially crafted scripts. Affects 7.0 through 8.1.4.0 versio…
|
NVD-CWE-noinfo
|
CVE-2021-25654
|
2024-11-21 14:55 |
2021-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196040
|
8.1 |
HIGH
Network
|
open-emr
|
openemr
|
In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malicious user is aware of the first 72 characters of t…
|
CWE-521
Weak Password Requirements
|
CVE-2021-25923
|
2024-11-21 14:55 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|