|
197671
|
6.1 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite through 7.10.4 allows XSS via a crafted Content-Disposition header in an uploaded HTML document to an ajax/share/<share-token>?delivery=view URI.
|
CWE-79
Cross-site Scripting
|
CVE-2021-23929
|
2024-11-21 14:52 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197672
|
6.1 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite through 7.10.3 allows XSS via the ajax/apps/manifests query string.
|
CWE-79
Cross-site Scripting
|
CVE-2021-23928
|
2024-11-21 14:52 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197673
|
6.4 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite through 7.10.4 allows SSRF via a URL with an @ character in an appsuite/api/oauth/proxy PUT request.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-23927
|
2024-11-21 14:52 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197674
|
9.1 |
CRITICAL
Network
|
ivanti
|
avalanche
|
An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.
|
NVD-CWE-noinfo
|
CVE-2021-22962
|
2024-11-21 14:51 |
2023-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197675
|
7.5 |
HIGH
Network
|
odoo
|
odoo
|
Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to download PDF reports for arbitrary documents, via cr…
|
NVD-CWE-Other
|
CVE-2021-23203
|
2024-11-21 14:51 |
2023-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197676
|
8.7 |
HIGH
Network
|
odoo
|
odoo
|
A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to access and modify database contents of other tenants, in a multi-tena…
|
NVD-CWE-noinfo
|
CVE-2021-23186
|
2024-11-21 14:51 |
2023-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197677
|
7.5 |
HIGH
Network
|
odoo
|
odoo
|
Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that belongs to another us…
|
NVD-CWE-noinfo
|
CVE-2021-23178
|
2024-11-21 14:51 |
2023-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197678
|
6.5 |
MEDIUM
Network
|
odoo
|
odoo
|
Improper access control in reporting engine of l10n_fr_fec module in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to extract accounting infor…
|
NVD-CWE-noinfo
|
CVE-2021-23176
|
2024-11-21 14:51 |
2023-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197679
|
8.7 |
HIGH
Network
|
odoo
|
odoo
|
A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and write local files on the server.
|
NVD-CWE-noinfo
|
CVE-2021-23166
|
2024-11-21 14:51 |
2023-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197680
|
5.5 |
MEDIUM
Local
|
sox_project
|
sox
|
A floating point exception (divide-by-zero) issue was discovered in SoX in functon read_samples() of voc.c file. An attacker with a crafted file, could cause an application to crash.
|
-
|
CVE-2021-23210
|
2024-11-21 14:51 |
2022-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|