|
197751
|
4.9 |
MEDIUM
Network
|
flatcore
|
flatcore
|
An issue was discovered in flatCore before 2.0.0 build 139. A local file disclosure vulnerability was identified in the docs_file HTTP request body parameter for the acp interface. This can be exploi…
|
CWE-20
Improper Input Validation
|
CVE-2021-23835
|
2024-11-21 14:51 |
2021-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197752
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 3.1.0 through 3.9.23. The lack of escaping of image-related parameters in multiple com_tags views cause lead to XSS attack vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-23125
|
2024-11-21 14:51 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197753
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 3.9.0 through 3.9.23. The lack of escaping in mod_breadcrumbs aria-label attribute allows XSS attacks.
|
CWE-79
Cross-site Scripting
|
CVE-2021-23124
|
2024-11-21 14:51 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197754
|
5.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 3.0.0 through 3.9.23. The lack of ACL checks in the orderPosition endpoint of com_modules leak names of unpublished and/or inaccessible modules.
|
CWE-862
Missing Authorization
|
CVE-2021-23123
|
2024-11-21 14:51 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197755
|
7.8 |
HIGH
Local
|
sudo_project netapp fedoraproject
|
sudo solidfire hci_management_node fedora
|
selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary …
|
CWE-59
Link Following
|
CVE-2021-23240
|
2024-11-21 14:51 |
2021-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197756
|
2.5 |
LOW
Local
|
sudo_project netapp fedoraproject debian
|
sudo cloud_backup solidfire hci_management_node fedora debian_linux
|
The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled…
|
CWE-59
Link Following
|
CVE-2021-23239
|
2024-11-21 14:51 |
2021-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197757
|
5.3 |
MEDIUM
Network
|
opera
|
opera_mini
|
Opera Mini for Android below 53.1 displays URL left-aligned in the address field. This allows a malicious attacker to craft a URL with a long domain name, e.g. www.safe.opera.com.attacker.com. With t…
|
NVD-CWE-Other
|
CVE-2021-23253
|
2024-11-21 14:51 |
2021-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197758
|
5.3 |
MEDIUM
Network
|
mercusys
|
mercury_x18g_firmware
|
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ to the UPnP server, as demonstrated by the /../../conf/template/uhttpd.json URI.
|
CWE-22
Path Traversal
|
CVE-2021-23242
|
2024-11-21 14:51 |
2021-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197759
|
5.3 |
MEDIUM
Network
|
mercusys
|
mercury_x18g_firmware
|
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (for authentication bypass) to the web server, as demonstrated by the /loginLess…
|
CWE-22
Path Traversal
|
CVE-2021-23241
|
2024-11-21 14:51 |
2021-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197760
|
- |
|
-
|
-
|
A potential vulnerability has been identified for OpenText Operations Bridge Reporter. The vulnerability could be exploited to inject malicious SQL queries. An attack requires to be an authenticate…
|
-
|
CVE-2021-22508
|
2024-11-21 14:50 |
2024-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|