|
194031
|
7.8 |
HIGH
Local
|
mpv
|
mpv
|
A format string vulnerability in mpv through 0.33.0 allows user-assisted remote attackers to achieve code execution via a crafted m3u playlist file.
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2021-30145
|
2024-11-21 15:03 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194032
|
7.5 |
HIGH
Network
|
octopus
|
server
|
Cleartext storage of sensitive information in multiple versions of Octopus Server where in certain situations when running import or export processes, the password used to encrypt and decrypt sensiti…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2021-30183
|
2024-11-21 15:03 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194033
|
5.4 |
MEDIUM
Network
|
eng
|
knowage
|
Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' parameter.
|
CWE-74
Injection
|
CVE-2021-30214
|
2024-11-21 15:03 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194034
|
6.1 |
MEDIUM
Network
|
eng
|
knowage
|
Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in '/servlet/AdapterHTTP' via the 'targetService' parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-30213
|
2024-11-21 15:03 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194035
|
5.4 |
MEDIUM
Network
|
eng
|
knowage
|
Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS). An attacker can inject arbitrary web script in '/knowage/restful-services/documentnotes/saveNote' via the 'nota' parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-30212
|
2024-11-21 15:03 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194036
|
5.4 |
MEDIUM
Network
|
eng
|
knowage
|
Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS). An attacker can inject arbitrary web script in '/knowage/restful-services/signup/update' via the 'surname' parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-30211
|
2024-11-21 15:03 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194037
|
7.5 |
HIGH
Network
|
jetbrains
|
intellij_idea
|
In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure.
|
CWE-611
XXE
|
CVE-2021-30006
|
2024-11-21 15:03 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194038
|
7.8 |
HIGH
Local
|
jetbrains
|
pycharm
|
In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2021-30005
|
2024-11-21 15:03 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194039
|
5.4 |
MEDIUM
Network
|
ruiyanai
|
cloudiso
|
RiyaLab CloudISO event item is added, special characters in specific field of time management page are not properly filtered, which allow remote authenticated attackers can inject malicious JavaScrip…
|
-
|
CVE-2021-30174
|
2024-11-21 15:03 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194040
|
6.5 |
MEDIUM
Network
|
junhetec
|
omnidirectional_communication_system
|
Local File Inclusion vulnerability of the omni-directional communication system allows remote authenticated attacker inject absolute path into Url parameter and access arbitrary file.
|
-
|
CVE-2021-30173
|
2024-11-21 15:03 |
2021-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|