|
196181
|
5.4 |
MEDIUM
Network
|
poweradmin
|
pa_server_monitor
|
A cross-site scripting (XSS) vulnerability in Power Admin PA Server Monitor 8.2.1.1 allows remote attackers to inject arbitrary web script or HTML via Console.exe.
|
CWE-79
Cross-site Scripting
|
CVE-2021-26844
|
2024-11-21 14:56 |
2021-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196182
|
8.8 |
HIGH
Network
|
playtuber_project
|
playtuber
|
An issue was discoverered in in customercentric-selling-poland PlayTube, allows authenticated attackers to execute arbitrary code via the purchace code to the config.php.
|
NVD-CWE-noinfo
|
CVE-2021-26786
|
2024-11-21 14:56 |
2021-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196183
|
9.8 |
CRITICAL
Network
|
doyocms_project
|
doyocms
|
Arbitrary file upload vulnerability sysupload.php in millken doyocms 2.3 allows attackers to execute arbitrary code.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-26740
|
2024-11-21 14:56 |
2021-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196184
|
9.8 |
CRITICAL
Network
|
doyocms_project
|
doyocms
|
SQL Injection vulnerability in pay.php in millken doyocms 2.3, allows attackers to execute arbitrary code, via the attribute parameter.
|
CWE-89
SQL Injection
|
CVE-2021-26739
|
2024-11-21 14:56 |
2021-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196185
|
8.8 |
HIGH
Network
|
nhn-commerce
|
godomall5
|
The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary …
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2021-26610
|
2024-11-21 14:56 |
2021-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196186
|
7.5 |
HIGH
Network
|
mangboard
|
mang_board
|
A vulnerability was found in Mangboard(WordPress plugin). A SQL-Injection vulnerability was found in order_type parameter. The order_type parameter makes a SQL query using unfiltered data. This vulne…
|
CWE-89
SQL Injection
|
CVE-2021-26609
|
2024-11-21 14:56 |
2021-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196187
|
9.8 |
CRITICAL
Network
|
tobesoft
|
nexacro
|
An Improper input validation in execDefaultBrowser method of NEXACRO17 allows a remote attacker to execute arbitrary command on affected systems.
|
CWE-20
Improper Input Validation
|
CVE-2021-26607
|
2024-11-21 14:56 |
2021-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196188
|
6.1 |
MEDIUM
Network
|
hpe
|
superdome_flex_firmware superdome_flex_280_firmware
|
A potential security vulnerability has been identified in HPE Superdome Flex Servers. The vulnerability could be remotely exploited to allow Cross Site Scripting (XSS) because the Session Cookie is m…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2021-26589
|
2024-11-21 14:56 |
2021-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196189
|
4.7 |
MEDIUM
Local
|
amd
|
athlon_firmware athlon_pro_firmware epyc_firmware ryzen_firmware ryzen_pro_firmware
|
A timing and power-based side channel attack leveraging the x86 PREFETCH instructions on some AMD CPUs could potentially result in leaked kernel address space information.
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2021-26318
|
2024-11-21 14:56 |
2021-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196190
|
7.0 |
HIGH
Local
|
microsoft
|
windows_server_2008 windows_server_2012 windows_8.1 windows_server_2016 windows_rt_8.1 windows_10 windows_server_2019 windows_server_2022 windows_7 windows_11
|
Windows HTTP.sys Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2021-26442
|
2024-11-21 14:56 |
2021-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|