|
197841
|
5.4 |
MEDIUM
Network
|
fortinet
|
fortianalyzer
|
An improper neutralization of input vulnerability [CWE-79] in FortiAnalyzer versions 6.4.3 and below, 6.2.7 and below and 6.0.10 and below may allow a remote authenticated attacker to perform a store…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24021
|
2024-11-21 14:52 |
2021-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197842
|
9.8 |
CRITICAL
Network
|
fortinet
|
forticlient_endpoint_management_server
|
An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below may allow an attacker to reuse the unexpired admin user session IDs to gain adm…
|
CWE-613
Insufficient Session Expiration
|
CVE-2021-24019
|
2024-11-21 14:52 |
2021-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197843
|
7.8 |
HIGH
Local
|
mcafee
|
drive_encryption
|
Privilege Escalation vulnerability in a Windows system driver of McAfee Drive Encryption (DE) prior to 7.3.0 could allow a local non-admin user to gain elevated system privileges via exploiting an un…
|
CWE-269
Improper Privilege Management
|
CVE-2021-23893
|
2024-11-21 14:52 |
2021-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197844
|
4.3 |
MEDIUM
Network
|
fortinet
|
fortimanager
|
An improper authentication in Fortinet FortiManager version 6.4.3 and below, 6.2.6 and below allows attacker to assign arbitrary Policy and Object modules via crafted requests to the request handler.
|
CWE-287
Improper Authentication
|
CVE-2021-24017
|
2024-11-21 14:52 |
2021-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197845
|
6.3 |
MEDIUM
Local
|
fortinet
|
fortimanager
|
An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and below allows attacker to execute arbitrary commands via crafted IPv4 field in …
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2021-24016
|
2024-11-21 14:52 |
2021-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197846
|
7.2 |
HIGH
Network
|
wp-domain-redirect_project
|
wp-domain-redirect
|
The Edit domain functionality in the WP Domain Redirect WordPress plugin through 1.0 has an `editid` parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leadin…
|
-
|
CVE-2021-24401
|
2024-11-21 14:52 |
2021-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197847
|
7.2 |
HIGH
Network
|
wp-display-users_project
|
wp-display-users
|
The Edit Role functionality in the Display Users WordPress plugin through 2.0.0 had an `id` parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL …
|
-
|
CVE-2021-24400
|
2024-11-21 14:52 |
2021-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197848
|
7.2 |
HIGH
Network
|
ombu
|
the_sorter
|
The check_order function of The Sorter WordPress plugin through 1.0 uses an `area_id` parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL inject…
|
-
|
CVE-2021-24399
|
2024-11-21 14:52 |
2021-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197849
|
7.2 |
HIGH
Network
|
webpsilon
|
responsive_3d_slider
|
The Add new scene functionality in the Responsive 3D Slider WordPress plugin through 1.2 uses an id parameter which is not sanitised, escaped or validated before being inserted to a SQL statement, le…
|
-
|
CVE-2021-24398
|
2024-11-21 14:52 |
2021-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197850
|
7.2 |
HIGH
Network
|
activemedia
|
microcopy
|
The edit functionality in the MicroCopy WordPress plugin through 1.1.0 makes a get request to fetch the related option. The id parameter used is not sanitised, escaped or validated before inserting t…
|
-
|
CVE-2021-24397
|
2024-11-21 14:52 |
2021-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|