|
198701
|
6.5 |
MEDIUM
Network
|
flatcore
|
flatcore
|
An issue was discovered in flatCore before 2.0.0 build 139. A time-based blind SQL injection was identified in the selected_folder HTTP request body parameter for the acp interface. The affected para…
|
CWE-89
SQL Injection
|
CVE-2021-23837
|
2024-11-21 14:51 |
2021-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198702
|
4.8 |
MEDIUM
Network
|
flatcore
|
flatcore
|
An issue was discovered in flatCore before 2.0.0 build 139. A stored XSS vulnerability was identified in the prefs_smtp_psw HTTP request body parameter for the acp interface. An admin user can inject…
|
CWE-79
Cross-site Scripting
|
CVE-2021-23836
|
2024-11-21 14:51 |
2021-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198703
|
4.9 |
MEDIUM
Network
|
flatcore
|
flatcore
|
An issue was discovered in flatCore before 2.0.0 build 139. A local file disclosure vulnerability was identified in the docs_file HTTP request body parameter for the acp interface. This can be exploi…
|
CWE-20
Improper Input Validation
|
CVE-2021-23835
|
2024-11-21 14:51 |
2021-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198704
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 3.1.0 through 3.9.23. The lack of escaping of image-related parameters in multiple com_tags views cause lead to XSS attack vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-23125
|
2024-11-21 14:51 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198705
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 3.9.0 through 3.9.23. The lack of escaping in mod_breadcrumbs aria-label attribute allows XSS attacks.
|
CWE-79
Cross-site Scripting
|
CVE-2021-23124
|
2024-11-21 14:51 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198706
|
5.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 3.0.0 through 3.9.23. The lack of ACL checks in the orderPosition endpoint of com_modules leak names of unpublished and/or inaccessible modules.
|
CWE-862
Missing Authorization
|
CVE-2021-23123
|
2024-11-21 14:51 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198707
|
7.8 |
HIGH
Local
|
sudo_project netapp fedoraproject
|
sudo solidfire hci_management_node fedora
|
selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary …
|
CWE-59
Link Following
|
CVE-2021-23240
|
2024-11-21 14:51 |
2021-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198708
|
2.5 |
LOW
Local
|
sudo_project netapp fedoraproject debian
|
sudo cloud_backup solidfire hci_management_node fedora debian_linux
|
The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled…
|
CWE-59
Link Following
|
CVE-2021-23239
|
2024-11-21 14:51 |
2021-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198709
|
5.3 |
MEDIUM
Network
|
opera
|
opera_mini
|
Opera Mini for Android below 53.1 displays URL left-aligned in the address field. This allows a malicious attacker to craft a URL with a long domain name, e.g. www.safe.opera.com.attacker.com. With t…
|
NVD-CWE-Other
|
CVE-2021-23253
|
2024-11-21 14:51 |
2021-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198710
|
5.3 |
MEDIUM
Network
|
mercusys
|
mercury_x18g_firmware
|
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ to the UPnP server, as demonstrated by the /../../conf/template/uhttpd.json URI.
|
CWE-22
Path Traversal
|
CVE-2021-23242
|
2024-11-21 14:51 |
2021-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|