|
194021
|
7.5 |
HIGH
Network
|
codesys
|
v2_web_server
|
CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input.
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-30191
|
2024-11-21 15:03 |
2021-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194022
|
9.8 |
CRITICAL
Network
|
codesys
|
v2_web_server
|
CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-30190
|
2024-11-21 15:03 |
2021-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194023
|
9.8 |
CRITICAL
Network
|
codesys
|
v2_web_server
|
CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-30189
|
2024-11-21 15:03 |
2021-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194024
|
9.8 |
CRITICAL
Network
|
codesys
|
v2_runtime_system_sp
|
CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-30188
|
2024-11-21 15:03 |
2021-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194025
|
7.5 |
HIGH
Network
|
codesys
|
plcwinnt runtime_toolkit
|
CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-30186
|
2024-11-21 15:03 |
2021-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194026
|
5.3 |
MEDIUM
Local
|
codesys
|
runtime_toolkit
|
CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command.
|
CWE-78
OS Command
|
CVE-2021-30187
|
2024-11-21 15:03 |
2021-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194027
|
9.1 |
CRITICAL
Network
|
feehi
|
feehi_cms
|
Feehi CMS 2.1.1 is affected by a Server-side request forgery (SSRF) vulnerability. When the user modifies the HTTP Referer header to any url, the server can make a request to it.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-30108
|
2024-11-21 15:03 |
2021-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194028
|
6.1 |
MEDIUM
Network
|
webfairy
|
mediat
|
An issue was discovered in Mediat 1.4.1. There is a Reflected XSS vulnerability which allows remote attackers to inject arbitrary web script or HTML without authentication via the 'return' parameter …
|
CWE-79
Cross-site Scripting
|
CVE-2021-30083
|
2024-11-21 15:03 |
2021-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194029
|
6.1 |
MEDIUM
Network
|
gris_cms_project
|
gris_cms
|
An issue was discovered in Gris CMS v0.1. There is a Persistent XSS vulnerability which allows remote attackers to inject arbitrary web script or HTML via admin/dashboard.
|
CWE-79
Cross-site Scripting
|
CVE-2021-30082
|
2024-11-21 15:03 |
2021-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194030
|
8.8 |
HIGH
Network
|
emlog
|
emlog
|
An issue was discovered in emlog 6.0.0stable. There is a SQL Injection vulnerability that can execute any SQL statement and query server sensitive data via admin/navbar.php?action=add_page.
|
CWE-89
SQL Injection
|
CVE-2021-30081
|
2024-11-21 15:03 |
2021-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|