|
196441
|
9.8 |
CRITICAL
Network
|
visualware
|
myconnection_server
|
An issue was discovered in Visualware MyConnection Server before v11.1a. Unauthenticated Remote Code Execution can occur via Arbitrary File Upload in the web service when using a myspeed/sf?filename=…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-27198
|
2024-11-21 14:57 |
2021-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196442
|
9.8 |
CRITICAL
Network
|
isida
|
retriever
|
LMA ISIDA Retriever 5.2 allows SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2021-26904
|
2024-11-21 14:57 |
2021-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196443
|
6.1 |
MEDIUM
Network
|
isida
|
retriever
|
LMA ISIDA Retriever 5.2 is vulnerable to XSS via query['text'].
|
CWE-79
Cross-site Scripting
|
CVE-2021-26903
|
2024-11-21 14:57 |
2021-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196444
|
6.1 |
MEDIUM
Network
|
triconsole
|
datepicker_calendar
|
Triconsole Datepicker Calendar <3.77 is affected by cross-site scripting (XSS) in calendar_form.php. Attackers can read authentication cookies that are still active, which can be used to perform furt…
|
CWE-79
Cross-site Scripting
|
CVE-2021-27330
|
2024-11-21 14:57 |
2021-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196445
|
5.5 |
MEDIUM
Local
|
jasper_project fedoraproject
|
jasper fedora
|
A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of service.
|
-
|
CVE-2021-26927
|
2024-11-21 14:57 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196446
|
7.1 |
HIGH
Local
|
jasper_project fedoraproject
|
jasper fedora
|
A flaw was found in jasper before 2.0.25. An out of bounds read issue was found in jp2_decode function whic may lead to disclosure of information or program crash.
|
-
|
CVE-2021-26926
|
2024-11-21 14:57 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196447
|
5.9 |
MEDIUM
Network
|
cira
|
canadian_shield
|
The CIRA Canadian Shield app before 4.0.13 for iOS lacks SSL Certificate Validation.
|
CWE-295
Improper Certificate Validation
|
CVE-2021-27189
|
2024-11-21 14:57 |
2021-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196448
|
5.4 |
MEDIUM
Network
|
mybb
|
mybb
|
MyBB before 1.8.25 allows stored XSS via nested [email] tags with MyCode (aka BBCode).
|
CWE-79
Cross-site Scripting
|
CVE-2021-27279
|
2024-11-21 14:57 |
2021-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196449
|
9.8 |
CRITICAL
Network
|
shinobi
|
shinobi_pro
|
An issue was discovered in Shinobi through ocean version 1. lib/auth.js has Incorrect Access Control. Valid API Keys are held in an internal JS Object. Therefore an attacker can use JS Proto Method n…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2021-27228
|
2024-11-21 14:57 |
2021-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196450
|
5.4 |
MEDIUM
Network
|
monicahq
|
monica
|
The Contact page in Monica 2.19.1 allows stored XSS via the Description field.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27371
|
2024-11-21 14:57 |
2021-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|