|
196931
|
7.8 |
HIGH
Local
|
hpe
|
baseboard_management_controller
|
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgetactivexcfg function.
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-26571
|
2024-11-21 14:56 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196932
|
7.8 |
HIGH
Local
|
hpe
|
baseboard_management_controller
|
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webifc_setadconfig function.
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-26570
|
2024-11-21 14:56 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196933
|
9.8 |
CRITICAL
Network
|
gitlog_project
|
gitlog
|
The gitlog function in src/index.ts in gitlog before 4.0.4 has a command injection vulnerability.
|
CWE-78
OS Command
|
CVE-2021-26541
|
2024-11-21 14:56 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196934
|
5.3 |
MEDIUM
Network
|
apostrophecms
|
sanitize-html
|
Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows …
|
NVD-CWE-noinfo
|
CVE-2021-26540
|
2024-11-21 14:56 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196935
|
5.3 |
MEDIUM
Network
|
apostrophecms
|
sanitize-html
|
Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypass hostname whitelist validation set by the "allow…
|
NVD-CWE-noinfo
|
CVE-2021-26539
|
2024-11-21 14:56 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196936
|
7.8 |
HIGH
Local
|
godotengine
|
godot_engine
|
A stack overflow issue exists in Godot Engine up to v3.2 and is caused by improper boundary checks when loading .TGA image files. Depending on the context of the application, attack vector can be loc…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-26826
|
2024-11-21 14:56 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196937
|
7.8 |
HIGH
Local
|
godotengine
|
godot_engine
|
An integer overflow issue exists in Godot Engine up to v3.2 that can be triggered when loading specially crafted.TGA image files. The vulnerability exists in ImageLoaderTGA::load_image() function at …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2021-26825
|
2024-11-21 14:56 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196938
|
9.8 |
CRITICAL
Network
|
wpdatatables
|
wpdatatables
|
wpDataTables before 3.4.1 mishandles order direction for server-side tables, aka admin-ajax.php?action=get_wdtable order[0][dir] SQL injection.
|
CWE-89
SQL Injection
|
CVE-2021-26754
|
2024-11-21 14:56 |
2021-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196939
|
7.5 |
HIGH
Network
|
sthttpd_project
|
sthttpd
|
An issue was discovered in sthttpd through 2.27.1. On systems where the strcpy function is implemented with memcpy, the de_dotdot function may cause a Denial-of-Service (daemon crash) due to overlapp…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2021-26843
|
2024-11-21 14:56 |
2021-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196940
|
6.1 |
MEDIUM
Network
|
jenzabar
|
jenzabar
|
Jenzabar 9.2.x through 9.2.2 allows /ics?tool=search&query= XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2021-26723
|
2024-11-21 14:56 |
2021-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|