|
196151
|
5.5 |
MEDIUM
Local
|
polarisoffice
|
polaris_office
|
Polaris Office v9.102.66 is affected by a divide-by-zero error in PolarisOffice.exe and EngineDLL.dll that may cause a local denial of service. To exploit the vulnerability, someone must open a craft…
|
CWE-369
Divide By Zero
|
CVE-2021-27550
|
2024-11-21 14:58 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196152
|
5.9 |
MEDIUM
Network
|
json-smart_project oracle
|
json-smart-v1 json-smart-v2 weblogic_server utilities_framework peoplesoft_enterprise_peopletools communications_cloud_native_core_policy oss_support_tools
|
An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatExcepti…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2021-27568
|
2024-11-21 14:58 |
2021-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196153
|
5.4 |
MEDIUM
Network
|
appspace
|
appspace
|
A stored XSS issue exists in Appspace 6.2.4. After a user is authenticated and enters an XSS payload under the groups section of the network tab, it is stored as the group name. Whenever another memb…
|
CWE-79
Cross-site Scripting
|
CVE-2021-27564
|
2024-11-21 14:58 |
2021-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196154
|
5.3 |
MEDIUM
Network
|
genymobile
|
genymotion_desktop
|
Genymotion Desktop through 3.2.0 leaks the host's clipboard data to the Android application by default. NOTE: the vendor's position is that this is intended behavior that can be changed through the S…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2021-27549
|
2024-11-21 14:58 |
2021-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196155
|
5.4 |
MEDIUM
Network
|
monicahq
|
monica
|
The Contact page in Monica 2.19.1 allows stored XSS via the Nickname field.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27559
|
2024-11-21 14:58 |
2021-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196156
|
7.5 |
HIGH
Network
|
uri.js_project
|
uri.js
|
URI.js (aka urijs) before 1.19.6 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.
|
NVD-CWE-noinfo
|
CVE-2021-27516
|
2024-11-21 14:58 |
2021-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196157
|
5.3 |
MEDIUM
Network
|
url-parse_project
|
url-parse
|
url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.
|
NVD-CWE-noinfo
|
CVE-2021-27515
|
2024-11-21 14:58 |
2021-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196158
|
9.8 |
CRITICAL
Network
|
eyesofnetwork
|
eyesofnetwork
|
EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication bypass (such as in CVE-2021-27513 exploitation).
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2021-27514
|
2024-11-21 14:58 |
2021-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196159
|
8.8 |
HIGH
Network
|
eyesofnetwork
|
eyesofnetwork
|
The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files because it relies on "le filtre userside."
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-27513
|
2024-11-21 14:58 |
2021-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196160
|
7.5 |
HIGH
Network
|
visualware
|
myconnection_server
|
In Visualware MyConnection Server before 11.0b build 5382, each published report is not associated with its own access code.
|
CWE-863
Incorrect Authorization
|
CVE-2021-27509
|
2024-11-21 14:58 |
2021-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|