Search Results (361486 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-30151 3 Contribsys, Debian, Redhat 3 Sidekiq, Debian Linux, Satellite 2024-11-21 6.1 Medium
Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.
CVE-2021-30150 1 Ocproducts 1 Composr 2024-11-21 6.1 Medium
Composr 10.0.36 allows XSS in an XML script.
CVE-2021-30149 1 Ocproducts 1 Composr 2024-11-21 9.8 Critical
Composr 10.0.36 allows upload and execution of PHP files.
CVE-2021-30147 1 Dmasoftlab 1 Radius Manager 2024-11-21 8.8 High
DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.
CVE-2021-30146 1 Seafile 1 Seafile 2024-11-21 5.4 Medium
Seafile 7.0.5 (2019) allows Persistent XSS via the "share of library functionality."
CVE-2021-30145 1 Mpv 1 Mpv 2024-11-21 7.8 High
A format string vulnerability in mpv through 0.33.0 allows user-assisted remote attackers to achieve code execution via a crafted m3u playlist file.
CVE-2021-30144 1 Glpi-project 1 Dashboard 2024-11-21 4.3 Medium
The Dashboard plugin through 1.0.2 for GLPI allows remote low-privileged users to bypass access control on viewing information about the last ten events, the connected users, and the users in the tech category. For example, plugins/dashboard/front/main2.php can be used.
CVE-2021-30141 1 Friendica 1 Friendica 2024-11-21 7.5 High
Module/Settings/UserExport.php in Friendica through 2021.01 allows settings/userexport to be used by anonymous users, as demonstrated by an attempted access to an array offset on a value of type null, and excessive memory consumption. NOTE: the vendor states "the feature still requires a valid authentication cookie even if the route is accessible to non-logged users.
CVE-2021-30140 1 Liquidfiles 1 Liquidfiles 2024-11-21 5.4 Medium
LiquidFiles 3.4.15 has stored XSS through the "send email" functionality when sending a file via email to an administrator. When a file has no extension and contains malicious HTML / JavaScript content (such as SVG with HTML content), the payload is executed upon a click. This is fixed in 3.5.
CVE-2021-30139 1 Alpinelinux 1 Apk-tools 2024-11-21 7.5 High
In Alpine Linux apk-tools before 2.12.5, the tarball parser allows a buffer overflow and crash.
CVE-2021-30137 1 Axiossystems 1 Assyst 2024-11-21 7.7 High
Assyst 10 SP7.5 has authenticated XXE leading to SSRF via XML unmarshalling. The application allows users to send JSON or XML data to the server. It was possible to inject malicious XML data through several access points.
CVE-2021-30133 1 Cloverdx 1 Cloverdx 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability in CloverDX Server 5.9.0, CloverDX 5.8.1, CloverDX 5.7.0, and earlier allows remote attackers to inject arbitrary web script or HTML via the sessionToken parameter of multiple methods in Simple HTTP API. This is resolved in 5.9.1 and 5.10.
CVE-2021-30132 1 Cloudera 1 Cloudera Manager 2024-11-21 9.8 Critical
Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges.
CVE-2021-30130 2 Debian, Phpseclib 2 Debian Linux, Phpseclib 2024-11-21 7.5 High
phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification.
CVE-2021-30129 3 Apache, Oracle, Redhat 13 Sshd, Banking Payments, Banking Trade Finance and 10 more 2024-11-21 6.5 Medium
A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0
CVE-2021-30128 1 Apache 1 Ofbiz 2024-11-21 9.8 Critical
Apache OFBiz has unsafe deserialization prior to 17.12.07 version
CVE-2021-30127 1 Terra-master 2 F2-210, F2-210 Firmware 2024-11-21 7.3 High
TerraMaster F2-210 devices through 2021-04-03 use UPnP to make the admin web server accessible over the Internet on TCP port 8181, which is arguably inconsistent with the "It is only available on the local network" documentation. NOTE: manually editing /etc/upnp.json provides a partial but undocumented workaround.
CVE-2021-30126 1 Lightmeter 1 Controlcenter 2024-11-21 6.5 Medium
Lightmeter ControlCenter 1.1.0 through 1.5.x before 1.5.1 allows anyone who knows the URL of a publicly available Lightmeter instance to access application settings, possibly including an SMTP password and a Slack access token, via a settings HTTP query.
CVE-2021-30125 1 Jamf 1 Jamf 2024-11-21 6.1 Medium
Jamf Pro before 10.28.0 allows XSS related to inventory history, aka PI-009376.
CVE-2021-30124 1 Vscode-phpmd Project 1 Vscode-phpmd 2024-11-21 9.8 Critical
The unofficial vscode-phpmd (aka PHP Mess Detector) extension before 1.3.0 for Visual Studio Code allows remote attackers to execute arbitrary code via a crafted phpmd.command value in a workspace folder.