βΌ CVE-2021-3680 βΌ
π Read
via "National Vulnerability Database".
showdoc is vulnerable to Missing Cryptographic Stepπ Read
via "National Vulnerability Database".
βΌ CVE-2021-33336 βΌ
π Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in the Journal module's add article menu in Liferay Portal 7.3.0 through 7.3.3, and Liferay DXP 7.1 fix pack 18, and 7.2 fix pack 5 through 7, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_journal_web_portlet_JournalPortlet_name parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2021-33339 βΌ
π Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in the Fragment module in Liferay Portal 7.2.1 through 7.3.4, and Liferay DXP 7.2 before fix pack 9 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_site_admin_web_portlet_SiteAdminPortlet_name parameter.π Read
via "National Vulnerability Database".
β Phishing Campaign Dangles SharePoint File-Shares β
π Read
via "Threat Post".
Attackers spoof sender addresses to appear legitimate in a crafty campaign that can slip past numerous detections, Microsoft researchers have discovered.π Read
via "Threat Post".
Threat Post
Phishing Campaign Dangles SharePoint File-Shares
Attackers spoof sender addresses to appear legitimate in a crafty campaign that can slip past numerous detections, Microsoft researchers have discovered.
βΌ CVE-2020-24822 βΌ
π Read
via "National Vulnerability Database".
A vulnerability in the dwarf::cursor::uleb function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted ELF file.π Read
via "National Vulnerability Database".
βΌ CVE-2021-33337 βΌ
π Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in the Document Library module's add document menu in Liferay Portal 7.3.0 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_document_library_web_portlet_DLAdminPortlet_name parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2020-24826 βΌ
π Read
via "National Vulnerability Database".
A vulnerability in the elf::section::as_strtab function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted ELF file.π Read
via "National Vulnerability Database".
βΌ CVE-2020-24824 βΌ
π Read
via "National Vulnerability Database".
A global buffer overflow issue in the dwarf::line_table::line_table function of Libelfin v0.3 allows attackers to cause a denial of service (DOS).π Read
via "National Vulnerability Database".
βΌ CVE-2020-24827 βΌ
π Read
via "National Vulnerability Database".
A vulnerability in the dwarf::cursor::skip_form function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted ELF file.π Read
via "National Vulnerability Database".
βΌ CVE-2021-29765 βΌ
π Read
via "National Vulnerability Database".
IBM PowerVM Hypervisor FW940 and FW950 could allow an attacker to obtain sensitive information if they gain service access to the FSP. IBM X-Force ID: 202476.π Read
via "National Vulnerability Database".
βΌ CVE-2021-32590 βΌ
π Read
via "National Vulnerability Database".
Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier may allow an attacker with regular user's privileges to execute arbitrary commands on the underlying SQL database via specifically crafted HTTP requests.π Read
via "National Vulnerability Database".
βΌ CVE-2021-35463 βΌ
π Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 allows remote attackers to inject arbitrary web script or HTML into the management toolbar search via the `keywords` parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2020-24821 βΌ
π Read
via "National Vulnerability Database".
A vulnerability in the dwarf::cursor::skip_form function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted ELF file.π Read
via "National Vulnerability Database".
βΌ CVE-2021-26098 βΌ
π Read
via "National Vulnerability Database".
An instance of small space of random values in the RPC API of FortiSandbox before 4.0.0 may allow an attacker in possession of a few information pieces about the state of the device to possibly predict valid session IDs.π Read
via "National Vulnerability Database".
βΌ CVE-2021-24010 βΌ
π Read
via "National Vulnerability Database".
Improper limitation of a pathname to a restricted directoryΓ vulnerabilities in FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated user to obtain unauthorized access to files and data via specifially crafted web requests.π Read
via "National Vulnerability Database".
βΌ CVE-2021-32594 βΌ
π Read
via "National Vulnerability Database".
An unrestricted file upload vulnerability in the web interface of FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier may allow a low-privileged user to potentially tamper with the underlying system's files via the upload of specifically crafted files.π Read
via "National Vulnerability Database".
βΌ CVE-2020-4707 βΌ
π Read
via "National Vulnerability Database".
IBM API Connect 5.0.0.0 through 5.0.8.11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 187370.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36764 βΌ
π Read
via "National Vulnerability Database".
In CODESYS Gateway V3 before 3.5.17.10, there is a NULL Pointer Dereference. Crafted communication requests may cause a Null pointer dereference in the affected CODESYS products and may result in a denial-of-service condition.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36168 βΌ
π Read
via "National Vulnerability Database".
A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Fortinet FortiPortal 6.x before 6.0.5, FortiPortal 5.3.x before 5.3.6 and any FortiPortal before 6.2.5 allows authenticated attacker to disclosure information via crafted GET requestΓ with maliciousΓ parameter values.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36765 βΌ
π Read
via "National Vulnerability Database".
In CODESYS EtherNetIP before 4.1.0.0, specific EtherNet/IP requests may cause a null pointer dereference in the downloaded vulnerable EtherNet/IP stack that is executed by the CODESYS Control runtime system.π Read
via "National Vulnerability Database".
βΌ CVE-2021-24018 βΌ
π Read
via "National Vulnerability Database".
A buffer underwrite vulnerability in the firmware verification routine of FortiOS before 7.0.1 may allow an attacker located in the adjacent network to potentially execute arbitrary code via a specifically crafted firmware image.π Read
via "National Vulnerability Database".