Show filters
1,232 Total Results
Displaying 271-280 of 1,232
Sort by:
Attacker Value
Unknown
CVE-2021-28567
Disclosure Date: May 11, 2021 (last updated February 23, 2025)
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Improper Authorization vulnerability in the customers module. Successful exploitation could allow a low-privileged user to modify customer data. Access to the admin console is required for successful exploitation.
0
Attacker Value
Unknown
CVE-2021-28556
Disclosure Date: May 11, 2021 (last updated February 22, 2025)
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a DOM-based Cross-Site Scripting vulnerability on mage-messages cookies. Successful exploitation could lead to arbitrary JavaScript execution by an unauthenticated attacker. User interaction is required for successful exploitation.
0
Attacker Value
Unknown
CVE-2021-24236
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Content-Type in the request to forbid dangerous files. This allows unauthenticated attackers to upload arbitrary files by using a valid image Content-Type along with a PHP filename and code, leading to RCE.
0
Attacker Value
Unknown
CVE-2021-24293
Disclosure Date: May 05, 2021 (last updated February 22, 2025)
In the eCommerce module of the NextGEN Gallery Pro WordPress plugin before 3.1.11, there is an action to call get_cart_items via photocrati_ajax , after that the settings[shipping_address][name] is able to inject malicious javascript.
0
Attacker Value
Unknown
CVE-2021-21427
Disclosure Date: April 21, 2021 (last updated February 22, 2025)
Magento-lts is a long-term support alternative to Magento Community Edition (CE). A vulnerability in magento-lts versions before 19.4.13 and 20.0.9 potentially allows an administrator unauthorized access to restricted resources. This is a backport of CVE-2021-21024. The vulnerability is patched in versions 19.4.13 and 20.0.9.
0
Attacker Value
Unknown
CVE-2021-21426
Disclosure Date: April 21, 2021 (last updated February 22, 2025)
Magento-lts is a long-term support alternative to Magento Community Edition (CE). In magento-lts versions 19.4.12 and prior and 20.0.8 and prior, there is a vulnerability caused by the unsecured deserialization of an object. A patch in versions 19.4.13 and 20.0.9 was back ported from Zend Framework 3. The vulnerability was assigned CVE-2021-3007 in Zend Framework.
0
Attacker Value
Unknown
CVE-2020-27829
Disclosure Date: March 26, 2021 (last updated February 22, 2025)
A heap based buffer overflow in coders/tiff.c may result in program crash and denial of service in ImageMagick before 7.0.10-45.
0
Attacker Value
Unknown
CVE-2021-20244
Disclosure Date: March 09, 2021 (last updated February 22, 2025)
A flaw was found in ImageMagick in MagickCore/visual-effects.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.
0
Attacker Value
Unknown
CVE-2021-20246
Disclosure Date: March 09, 2021 (last updated February 22, 2025)
A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.
0
Attacker Value
Unknown
CVE-2021-20245
Disclosure Date: March 09, 2021 (last updated February 22, 2025)
A flaw was found in ImageMagick in coders/webp.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.
0