Show filters
1,232 Total Results
Displaying 271-280 of 1,232
Sort by:
Attacker Value
Unknown

CVE-2021-28567

Disclosure Date: May 11, 2021 (last updated February 23, 2025)
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Improper Authorization vulnerability in the customers module. Successful exploitation could allow a low-privileged user to modify customer data. Access to the admin console is required for successful exploitation.
Attacker Value
Unknown

CVE-2021-28556

Disclosure Date: May 11, 2021 (last updated February 22, 2025)
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a DOM-based Cross-Site Scripting vulnerability on mage-messages cookies. Successful exploitation could lead to arbitrary JavaScript execution by an unauthenticated attacker. User interaction is required for successful exploitation.
Attacker Value
Unknown

CVE-2021-24236

Disclosure Date: May 06, 2021 (last updated February 22, 2025)
The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Content-Type in the request to forbid dangerous files. This allows unauthenticated attackers to upload arbitrary files by using a valid image Content-Type along with a PHP filename and code, leading to RCE.
Attacker Value
Unknown

CVE-2021-24293

Disclosure Date: May 05, 2021 (last updated February 22, 2025)
In the eCommerce module of the NextGEN Gallery Pro WordPress plugin before 3.1.11, there is an action to call get_cart_items via photocrati_ajax , after that the settings[shipping_address][name] is able to inject malicious javascript.
Attacker Value
Unknown

CVE-2021-21427

Disclosure Date: April 21, 2021 (last updated February 22, 2025)
Magento-lts is a long-term support alternative to Magento Community Edition (CE). A vulnerability in magento-lts versions before 19.4.13 and 20.0.9 potentially allows an administrator unauthorized access to restricted resources. This is a backport of CVE-2021-21024. The vulnerability is patched in versions 19.4.13 and 20.0.9.
Attacker Value
Unknown

CVE-2021-21426

Disclosure Date: April 21, 2021 (last updated February 22, 2025)
Magento-lts is a long-term support alternative to Magento Community Edition (CE). In magento-lts versions 19.4.12 and prior and 20.0.8 and prior, there is a vulnerability caused by the unsecured deserialization of an object. A patch in versions 19.4.13 and 20.0.9 was back ported from Zend Framework 3. The vulnerability was assigned CVE-2021-3007 in Zend Framework.
Attacker Value
Unknown

CVE-2020-27829

Disclosure Date: March 26, 2021 (last updated February 22, 2025)
A heap based buffer overflow in coders/tiff.c may result in program crash and denial of service in ImageMagick before 7.0.10-45.
Attacker Value
Unknown

CVE-2021-20244

Disclosure Date: March 09, 2021 (last updated February 22, 2025)
A flaw was found in ImageMagick in MagickCore/visual-effects.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.
Attacker Value
Unknown

CVE-2021-20246

Disclosure Date: March 09, 2021 (last updated February 22, 2025)
A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.
Attacker Value
Unknown

CVE-2021-20245

Disclosure Date: March 09, 2021 (last updated February 22, 2025)
A flaw was found in ImageMagick in coders/webp.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.