Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-27513PUBLISHED: 2021-02-22The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files because it relies on "le filtre userside."
CVE-2021-27514PUBLISHED: 2021-02-22EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication bypass (such as in CVE-2021-27513 exploitation).
CVE-2021-27515PUBLISHED: 2021-02-22url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.
CVE-2021-27516PUBLISHED: 2021-02-22URI.js (aka urijs) before 1.19.6 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.
CVE-2021-26716PUBLISHED: 2021-02-21Modules/input/Views/schedule.php in Emoncms through 10.2.7 allows XSS via the node parameter.