|
199991
|
6.5 |
MEDIUM
Adjacent
|
vagrant_project
|
vagrant
|
The `com.bmuschko:gradle-vagrant-plugin` Gradle plugin contains an information disclosure vulnerability due to the logging of the system environment variables. When this Gradle plugin is executed in …
|
-
|
CVE-2021-21361
|
2024-11-21 14:48 |
2021-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199992
|
6.1 |
MEDIUM
Network
|
dell
|
idrac8_firmware
|
Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary ‘Host’ hea…
|
CWE-74
Injection
|
CVE-2021-21510
|
2024-11-21 14:48 |
2021-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199993
|
8.8 |
HIGH
Network
|
dell
|
emc_powerscale_onefs
|
PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in its API handler. An un-authtenticated with ISI_PRIV_SYS_SUPPORT and ISI_PRIV_LOGIN_PAPI privileges could potent…
|
CWE-20
Improper Input Validation
|
CVE-2021-21506
|
2024-11-21 14:48 |
2021-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199994
|
5.3 |
MEDIUM
Network
|
zope
|
products.genericsetup
|
Products.GenericSetup is a mini-framework for expressing the configured state of a Zope Site as a set of filesystem artifacts. In Products.GenericSetup before version 2.1.1 there is an information di…
|
-
|
CVE-2021-21360
|
2024-11-21 14:48 |
2021-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199995
|
7.8 |
HIGH
Local
|
dell
|
emc_powerscale_onefs
|
PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in a command. The Compadmin user could potentially exploit this vulnerability, leading to potential privileges esc…
|
CWE-78
OS Command
|
CVE-2021-21503
|
2024-11-21 14:48 |
2021-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199996
|
6.1 |
MEDIUM
Network
|
zope
|
products.pluggableauthservice
|
Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 there is an open redirect vulnerability. A maliciou…
|
-
|
CVE-2021-21337
|
2024-11-21 14:48 |
2021-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199997
|
9.8 |
CRITICAL
Network
|
spnego_http_authentication_module_project
|
spnego_http_authentication_module
|
In the SPNEGO HTTP Authentication Module for nginx (spnego-http-auth-nginx-module) before version 1.1.1 basic Authentication can be bypassed using a malformed username. This affects users of spnego-h…
|
-
|
CVE-2021-21335
|
2024-11-21 14:48 |
2021-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199998
|
9.8 |
CRITICAL
Network
|
ratcf
|
ratcf
|
RATCF is an open-source framework for hosting Cyber-Security Capture the Flag events. In affected versions of RATCF users with multi factor authentication enabled are able to log in without a valid t…
|
-
|
CVE-2021-21329
|
2024-11-21 14:48 |
2021-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199999
|
6.5 |
MEDIUM
Network
|
zope plone
|
products.pluggableauthservice plone
|
Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 there is an information disclosure vulnerability - …
|
-
|
CVE-2021-21336
|
2024-11-21 14:48 |
2021-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200000
|
6.5 |
MEDIUM
Network
|
minio
|
minio
|
MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage service. In MinIO before version RELEASE.2021-03-04T00-53-13Z it is possible to b…
|
CWE-863
Incorrect Authorization
|
CVE-2021-21362
|
2024-11-21 14:48 |
2021-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|