|
199921
|
8.2 |
HIGH
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to e…
|
CWE-611
XXE
|
CVE-2021-20454
|
2024-11-21 14:46 |
2021-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199922
|
8.2 |
HIGH
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose…
|
CWE-611
XXE
|
CVE-2021-20453
|
2024-11-21 14:46 |
2021-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199923
|
6.1 |
MEDIUM
Local
|
samba redhat fedoraproject
|
cifs-utils enterprise_linux fedora
|
A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vul…
|
CWE-269
Improper Privilege Management
|
CVE-2021-20208
|
2024-11-21 14:46 |
2021-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199924
|
7.2 |
HIGH
Network
|
ibm
|
resilient
|
IBM Resilient SOAR V38.0 could allow a privileged user to create create malicious scripts that could be executed as another user. IBM X-Force ID: 198759.
|
CWE-77
Command Injection
|
CVE-2021-20527
|
2024-11-21 14:46 |
2021-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199925
|
4.4 |
MEDIUM
Local
|
ibm
|
spectrum_protect
|
IBM Spectrum Protect Server 7.1 and 8.1 is subject to a stack-based buffer overflow caused by improper bounds checking during the parsing of commands. By issuing such a command with an improper param…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-20491
|
2024-11-21 14:46 |
2021-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199926
|
7.5 |
HIGH
Network
|
mitsubishielectric
|
got2000_gt27_firmware got2000_gt25_firmware gt2107-wtbd_firmware gt2107-wtsd_firmware gs2110-wtbd-n_firmware gs2107-wtbd-n_firmware
|
Improper authentication vulnerability in GOT2000 series GT27 model VNC server versions 01.39.010 and prior, GOT2000 series GT25 model VNC server versions 01.39.010 and prior, GOT2000 series GT21 mode…
|
CWE-287
Improper Authentication
|
CVE-2021-20590
|
2024-11-21 14:46 |
2021-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199927
|
7.2 |
HIGH
Network
|
linuxfoundation redhat fedoraproject debian
|
ceph ceph_storage fedora debian_linux
|
An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who …
|
CWE-287
Improper Authentication
|
CVE-2021-20288
|
2024-11-21 14:46 |
2021-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199928
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_engineering_lifecycle_manager rhapsody_model_manager collaborative_lifecycle_management engineering_test_management engineeri…
|
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potenti…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20519
|
2024-11-21 14:46 |
2021-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199929
|
6.5 |
MEDIUM
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticated attacker could exploit this vuln…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-20480
|
2024-11-21 14:46 |
2021-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199930
|
7.8 |
HIGH
Local
|
mongodb
|
compass
|
A malicious 3rd party with local access to the Windows machine where MongoDB Compass is installed can execute arbitrary software with the privileges of the user who is running MongoDB Compass. This i…
|
CWE-269
Improper Privilege Management
|
CVE-2021-20334
|
2024-11-21 14:46 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|