|
201391
|
6.1 |
MEDIUM
Network
|
schneider-electric
|
network_management_card_2_firmware network_management_card_3_firmware
|
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists which could cause arbritrary script execution when a malicious file is read and dis…
|
CWE-79
Cross-site Scripting
|
CVE-2021-22814
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
201392
|
8.8 |
HIGH
Network
|
schneider-electric
|
evc1s22p4_firmware evc1s7p4_firmware evw2_firmware evf2_firmware evp2pe_firmware evb1a_firmware
|
A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to impersonate the user or carry out actions on their behalf when crafted malicious parameters are submit…
|
CWE-352
Origin Validation Error
|
CVE-2021-22725
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
201393
|
8.8 |
HIGH
Network
|
schneider-electric
|
evc1s22p4_firmware evc1s7p4_firmware evw2_firmware evf2_firmware evp2pe_firmware evb1a_firmware
|
A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to impersonate the user or carry out actions on their behalf when crafted malicious parameters are submit…
|
CWE-352
Origin Validation Error
|
CVE-2021-22724
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
201394
|
6.1 |
MEDIUM
Network
|
schneider-electric
|
network_management_card_2_firmware network_management_card_3_firmware
|
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause arbritrary script execution when a privileged account clicks on a …
|
CWE-79
Cross-site Scripting
|
CVE-2021-22813
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
201395
|
6.1 |
MEDIUM
Network
|
schneider-electric
|
network_management_card_2_firmware network_management_card_3_firmware
|
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause arbritrary script execution when a privileged account clicks on a …
|
CWE-79
Cross-site Scripting
|
CVE-2021-22812
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
201396
|
6.1 |
MEDIUM
Network
|
schneider-electric
|
network_management_card_2_firmware network_management_card_3_firmware
|
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause script execution when the request of a privileged account accessin…
|
CWE-79
Cross-site Scripting
|
CVE-2021-22811
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
201397
|
6.1 |
MEDIUM
Network
|
schneider-electric
|
network_management_card_2_firmware network_management_card_3_firmware
|
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause arbritrary script execution when a privileged account clicks on a …
|
CWE-79
Cross-site Scripting
|
CVE-2021-22810
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
201398
|
7.0 |
HIGH
Local
|
linux debian netapp
|
linux_kernel debian_linux h410c_firmware h300s_firmware h500s_firmware h700s_firmware h410s_firmware
|
A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past t…
|
CWE-415
Double Free
|
CVE-2021-22600
|
2024-11-21 14:50 |
2022-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
201399
|
5.5 |
MEDIUM
Local
|
google debian fedoraproject oracle netapp
|
protobuf debian_linux fedora mysql snapcenter oncommand_workflow_automation oncommand_insight active_iq_unified_manager
|
Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error m…
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-22570
|
2024-11-21 14:50 |
2022-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
201400
|
9.8 |
CRITICAL
Network
|
google
|
fuchsia
|
An incorrect setting of UXN bits within mmu_flags_to_s1_pte_attr lead to privileged executable pages being mapped as executable from an unprivileged context. This can be leveraged by an attacker to b…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2021-22566
|
2024-11-21 14:50 |
2022-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|