|
197411
|
6.5 |
MEDIUM
Network
|
mongodb
|
mongodb
|
A user authorized to performing a specific type of find query may trigger a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.4.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2021-20326
|
2024-11-21 14:46 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197412
|
7.8 |
HIGH
Local
|
gnu
|
binutils
|
A flaw was found in binutils readelf 2.35 program. An attacker who is able to convince a victim using readelf to read a crafted file could trigger a stack buffer overflow, out-of-bounds write of arbi…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-20294
|
2024-11-21 14:46 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197413
|
7.5 |
HIGH
Network
|
redhat debian
|
ansible_engine ansible_tower ansible_automation_platform debian_linux
|
A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This …
|
CWE-200
Information Exposure
|
CVE-2021-20228
|
2024-11-21 14:46 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197414
|
5.4 |
MEDIUM
Network
|
ibm
|
content_navigator
|
IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potential…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20550
|
2024-11-21 14:46 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197415
|
5.4 |
MEDIUM
Network
|
ibm
|
content_navigator
|
IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potential…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20549
|
2024-11-21 14:46 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197416
|
5.4 |
MEDIUM
Network
|
ibm
|
content_navigator
|
IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potential…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20448
|
2024-11-21 14:46 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197417
|
5.5 |
MEDIUM
Local
|
ibm
|
spectrum_protect_client spectrum_protect_for_space_management
|
IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and cause the applica…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-20546
|
2024-11-21 14:46 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197418
|
6.2 |
MEDIUM
Local
|
ibm
|
spectrum_protect_plus
|
IBM Spectrum Protect Plus File Systems Agent 10.1.6 and 10.1.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 198836.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2021-20536
|
2024-11-21 14:46 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197419
|
7.8 |
HIGH
Local
|
ibm
|
spectrum_protect_backup-archive_client spectrum_protect_for_virtual_environments
|
IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 could allow a local user to escalate their privileges to take full control of the system due to insecure directory permissions. IBM X-Force ID: 19…
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-20532
|
2024-11-21 14:46 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197420
|
6.5 |
MEDIUM
Network
|
ibm
|
spectrum_protect_plus
|
IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domai…
|
NVD-CWE-Other
|
CVE-2021-20432
|
2024-11-21 14:46 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|