|
196881
|
6.5 |
MEDIUM
Network
|
otrs
|
otrs
|
Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS …
|
NVD-CWE-noinfo
|
CVE-2021-21440
|
2024-11-21 14:48 |
2021-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196882
|
6.5 |
MEDIUM
Network
|
combodo
|
itop
|
Combodo iTop is an open source, web based IT Service Management tool. Prior to version 2.7.4, the CSRF token validation can be bypassed through iTop portal via a tricky browser procedure. The vulnera…
|
CWE-352
Origin Validation Error
|
CVE-2021-21407
|
2024-11-21 14:48 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196883
|
8.8 |
HIGH
Network
|
combodo
|
itop
|
Combodo iTop is an open source, web based IT Service Management tool. In versions prior to 2.7.4, there is a command injection vulnerability in the Setup Wizard when providing Graphviz executable pat…
|
CWE-77
Command Injection
|
CVE-2021-21406
|
2024-11-21 14:48 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196884
|
6.1 |
MEDIUM
Network
|
advantech
|
r-seenet
|
Cross-site scripting vulnerabilities exist in the ssh_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can lead to arbitrary Jav…
|
CWE-79
Cross-site Scripting
|
CVE-2021-21800
|
2024-11-21 14:48 |
2021-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196885
|
6.1 |
MEDIUM
Network
|
advantech
|
r-seenet
|
Cross-site scripting vulnerabilities exist in the telnet_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can lead to arbitrary …
|
CWE-79
Cross-site Scripting
|
CVE-2021-21799
|
2024-11-21 14:48 |
2021-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196886
|
3.3 |
LOW
Local
|
dell
|
wyse_management_suite
|
Dell Wyse Management Suite versions 3.2 and earlier contain a full path disclosure vulnerability. A local unauthenticated attacker could exploit this vulnerability in order to obtain the path of file…
|
CWE-200
Information Exposure
|
CVE-2021-21587
|
2024-11-21 14:48 |
2021-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196887
|
6.5 |
MEDIUM
Network
|
dell
|
wyse_management_suite
|
Wyse Management Suite versions 3.2 and earlier contain an absolute path traversal vulnerability. A remote authenticated malicious user could exploit this vulnerability in order to read arbitrary file…
|
CWE-22
Path Traversal
|
CVE-2021-21586
|
2024-11-21 14:48 |
2021-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196888
|
6.7 |
MEDIUM
Local
|
dell
|
emc_unity_operating_environment emc_unityvsa_operating_environment emc_unity_xt_operating_environment
|
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2021-21591
|
2024-11-21 14:48 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196889
|
6.7 |
MEDIUM
Local
|
dell
|
emc_unity_operating_environment emc_unityvsa_operating_environment emc_unity_xt_operating_environment
|
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2021-21590
|
2024-11-21 14:48 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196890
|
6.7 |
MEDIUM
Local
|
dell
|
emc_unity_operating_environment emc_unityvsa_operating_environment emc_unity_xt_operating_environment
|
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 do not exit on failed Initialization. A local authenticated Service user could potentially exploit this vulnerability to escalat…
|
NVD-CWE-Other
|
CVE-2021-21589
|
2024-11-21 14:48 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|