|
197071
|
7.5 |
HIGH
Network
|
wago
|
0852-0303_firmware 0852-1305_firmware 0852-1505_firmware 0852-1305\/000-001_firmware 0852-1505\/000-001_firmware
|
In multiple managed switches by WAGO in different versions the webserver cookies of the web based UI contain user credentials.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2021-20995
|
2024-11-21 14:47 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197072
|
6.1 |
MEDIUM
Network
|
wago
|
0852-0303_firmware 0852-1305_firmware 0852-1505_firmware 0852-1305\/000-001_firmware 0852-1505\/000-001_firmware
|
In multiple managed switches by WAGO in different versions an attacker may trick a legitimate user to click a link to inject possible malicious code into the Web-Based Management.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20994
|
2024-11-21 14:47 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197073
|
5.3 |
MEDIUM
Network
|
wago
|
0852-0303_firmware 0852-1305_firmware 0852-1505_firmware 0852-1305\/000-001_firmware 0852-1505\/000-001_firmware
|
In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the index of the resources located inside the directory.
|
CWE-200
Information Exposure
|
CVE-2021-20993
|
2024-11-21 14:47 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197074
|
7.5 |
HIGH
Network
|
hilscher pepperl-fuchs
|
rcx_rtos ice1-16di-g60l-v1d_firmware ice1-16dio-g60l-c1-v1d_firmware ice1-16dio-g60l-v1d_firmware ice1-8di8do-g60l-c1-v1d_firmware ice1-8di8do-g60l-v1d_firmware ice1-8iol-g30l-v1d_f…
|
In Hilscher rcX RTOS versions prios to V2.1.14.1 the actual UDP packet length is not verified against the length indicated by the packet. This may lead to a denial of service of the affected device.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2021-20988
|
2024-11-21 14:47 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197075
|
6.1 |
MEDIUM
Network
|
ec-cube
|
ec-cube
|
Cross-site scripting vulnerability in EC-CUBE 4.0.0 to 4.0.5 allows a remote attacker to inject a specially crafted script in the specific input field of the EC web site which is created using EC-CUB…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20717
|
2024-11-21 14:47 |
2021-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197076
|
5.2 |
MEDIUM
Local
|
octobercms
|
october
|
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-26231 (fixed in 1.0.470/471 and 1.1.1) was discovered that has the same impact as CVE…
|
NVD-CWE-Other
|
CVE-2021-21264
|
2024-11-21 14:47 |
2021-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197077
|
8.8 |
HIGH
Network
|
google fedoraproject debian
|
chrome fedora debian_linux
|
Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-21233
|
2024-11-21 14:47 |
2021-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197078
|
8.8 |
HIGH
Network
|
google fedoraproject debian
|
chrome fedora debian_linux
|
Use after free in Dev Tools in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-416
Use After Free
|
CVE-2021-21232
|
2024-11-21 14:47 |
2021-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197079
|
8.8 |
HIGH
Network
|
google debian fedoraproject
|
chrome debian_linux fedora
|
Insufficient data validation in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-21231
|
2024-11-21 14:47 |
2021-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197080
|
8.8 |
HIGH
Network
|
google fedoraproject debian
|
chrome fedora debian_linux
|
Type confusion in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-843
Type Confusion
|
CVE-2021-21230
|
2024-11-21 14:47 |
2021-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|