|
196331
|
8.8 |
HIGH
Network
|
fortinet
|
fortiweb
|
An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x, 5.9.x may allow a remote authenticated attacker to execute arbitrary commands …
|
CWE-78
OS Command
|
CVE-2021-22123
|
2024-11-21 14:49 |
2021-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196332
|
7.8 |
HIGH
Local
|
vmware oracle netapp
|
spring_framework retail_order_broker retail_predictive_application_server enterprise_data_quality retail_assortment_planning retail_financial_integration communications_network_inte…
|
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, …
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2021-22118
|
2024-11-21 14:49 |
2021-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196333
|
5.5 |
MEDIUM
Local
|
huawei
|
mate_30_firmware mate_30_5g_firmware
|
There is a denial of service vulnerability in the versions 10.1.0.126(C00E125R5P3) of HUAWEI Mate 30 and 10.1.0.152(C00E136R7P2) of HUAWEI Mate 30 (5G) . A module does not verify certain parameters s…
|
NVD-CWE-noinfo
|
CVE-2021-22364
|
2024-11-21 14:49 |
2021-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196334
|
5.3 |
MEDIUM
Network
|
huawei
|
cloudengine_12800_firmware cloudengine_5800_firmware cloudengine_6800_firmware cloudengine_7800_firmware
|
There is an out of bounds write vulnerability in some Huawei products. An attacker can exploit this vulnerability by sending crafted data in the packet to the target device. Due to insufficient valid…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-22362
|
2024-11-21 14:49 |
2021-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196335
|
4.9 |
MEDIUM
Network
|
huawei
|
usg9500_firmware
|
There is a resource management error vulnerability in the verisions V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200 of USG9500. An authentication attacker needs to perform specific operations…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2021-22360
|
2024-11-21 14:49 |
2021-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196336
|
7.5 |
HIGH
Network
|
huawei
|
s5700_firmware s6700_firmware
|
There is a denial of service vulnerability in the verisions V200R005C00SPC500 of S5700 and V200R005C00SPC500 of S6700. An attacker could exploit this vulnerability by sending specific message to a ta…
|
CWE-20
Improper Input Validation
|
CVE-2021-22359
|
2024-11-21 14:49 |
2021-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196337
|
4.3 |
MEDIUM
Network
|
huawei
|
fusioncompute
|
There is an insufficient input validation vulnerability in FusionCompute 8.0.0. Due to the input validation is insufficient, an attacker can exploit this vulnerability to upload any files to the devi…
|
CWE-20
Improper Input Validation
|
CVE-2021-22358
|
2024-11-21 14:49 |
2021-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196338
|
9.8 |
CRITICAL
Network
|
vmware
|
vcenter_server cloud_foundation
|
The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Lifecycle Manager, and VMware Cloud Director Availab…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-21986
|
2024-11-21 14:49 |
2021-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196339
|
9.8 |
CRITICAL
Network
|
vmware
|
vcenter_server cloud_foundation
|
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A mali…
|
CWE-20
Improper Input Validation
|
CVE-2021-21985
|
2024-11-21 14:49 |
2021-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196340
|
9.8 |
CRITICAL
Network
|
apache
|
pulsar
|
If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if the algorithm of the presented token is set to "none…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2021-22160
|
2024-11-21 14:49 |
2021-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|