|
196381
|
6.5 |
MEDIUM
Network
|
dell
|
alienware_m15_r6_firmware chengming_3990_firmware chengming_3991_firmware g15_5510_firmware g15_5511_firmware g3_3500_firmware g5_5500_firmware g7_7500_firmware g7_7700_firmwa…
|
Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability. A remote unauthenticated attacker may explo…
|
CWE-295
Improper Certificate Validation
|
CVE-2021-21571
|
2024-11-21 14:48 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196382
|
7.5 |
HIGH
Network
|
zte
|
zxv10_b860h_v5.0_firmware
|
A smart STB product of ZTE is impacted by a permission and access control vulnerability. Due to insufficient protection of system application, attackers could use this vulnerability to tamper with th…
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-21737
|
2024-11-21 14:48 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196383
|
6.1 |
MEDIUM
Network
|
mongo-express_project
|
mongo-express
|
mongo-express is a web-based MongoDB admin interface, written with Node.js and express. 1: As mentioned in this issue: https://github.com/mongo-express/mongo-express/issues/577, when the content of a…
|
-
|
CVE-2021-21422
|
2024-11-21 14:48 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196384
|
9.1 |
CRITICAL
Network
|
contiki-ng
|
contiki-ng
|
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An out-of-bounds read can be triggered by 6LoWPAN packets sent to devices running Contiki-NG 4.6 and pri…
|
-
|
CVE-2021-21410
|
2024-11-21 14:48 |
2021-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196385
|
9.8 |
CRITICAL
Network
|
jenkins
|
generic_webhook_trigger
|
Jenkins Generic Webhook Trigger Plugin 1.72 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
-
|
CVE-2021-21669
|
2024-11-21 14:48 |
2021-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196386
|
10.0 |
CRITICAL
Network
|
opener_project
|
opener
|
An information disclosure vulnerability exists in the Ethernet/IP UDP handler functionality of EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A specially crafted network request can lead …
|
CWE-125
Out-of-bounds Read
|
CVE-2021-21777
|
2024-11-21 14:48 |
2021-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196387
|
5.4 |
MEDIUM
Network
|
jenkins
|
scriptler
|
Jenkins Scriptler Plugin 3.1 and earlier does not escape script content, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Scriptler/Configure permission.
|
CWE-79
Cross-site Scripting
|
CVE-2021-21668
|
2024-11-21 14:48 |
2021-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196388
|
5.4 |
MEDIUM
Network
|
jenkins
|
scriptler
|
Jenkins Scriptler Plugin 3.2 and earlier does not escape parameter names shown in job configuration forms, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with…
|
CWE-79
Cross-site Scripting
|
CVE-2021-21667
|
2024-11-21 14:48 |
2021-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196389
|
7.5 |
HIGH
Network
|
otrs
|
otrs
|
There is a XSS vulnerability in the ticket overview screens. It's possible to collect various information by having an e-mail shown in the overview screen. Attack can be performed by sending speciall…
|
CWE-79
Cross-site Scripting
|
CVE-2021-21441
|
2024-11-21 14:48 |
2021-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196390
|
6.7 |
MEDIUM
Local
|
dell
|
poweredge_r640_firmware poweredge_r740_firmware poweredge_r740xd_firmware poweredge_r940_firmware poweredge_r540_firmware poweredge_r440_firmware poweredge_t440_firmware poweredg…
|
Dell PowerEdge Server BIOS and select Dell Precision Rack BIOS contain an out-of-bounds array access vulnerability. A local malicious user with high privileges may potentially exploit this vulnerabil…
|
CWE-125
Out-of-bounds Read
|
CVE-2021-21557
|
2024-11-21 14:48 |
2021-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|