|
195891
|
7.5 |
HIGH
Network
|
nodejs fedoraproject netapp oracle siemens
|
node.js fedora snapcenter oncommand_workflow_automation oncommand_insight active_iq_unified_manager e-series_performance_analyzer peoplesoft_enterprise_peopletools graalvm …
|
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordi…
|
NVD-CWE-Other
|
CVE-2021-22884
|
2024-11-21 14:50 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195892
|
7.5 |
HIGH
Network
|
nodejs fedoraproject netapp oracle siemens
|
node.js fedora e-series_performance_analyzer peoplesoft_enterprise_peopletools graalvm nosql_database mysql_cluster jd_edwards_enterpriseone_tools sinec_infrastructure_network…
|
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of …
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2021-22883
|
2024-11-21 14:50 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195893
|
9.8 |
CRITICAL
Network
|
rockwellautomation
|
factorytalk_services_platform rslogix_5000 studio_5000_logix_designer
|
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactL…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2021-22681
|
2024-11-21 14:50 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195894
|
7.8 |
HIGH
Local
|
fatek
|
fvdesigner
|
Fatek FvDesigner Version 1.5.76 and prior is vulnerable to an out-of-bounds write while processing project files, allowing an attacker to craft a special project file that may permit arbitrary code e…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-22683
|
2024-11-21 14:50 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195895
|
7.8 |
HIGH
Local
|
fatek
|
fvdesigner
|
An uninitialized pointer may be exploited in Fatek FvDesigner Version 1.5.76 and prior while the application is processing project files, allowing an attacker to craft a special project file that may…
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2021-22670
|
2024-11-21 14:50 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195896
|
7.8 |
HIGH
Local
|
fatek
|
fvdesigner
|
Fatek FvDesigner Version 1.5.76 and prior is vulnerable to a stack-based buffer overflow while project files are being processed, allowing an attacker to craft a special project file that may permit …
|
CWE-787
Out-of-bounds Write
|
CVE-2021-22666
|
2024-11-21 14:50 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195897
|
7.8 |
HIGH
Local
|
fatek
|
fvdesigner
|
A use after free issue has been identified in Fatek FvDesigner Version 1.5.76 and prior in the way the application processes project files, allowing an attacker to craft a special project file that m…
|
CWE-416
Use After Free
|
CVE-2021-22662
|
2024-11-21 14:50 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195898
|
7.8 |
HIGH
Local
|
fatek
|
fvdesigner
|
Fatek FvDesigner Version 1.5.76 and prior is vulnerable to an out-of-bounds read while processing project files, allowing an attacker to craft a special project file that may permit arbitrary code ex…
|
CWE-125
Out-of-bounds Read
|
CVE-2021-22638
|
2024-11-21 14:50 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195899
|
8.1 |
HIGH
Network
|
github
|
github
|
An improper access control vulnerability was identified in the GitHub Enterprise Server GraphQL API that allowed authenticated users of the instance to modify the maintainer collaboration permission …
|
NVD-CWE-Other
|
CVE-2021-22863
|
2024-11-21 14:50 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195900
|
6.5 |
MEDIUM
Network
|
github
|
github
|
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with the ability to fork a repository to disclose Actions secrets for the parent…
|
NVD-CWE-Other
|
CVE-2021-22862
|
2024-11-21 14:50 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|