|
195911
|
7.5 |
HIGH
Network
|
schneider-electric
|
powerlogic_ion7400_firmware powerlogic_ion7650_firmware powerlogic_ion7700_firmware powerlogic_ion7300_firmware powerlogic_ion8600_firmware powerlogic_ion8650_firmware powerlogic_io…
|
A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION7700/73xx, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notifica…
|
-
|
CVE-2021-22702
|
2024-11-21 14:50 |
2021-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195912
|
4.5 |
MEDIUM
Network
|
schneider-electric
|
powerlogic_ion7400_firmware powerlogic_ion7650_firmware powerlogic_ion8600_firmware powerlogic_ion8650_firmware powerlogic_ion8800_firmware powerlogic_ion9000_firmware powerlogic_pm…
|
A CWE-352: Cross-Site Request Forgery vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that c…
|
-
|
CVE-2021-22701
|
2024-11-21 14:50 |
2021-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195913
|
9.8 |
CRITICAL
Network
|
hr_portal_project
|
hr_portal
|
The specific function of HR Portal of Soar Cloud System accepts any type of object to be deserialized. Attackers can send malicious serialized objects to execute arbitrary commands.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-22855
|
2024-11-21 14:50 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195914
|
7.5 |
HIGH
Network
|
hr_portal_project
|
hr_portal
|
The HR Portal of Soar Cloud System fails to filter specific parameters. Remote attackers can inject SQL syntax and obtain all data in the database without privilege.
|
CWE-89
SQL Injection
|
CVE-2021-22854
|
2024-11-21 14:50 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195915
|
5.4 |
MEDIUM
Network
|
hr_portal_project
|
hr_portal
|
The HR Portal of Soar Cloud System fails to manage access control. While obtaining user ID, remote attackers can access sensitive data via a specific data packet, such as user’s login information, fu…
|
NVD-CWE-Other
|
CVE-2021-22853
|
2024-11-21 14:50 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195916
|
7.5 |
HIGH
Network
|
google
|
gerrit
|
Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not automatically dispose of the session. Over multiple git actions, this can lead …
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2021-22553
|
2024-11-21 14:50 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195917
|
8.8 |
HIGH
Network
|
changjia_property_management_system_project
|
changjia_property_management_system
|
Attackers can access the CGE account management function without privilege for permission elevation and execute arbitrary commands or files after obtaining user permissions.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-22858
|
2024-11-21 14:50 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195918
|
7.5 |
HIGH
Network
|
changjia_property_management_system_project
|
changjia_property_management_system
|
The CGE page with download function contains a Directory Traversal vulnerability. Attackers can use this loophole to download system files arbitrarily.
|
CWE-22
Path Traversal
|
CVE-2021-22857
|
2024-11-21 14:50 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195919
|
7.5 |
HIGH
Network
|
changjia_property_management_system_project
|
changjia_property_management_system
|
The CGE property management system contains SQL Injection vulnerabilities. Remote attackers can inject SQL commands into the parameters in Cookie and obtain data in the database without privilege.
|
CWE-89
SQL Injection
|
CVE-2021-22856
|
2024-11-21 14:50 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195920
|
9.8 |
CRITICAL
Network
|
microfocus
|
operations_bridge_manager
|
Arbitrary code execution vulnerability on Micro Focus Operations Bridge Manager product, affecting versions 10.1x, 10.6x, 2018.05, 2018.11, 2019.05, 2019.11, 2020.05, 2020.10. The vulnerability could…
|
NVD-CWE-noinfo
|
CVE-2021-22504
|
2024-11-21 14:50 |
2021-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|