|
196001
|
10.0 |
CRITICAL
Network
|
sealevel
|
seaconnect_370w_firmware
|
A stack-based buffer overflow vulnerability exists in the NBNS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted network packet can lead to remote code execution. A…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-21961
|
2024-11-21 14:49 |
2022-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196002
|
10.0 |
CRITICAL
Network
|
sealevel
|
seaconnect_370w_firmware
|
A stack-based buffer overflow vulnerability exists in both the LLMNR functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted network packet can lead to remote code execut…
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2021-21960
|
2024-11-21 14:49 |
2022-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196003
|
8.1 |
HIGH
Network
|
sealevel
|
seaconnect_370w_firmware
|
A misconfiguration exists in the MQTTS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. This misconfiguration significantly simplifies a man-in-the-middle attack, which directly leads…
|
CWE-295
Improper Certificate Validation
|
CVE-2021-21959
|
2024-11-21 14:49 |
2022-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196004
|
4.3 |
MEDIUM
Network
|
vmware oracle
|
spring_framework communications_cloud_native_core_console communications_cloud_native_core_service_communication_proxy
|
In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. Thi…
|
NVD-CWE-noinfo
|
CVE-2021-22060
|
2024-11-21 14:49 |
2022-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196005
|
7.8 |
HIGH
Local
|
vmware
|
cloud_foundation workstation fusion esxi
|
VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerability in CD-ROM device …
|
CWE-787
Out-of-bounds Write
|
CVE-2021-22045
|
2024-11-21 14:49 |
2022-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196006
|
8.1 |
HIGH
Network
|
anker
|
eufy_homebase_2_firmware
|
An authentication bypass vulnerability exists in the process_msg() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted man-in-the-middle attack can lead to inc…
|
NVD-CWE-Other
|
CVE-2021-21953
|
2024-11-21 14:49 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196007
|
9.8 |
CRITICAL
Network
|
anker
|
eufy_homebase_2_firmware
|
An authentication bypass vulnerability exists in the CMD_DEVICE_GET_RSA_KEY_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network pac…
|
CWE-287
Improper Authentication
|
CVE-2021-21952
|
2024-11-21 14:49 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196008
|
6.5 |
MEDIUM
Network
|
advantech
|
r-seenet
|
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘host_alt_filter’ parameter. This can be done as any auth…
|
CWE-89
SQL Injection
|
CVE-2021-21937
|
2024-11-21 14:49 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196009
|
8.8 |
HIGH
Network
|
advantech
|
r-seenet
|
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘health_alt_filter’ parameter. This can be done as any au…
|
CWE-89
SQL Injection
|
CVE-2021-21936
|
2024-11-21 14:49 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196010
|
6.5 |
MEDIUM
Network
|
advantech
|
r-seenet
|
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘host_alt_filter2’ parameter. This can be done as any aut…
|
CWE-89
SQL Injection
|
CVE-2021-21935
|
2024-11-21 14:49 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|