|
196021
|
8.4 |
HIGH
Local
|
qualcomm
|
aqt1000_firmware ar8035_firmware csrb31024_firmware qca6174a_firmware qca6390_firmware qca6391_firmware qca6420_firmware qca6421_firmware qca6426_firmware qca6430_firmware<…
|
Possible integer overflow due to improper length check while updating grace period and count record in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdra…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2021-1913
|
2024-11-21 14:45 |
2021-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196022
|
8.8 |
HIGH
Network
|
zohocorp
|
manageengine_admanager_plus
|
ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the Personalization interface.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-20131
|
2024-11-21 14:45 |
2021-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196023
|
8.8 |
HIGH
Network
|
zohocorp
|
manageengine_admanager_plus
|
ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the PasswordExpiry interface.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-20130
|
2024-11-21 14:45 |
2021-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196024
|
7.5 |
HIGH
Network
|
draytek
|
vigorconnect
|
An information disclosure vulnerability exists in Draytek VigorConnect 1.6.0-B3, allowing an unauthenticated attacker to export system logs.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2021-20129
|
2024-11-21 14:45 |
2021-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196025
|
5.4 |
MEDIUM
Network
|
draytek
|
vigorconnect
|
The Profile Name field in the floor plan (Network Menu) page in Draytek VigorConnect 1.6.0-B3 was found to be vulnerable to stored XSS, as user input is not properly sanitized.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20128
|
2024-11-21 14:45 |
2021-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196026
|
8.1 |
HIGH
Network
|
draytek
|
vigorconnect
|
An arbitrary file deletion vulnerability exists in the file delete functionality of the Html5Servlet endpoint of Draytek VigorConnect 1.6.0-B3. This allows an authenticated user to arbitrarily delete…
|
NVD-CWE-noinfo
|
CVE-2021-20127
|
2024-11-21 14:45 |
2021-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196027
|
8.8 |
HIGH
Network
|
draytek
|
vigorconnect
|
Draytek VigorConnect 1.6.0-B3 lacks cross-site request forgery protections and does not sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who…
|
CWE-352
Origin Validation Error
|
CVE-2021-20126
|
2024-11-21 14:45 |
2021-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196028
|
9.8 |
CRITICAL
Network
|
draytek
|
vigorconnect
|
An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek VigorConnect 1.6.0-B3. An unauthenticated attacker could lever…
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2021-20125
|
2024-11-21 14:45 |
2021-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196029
|
7.5 |
HIGH
Network
|
draytek
|
vigorconnect
|
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerabili…
|
CWE-22
Path Traversal
|
CVE-2021-20124
|
2024-11-21 14:45 |
2021-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196030
|
7.5 |
HIGH
Network
|
draytek
|
vigorconnect
|
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vu…
|
CWE-22
Path Traversal
|
CVE-2021-20123
|
2024-11-21 14:45 |
2021-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|