|
195721
|
10.0 |
CRITICAL
Network
|
anker
|
eufy_homebase_2_firmware
|
An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h in function recv_server_device_respon…
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2021-21950
|
2024-11-21 14:49 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195722
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encrypted content
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2021-22170
|
2024-11-21 14:49 |
2021-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195723
|
6.5 |
MEDIUM
Network
|
vmware
|
spring_advanced_message_queuing_protocol
|
In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object from the message body, regardless of its size. Thi…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-22095
|
2024-11-21 14:49 |
2021-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195724
|
9.8 |
CRITICAL
Network
|
vmware
|
vcenter_server
|
The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A malicious actor with network access to port 443 on vCenter…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-22049
|
2024-11-21 14:49 |
2021-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195725
|
7.5 |
HIGH
Network
|
vmware
|
vcenter_server cloud_foundation
|
The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain acce…
|
NVD-CWE-noinfo
|
CVE-2021-21980
|
2024-11-21 14:49 |
2021-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195726
|
5.9 |
MEDIUM
Network
|
huawei
|
ips_module_firmware ngfw_module_firmware secospace_usg6300_firmware secospace_usg6500_firmware secospace_usg6600_firmware usg9500_firmware
|
There is a weak secure algorithm vulnerability in Huawei products. A weak secure algorithm is used in a module. Attackers can exploit this vulnerability by capturing and analyzing the messages betwee…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2021-22356
|
2024-11-21 14:49 |
2021-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195727
|
8.8 |
HIGH
Network
|
librecad debian fedoraproject
|
libdxfrw debian_linux fedora
|
A code execution vulnerability exists in the dwgCompressor::decompress18() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to an out-of-bounds write.…
|
-
|
CVE-2021-21898
|
2024-11-21 14:49 |
2021-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195728
|
8.8 |
HIGH
Network
|
librecad debian fedoraproject
|
libdxfrw debian_linux fedora
|
A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dxf file can lead to a use-after-free vulnerability.…
|
-
|
CVE-2021-21900
|
2024-11-21 14:49 |
2021-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195729
|
8.8 |
HIGH
Network
|
librecad fedoraproject debian
|
libdxfrw fedora debian_linux
|
A code execution vulnerability exists in the dwgCompressor::copyCompBytes21 functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to a heap buffer overflow…
|
-
|
CVE-2021-21899
|
2024-11-21 14:49 |
2021-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195730
|
6.5 |
MEDIUM
Network
|
greenplum
|
greenplum
|
In versions of Greenplum database prior to 5.28.14 and 6.17.0, certain statements execution led to the storage of sensitive(credential) information in the logs of the database. A malicious user with …
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2021-22030
|
2024-11-21 14:49 |
2021-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|