|
195391
|
9.8 |
CRITICAL
Network
|
nodejs netapp siemens debian
|
node.js nextgen_api sinec_infrastructure_network_services debian_linux
|
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.
|
CWE-416
Use After Free
|
CVE-2021-22930
|
2024-11-21 14:50 |
2021-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195392
|
7.8 |
HIGH
Local
|
google
|
slo_generator
|
SLO generator allows for loading of YAML files that if crafted in a specific format can allow for code execution within the context of the SLO Generator. We recommend upgrading SLO Generator past htt…
|
CWE-78
OS Command
|
CVE-2021-22557
|
2024-11-21 14:50 |
2021-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195393
|
5.9 |
MEDIUM
Network
|
haxx fedoraproject debian netapp oracle siemens apple splunk
|
curl fedora debian_linux cloud_backup clustered_data_ontap h300s_firmware h500s_firmware h700s_firmware h300e_firmware h500e_firmware h700e_firmware h410s_firmware
|
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that c…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2021-22947
|
2024-11-21 14:50 |
2021-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195394
|
7.5 |
HIGH
Network
|
haxx debian fedoraproject netapp oracle apple siemens splunk
|
curl debian_linux fedora cloud_backup snapcenter oncommand_workflow_automation oncommand_insight clustered_data_ontap h300s_firmware h500s_firmware h700s_firmware h30…
|
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSES…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2021-22946
|
2024-11-21 14:50 |
2021-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195395
|
4.9 |
MEDIUM
Network
|
microfocus
|
netiq_directory_and_resource_administrator
|
Unauthorized information security disclosure vulnerability on Micro Focus Directory and Resource Administrator (DRA) product, affecting all DRA versions prior to 10.1 Patch 1. The vulnerability could…
|
CWE-863
Incorrect Authorization
|
CVE-2021-22535
|
2024-11-21 14:50 |
2021-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195396
|
9.8 |
CRITICAL
Network
|
github
|
enterprise_server
|
An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted runner group it should not have had access to. This affects customers using sel…
|
CWE-287
Improper Authentication
|
CVE-2021-22869
|
2024-11-21 14:50 |
2021-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195397
|
4.3 |
MEDIUM
Network
|
github
|
enterprise_server
|
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were no…
|
CWE-22
Path Traversal
|
CVE-2021-22868
|
2024-11-21 14:50 |
2021-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195398
|
9.1 |
CRITICAL
Network
|
haxx fedoraproject netapp oracle apple siemens debian splunk
|
libcurl fedora cloud_backup clustered_data_ontap mysql_server h300s_firmware h500s_firmware h700s_firmware h300e_firmware h500e_firmware h700e_firmware h410s_firmware…
|
When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call t…
|
CWE-415
Double Free
|
CVE-2021-22945
|
2024-11-21 14:50 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195399
|
9.8 |
CRITICAL
Network
|
citrix
|
sharefile_storagezones_controller
|
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.
|
NVD-CWE-Other
|
CVE-2021-22941
|
2024-11-21 14:50 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195400
|
5.4 |
MEDIUM
Network
|
microfocus
|
access_manager
|
Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4
|
CWE-79
Cross-site Scripting
|
CVE-2021-22528
|
2024-11-21 14:50 |
2021-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|