|
194401
|
9.8 |
CRITICAL
Network
|
servicetonic
|
servicetonic
|
Unauthorized system access in the login form in ServiceTonic Helpdesk software version < 9.0.35937 allows attacker to login without using a password.
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2021-28024
|
2024-11-21 14:58 |
2021-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194402
|
9.8 |
CRITICAL
Network
|
servicetonic
|
servicetonic
|
Arbitrary file upload in Service import feature in ServiceTonic Helpdesk software version < 9.0.35937 allows a malicious user to execute JSP code by uploading a zip that extracts files in relative pa…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-28023
|
2024-11-21 14:58 |
2021-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194403
|
7.5 |
HIGH
Network
|
servicetonic
|
servicetonic
|
Blind SQL injection in the login form in ServiceTonic Helpdesk software < 9.0.35937 allows attacker to exfiltrate information via specially crafted HQL-compatible time-based SQL queries.
|
CWE-89
SQL Injection
|
CVE-2021-28022
|
2024-11-21 14:58 |
2021-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194404
|
6.5 |
MEDIUM
Network
|
libxls_project fedoraproject
|
libxls fedora
|
An issue was discoverered in in function xls_getWorkSheet in xls.c in libxls 1.6.2, allows attackers to cause a denial of service, via a crafted XLS file.
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-27836
|
2024-11-21 14:58 |
2021-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194405
|
7.5 |
HIGH
Network
|
nsasoft
|
spotauditor
|
An issue was discovered in Nsasoft US LLC SpotAuditor 5.3.5. The program can be crashed by entering 300 bytes char data into the "Key" or "Name" field while registering.
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-27722
|
2024-11-21 14:58 |
2021-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194406
|
8.8 |
HIGH
Network
|
apache
|
dolphinscheduler
|
In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data source with internal login account password)
|
CWE-89
SQL Injection
|
CVE-2021-27644
|
2024-11-21 14:58 |
2021-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194407
|
5.4 |
MEDIUM
Network
|
hcltechsw
|
connections
|
"HCL Connections Security Update for Reflected Cross-Site Scripting (XSS) Vulnerability"
|
CWE-79
Cross-site Scripting
|
CVE-2021-27746
|
2024-11-21 14:58 |
2021-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194408
|
7.8 |
HIGH
Local
|
stb_project fedoraproject debian
|
stb fedora debian_linux
|
Buffer overflow vulnerability in function stbi__extend_receive in stb_image.h in stb 2.26 via a crafted JPEG file.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-28021
|
2024-11-21 14:58 |
2021-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194409
|
7.5 |
HIGH
Network
|
johnsoncontrols
|
exacqvision_server
|
An unauthenticated remote user could exploit a potential integer overflow condition in the exacqVision Server with a specially crafted script and cause denial-of-service condition.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2021-27665
|
2024-11-21 14:58 |
2021-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194410
|
9.8 |
CRITICAL
Network
|
johnsoncontrols
|
exacqvision_web_service
|
Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVision Server.
|
CWE-269
Improper Privilege Management
|
CVE-2021-27664
|
2024-11-21 14:58 |
2021-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|