|
195041
|
7.5 |
HIGH
Network
|
ge
|
multilin_b30_firmware multilin_b90_firmware multilin_c60_firmware multilin_c70_firmware multilin_c95_firmware multilin_d30_firmware multilin_d60_firmware multilin_f35_firmware
|
GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2021-27422
|
2024-11-21 14:57 |
2022-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195042
|
5.3 |
MEDIUM
Network
|
ge
|
multilin_b30_firmware multilin_b90_firmware multilin_c60_firmware multilin_c70_firmware multilin_c95_firmware multilin_d30_firmware multilin_d60_firmware multilin_f35_firmware
|
GE UR firmware versions prior to version 8.1x web server task does not properly handle receipt of unsupported HTTP verbs, resulting in the web server becoming temporarily unresponsive after receiving…
|
CWE-20
Improper Input Validation
|
CVE-2021-27420
|
2024-11-21 14:57 |
2022-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195043
|
6.1 |
MEDIUM
Network
|
ge
|
multilin_b30_firmware multilin_b90_firmware multilin_c60_firmware multilin_c70_firmware multilin_c95_firmware multilin_d30_firmware multilin_d60_firmware multilin_f35_firmware
|
GE UR firmware versions prior to version 8.1x supports web interface with read-only access. The device fails to properly validate user input, making it possible to perform cross-site scripting attack…
|
CWE-79
Cross-site Scripting
|
CVE-2021-27418
|
2024-11-21 14:57 |
2022-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195044
|
5.4 |
MEDIUM
Network
|
hitachienergy
|
ellipse_enterprise_asset_management
|
An attacker could exploit this vulnerability in Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25 by tricking a user to click on a link containi…
|
CWE-79
Cross-site Scripting
|
CVE-2021-27416
|
2024-11-21 14:57 |
2022-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195045
|
6.1 |
MEDIUM
Network
|
hitachienergy
|
ellipse_enterprise_asset_management
|
An attacker could trick a user of Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25 into visiting a malicious website posing as a login page for…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2021-27414
|
2024-11-21 14:57 |
2022-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195046
|
7.8 |
HIGH
Local
|
htmldoc_project
|
htmldoc
|
Null pointer dereference in the htmldoc v1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service via a crafted html file.
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-26948
|
2024-11-21 14:57 |
2022-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195047
|
9.8 |
CRITICAL
Network
|
netapp
|
virtual_desktop_service
|
NetApp Virtual Desktop Service (VDS) when used with an HTML5 gateway is susceptible to a vulnerability which when successfully exploited could allow an unauthenticated attacker to takeover a Remote D…
|
NVD-CWE-noinfo
|
CVE-2021-27007
|
2024-11-21 14:57 |
2021-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195048
|
4.4 |
MEDIUM
Local
|
netapp
|
storagegrid
|
StorageGRID (formerly StorageGRID Webscale) versions 11.5 prior to 11.5.0.5 are susceptible to a vulnerability which may allow an administrative user to escalate their privileges and modify settings …
|
NVD-CWE-noinfo
|
CVE-2021-27006
|
2024-11-21 14:57 |
2021-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195049
|
4.4 |
MEDIUM
Local
|
puppet
|
puppet puppet_connect puppet_enterprise
|
A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2021-27026
|
2024-11-21 14:57 |
2021-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195050
|
6.5 |
MEDIUM
Network
|
puppet fedoraproject
|
puppet_agent puppet puppet_enterprise fedora
|
A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.
|
NVD-CWE-noinfo
|
CVE-2021-27025
|
2024-11-21 14:57 |
2021-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|