|
193991
|
7.5 |
HIGH
Network
|
oracle
|
outside_in_technology
|
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). The supported version that is affected is 8.5.5. Easily exploitable vulnerabilit…
|
NVD-CWE-noinfo
|
CVE-2021-2451
|
2024-11-21 15:03 |
2021-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193992
|
7.5 |
HIGH
Network
|
oracle
|
outside_in_technology
|
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). The supported version that is affected is 8.5.5. Easily exploitable vulnerabilit…
|
NVD-CWE-noinfo
|
CVE-2021-2450
|
2024-11-21 15:03 |
2021-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193993
|
7.5 |
HIGH
Network
|
oracle
|
outside_in_technology
|
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). The supported version that is affected is 8.5.5. Easily exploitable vulnerabilit…
|
NVD-CWE-noinfo
|
CVE-2021-2449
|
2024-11-21 15:03 |
2021-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193994
|
3.7 |
LOW
Local
|
oracle
|
financial_services_crime_and_compliance_investigation_hub
|
Vulnerability in the Oracle Financial Services Crime and Compliance Investigation Hub product of Oracle Financial Services Applications (component: Reports). The supported version that is affected is…
|
NVD-CWE-noinfo
|
CVE-2021-2448
|
2024-11-21 15:03 |
2021-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193995
|
6.5 |
MEDIUM
Network
|
apache oracle
|
sshd retail_customer_management_and_segmentation_foundation flexcube_universal_banking middleware_common_libraries_and_tools communications_cloud_native_core_console banking_payments
|
A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD v…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2021-30129
|
2024-11-21 15:03 |
2021-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193996
|
7.5 |
HIGH
Network
|
kaseya
|
vsa
|
The API /vsaWS/KaseyaWS.asmx can be used to submit XML to the system. When this XML is processed (external) entities are insecurely processed and fetched by the system and returned to the attacker. D…
|
CWE-611
XXE
|
CVE-2021-30201
|
2024-11-21 15:03 |
2021-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193997
|
6.5 |
MEDIUM
Network
|
kaseya
|
vsa
|
Semi-authenticated local file inclusion The contents of arbitrary files can be returned by the webserver Example request: `https://x.x.x.x/KLC/js/Kaseya.SB.JS/js.aspx?path=C:\Kaseya\WebPages\dl.asp` …
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2021-30121
|
2024-11-21 15:03 |
2021-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193998
|
7.5 |
HIGH
Network
|
kaseya
|
vsa
|
Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. T…
|
CWE-669
Incorrect Resource Transfer Between Spheres
|
CVE-2021-30120
|
2024-11-21 15:03 |
2021-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193999
|
5.4 |
MEDIUM
Network
|
kaseya
|
vsa
|
Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested web page and can be used to perform a Cross Site S…
|
CWE-79
Cross-site Scripting
|
CVE-2021-30119
|
2024-11-21 15:03 |
2021-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194000
|
9.8 |
CRITICAL
Network
|
kaseya
|
vsa
|
An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring & Management (RMM) 9.5.4.2149 and subsequently use these files to execute asp comman…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-30118
|
2024-11-21 15:03 |
2021-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|