|
194161
|
9.8 |
CRITICAL
Network
|
qnap
|
hybrid_backup_sync
|
An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attackers to compromise the security of the operating sy…
|
-
|
CVE-2021-28809
|
2024-11-21 15:00 |
2021-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194162
|
8.8 |
HIGH
Network
|
fork-cms
|
fork_cms
|
Arbitrary file upload vulnerability in Fork CMS 5.9.2 allows attackers to create or replace arbitrary files in the /themes directory via a crafted zip file uploaded to the Themes panel.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-28931
|
2024-11-21 15:00 |
2021-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194163
|
9.8 |
CRITICAL
Network
|
qnap
|
quts_hero qts
|
A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This …
|
-
|
CVE-2021-28804
|
2024-11-21 15:00 |
2021-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194164
|
5.4 |
MEDIUM
Network
|
qnap
|
q\'center
|
This issue affects: QNAP Systems Inc. Q'center versions prior to 1.11.1004.
|
CWE-79
Cross-site Scripting
|
CVE-2021-28803
|
2024-11-21 15:00 |
2021-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194165
|
9.8 |
CRITICAL
Network
|
qnap
|
quts_hero qts
|
A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This …
|
-
|
CVE-2021-28802
|
2024-11-21 15:00 |
2021-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194166
|
7.5 |
HIGH
Network
|
plixer
|
scrutinizer
|
Plixer Scrutinizer 19.0.2 is affected by: SQL Injection. The impact is: obtain sensitive information (remote).
|
CWE-89
SQL Injection
|
CVE-2021-28993
|
2024-11-21 15:00 |
2021-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194167
|
5.5 |
MEDIUM
Local
|
xen
|
xen
|
xen/arm: Boot modules are not scrubbed The bootloader will load boot modules (e.g. kernel, initramfs...) in a temporary area before they are copied by Xen to each domain memory. To ensure sensitive d…
|
NVD-CWE-noinfo
|
CVE-2021-28693
|
2024-11-21 15:00 |
2021-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194168
|
7.1 |
HIGH
Local
|
xen
|
xen
|
inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such commands. In the current implementation in Xen, a…
|
CWE-269
Improper Privilege Management
|
CVE-2021-28692
|
2024-11-21 15:00 |
2021-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194169
|
7.8 |
HIGH
Local
|
tibco
|
spotfire_server spotfire_statistics_services spotfire_analytics_platform enterprise_runtime_for_r
|
The TIBCO Spotfire Server and TIBCO Enterprise Runtime for R components of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBC…
|
NVD-CWE-noinfo
|
CVE-2021-28830
|
2024-11-21 15:00 |
2021-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194170
|
6.5 |
MEDIUM
Network
|
xen
|
xen
|
x86: TSX Async Abort protections not restored after S3 This issue relates to the TSX Async Abort speculative security vulnerability. Please see https://xenbits.xen.org/xsa/advisory-305.html for detai…
|
NVD-CWE-noinfo
|
CVE-2021-28690
|
2024-11-21 15:00 |
2021-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|