|
194021
|
8.8 |
HIGH
Network
|
cuppacms
|
cuppacms
|
Session fixation vulnerability in CuppaCMS thru commit 4c9b742b23b924cf4c1f943f48b278e06a17e297 on November 12, 2019 allows attackers to gain access to arbitrary user sessions.
|
CWE-384
Session Fixation
|
CVE-2021-29368
|
2024-11-21 15:01 |
2023-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194022
|
6.5 |
MEDIUM
Network
|
ibm netapp
|
cognos_analytics oncommand_insight
|
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that th…
|
CWE-352
Origin Validation Error
|
CVE-2021-29823
|
2024-11-21 15:01 |
2022-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194023
|
6.1 |
MEDIUM
Network
|
ibm
|
security_identity_manager
|
IBM Security Identity Manager 6.0 and 6.0.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a r…
|
CWE-601
Open Redirect
|
CVE-2021-29864
|
2024-11-21 15:01 |
2022-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194024
|
4.9 |
MEDIUM
Network
|
ibm
|
power_system_ac922_\(8335-gtg\)_firmware power_system_ac922_\(8335-gtx\)_firmware power_system_ac922_\(8335-gth\)_firmware hardware_management_console_7063-cr2_firmware
|
IBM OPENBMC OP910 and OP940 could allow a privileged user to upload an improper site identity certificate that may cause it to lose network services. IBM X-Force ID: 207221.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-29891
|
2024-11-21 15:01 |
2022-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194025
|
7.5 |
HIGH
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar SIEM 7.3, 7.4, and 7.5 does not preform proper certificate validation for some inter-host communications. IBM X-Force ID: 202015.
|
CWE-295
Improper Certificate Validation
|
CVE-2021-29755
|
2024-11-21 15:01 |
2022-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194026
|
6.5 |
MEDIUM
Network
|
ibm
|
engineering_requirements_quality_assistant_on-premises
|
IBM Engineering Requirements Quality Assistant On-Premises (All versions) could allow an authenticated user to obtain sensitive information due to improper client side validation. IBM X-Force ID: 203…
|
NVD-CWE-Other
|
CVE-2021-29799
|
2024-11-21 15:01 |
2022-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194027
|
5.4 |
MEDIUM
Network
|
ibm
|
engineering_requirements_quality_assistant_on-premises
|
IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …
|
CWE-79
Cross-site Scripting
|
CVE-2021-29790
|
2024-11-21 15:01 |
2022-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194028
|
5.4 |
MEDIUM
Network
|
ibm
|
engineering_requirements_quality_assistant_on-premises
|
IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …
|
CWE-79
Cross-site Scripting
|
CVE-2021-29788
|
2024-11-21 15:01 |
2022-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194029
|
5.4 |
MEDIUM
Network
|
ibm
|
jazz_team_server
|
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote at…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2021-29865
|
2024-11-21 15:01 |
2022-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194030
|
6.5 |
MEDIUM
Network
|
ibm netapp
|
cognos_analytics oncommand_insight
|
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a low level user to obtain sensitive information from the details of the 'Cloud Storage' page for which they should not have access. IBM X-…
|
NVD-CWE-noinfo
|
CVE-2021-29768
|
2024-11-21 15:01 |
2022-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|