|
194041
|
9.8 |
CRITICAL
Network
|
globalnorthstar
|
northstar_club_management
|
Systemic Insecure Permissions in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to use various functionalities without authentication.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2021-29396
|
2024-11-21 15:01 |
2022-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194042
|
7.5 |
HIGH
Network
|
globalnorthstar
|
northstar_club_management
|
Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to download arbitrary files, including JSP so…
|
CWE-22
Path Traversal
|
CVE-2021-29395
|
2024-11-21 15:01 |
2022-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194043
|
6.5 |
MEDIUM
Network
|
globalnorthstar
|
northstar_club_management
|
Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote authenticated users to change the password of any targeted user acco…
|
CWE-863
Incorrect Authorization
|
CVE-2021-29394
|
2024-11-21 15:01 |
2022-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194044
|
9.8 |
CRITICAL
Network
|
globalnorthstar
|
northstar_club_management
|
Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to inject and execute arbitrary system commands…
|
CWE-78
OS Command
|
CVE-2021-29393
|
2024-11-21 15:01 |
2022-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194045
|
2.7 |
LOW
Network
|
ibm
|
security_guardium_insights
|
IBM Security Guardium Insights 3.0 could allow an authenticated user to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 205256.
|
CWE-613
Insufficient Session Expiration
|
CVE-2021-29846
|
2024-11-21 15:01 |
2022-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194046
|
8.8 |
HIGH
Network
|
ibm
|
security_guardium_insights
|
IBM Security Guardium Insights 3.0 could allow an authenticated user to perform unauthorized actions due to improper input validation. IBM X-Force ID: 205255.
|
CWE-20
Improper Input Validation
|
CVE-2021-29845
|
2024-11-21 15:01 |
2022-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194047
|
5.9 |
MEDIUM
Network
|
ibm
|
security_guardium_insights
|
IBM Security Guardium Insights 3.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit th…
|
CWE-200
Information Exposure
|
CVE-2021-29838
|
2024-11-21 15:01 |
2022-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194048
|
5.9 |
MEDIUM
Network
|
ibm
|
soar
|
IBM Security SOAR V42 and V43could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vul…
|
NVD-CWE-noinfo
|
CVE-2021-29785
|
2024-11-21 15:01 |
2022-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194049
|
7.5 |
HIGH
Network
|
freebsd
|
freebsd
|
In FreeBSD 13.0-STABLE before n247428-9352de39c3dc, 12.2-STABLE before r370674, 13.0-RELEASE before p6, and 12.2-RELEASE before p12, certain conditions involving use of the highlight buffer while tex…
|
NVD-CWE-noinfo
|
CVE-2021-29632
|
2024-11-21 15:01 |
2022-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194050
|
5.4 |
MEDIUM
Network
|
ibm
|
cloud_pak_for_automation
|
IBM Cloud Pak for Automation 21.0.1 and 21.0.2 - Business Automation Studio Component is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a …
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2021-29872
|
2024-11-21 15:01 |
2022-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|