|
194171
|
7.8 |
HIGH
Local
|
linux netapp
|
linux_kernel cloud_backup h410c_firmware h300s_firmware h500s_firmware h700s_firmware h300e_firmware h500e_firmware h700e_firmware h410s_firmware
|
Guest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to disable the interface and terminate the receive kernel thread associated with q…
|
CWE-416
Use After Free
|
CVE-2021-28691
|
2024-11-21 15:00 |
2021-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194172
|
5.5 |
MEDIUM
Local
|
dovecot fedoraproject
|
dovecot fedora
|
Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled locatio…
|
CWE-22
Path Traversal
|
CVE-2021-29157
|
2024-11-21 15:00 |
2021-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194173
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_adselfservice_plus
|
Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.
|
CWE-78
OS Command
|
CVE-2021-28958
|
2024-11-21 15:00 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194174
|
9.8 |
CRITICAL
Network
|
qnap
|
qts
|
A command injection vulnerability has been reported to affect QNAP NAS running legacy versions of QTS. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised…
|
-
|
CVE-2021-28800
|
2024-11-21 15:00 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194175
|
4.8 |
MEDIUM
Network
|
get-simple
|
getsimplecms
|
Cross Site Scripting vulnerability in GetSimpleCMS 3.3.16 in admin/upload.php by adding comments or jpg and other file header information to the content of xla, pages, and gzip files,
|
CWE-79
Cross-site Scripting
|
CVE-2021-28977
|
2024-11-21 15:00 |
2021-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194176
|
7.2 |
HIGH
Network
|
get-simple
|
getsimplecms
|
Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-28976
|
2024-11-21 15:00 |
2021-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194177
|
7.5 |
HIGH
Network
|
synology
|
diskstation_manager diskstation_manager_unified_controller
|
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to …
|
-
|
CVE-2021-29087
|
2024-11-21 15:00 |
2021-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194178
|
7.5 |
HIGH
Network
|
synology
|
diskstation_manager diskstation_manager_unified_controller
|
Exposure of sensitive information to an unauthorized actor vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to obtain sensitive inf…
|
CWE-200
Information Exposure
|
CVE-2021-29086
|
2024-11-21 15:00 |
2021-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194179
|
7.5 |
HIGH
Network
|
synology
|
diskstation_manager diskstation_manager_unified_controller
|
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in file sharing management component in Synology DiskStation Manager (DSM) before 6.2.…
|
-
|
CVE-2021-29085
|
2024-11-21 15:00 |
2021-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194180
|
7.5 |
HIGH
Network
|
synology
|
diskstation_manager diskstation_manager_unified_controller
|
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in Security Advisor report management component in Synology DiskStation Manager (DSM) …
|
-
|
CVE-2021-29084
|
2024-11-21 15:00 |
2021-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|