|
195581
|
6.5 |
MEDIUM
Network
|
devolutions
|
devolutions_server
|
An overly permissive CORS policy in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows a remote attacker to leak cross-origin data via a crafted HTML page.
|
CWE-346
Origin Validation Error
|
CVE-2021-28048
|
2024-11-21 14:59 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195582
|
7.5 |
HIGH
Network
|
yubico fedoraproject
|
yubihsm_connector fedora
|
An issue was discovered in the /api/connector endpoint handler in Yubico yubihsm-connector before 3.0.1 (in YubiHSM SDK before 2021.04). The handler did not validate the length of the request, which …
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2021-28484
|
2024-11-21 14:59 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195583
|
5.3 |
MEDIUM
Network
|
group-office
|
group_office
|
A Server-Side Request Forgery (SSRF) vulnerability in Group Office 6.4.196 allows a remote attacker to forge GET requests to arbitrary URLs via the url parameter to group/api/upload.php.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-28060
|
2024-11-21 14:59 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195584
|
7.8 |
HIGH
Local
|
forescout
|
counteract
|
An issue was discovered in Forescout CounterACT before 8.1.4. A local privilege escalation vulnerability is present in the logging function. SecureConnector runs with administrative privileges and wr…
|
CWE-59 CWE-427 CWE-732
Link Following Uncontrolled Search Path Element Incorrect Permission Assignment for Critical Resource
|
CVE-2021-28098
|
2024-11-21 14:59 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195585
|
9.8 |
CRITICAL
Network
|
gpac
|
gpac
|
NULL Pointer Dereference in the "isomedia/track.c" module's "MergeTrack()" function of GPAC v0.5.2 allows attackers to execute arbitrary code or cause a Denial-of-Service (DoS) by uploading a malicio…
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-28300
|
2024-11-21 14:59 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195586
|
9.0 |
CRITICAL
Adjacent
|
microsoft
|
exchange_server
|
Microsoft Exchange Server Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2021-28483
|
2024-11-21 14:59 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195587
|
8.8 |
HIGH
Network
|
microsoft
|
exchange_server
|
Microsoft Exchange Server Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2021-28482
|
2024-11-21 14:59 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195588
|
9.8 |
CRITICAL
Network
|
microsoft
|
exchange_server
|
Microsoft Exchange Server Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2021-28481
|
2024-11-21 14:59 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195589
|
9.8 |
CRITICAL
Network
|
microsoft
|
exchange_server
|
Microsoft Exchange Server Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2021-28480
|
2024-11-21 14:59 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195590
|
7.0 |
HIGH
Local
|
microsoft
|
visual_studio_code
|
Visual Studio Code Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2021-28477
|
2024-11-21 14:59 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|