|
199081
|
7.8 |
HIGH
Local
|
less-openui5_project
|
less-openui5
|
less-openui5 is an npm package which enables building OpenUI5 themes with Less.js. In less-openui5 before version 0.10., when processing theming resources (i.e. `*.less` files) with less-openui5 that…
|
-
|
CVE-2021-21316
|
2024-11-21 14:48 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199082
|
7.8 |
HIGH
Local
|
systeminformation apache
|
systeminformation cordova
|
The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation b…
|
CWE-78
OS Command
|
CVE-2021-21315
|
2024-11-21 14:48 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199083
|
8.1 |
HIGH
Network
|
dell
|
emc_avamar_server emc_integrated_data_protection_appliance
|
Dell EMC Avamar Server, versions 19.3 and 19.4 contain an Improper Authorization vulnerability in the web UI. A remote low privileged attacker could potentially exploit this vulnerability, to gain un…
|
NVD-CWE-Other
|
CVE-2021-21511
|
2024-11-21 14:48 |
2021-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199084
|
7.5 |
HIGH
Network
|
php debian netapp oracle
|
php debian_linux clustered_data_ontap communications_diameter_signaling_router
|
In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a SOAP server, a malicious SOAP server could return malformed XML data as a respo…
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-21702
|
2024-11-21 14:48 |
2021-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199085
|
9.8 |
CRITICAL
Network
|
dell
|
emc_powerscale_onefs
|
Dell PowerScale OneFS versions 8.1.0 – 9.1.0 contain a "use of SSH key past account expiration" vulnerability. A user on the network with the ISI_PRIV_AUTH_SSH RBAC privilege that has an expired acco…
|
CWE-287
Improper Authentication
|
CVE-2021-21502
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199086
|
9.1 |
CRITICAL
Network
|
sap
|
scimono
|
In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system.
|
CWE-74
Injection
|
CVE-2021-21479
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199087
|
6.1 |
MEDIUM
Network
|
sap
|
web_dynpro_abap
|
SAP Web Dynpro ABAP allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.
|
CWE-601
Open Redirect
|
CVE-2021-21478
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199088
|
9.9 |
CRITICAL
Network
|
sap
|
commerce
|
SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attacker with this privilege will be able to inject mali…
|
CWE-94
Code Injection
|
CVE-2021-21477
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199089
|
6.1 |
MEDIUM
Network
|
sap
|
ui5
|
SAP UI5 versions before 1.38.49, 1.52.49, 1.60.34, 1.71.31, 1.78.18, 1.84.5, 1.85.4, 1.86.1 allows an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerab…
|
CWE-601
Open Redirect
|
CVE-2021-21476
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199090
|
7.5 |
HIGH
Network
|
sap
|
netweaver_master_data_management_server
|
Under specific circumstances SAP Master Data Management, versions - 710, 710.750, allows an unauthorized attacker to exploit insufficient validation of path information provided by users, thus charac…
|
CWE-22
Path Traversal
|
CVE-2021-21475
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|