|
199201
|
5.3 |
MEDIUM
Adjacent
|
dell
|
emc_networker
|
Dell EMC NetWorker, versions 18.x, 19.1.x, 19.2.x 19.3.x, 19.4, and 19.4.0.1 contain an Improper Certificate Validation vulnerability in the client (NetWorker Management Console) components which use…
|
CWE-295
Improper Certificate Validation
|
CVE-2021-21559
|
2024-11-21 14:48 |
2021-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199202
|
6.5 |
MEDIUM
Network
|
zte
|
zxa10_f821_firmware zxa10_f822_firmware zxa10_f819_firmware zxa10_f832_firmware zxa10_f839_firmware zxa10_f809_firmware zxa10_f822p_firmware zxa10_f832v2_firmware
|
Some PON MDU devices of ZTE stored sensitive information in plaintext, and users with login authority can obtain it by inputing command. This affects: ZTE PON MDU device ZXA10 F821 V1.7.0P3T22, ZXA10…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2021-21734
|
2024-11-21 14:48 |
2021-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199203
|
5.4 |
MEDIUM
Network
|
jenkins
|
markdown_formatter
|
Jenkins Markdown Formatter Plugin 0.1.0 and earlier does not sanitize crafted link target URLs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with the abilit…
|
CWE-79
Cross-site Scripting
|
CVE-2021-21660
|
2024-11-21 14:48 |
2021-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199204
|
8.1 |
HIGH
Network
|
jenkins
|
urltrigger
|
Jenkins URLTrigger Plugin 0.48 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
-
|
CVE-2021-21659
|
2024-11-21 14:48 |
2021-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199205
|
9.1 |
CRITICAL
Network
|
jenkins
|
nuget
|
Jenkins Nuget Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
-
|
CVE-2021-21658
|
2024-11-21 14:48 |
2021-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199206
|
8.8 |
HIGH
Network
|
jenkins
|
filesystem_trigger
|
Jenkins Filesystem Trigger Plugin 0.40 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
-
|
CVE-2021-21657
|
2024-11-21 14:48 |
2021-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199207
|
8.8 |
HIGH
Local
|
microsoft
|
windows_10
|
Dell Wyse Windows Embedded System versions WIE10 LTSC 2019 and earlier contain an improper authorization vulnerability. A local authenticated malicious user with low privileges may potentially exploi…
|
NVD-CWE-Other
|
CVE-2021-21552
|
2024-11-21 14:48 |
2021-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199208
|
8.8 |
HIGH
Network
|
dell
|
xtremio_management_server
|
Dell EMC XtremIO Versions prior to 6.3.3-8, contain a Cross-Site Request Forgery Vulnerability in XMS. A non-privileged attacker could potentially exploit this vulnerability, leading to a privileged …
|
CWE-352
Origin Validation Error
|
CVE-2021-21549
|
2024-11-21 14:48 |
2021-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199209
|
4.9 |
MEDIUM
Network
|
zte
|
zxcdn
|
The management system of ZXCDN is impacted by the information leak vulnerability. Attackers can make further analysis according to the information returned by the program, and then obtain some sensit…
|
CWE-200
Information Exposure
|
CVE-2021-21733
|
2024-11-21 14:48 |
2021-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199210
|
7.5 |
HIGH
Network
|
zte
|
axon_11_5g_firmware
|
A mobile phone of ZTE is impacted by improper access control vulnerability. Due to improper permission settings, third-party applications can read some files in the proc file system without authoriza…
|
NVD-CWE-Other
|
CVE-2021-21732
|
2024-11-21 14:48 |
2021-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|