|
197911
|
6.3 |
MEDIUM
Network
|
sap
|
netweaver_application_server_abap
|
SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, contains function module SRM_RFC_SUBMIT_REPORT which fails to validate authorizati…
|
CWE-862
Missing Authorization
|
CVE-2021-21473
|
2024-11-21 14:48 |
2021-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197912
|
4.4 |
MEDIUM
Local
|
dell
|
emc_networker
|
Dell EMC NetWorker, 18.x, 19.1.x, 19.2.x 19.3.x, 19.4 and 19.4.0.1, contains an Information Disclosure vulnerability. A local administrator of the gstd system may potentially exploit this vulnerabili…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2021-21558
|
2024-11-21 14:48 |
2021-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197913
|
5.3 |
MEDIUM
Adjacent
|
dell
|
emc_networker
|
Dell EMC NetWorker, versions 18.x, 19.1.x, 19.2.x 19.3.x, 19.4, and 19.4.0.1 contain an Improper Certificate Validation vulnerability in the client (NetWorker Management Console) components which use…
|
CWE-295
Improper Certificate Validation
|
CVE-2021-21559
|
2024-11-21 14:48 |
2021-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197914
|
6.5 |
MEDIUM
Network
|
zte
|
zxa10_f821_firmware zxa10_f822_firmware zxa10_f819_firmware zxa10_f832_firmware zxa10_f839_firmware zxa10_f809_firmware zxa10_f822p_firmware zxa10_f832v2_firmware
|
Some PON MDU devices of ZTE stored sensitive information in plaintext, and users with login authority can obtain it by inputing command. This affects: ZTE PON MDU device ZXA10 F821 V1.7.0P3T22, ZXA10…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2021-21734
|
2024-11-21 14:48 |
2021-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197915
|
5.4 |
MEDIUM
Network
|
jenkins
|
markdown_formatter
|
Jenkins Markdown Formatter Plugin 0.1.0 and earlier does not sanitize crafted link target URLs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with the abilit…
|
CWE-79
Cross-site Scripting
|
CVE-2021-21660
|
2024-11-21 14:48 |
2021-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197916
|
8.1 |
HIGH
Network
|
jenkins
|
urltrigger
|
Jenkins URLTrigger Plugin 0.48 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
-
|
CVE-2021-21659
|
2024-11-21 14:48 |
2021-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197917
|
9.1 |
CRITICAL
Network
|
jenkins
|
nuget
|
Jenkins Nuget Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
-
|
CVE-2021-21658
|
2024-11-21 14:48 |
2021-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197918
|
8.8 |
HIGH
Network
|
jenkins
|
filesystem_trigger
|
Jenkins Filesystem Trigger Plugin 0.40 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
-
|
CVE-2021-21657
|
2024-11-21 14:48 |
2021-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197919
|
8.8 |
HIGH
Local
|
microsoft
|
windows_10
|
Dell Wyse Windows Embedded System versions WIE10 LTSC 2019 and earlier contain an improper authorization vulnerability. A local authenticated malicious user with low privileges may potentially exploi…
|
NVD-CWE-Other
|
CVE-2021-21552
|
2024-11-21 14:48 |
2021-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197920
|
8.8 |
HIGH
Network
|
dell
|
xtremio_management_server
|
Dell EMC XtremIO Versions prior to 6.3.3-8, contain a Cross-Site Request Forgery Vulnerability in XMS. A non-privileged attacker could potentially exploit this vulnerability, leading to a privileged …
|
CWE-352
Origin Validation Error
|
CVE-2021-21549
|
2024-11-21 14:48 |
2021-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|