|
197851
|
4.4 |
MEDIUM
Local
|
mongodb
|
rust_driver
|
Specific MongoDB Rust Driver versions can include credentials used by the connection pool to authenticate connections in the monitoring event that is emitted when the pool is created. The user's logg…
|
NVD-CWE-noinfo
|
CVE-2021-20332
|
2024-11-21 14:46 |
2021-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197852
|
4.4 |
MEDIUM
Network
|
ibm
|
powervm_hypervisor
|
The PowerVM Logical Partition Mobility(LPM) (PowerVM Hypervisor FW920, FW930, FW940, and FW950) encryption key exchange protocol can be compromised. If an attacker has the ability to capture encrypte…
|
NVD-CWE-noinfo
|
CVE-2021-20505
|
2024-11-21 14:46 |
2021-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197853
|
5.4 |
MEDIUM
Network
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_3 and 6.1.0.0 through 6.1.0.2 vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20562
|
2024-11-21 14:46 |
2021-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197854
|
9.1 |
CRITICAL
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM Qradar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerabilit…
|
CWE-611
XXE
|
CVE-2021-20399
|
2024-11-21 14:46 |
2021-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197855
|
5.4 |
MEDIUM
Network
|
ibm
|
sterling_connect_direct_user_interface
|
IBM Sterling Connect:Direct Browser User Interface 1.4.1.1 and 1.5.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site,…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2021-20560
|
2024-11-21 14:46 |
2021-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197856
|
6.5 |
MEDIUM
Network
|
ibm
|
i2_analysts_notebook
|
IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 does not invalidate session after logout which could allow an an attacker to obtain sensitive information from the system. IBM X-Force ID: 19…
|
CWE-613
Insufficient Session Expiration
|
CVE-2021-20431
|
2024-11-21 14:46 |
2021-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197857
|
5.3 |
MEDIUM
Network
|
ibm
|
i2_analyze
|
IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the bro…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2021-20430
|
2024-11-21 14:46 |
2021-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197858
|
7.5 |
HIGH
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 1…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2021-20337
|
2024-11-21 14:46 |
2021-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197859
|
5.3 |
MEDIUM
Network
|
mongodb
|
mongodb
|
Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.…
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2021-20333
|
2024-11-21 14:46 |
2021-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197860
|
7.5 |
HIGH
Network
|
mitsubishielectric
|
fx3u-enet-p502_firmware fx3u-enet-l_firmware fx3u-enet_firmware
|
NULL Pointer Dereference in MELSEC-F Series FX3U-ENET firmware version 1.14 and prior, FX3U-ENET-L firmware version 1.14 and prior and FX3U-ENET-P502 firmware version 1.14 and prior allows a remote u…
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-20596
|
2024-11-21 14:46 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|