|
197461
|
5.4 |
MEDIUM
Network
|
ibm
|
content_navigator
|
IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potential…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20549
|
2024-11-21 14:46 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197462
|
5.4 |
MEDIUM
Network
|
ibm
|
content_navigator
|
IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potential…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20448
|
2024-11-21 14:46 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197463
|
5.5 |
MEDIUM
Local
|
ibm
|
spectrum_protect_client spectrum_protect_for_space_management
|
IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and cause the applica…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-20546
|
2024-11-21 14:46 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197464
|
6.2 |
MEDIUM
Local
|
ibm
|
spectrum_protect_plus
|
IBM Spectrum Protect Plus File Systems Agent 10.1.6 and 10.1.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 198836.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2021-20536
|
2024-11-21 14:46 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197465
|
7.8 |
HIGH
Local
|
ibm
|
spectrum_protect_backup-archive_client spectrum_protect_for_virtual_environments
|
IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 could allow a local user to escalate their privileges to take full control of the system due to insecure directory permissions. IBM X-Force ID: 19…
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-20532
|
2024-11-21 14:46 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197466
|
6.5 |
MEDIUM
Network
|
ibm
|
spectrum_protect_plus
|
IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domai…
|
NVD-CWE-Other
|
CVE-2021-20432
|
2024-11-21 14:46 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197467
|
6.1 |
MEDIUM
Network
|
nec
|
aterm_wg1900hp2_firmware aterm_wg1900hp_firmware aterm_wg1800hp4_firmware aterm_wg1800hp3_firmware aterm_wg1200hs3_firmware aterm_wg1200hs2_firmware aterm_wg1200hp3_firmware ater…
|
Cross-site scripting vulnerability in NEC Aterm devices (Aterm WG1900HP2 firmware Ver.1.3.1 and earlier, Aterm WG1900HP firmware Ver.2.5.1 and earlier, Aterm WG1800HP4 firmware Ver.1.3.1 and earlier,…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20680
|
2024-11-21 14:46 |
2021-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197468
|
8.2 |
HIGH
Network
|
ibm
|
i
|
IBM i 7.1, 7.2, 7.3, and 7.4 SMTP allows a network attacker to send emails to non-existent local-domain recipients to the SMTP server, caused by using a non-default configuration. An attacker could e…
|
NVD-CWE-noinfo
|
CVE-2021-20501
|
2024-11-21 14:46 |
2021-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197469
|
8.2 |
HIGH
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to e…
|
CWE-611
XXE
|
CVE-2021-20454
|
2024-11-21 14:46 |
2021-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197470
|
8.2 |
HIGH
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose…
|
CWE-611
XXE
|
CVE-2021-20453
|
2024-11-21 14:46 |
2021-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|