|
196621
|
7.5 |
HIGH
Network
|
wisa
|
smart_wing_cms
|
This vulnerability is caused by the lack of validation of input values for specific functions if WISA Smart Wing CMS. Remote attackers can use this vulnerability to leak all files in the server witho…
|
CWE-20 CWE-494
Improper Input Validation Download of Code Without Integrity Check
|
CVE-2021-26639
|
2024-11-21 14:56 |
2022-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196622
|
7.8 |
HIGH
Local
|
amd
|
ryzen_7_5700g_firmware ryzen_7_5700ge_firmware ryzen_5_5600g_firmware ryzen_5_5600ge_firmware ryzen_3_5300g_firmware ryzen_3_5300ge_firmware ryzen_9_5980hx_firmware ryzen_9_5980h…
|
A malformed SMI (System Management Interface) command may allow an attacker to establish a corrupted SMI Trigger Info data structure, potentially leading to out-of-bounds memory reads and writes when…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2021-26384
|
2024-11-21 14:56 |
2022-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196623
|
4.4 |
MEDIUM
Local
|
amd
|
ryzen_7_5700g_firmware ryzen_7_5700ge_firmware ryzen_5_5600g_firmware ryzen_5_5600ge_firmware ryzen_3_5300g_firmware ryzen_3_5300ge_firmware ryzen_9_5980hx_firmware ryzen_9_5980h…
|
An attacker with root account privileges can load any legitimately signed firmware image into the Audio Co-Processor (ACP,) irrespective of the respective signing key being declared as usable for aut…
|
NVD-CWE-noinfo
|
CVE-2021-26382
|
2024-11-21 14:56 |
2022-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196624
|
9.8 |
CRITICAL
Network
|
xisnd
|
s\&d_smarthome
|
Improper Authentication vulnerability in S&D smarthome(smartcare) application can cause authentication bypass and information exposure. Remote attackers can use this vulerability to take control of t…
|
CWE-287
Improper Authentication
|
CVE-2021-26638
|
2024-11-21 14:56 |
2022-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196625
|
9.8 |
CRITICAL
Network
|
shinasys
|
sihas_sgw-300_firmware sihas_acm-300_firmware sihas_gcm-300_firmware
|
There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized users can remotely control the device.
|
CWE-306 CWE-862
Missing Authentication for Critical Function Missing Authorization
|
CVE-2021-26637
|
2024-11-21 14:56 |
2022-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196626
|
9.6 |
CRITICAL
Network
|
maxb
|
maxboard
|
Stored XSS and SQL injection vulnerability in MaxBoard could lead to occur Remote Code Execution, which could lead to information exposure and privilege escalation.
|
CWE-79 CWE-89
Cross-site Scripting SQL Injection
|
CVE-2021-26636
|
2024-11-21 14:56 |
2022-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196627
|
7.8 |
HIGH
Local
|
bandisoft
|
ark_library
|
In the code that verifies the file size in the ark library, it is possible to manipulate the offset read from the target file due to the wrong use of the data type. An attacker could use this vulnera…
|
CWE-843
Type Confusion
|
CVE-2021-26635
|
2024-11-21 14:56 |
2022-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196628
|
9.8 |
CRITICAL
Network
|
maxb
|
maxboard
|
SQL injection and file upload attacks are possible due to insufficient validation of input values in some parameters and variables of files compromising Maxboard, which may lead to arbitrary code exe…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-26634
|
2024-11-21 14:56 |
2022-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196629
|
9.8 |
CRITICAL
Network
|
maxb
|
maxboard
|
SQL injection and Local File Inclusion (LFI) vulnerabilities in MaxBoard can cause information leakage and privilege escalation. This vulnerabilities can be exploited by manipulating a variable with …
|
CWE-89
SQL Injection
|
CVE-2021-26633
|
2024-11-21 14:56 |
2022-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196630
|
7.5 |
HIGH
Network
|
mangboard
|
commerce
|
Improper input validation vulnerability in Mangboard commerce package could lead to occur for abnormal request. A remote attacker can exploit this vulnerability to manipulate the total order amount i…
|
CWE-20
Improper Input Validation
|
CVE-2021-26631
|
2024-11-21 14:56 |
2022-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|