|
197281
|
8.8 |
HIGH
Network
|
google
|
exposure_notifications_verification_server
|
A privilege escalation vulnerability impacting the Google Exposure Notification Verification Server (versions prior to 0.23.1), allows an attacker who (1) has UserWrite permissions and (2) is using a…
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-22538
|
2024-11-21 14:50 |
2021-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197282
|
6.1 |
MEDIUM
Network
|
rocket.chat
|
rocket.chat
|
Rocket.Chat before 3.11, 3.10.5, 3.9.7, 3.8.8 is vulnerable to persistent cross-site scripting (XSS) using nested markdown tags allowing a remote attacker to inject arbitrary JavaScript in a message.…
|
CWE-79
Cross-site Scripting
|
CVE-2021-22886
|
2024-11-21 14:50 |
2021-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197283
|
7.5 |
HIGH
Network
|
microfocus
|
access_manager
|
Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage.
|
NVD-CWE-noinfo
|
CVE-2021-22506
|
2024-11-21 14:50 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197284
|
6.1 |
MEDIUM
Network
|
revive-adserver
|
revive_adserver
|
Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `statsBreakdown` parameter of stats.php (and possibly other scripts) due to single quotes not being escaped. An att…
|
CWE-79
Cross-site Scripting
|
CVE-2021-22889
|
2024-11-21 14:50 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197285
|
6.1 |
MEDIUM
Network
|
revive-adserver
|
revive_adserver
|
Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `status` parameter of campaign-zone-zones.php. An attacker could trick a user with access to the user interface of …
|
CWE-79
Cross-site Scripting
|
CVE-2021-22888
|
2024-11-21 14:50 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197286
|
8.6 |
HIGH
Network
|
rockwellautomation
|
micrologix_1400_firmware
|
Rockwell Automation MicroLogix 1400 Version 21.6 and below may allow a remote unauthenticated attacker to send a specially crafted Modbus packet allowing the attacker to retrieve or modify random val…
|
-
|
CVE-2021-22659
|
2024-11-21 14:50 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197287
|
7.5 |
HIGH
Network
|
microfocus
|
access_manager
|
Authentication Bypass Vulnerability in Micro Focus Access Manager Product, affects all version prior to version 4.5.3.3. The vulnerability could cause information leakage.
|
CWE-287
Improper Authentication
|
CVE-2021-22496
|
2024-11-21 14:50 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197288
|
8.8 |
HIGH
Network
|
github
|
enterprise_server
|
A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages …
|
NVD-CWE-noinfo
|
CVE-2021-22864
|
2024-11-21 14:50 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197289
|
7.8 |
HIGH
Local
|
rockwellautomation
|
drivetools_sp drivetools_add-on_profiles
|
Rockwell Automation DriveTools SP v5.13 and below and Drives AOP v4.12 and below both contain a vulnerability that a local attacker with limited privileges may be able to exploit resulting in privile…
|
-
|
CVE-2021-22665
|
2024-11-21 14:50 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197290
|
9.8 |
CRITICAL
Network
|
hgiga
|
msr45_isherlock-antispam msr45_isherlock-user ssr45_isherlock-antispam ssr45_isherlock-user
|
HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL parameter of email pages without privilege.
|
CWE-89
SQL Injection
|
CVE-2021-22848
|
2024-11-21 14:50 |
2021-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|