|
196961
|
5.3 |
MEDIUM
Network
|
vmware
|
vcenter_server cloud_foundation
|
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 44…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-21973
|
2024-11-21 14:49 |
2021-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196962
|
9.8 |
CRITICAL
Network
|
vmware
|
vcenter_server cloud_foundation
|
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with…
|
CWE-22
Path Traversal
|
CVE-2021-21972
|
2024-11-21 14:49 |
2021-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196963
|
8.8 |
HIGH
Network
|
vmware pivotal_software oracle
|
spring_security hospitality_cruise_shipboard_property_management_system communications_interactive_session_recorder communications_unified_inventory_management insurance_policy_administra…
|
Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is changed more than once i…
|
NVD-CWE-noinfo
|
CVE-2021-22112
|
2024-11-21 14:49 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196964
|
5.3 |
MEDIUM
Network
|
vmware
|
spring_cloud_netflix_zuul
|
Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vulnerable to bypassing the “Sensitive Headers” restriction when executing request…
|
CWE-863
Incorrect Authorization
|
CVE-2021-22113
|
2024-11-21 14:49 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196965
|
7.5 |
HIGH
Network
|
wireshark fedoraproject oracle
|
wireshark fedora zfs_storage_appliance
|
Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2021-22174
|
2024-11-21 14:49 |
2021-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196966
|
7.5 |
HIGH
Network
|
wireshark fedoraproject oracle
|
wireshark fedora zfs_storage_appliance
|
Memory leak in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2021-22173
|
2024-11-21 14:49 |
2021-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196967
|
7.2 |
HIGH
Network
|
vmware
|
vsphere_replication
|
vSphere Replication 8.3.x prior to 8.3.1.2, 8.2.x prior to 8.2.1.1, 8.1.x prior to 8.1.2.3 and 6.5.x prior to 6.5.1.5 contain a post-authentication command injection vulnerability which may allow an …
|
CWE-78
OS Command
|
CVE-2021-21976
|
2024-11-21 14:49 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196968
|
2.4 |
LOW
Adjacent
|
elastic
|
apm_agent
|
The Elastic APM agent for Go versions before 1.11.0 can leak sensitive HTTP header information when logging the details during an application panic. Normally, the APM agent will sanitize sensitive HT…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2021-22133
|
2024-11-21 14:49 |
2021-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196969
|
5.9 |
MEDIUM
Network
|
hpe
|
web_viewpoint
|
Idelji Web ViewPoint Suite, as used in conjunction with HPE NonStop, allows a remote replay attack for T0320L01^ABP through T0320L01^ABZ, T0952L01^AAH through T0952L01^AAR, T0986L01 through T0986L01^…
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2021-22267
|
2024-11-21 14:49 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196970
|
6.1 |
MEDIUM
Network
|
fortinet
|
fortiweb
|
An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to perform a reflec…
|
CWE-79
Cross-site Scripting
|
CVE-2021-22122
|
2024-11-21 14:49 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|