|
196131
|
8.8 |
HIGH
Network
|
tobesoft
|
nexacro
|
Insufficient Verification of input Data leading to arbitrary file download and execute was discovered in Nexacro platform. This vulnerability is caused by an automatic update function that does not v…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2021-26625
|
2024-11-21 14:56 |
2022-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196132
|
8.8 |
HIGH
Network
|
escanav
|
escan_anti-virus
|
An local privilege escalation vulnerability due to a "runasroot" command in eScan Anti-Virus. This vulnerability is due to invalid arguments and insufficient execution conditions related to "runasroo…
|
CWE-20
Improper Input Validation
|
CVE-2021-26624
|
2024-11-21 14:56 |
2022-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196133
|
9.8 |
CRITICAL
Network
|
bandisoft
|
bandizip
|
A remote code execution vulnerability due to incomplete check for 'xheader_decode_path_record' function's parameter length value in the ark library. Remote attackers can induce exploit malicious code…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2021-26623
|
2024-11-21 14:56 |
2022-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196134
|
8.1 |
HIGH
Network
|
impresscms
|
impresscms
|
ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal.
|
CWE-22
Path Traversal
|
CVE-2021-26601
|
2024-11-21 14:56 |
2022-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196135
|
9.8 |
CRITICAL
Network
|
impresscms
|
impresscms
|
ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==).
|
CWE-843
Type Confusion
|
CVE-2021-26600
|
2024-11-21 14:56 |
2022-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196136
|
9.8 |
CRITICAL
Network
|
impresscms
|
impresscms
|
ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2021-26599
|
2024-11-21 14:56 |
2022-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196137
|
5.3 |
MEDIUM
Network
|
impresscms
|
impresscms
|
ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, able to have a security token).
|
CWE-287
Improper Authentication
|
CVE-2021-26598
|
2024-11-21 14:56 |
2022-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196138
|
10.0 |
CRITICAL
Network
|
genians
|
genian_nac
|
An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote attackers are able to execute arbitrary malicious…
|
CWE-94
Code Injection
|
CVE-2021-26622
|
2024-11-21 14:56 |
2022-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196139
|
9.8 |
CRITICAL
Network
|
netu
|
mex01_firmware
|
An Buffer Overflow vulnerability leading to remote code execution was discovered in MEX01. Remote attackers can use this vulnerability by using the property that the target program copies parameter v…
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-26621
|
2024-11-21 14:56 |
2022-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196140
|
7.5 |
HIGH
Network
|
iptime
|
nas101_firmware nas1dual_firmware nas2dual_firmware nas3_firmware nas4_firmware nas4dual_firmware nas-i_firmware nas-ii_firmware nas-iie_firmware
|
An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by exploiting vulnera…
|
CWE-287
Improper Authentication
|
CVE-2021-26620
|
2024-11-21 14:56 |
2022-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|