|
196761
|
6.5 |
MEDIUM
Network
|
gallagher
|
command_centre
|
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gallagher Command Centre Server allows OSDP key material to be exposed to Command Centre Operators. This issue affects: Gal…
|
CWE-862
Missing Authorization
|
CVE-2021-23204
|
2024-11-21 14:51 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196762
|
4.4 |
MEDIUM
Local
|
gallagher
|
command_centre
|
Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows OSDP reader master keys to be discoverable in server memory dumps. This issue affects: Gal…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2021-23182
|
2024-11-21 14:51 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196763
|
8.8 |
HIGH
Network
|
gallagher
|
command_centre
|
Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Command Centre Operator. This issue affects: Gallagher Command Cen…
|
NVD-CWE-Other
|
CVE-2021-23140
|
2024-11-21 14:51 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196764
|
6.5 |
MEDIUM
Network
|
gallagher
|
command_centre
|
Improper Authorization vulnerability in Gallagher Command Centre Server allows macro overrides to be performed by an unprivileged Command Centre Operator. This issue affects: Gallagher Command Centre…
|
NVD-CWE-Other
|
CVE-2021-23136
|
2024-11-21 14:51 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196765
|
5.4 |
MEDIUM
Network
|
flask_unchained_project
|
flask_unchained
|
This affects the package Flask-Unchained before 0.9.0. When using the the _validate_redirect_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing…
|
CWE-601
Open Redirect
|
CVE-2021-23393
|
2024-11-21 14:51 |
2021-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196766
|
7.8 |
HIGH
Local
|
f5
|
big-ip_access_policy_manager big-ip_access_policy_manager_client
|
On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, the BIG-IP Edge Client Windows Installer Service's temporary folder has weak file and folder permissions. Note: Software versions …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2021-23022
|
2024-11-21 14:51 |
2021-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196767
|
7.2 |
HIGH
Network
|
f5
|
big-iq_centralized_management
|
On version 8.0.x before 8.0.0.1, and all 6.x and 7.x versions, the BIG-IQ Configuration utility has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versio…
|
NVD-CWE-noinfo
|
CVE-2021-23024
|
2024-11-21 14:51 |
2021-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196768
|
7.8 |
HIGH
Local
|
f5
|
big-ip_access_policy_manager
|
On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, a DLL hijacking issue exists in cachecleaner.dll included in the BIG-IP Edge Client Windows Installer. Note: Software versions whi…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2021-23023
|
2024-11-21 14:51 |
2021-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196769
|
6.1 |
MEDIUM
Network
|
bosch
|
cpp6_firmware cpp7_firmware cpp7.3_firmware cpp13_firmware
|
An error in the handling of a page parameter in Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. This issue only affects versions 7.7x and 7.6x. All oth…
|
CWE-79
Cross-site Scripting
|
CVE-2021-23854
|
2024-11-21 14:51 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196770
|
9.8 |
CRITICAL
Network
|
bosch
|
cpp4_firmware cpp6_firmware cpp7_firmware cpp7.3_firmware cpp13_firmware
|
In Bosch IP cameras, improper validation of the HTTP header allows an attacker to inject arbitrary HTTP headers through crafted URLs.
|
CWE-20
Improper Input Validation
|
CVE-2021-23853
|
2024-11-21 14:51 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|