|
196151
|
7.8 |
HIGH
Local
|
zscaler
|
client_connector
|
Multiple vulnerabilities in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 allowed execution of binaries from a low privileged path. A local adversary may be able to …
|
CWE-22
Path Traversal
|
CVE-2021-26736
|
2024-11-21 14:56 |
2023-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196152
|
7.8 |
HIGH
Local
|
zscaler
|
client_connector
|
The Zscaler Client Connector Installer and Unsintallers for Windows prior to 3.6 had an unquoted search path vulnerability. A local adversary may be able to execute code with SYSTEM privileges.
|
CWE-428
Unquoted Search Path or Element
|
CVE-2021-26735
|
2024-11-21 14:56 |
2023-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196153
|
5.5 |
MEDIUM
Local
|
zscaler
|
client_connector
|
Zscaler Client Connector Installer on Windows before version 3.4.0.124 improperly handled directory junctions during uninstallation. A local adversary may be able to delete folders in an elevated con…
|
NVD-CWE-noinfo
|
CVE-2021-26734
|
2024-11-21 14:56 |
2023-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196154
|
9.8 |
CRITICAL
Network
|
fortra
|
delivernow
|
SQL Injection vulnerability in SearchTextBox parameter in Fortra (Formerly HelpSystems) DeliverNow before version 1.2.18, allows attackers to execute arbitrary code, escalate privileges, and gain sen…
|
CWE-89
SQL Injection
|
CVE-2021-26837
|
2024-11-21 14:56 |
2023-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196155
|
9.8 |
CRITICAL
Network
|
hello.js_project
|
hello.js
|
Prototype pollution vulnerability in MrSwitch hello.js version 1.18.6, allows remote attackers to execute arbitrary code via hello.utils.extend function.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-26505
|
2024-11-21 14:56 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196156
|
7.5 |
HIGH
Network
|
dgtl
|
huemagic
|
Directory Traversal vulnerability in Foddy node-red-contrib-huemagic version 3.0.0, allows remote attackers to gain sensitive information via crafted request in res.sendFile API in hue-magic.js.
|
CWE-22
Path Traversal
|
CVE-2021-26504
|
2024-11-21 14:56 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196157
|
7.5 |
HIGH
Network
|
amd
|
epyc_7232p_firmware epyc_7252_firmware epyc_7262_firmware epyc_7272_firmware epyc_7282_firmware epyc_7302_firmware epyc_7302p_firmware epyc_7352_firmware epyc_7402_firmware
|
Insufficient validation in parsing Owner's
Certificate Authority (OCA) certificates in SEV (AMD Secure Encrypted Virtualization)
and SEV-ES user application can lead to a host crash potentially resul…
|
NVD-CWE-noinfo
|
CVE-2021-26406
|
2024-11-21 14:56 |
2023-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196158
|
7.1 |
HIGH
Local
|
amd
|
epyc_72f3_firmware epyc_7313_firmware epyc_7313p_firmware epyc_7343_firmware epyc_7373x_firmware epyc_73f3_firmware epyc_7413_firmware epyc_7443_firmware epyc_7443p_firmware
|
Insufficient address validation, may allow an
attacker with a compromised ABL and UApp to corrupt sensitive memory locations
potentially resulting in a loss of integrity or availability.
|
NVD-CWE-noinfo
|
CVE-2021-26397
|
2024-11-21 14:56 |
2023-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196159
|
9.8 |
CRITICAL
Network
|
amd
|
epyc_72f3_firmware epyc_7313_firmware epyc_7313p_firmware epyc_7343_firmware epyc_7373x_firmware epyc_73f3_firmware epyc_7413_firmware epyc_7443_firmware epyc_7443p_firmware
|
Insufficient input validation of mailbox data in the
SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially
leading to a loss of integrity and privilege escalation.
|
NVD-CWE-noinfo
|
CVE-2021-26379
|
2024-11-21 14:56 |
2023-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196160
|
5.5 |
MEDIUM
Local
|
amd
|
epyc_7773x_firmware epyc_7763_firmware epyc_7713p_firmware epyc_7713_firmware epyc_7663_firmware epyc_7643_firmware epyc_75f3_firmware epyc_7573x_firmware epyc_7543p_firmware<…
|
A compromised or malicious ABL or UApp could
send a SHA256 system call to the bootloader, which may result in exposure of
ASP memory to userspace, potentially leading to information disclosure.
…
|
NVD-CWE-noinfo
|
CVE-2021-26371
|
2024-11-21 14:56 |
2023-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|