|
196061
|
9.8 |
CRITICAL
Network
|
riot-os
|
riot
|
RIOT-OS 2021.01 contains a buffer overflow vulnerability in sys/net/gnrc/routing/rpl/gnrc_rpl_validation.c through the gnrc_rpl_validation_options() function.
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-27697
|
2024-11-21 14:58 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196062
|
7.2 |
HIGH
Network
|
piwigo
|
piwigo
|
SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages.
|
CWE-89
SQL Injection
|
CVE-2021-27973
|
2024-11-21 14:58 |
2021-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196063
|
4.9 |
MEDIUM
Network
|
pega
|
infinity
|
Misconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data exposure.
|
NVD-CWE-noinfo
|
CVE-2021-27653
|
2024-11-21 14:58 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196064
|
7.8 |
HIGH
Local
|
ge
|
reason_dr60_firmware
|
The software performs an operation at a privilege level higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses on the Reason DR60 (all …
|
CWE-269
Improper Privilege Management
|
CVE-2021-27454
|
2024-11-21 14:58 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196065
|
7.8 |
HIGH
Local
|
ge
|
mu320e_firmware
|
The software contains a hard-coded password that could allow an attacker to take control of the merging unit using these hard-coded credentials on the MU320E (all firmware versions prior to v04A00.1).
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2021-27452
|
2024-11-21 14:58 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196066
|
7.8 |
HIGH
Local
|
ge
|
mu320e_firmware
|
SSH server configuration file does not implement some best practices. This could lead to a weakening of the SSH protocol strength, which could lead to additional misconfiguration or be leveraged as p…
|
-
|
CVE-2021-27450
|
2024-11-21 14:58 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196067
|
7.8 |
HIGH
Local
|
ge
|
mu320e_firmware
|
A miscommunication in the file system allows adversaries with access to the MU320E to escalate privileges on the MU320E (all firmware versions prior to v04A00.1).
|
CWE-269
Improper Privilege Management
|
CVE-2021-27448
|
2024-11-21 14:58 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196068
|
4.4 |
MEDIUM
Local
|
acquia
|
mautic
|
In all versions prior to Mautic 3.3.2, secret parameters such as database credentials could be exposed publicly by an authorized admin user through leveraging Symfony parameter syntax in any of the f…
|
CWE-74
Injection
|
CVE-2021-27908
|
2024-11-21 14:58 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196069
|
4.8 |
MEDIUM
Network
|
boonex
|
dolphin
|
Dolphin CMS 7.4.2 is vulnerable to stored XSS via the Page Builder "width" parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27969
|
2024-11-21 14:58 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196070
|
4.8 |
MEDIUM
Network
|
dynpg
|
dynpg
|
A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "query" parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27531
|
2024-11-21 14:58 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|