|
196371
|
8.8 |
HIGH
Network
|
expressionengine
|
expressionengine
|
ExpressionEngine before 5.4.2 and 6.x before 6.0.3 allows PHP Code Injection by certain authenticated users who can leverage Translate::save() to write to an _lang.php file under the system/user/lang…
|
CWE-94
Code Injection
|
CVE-2021-27230
|
2024-11-21 14:57 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196372
|
9.8 |
CRITICAL
Network
|
vmware netapp
|
spring_boot solidfire_\&_hci_management_node management_services_for_element_software_and_netapp_hci element_plug-in_for_vcenter_server
|
Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability which when successfully exploited could lead to R…
|
NVD-CWE-noinfo
|
CVE-2021-26987
|
2024-11-21 14:57 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196373
|
7.8 |
HIGH
Local
|
siemens
|
solid_edge
|
A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP13), Solid Edge SE2021 (All Versions < SE2021MP3). Affected applications lack proper validation of user-supplied data …
|
-
|
CVE-2021-27381
|
2024-11-21 14:57 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196374
|
7.8 |
HIGH
Local
|
siemens
|
solid_edge
|
A vulnerability has been identified in Solid Edge SE2020 (All versions < SE2020MP13), Solid Edge SE2021 (All Versions < SE2021MP4). Affected applications lack proper validation of user-supplied data …
|
-
|
CVE-2021-27380
|
2024-11-21 14:57 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196375
|
6.1 |
MEDIUM
Network
|
argoproj
|
argo_cd
|
An issue was discovered in Argo CD before 1.8.4. Browser XSS protection is not activated due to the missing XSS protection header.
|
CWE-79
Cross-site Scripting
|
CVE-2021-26924
|
2024-11-21 14:57 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196376
|
7.5 |
HIGH
Network
|
argoproj
|
argo_cd
|
An issue was discovered in Argo CD before 1.8.4. Accessing the endpoint /api/version leaks internal information for the system, and this endpoint is not protected with authentication.
|
CWE-200
Information Exposure
|
CVE-2021-26923
|
2024-11-21 14:57 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196377
|
6.8 |
MEDIUM
Physics
|
xilinx
|
zynq-7000s_firmware zynq-7000_firmware
|
When booting a Zync-7000 SOC device from nand flash memory, the nand driver in the ROM does not validate the inputs when reading in any parameters in the nand’s parameter page. IF a field read in fro…
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-27208
|
2024-11-21 14:57 |
2021-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196378
|
7.5 |
HIGH
Network
|
ssri_project oracle siemens
|
ssri graalvm sinec_infrastructure_network_services
|
ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial …
|
NVD-CWE-Other
|
CVE-2021-27290
|
2024-11-21 14:57 |
2021-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196379
|
7.8 |
HIGH
Local
|
microsoft
|
visual_studio_code
|
Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2021-27084
|
2024-11-21 14:57 |
2021-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196380
|
7.8 |
HIGH
Local
|
microsoft
|
remote_development
|
Remote Development Extension for Visual Studio Code Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2021-27083
|
2024-11-21 14:57 |
2021-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|