|
196021
|
4.6 |
MEDIUM
Physics
|
coolkit
|
ewelink
|
Unconstrained Web access to the device's private encryption key in the QR code pairing mode in the eWeLink mobile application (through 4.9.2 on Android and through 4.9.1 on iOS) allows a physically p…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2021-27941
|
2024-11-21 14:58 |
2021-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196022
|
9.8 |
CRITICAL
Network
|
pega
|
infinity
|
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks.
|
CWE-287
Improper Authentication
|
CVE-2021-27651
|
2024-11-21 14:58 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196023
|
8.8 |
HIGH
Network
|
synology
|
antivirus_essential
|
Externally controlled reference to a resource in another sphere in quarantine functionality in Synology Antivirus Essential before 1.4.8-2801 allows remote authenticated users to obtain privilege via…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2021-27648
|
2024-11-21 14:58 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196024
|
6.1 |
MEDIUM
Network
|
pfsense
|
pfsense
|
pfSense 2.5.0 allows XSS via the services_wol_edit.php Description field.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27933
|
2024-11-21 14:58 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196025
|
9.8 |
CRITICAL
Network
|
deltaww
|
industrial_automation_commgr
|
Delta Industrial Automation COMMGR Versions 1.12 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute remote code.
|
-
|
CVE-2021-27480
|
2024-11-21 14:58 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196026
|
5.5 |
MEDIUM
Local
|
gnu
|
guix
|
A security vulnerability that can lead to local privilege escalation has been found in ’guix-daemon’. It affects multi-user setups in which ’guix-daemon’ runs locally. The attack consists in having a…
|
CWE-59
Link Following
|
CVE-2021-27851
|
2024-11-21 14:58 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196027
|
6.5 |
MEDIUM
Network
|
fusionauth
|
saml_v2
|
FusionAuth fusionauth-samlv2 before 0.5.4 allows XXE attacks via a forged AuthnRequest or LogoutRequest because parseFromBytes uses javax.xml.parsers.DocumentBuilderFactory unsafely.
|
CWE-611
XXE
|
CVE-2021-27736
|
2024-11-21 14:58 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196028
|
9.8 |
CRITICAL
Network
|
tendacn
|
g1_firmware g3_firmware
|
Command Injection in Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS commands via a crafted "action/umountU…
|
CWE-119 CWE-78
Incorrect Access of Indexable Resource ('Range Error') OS Command
|
CVE-2021-27692
|
2024-11-21 14:58 |
2021-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196029
|
9.8 |
CRITICAL
Network
|
tendacn
|
g0_firmware g1_firmware g3_firmware
|
Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)…
|
CWE-119 CWE-78
Incorrect Access of Indexable Resource ('Range Error') OS Command
|
CVE-2021-27691
|
2024-11-21 14:58 |
2021-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196030
|
4.8 |
MEDIUM
Network
|
tribalsystems
|
zenario
|
Cross Site Scripting (XSS) in the "admin_boxes.ajax.php" component of Tribal Systems Zenario CMS v8.8.52729 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "cID…
|
CWE-79
Cross-site Scripting
|
CVE-2021-27673
|
2024-11-21 14:58 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|