|
195731
|
5.4 |
MEDIUM
Network
|
ca
|
ehealth_performance_manager
|
CA eHealth Performance Manager through 6.3.2.12 is affected by Cross Site Scripting (XSS). The impact is: An authenticated remote user is able to inject arbitrary web script or HTML due to incorrect …
|
CWE-79
Cross-site Scripting
|
CVE-2021-28247
|
2024-11-21 14:59 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195732
|
7.8 |
HIGH
Local
|
broadcom
|
ehealth
|
CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. A regular user must create a malicious library in the writable RPAT…
|
CWE-426
Untrusted Search Path
|
CVE-2021-28246
|
2024-11-21 14:59 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195733
|
7.5 |
HIGH
Network
|
contiki-os
|
contiki
|
An issue was discovered in Contiki through 3.0. When sending an ICMPv6 error message because of invalid extension header options in an incoming IPv6 packet, there is an attempt to remove the RPL exte…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2021-28362
|
2024-11-21 14:59 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195734
|
5.5 |
MEDIUM
Local
|
netflix
|
priam
|
Priam uses File.createTempFile, which gives the permissions on that file -rw-r--r--. An attacker with read access to the local filesystem can read anything written there by the Priam process.
|
NVD-CWE-noinfo
|
CVE-2021-28100
|
2024-11-21 14:59 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195735
|
4.4 |
MEDIUM
Local
|
netflix
|
hollow
|
In Netflix OSS Hollow, since the Files.exists(parent) is run before creating the directories, an attacker can pre-create these directories with wide permissions. Additionally, since an insecure sourc…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2021-28099
|
2024-11-21 14:59 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195736
|
7.5 |
HIGH
Network
|
grafana
|
grafana
|
One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication. This allows any unauthenticate…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-28148
|
2024-11-21 14:59 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195737
|
6.5 |
MEDIUM
Network
|
grafana
|
grafana
|
The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication s…
|
NVD-CWE-Other
|
CVE-2021-28147
|
2024-11-21 14:59 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195738
|
6.5 |
MEDIUM
Network
|
grafana
|
grafana
|
The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any aut…
|
CWE-863
Incorrect Authorization
|
CVE-2021-28146
|
2024-11-21 14:59 |
2021-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195739
|
7.5 |
HIGH
Network
|
kde
|
discover
|
libdiscover/backends/KNSBackend/KNSResource.cpp in KDE Discover before 5.21.3 automatically creates links to potentially dangerous URLs (that are neither https:// nor http://) based on the content of…
|
NVD-CWE-noinfo
|
CVE-2021-28117
|
2024-11-21 14:59 |
2021-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195740
|
5.3 |
MEDIUM
Network
|
torproject fedoraproject
|
tor fedora
|
Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka TROVE-2021-002.
|
CWE-617
Reachable Assertion
|
CVE-2021-28090
|
2024-11-21 14:59 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|