|
195721
|
5.4 |
MEDIUM
Network
|
devolutions
|
remote_desktop_manager
|
Cross-Site Scripting (XSS) in Administrative Reports in Devolutions Remote Desktop Manager before 2021.1 allows remote authenticated users to inject arbitrary web script or HTML via multiple input fi…
|
CWE-79
Cross-site Scripting
|
CVE-2021-28047
|
2024-11-21 14:59 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195722
|
7.5 |
HIGH
Network
|
eclipse oracle jenkins netapp
|
jetty communications_services_gatekeeper autovue_for_agile_product_lifecycle_management siebel_core_-_automation communications_element_manager communications_cloud_native_core_policy<…
|
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2021-28165
|
2024-11-21 14:59 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195723
|
5.3 |
MEDIUM
Network
|
eclipse netapp oracle
|
jetty santricity_cloud_connector snapcenter e-series_performance_analyzer e-series_santricity_web_services virtual_storage_console storage_replication_adapter_for_clustered_data_ont…
|
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF direc…
|
NVD-CWE-Other
|
CVE-2021-28164
|
2024-11-21 14:59 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195724
|
6.5 |
MEDIUM
Network
|
adobe
|
acrobat acrobat_dc acrobat_reader acrobat_reader_dc
|
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are missing support for an integrity check. An unauthenticated attacker…
|
-
|
CVE-2021-28546
|
2024-11-21 14:59 |
2021-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195725
|
8.1 |
HIGH
Network
|
adobe
|
acrobat acrobat_dc acrobat_reader acrobat_reader_dc
|
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are missing support for an integrity check. An unauthenticated attacker…
|
-
|
CVE-2021-28545
|
2024-11-21 14:59 |
2021-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195726
|
2.7 |
LOW
Network
|
eclipse fedoraproject apache netapp oracle
|
jetty fedora solr ignite santricity_cloud_connector snapcenter e-series_performance_analyzer e-series_santricity_web_services virtual_storage_console storage_replication_ad…
|
In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a sta…
|
CWE-59
Link Following
|
CVE-2021-28163
|
2024-11-21 14:59 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195727
|
7.5 |
HIGH
Network
|
pbootcms
|
pbootcms
|
PbootCMS 3.0.4 contains a SQL injection vulnerability through index.php via the search parameter that can reveal sensitive information through adding an admin account.
|
CWE-89
SQL Injection
|
CVE-2021-28245
|
2024-11-21 14:59 |
2021-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195728
|
7.8 |
HIGH
Local
|
ca
|
ehealth_performance_manager
|
CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a setuid (and/or setgid) file. When a component is run as an argument of the runpicEhealth executable, the scri…
|
CWE-269
Improper Privilege Management
|
CVE-2021-28250
|
2024-11-21 14:59 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195729
|
8.8 |
HIGH
Local
|
ca
|
ehealth_performance_manager
|
CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. To exploit the vulnerability, the ehealth user must create a malici…
|
CWE-426
Untrusted Search Path
|
CVE-2021-28249
|
2024-11-21 14:59 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195730
|
7.5 |
HIGH
Network
|
broadcom
|
ehealth
|
CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is able to perform an arbitrary number of /web/frames/ authentica…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2021-28248
|
2024-11-21 14:59 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|