|
195941
|
7.8 |
HIGH
Local
|
schneider-electric
|
ecostruxure_power_build_-_rapsody
|
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior) that could allow a stack-based buffer overflow to…
|
-
|
CVE-2021-22698
|
2024-11-21 14:50 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195942
|
7.8 |
HIGH
Local
|
schneider-electric
|
ecostruxure_power_build_-_rapsody
|
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior) that could allow a use-after-free condition which…
|
-
|
CVE-2021-22697
|
2024-11-21 14:50 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195943
|
5.4 |
MEDIUM
Network
|
hyweb
|
hycms-j1
|
Hyweb HyCMS-J1 backend editing function does not filter special characters. Users after log-in can inject JavaScript syntax to perform a stored XSS (Stored Cross-site scripting) attack.
|
CWE-79
Cross-site Scripting
|
CVE-2021-22849
|
2024-11-21 14:50 |
2021-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195944
|
8.8 |
HIGH
Network
|
hyweb
|
hycms-j1
|
Hyweb HyCMS-J1's API fail to filter POST request parameters. Remote attackers can inject SQL syntax and execute commands without privilege.
|
CWE-89
SQL Injection
|
CVE-2021-22847
|
2024-11-21 14:50 |
2021-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195945
|
8.1 |
HIGH
Network
|
microfocus
|
application_lifecycle_management
|
XML External Entity Injection vulnerability in Micro Focus Application Lifecycle Management (Previously known as Quality Center) product. The vulnerability affects versions 12.x, 12.60 Patch 5 and ea…
|
CWE-611
XXE
|
CVE-2021-22498
|
2024-11-21 14:50 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195946
|
8.8 |
HIGH
Network
|
hgiga
|
oaklouds_openid
|
HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (online registration) to obtain database schema and data.
|
CWE-89
SQL Injection
|
CVE-2021-22852
|
2024-11-21 14:50 |
2021-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195947
|
9.8 |
CRITICAL
Network
|
hgiga
|
oaklouds_openid
|
HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (document management page) to obtain database schema and data.
|
CWE-89
SQL Injection
|
CVE-2021-22851
|
2024-11-21 14:50 |
2021-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195948
|
9.8 |
CRITICAL
Network
|
hgiga
|
oaklouds_portal
|
HGiga EIP product lacks ineffective access control in certain pages that allow attackers to access database or perform privileged functions.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-22850
|
2024-11-21 14:50 |
2021-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195949
|
5.5 |
MEDIUM
Local
|
google
|
android
|
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) (Exynos chipsets) software. The Mali GPU driver allows out-of-bounds access and a device reset. The Samsung…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-22495
|
2024-11-21 14:50 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195950
|
5.5 |
MEDIUM
Local
|
google
|
android
|
An issue was discovered in the fingerprint scanner on Samsung Note20 mobile devices with Q(10.0) software. When a screen protector is used, the required image compensation is not present. Consequentl…
|
NVD-CWE-noinfo
|
CVE-2021-22494
|
2024-11-21 14:50 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|