|
195881
|
7.5 |
HIGH
Network
|
ibm
|
security_verify_bridge
|
IBM Security Verify Bridge contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, o…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2021-20442
|
2024-11-21 14:46 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195882
|
5.9 |
MEDIUM
Network
|
ibm
|
security_verify_bridge
|
IBM Security Verify Bridge uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196617.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2021-20441
|
2024-11-21 14:46 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195883
|
8.2 |
HIGH
Local
|
gnu redhat fedoraproject netapp
|
grub2 enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux enterprise_linux_server_tus enterprise_linux_server_eus fedora ontap_select_deploy_administration_…
|
A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 …
|
CWE-787
Out-of-bounds Write
|
CVE-2021-20233
|
2024-11-21 14:46 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195884
|
6.7 |
MEDIUM
Local
|
gnu redhat fedoraproject netapp
|
grub2 enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux enterprise_linux_server_tus enterprise_linux_server_eus fedora ontap_select_deploy_administration_…
|
A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a heap-allocated buffer by calling certain commands with a large number of specific …
|
CWE-787
Out-of-bounds Write
|
CVE-2021-20225
|
2024-11-21 14:46 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195885
|
3.2 |
LOW
Local
|
qemu fedoraproject debian
|
qemu fedora debian_linux
|
An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameter…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2021-20203
|
2024-11-21 14:46 |
2021-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195886
|
6.8 |
MEDIUM
Adjacent
|
mongodb quarkus
|
java_driver quarkus
|
Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KMS server’s certificate. This vulnerability in comb…
|
CWE-295
Improper Certificate Validation
|
CVE-2021-20328
|
2024-11-21 14:46 |
2021-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195887
|
6.8 |
MEDIUM
Adjacent
|
mongodb
|
libmongocrypt
|
A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate. This vulnerability in combination with a privileged network pos…
|
CWE-295
Improper Certificate Validation
|
CVE-2021-20327
|
2024-11-21 14:46 |
2021-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195888
|
7.5 |
HIGH
Network
|
contec
|
sv-cpt-mc310_firmware
|
Missing authentication for critical function in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to alter the setting information without the access privileges via unspecified vecto…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-20662
|
2024-11-21 14:46 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195889
|
8.1 |
HIGH
Network
|
contec
|
sv-cpt-mc310_firmware
|
Directory traversal vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows authenticated attackers to delete arbitrary files and/or directories on the server via unspecified vectors.
|
CWE-22
Path Traversal
|
CVE-2021-20661
|
2024-11-21 14:46 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195890
|
6.1 |
MEDIUM
Network
|
contec
|
sv-cpt-mc310_firmware
|
Cross-site scripting vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to inject an arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20660
|
2024-11-21 14:46 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|