|
195501
|
6.5 |
MEDIUM
Network
|
github
|
enterprise_server
|
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were no…
|
CWE-22
Path Traversal
|
CVE-2021-22867
|
2024-11-21 14:50 |
2021-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195502
|
5.5 |
MEDIUM
Local
|
schneider-electric
|
ecostruxure_process_expert ecostruxure_control_expert remoteconnect
|
Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all version…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2021-22781
|
2024-11-21 14:50 |
2021-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195503
|
7.1 |
HIGH
Local
|
schneider-electric
|
ecostruxure_process_expert ecostruxure_control_expert remoteconnect
|
Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all version…
|
-
|
CVE-2021-22778
|
2024-11-21 14:50 |
2021-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195504
|
5.5 |
MEDIUM
Local
|
schneider-electric
|
ecostruxure_process_expert ecostruxure_control_expert remoteconnect
|
Missing Encryption of Sensitive Data vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all version…
|
-
|
CVE-2021-22782
|
2024-11-21 14:50 |
2021-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195505
|
7.1 |
HIGH
Local
|
schneider-electric
|
ecostruxure_process_expert ecostruxure_control_expert remoteconnect
|
Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all version…
|
-
|
CVE-2021-22780
|
2024-11-21 14:50 |
2021-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195506
|
9.1 |
CRITICAL
Network
|
schneider-electric
|
ecostruxure_process_expert ecostruxure_control_expert remoteconnect modicon_m580_bmep581020_firmware modicon_m580_bmep581020h_firmware modicon_m580_bmep582020_firmware modicon_m580_…
|
Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoS…
|
-
|
CVE-2021-22779
|
2024-11-21 14:50 |
2021-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195507
|
4.6 |
MEDIUM
Physics
|
huawei
|
mate_20_firmware mate_20_pro_firmware hima-l29c_firmware laya-al00ep_firmware oxfords-an00a_firmware tony-al00b_firmware
|
There is a path traversal vulnerability in some Huawei products. The vulnerability is due to that the software uses external input to construct a pathname that is intended to identify a file or direc…
|
CWE-22
Path Traversal
|
CVE-2021-22440
|
2024-11-21 14:50 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195508
|
5.5 |
MEDIUM
Local
|
huawei
|
p30_firmware
|
The Bluetooth function of some Huawei smartphones has a DoS vulnerability. Attackers can install third-party apps to send specific broadcasts, causing the Bluetooth module to crash. This vulnerabilit…
|
NVD-CWE-noinfo
|
CVE-2021-22399
|
2024-11-21 14:50 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195509
|
7.8 |
HIGH
Local
|
nodejs siemens
|
node.js sinec_infrastructure_network_services
|
Node.js before 16.4.1, 14.17.2, and 12.22.2 is vulnerable to local privilege escalation attacks under certain conditions on Windows platforms. More specifically, improper configuration of permissions…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2021-22921
|
2024-11-21 14:50 |
2021-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195510
|
5.3 |
MEDIUM
Network
|
nodejs siemens
|
node.js sinec_infrastructure_network_services
|
Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whethe…
|
CWE-125
Out-of-bounds Read
|
CVE-2021-22918
|
2024-11-21 14:50 |
2021-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|