|
195331
|
9.8 |
CRITICAL
Network
|
std42
|
elfinder
|
The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-23394
|
2024-11-21 14:51 |
2021-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195332
|
4.3 |
MEDIUM
Network
|
gallagher
|
command_centre
|
A SQL Injection vulnerability in the OPCUA interface of Gallagher Command Centre allows a remote unprivileged Command Centre Operator to modify Command Centre databases undetected. This issue affects…
|
CWE-89
SQL Injection
|
CVE-2021-23230
|
2024-11-21 14:51 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195333
|
4.4 |
MEDIUM
Local
|
gallagher
|
command_centre
|
Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows Cloud end-to-end encryption key to be discoverable in server memory dumps. This issue affe…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2021-23211
|
2024-11-21 14:51 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195334
|
8.1 |
HIGH
Network
|
gallagher
|
command_centre
|
Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator to alter the configuration of Controllers and other hardware items beyond their privilege. This issue…
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2021-23205
|
2024-11-21 14:51 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195335
|
6.5 |
MEDIUM
Network
|
gallagher
|
command_centre
|
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gallagher Command Centre Server allows OSDP key material to be exposed to Command Centre Operators. This issue affects: Gal…
|
CWE-862
Missing Authorization
|
CVE-2021-23204
|
2024-11-21 14:51 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195336
|
4.4 |
MEDIUM
Local
|
gallagher
|
command_centre
|
Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows OSDP reader master keys to be discoverable in server memory dumps. This issue affects: Gal…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2021-23182
|
2024-11-21 14:51 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195337
|
8.8 |
HIGH
Network
|
gallagher
|
command_centre
|
Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Command Centre Operator. This issue affects: Gallagher Command Cen…
|
NVD-CWE-Other
|
CVE-2021-23140
|
2024-11-21 14:51 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195338
|
6.5 |
MEDIUM
Network
|
gallagher
|
command_centre
|
Improper Authorization vulnerability in Gallagher Command Centre Server allows macro overrides to be performed by an unprivileged Command Centre Operator. This issue affects: Gallagher Command Centre…
|
NVD-CWE-Other
|
CVE-2021-23136
|
2024-11-21 14:51 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195339
|
5.4 |
MEDIUM
Network
|
flask_unchained_project
|
flask_unchained
|
This affects the package Flask-Unchained before 0.9.0. When using the the _validate_redirect_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing…
|
CWE-601
Open Redirect
|
CVE-2021-23393
|
2024-11-21 14:51 |
2021-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195340
|
7.8 |
HIGH
Local
|
f5
|
big-ip_access_policy_manager big-ip_access_policy_manager_client
|
On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, the BIG-IP Edge Client Windows Installer Service's temporary folder has weak file and folder permissions. Note: Software versions …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2021-23022
|
2024-11-21 14:51 |
2021-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|