|
195511
|
9.8 |
CRITICAL
Network
|
microfocus
|
operations_bridge_manager
|
Authentication bypass vulnerability in Micro Focus Operations Bridge Manager affects versions 2019.05, 2019.11, 2020.05 and 2020.10. The vulnerability could allow remote attackers to bypass user auth…
|
CWE-287
Improper Authentication
|
CVE-2021-22507
|
2024-11-21 14:50 |
2021-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195512
|
6.5 |
MEDIUM
Network
|
github
|
enterprise_server
|
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed access tokens generated from a GitHub App's web authentication flow to read private repository metadat…
|
NVD-CWE-Other
|
CVE-2021-22865
|
2024-11-21 14:50 |
2021-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195513
|
7.5 |
HIGH
Network
|
apache oracle
|
cxf business_intelligence communications_session_route_manager communications_session_report_manager communications_element_manager communications_diameter_intelligence_hub
|
CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR))…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-22696
|
2024-11-21 14:50 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195514
|
3.7 |
LOW
Network
|
haxx fedoraproject netapp broadcom debian siemens oracle splunk
|
libcurl fedora solidfire hci_management_node hci_storage_node fabric_operating_system debian_linux sinec_infrastructure_network_services communications_billing_and_revenue_man…
|
curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2021-22890
|
2024-11-21 14:50 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195515
|
5.3 |
MEDIUM
Network
|
haxx fedoraproject netapp broadcom debian siemens oracle splunk
|
libcurl fedora solidfire hci_management_node hci_storage_node hci_compute_node fabric_operating_system debian_linux sinec_infrastructure_network_services communications_bil…
|
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip o…
|
CWE-200
Information Exposure
|
CVE-2021-22876
|
2024-11-21 14:50 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195516
|
8.8 |
HIGH
Network
|
google
|
exposure_notifications_verification_server
|
A privilege escalation vulnerability impacting the Google Exposure Notification Verification Server (versions prior to 0.23.1), allows an attacker who (1) has UserWrite permissions and (2) is using a…
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-22538
|
2024-11-21 14:50 |
2021-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195517
|
6.1 |
MEDIUM
Network
|
rocket.chat
|
rocket.chat
|
Rocket.Chat before 3.11, 3.10.5, 3.9.7, 3.8.8 is vulnerable to persistent cross-site scripting (XSS) using nested markdown tags allowing a remote attacker to inject arbitrary JavaScript in a message.…
|
CWE-79
Cross-site Scripting
|
CVE-2021-22886
|
2024-11-21 14:50 |
2021-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195518
|
7.5 |
HIGH
Network
|
microfocus
|
access_manager
|
Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage.
|
NVD-CWE-noinfo
|
CVE-2021-22506
|
2024-11-21 14:50 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195519
|
6.1 |
MEDIUM
Network
|
revive-adserver
|
revive_adserver
|
Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `statsBreakdown` parameter of stats.php (and possibly other scripts) due to single quotes not being escaped. An att…
|
CWE-79
Cross-site Scripting
|
CVE-2021-22889
|
2024-11-21 14:50 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195520
|
6.1 |
MEDIUM
Network
|
revive-adserver
|
revive_adserver
|
Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `status` parameter of campaign-zone-zones.php. An attacker could trick a user with access to the user interface of …
|
CWE-79
Cross-site Scripting
|
CVE-2021-22888
|
2024-11-21 14:50 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|