|
195391
|
9.1 |
CRITICAL
Network
|
schneider-electric
|
ecostruxure_process_expert ecostruxure_control_expert remoteconnect modicon_m580_bmep581020_firmware modicon_m580_bmep581020h_firmware modicon_m580_bmep582020_firmware modicon_m580_…
|
Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoS…
|
-
|
CVE-2021-22779
|
2024-11-21 14:50 |
2021-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195392
|
4.6 |
MEDIUM
Physics
|
huawei
|
mate_20_firmware mate_20_pro_firmware hima-l29c_firmware laya-al00ep_firmware oxfords-an00a_firmware tony-al00b_firmware
|
There is a path traversal vulnerability in some Huawei products. The vulnerability is due to that the software uses external input to construct a pathname that is intended to identify a file or direc…
|
CWE-22
Path Traversal
|
CVE-2021-22440
|
2024-11-21 14:50 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195393
|
5.5 |
MEDIUM
Local
|
huawei
|
p30_firmware
|
The Bluetooth function of some Huawei smartphones has a DoS vulnerability. Attackers can install third-party apps to send specific broadcasts, causing the Bluetooth module to crash. This vulnerabilit…
|
NVD-CWE-noinfo
|
CVE-2021-22399
|
2024-11-21 14:50 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195394
|
7.8 |
HIGH
Local
|
nodejs siemens
|
node.js sinec_infrastructure_network_services
|
Node.js before 16.4.1, 14.17.2, and 12.22.2 is vulnerable to local privilege escalation attacks under certain conditions on Windows platforms. More specifically, improper configuration of permissions…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2021-22921
|
2024-11-21 14:50 |
2021-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195395
|
5.3 |
MEDIUM
Network
|
nodejs siemens
|
node.js sinec_infrastructure_network_services
|
Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whethe…
|
CWE-125
Out-of-bounds Read
|
CVE-2021-22918
|
2024-11-21 14:50 |
2021-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195396
|
6.5 |
MEDIUM
Network
|
brave
|
browser
|
Brave Browser Desktop between versions 1.17 and 1.20 is vulnerable to information disclosure by way of DNS requests in Tor windows not flowing through Tor if adblocking was enabled.
|
NVD-CWE-Other
|
CVE-2021-22917
|
2024-11-21 14:50 |
2021-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195397
|
5.9 |
MEDIUM
Network
|
brave
|
brave
|
In Brave Desktop between versions 1.17 and 1.26.60, when adblocking is enabled and a proxy browser extension is installed, the CNAME adblocking feature issues DNS requests that used the system DNS se…
|
NVD-CWE-Other
|
CVE-2021-22916
|
2024-11-21 14:50 |
2021-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195398
|
6.5 |
MEDIUM
Network
|
microfocus
|
netiq_advanced_authentication
|
Multi-Factor Authentication (MFA) functionality can be bypassed, allowing the use of single factor authentication in NetIQ Advanced Authentication versions prior to 6.3 SP4 Patch 1.
|
CWE-863
Incorrect Authorization
|
CVE-2021-22515
|
2024-11-21 14:50 |
2021-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195399
|
7.8 |
HIGH
Local
|
linux brocade netapp
|
linux_kernel fabric_operating_system fas_8300_firmware fas_8700_firmware aff_a400_firmware aff_a250_firmware aff_500f_firmware h610c_firmware h610s_firmware h615c_firmware<…
|
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-22555
|
2024-11-21 14:50 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195400
|
7.5 |
HIGH
Network
|
huawei
|
magic_ui emui
|
There is an Improper Validation of Array Index Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause stability risks.
|
CWE-129
Improper Validation of Array Index
|
CVE-2021-22374
|
2024-11-21 14:50 |
2021-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|