|
195401
|
8.8 |
HIGH
Network
|
combodo
|
itop
|
Combodo iTop is an open source, web based IT Service Management tool. In versions prior to 2.7.4, there is a command injection vulnerability in the Setup Wizard when providing Graphviz executable pat…
|
CWE-77
Command Injection
|
CVE-2021-21406
|
2024-11-21 14:48 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195402
|
6.1 |
MEDIUM
Network
|
advantech
|
r-seenet
|
Cross-site scripting vulnerabilities exist in the ssh_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can lead to arbitrary Jav…
|
CWE-79
Cross-site Scripting
|
CVE-2021-21800
|
2024-11-21 14:48 |
2021-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195403
|
6.1 |
MEDIUM
Network
|
advantech
|
r-seenet
|
Cross-site scripting vulnerabilities exist in the telnet_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can lead to arbitrary …
|
CWE-79
Cross-site Scripting
|
CVE-2021-21799
|
2024-11-21 14:48 |
2021-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195404
|
3.3 |
LOW
Local
|
dell
|
wyse_management_suite
|
Dell Wyse Management Suite versions 3.2 and earlier contain a full path disclosure vulnerability. A local unauthenticated attacker could exploit this vulnerability in order to obtain the path of file…
|
CWE-200
Information Exposure
|
CVE-2021-21587
|
2024-11-21 14:48 |
2021-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195405
|
6.5 |
MEDIUM
Network
|
dell
|
wyse_management_suite
|
Wyse Management Suite versions 3.2 and earlier contain an absolute path traversal vulnerability. A remote authenticated malicious user could exploit this vulnerability in order to read arbitrary file…
|
CWE-22
Path Traversal
|
CVE-2021-21586
|
2024-11-21 14:48 |
2021-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195406
|
6.7 |
MEDIUM
Local
|
dell
|
emc_unity_operating_environment emc_unityvsa_operating_environment emc_unity_xt_operating_environment
|
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2021-21591
|
2024-11-21 14:48 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195407
|
6.7 |
MEDIUM
Local
|
dell
|
emc_unity_operating_environment emc_unityvsa_operating_environment emc_unity_xt_operating_environment
|
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2021-21590
|
2024-11-21 14:48 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195408
|
6.7 |
MEDIUM
Local
|
dell
|
emc_unity_operating_environment emc_unityvsa_operating_environment emc_unity_xt_operating_environment
|
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 do not exit on failed Initialization. A local authenticated Service user could potentially exploit this vulnerability to escalat…
|
NVD-CWE-Other
|
CVE-2021-21589
|
2024-11-21 14:48 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195409
|
4.3 |
MEDIUM
Network
|
dell
|
powerflex_presentation_server
|
Dell EMC PowerFlex, v3.5.x contain a Cross-Site WebSocket Hijacking Vulnerability in the Presentation Server/WebUI. An unauthenticated attacker could potentially exploit this vulnerability by trickin…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2021-21588
|
2024-11-21 14:48 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195410
|
7.8 |
HIGH
Local
|
accusoft
|
imagegear
|
An out-of-bounds write vulnerability exists in the TIF bits_per_sample processing functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to memory corruption. An attack…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-21794
|
2024-11-21 14:48 |
2021-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|