|
195121
|
5.4 |
MEDIUM
Network
|
koa-remove-trailing-slashes_project
|
koa-remove-trailing-slashes
|
The package koa-remove-trailing-slashes before 2.0.2 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as https://example.…
|
CWE-601
Open Redirect
|
CVE-2021-23384
|
2024-11-21 14:51 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195122
|
5.5 |
MEDIUM
Local
|
argoproj
|
argo_cd
|
Exposure of System Data to an Unauthorized Control Sphere vulnerability in web UI of Argo CD allows attacker to cause leaked secret data into web UI error messages and logs. This issue affects Argo C…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2021-23135
|
2024-11-21 14:51 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195123
|
7.8 |
HIGH
Local
|
linux fedoraproject debian
|
linux_kernel fedora debian_linux
|
Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privi…
|
CWE-416
Use After Free
|
CVE-2021-23134
|
2024-11-21 14:51 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195124
|
7.8 |
HIGH
Local
|
mcafee
|
total_protection
|
Privilege Escalation vulnerability in the File Lock component of McAfee Total Protection (MTP) prior to 16.0.32 allows a local user to gain elevated privileges by manipulating a symbolic link in the …
|
CWE-59
Link Following
|
CVE-2021-23872
|
2024-11-21 14:51 |
2021-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195125
|
5.3 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager
|
On BIG-IP APM versions 15.1.x before 15.1.3, 14.1.x before 14.1.4.1, 13.1.x before 13.1.4, and all versions of 16.0.x, 12.1.x, and 11.6.x, an attacker may be able to bypass APM's internal restriction…
|
NVD-CWE-noinfo
|
CVE-2021-23016
|
2024-11-21 14:51 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195126
|
7.2 |
HIGH
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_analytics big-ip_application_security_manager big-ip_domain_name_system …
|
On BIG-IP 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.0.8 through 13.1.3.6, and all versions of 16.0.x, when running in Appliance Mode, an authenticated user assigned the 'Administrator' role …
|
CWE-863
Incorrect Authorization
|
CVE-2021-23015
|
2024-11-21 14:51 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195127
|
8.8 |
HIGH
Network
|
f5
|
big-ip_application_security_manager big-ip_advanced_web_application_firewall
|
On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, and 14.1.x before 14.1.4, BIG-IP Advanced WAF and ASM are missing authorization checks for file uploads to a specific directory within the RE…
|
CWE-862
Missing Authorization
|
CVE-2021-23014
|
2024-11-21 14:51 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195128
|
7.5 |
HIGH
Network
|
f5
|
big-ip_application_security_manager
|
On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and 12.1.x before 12.1.5.3, when the BIG-IP ASM/Advanced WAF system processes WebSocket reque…
|
NVD-CWE-noinfo
|
CVE-2021-23010
|
2024-11-21 14:51 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195129
|
8.2 |
HIGH
Local
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_analytics big-ip_application_security_manager big-ip_domain_name_system …
|
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, and 13.1.x before 13.1.4, lack of input validation for items used in the system support functionality may allow …
|
CWE-78
OS Command
|
CVE-2021-23012
|
2024-11-21 14:51 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195130
|
7.5 |
HIGH
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_analytics big-ip_application_security_manager big-ip_domain_name_system …
|
On BIG-IP version 16.0.x before 16.0.1.1 and 15.1.x before 15.1.3, malformed HTTP/2 requests may cause an infinite loop which causes a Denial of Service for Data Plane traffic. TMM takes the configur…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2021-23009
|
2024-11-21 14:51 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|