|
195181
|
8.8 |
HIGH
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_analytics big-ip_application_security_manager big-ip_domain_name_system …
|
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, TMUI, also referred to as the Conf…
|
NVD-CWE-noinfo
|
CVE-2021-22988
|
2024-11-21 14:51 |
2021-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195182
|
9.8 |
CRITICAL
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_analytics big-ip_application_security_manager big-ip_domain_name_system …
|
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-22986
|
2024-11-21 14:51 |
2021-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195183
|
8.8 |
HIGH
Network
|
kill-by-port_project
|
kill-by-port
|
This affects the package kill-by-port before 0.0.2. If (attacker-controlled) user input is given to the killByPort function, it is possible for an attacker to execute arbitrary commands. This is due …
|
CWE-78
OS Command
|
CVE-2021-23363
|
2024-11-21 14:51 |
2021-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195184
|
7.2 |
HIGH
Network
|
underscorejs debian tenable fedoraproject
|
underscore debian_linux tenable.sc fedora
|
The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is p…
|
CWE-94
Code Injection
|
CVE-2021-23358
|
2024-11-21 14:51 |
2021-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195185
|
5.3 |
MEDIUM
Network
|
npmjs siemens
|
hosted-git-info sinec_infrastructure_network_services
|
The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular …
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2021-23362
|
2024-11-21 14:51 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195186
|
9.8 |
CRITICAL
Network
|
tibco
|
api_exchange_gateway_distribution api_exchange_gateway
|
The Config UI component of TIBCO Software Inc.'s TIBCO API Exchange Gateway and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically allows an u…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2021-23274
|
2024-11-21 14:51 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195187
|
8.8 |
HIGH
Network
|
killport_project
|
killport
|
This affects the package killport before 1.0.2. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exe…
|
CWE-78
OS Command
|
CVE-2021-23360
|
2024-11-21 14:51 |
2021-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195188
|
8.8 |
HIGH
Network
|
port-killer_project
|
port-killer
|
This affects all versions of package port-killer. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process e…
|
CWE-78
OS Command
|
CVE-2021-23359
|
2024-11-21 14:51 |
2021-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195189
|
6.7 |
MEDIUM
Local
|
mcafee
|
endpoint_product_removal_tool
|
Unquoted service path vulnerability in McAfee Endpoint Product Removal (EPR) Tool prior to 21.2 allows local administrators to execute arbitrary code, with higher-level privileges, via execution from…
|
CWE-428
Unquoted Search Path or Element
|
CVE-2021-23879
|
2024-11-21 14:51 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195190
|
5.3 |
MEDIUM
Local
|
tyk
|
tyk
|
All versions of package github.com/tyktechnologies/tyk/gateway are vulnerable to Directory Traversal via the handleAddOrUpdateApi function. This function is able to delete arbitrary JSON files on the…
|
CWE-22
Path Traversal
|
CVE-2021-23357
|
2024-11-21 14:51 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|