|
195311
|
9.8 |
CRITICAL
Network
|
nodejs netapp oracle siemens
|
node.js snapcenter oncommand_workflow_automation oncommand_insight active_iq_unified_manager nextgen_api peoplesoft_enterprise_peopletools graalvm mysql_cluster sinec_infra…
|
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js d…
|
CWE-20
Improper Input Validation
|
CVE-2021-22931
|
2024-11-21 14:50 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195312
|
6.1 |
MEDIUM
Network
|
advantech
|
webaccess\/scada
|
UserExcelOut.asp within WebAccess/SCADA is vulnerable to cross-site scripting (XSS), which could allow an attacker to send malicious JavaScript code. This could result in hijacking of cookie/session …
|
CWE-79
Cross-site Scripting
|
CVE-2021-22676
|
2024-11-21 14:50 |
2021-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195313
|
6.5 |
MEDIUM
Network
|
advantech
|
webaccess\/scada
|
The affected product is vulnerable to a relative path traversal condition, which may allow an attacker access to unauthorized files and directories on the WebAccess/SCADA (WebAccess/SCADA versions pr…
|
CWE-22
Path Traversal
|
CVE-2021-22674
|
2024-11-21 14:50 |
2021-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195314
|
7.0 |
HIGH
Local
|
huawei
|
magic_ui emui
|
A component of the Huawei smartphone has a Double Free vulnerability. Local attackers may exploit this vulnerability to cause Root Elevation of Privileges.
|
CWE-415
Double Free
|
CVE-2021-22386
|
2024-11-21 14:50 |
2021-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195315
|
7.8 |
HIGH
Local
|
huawei
|
magic_ui emui
|
A component of the Huawei smartphone has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause Kernel Code Execution.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2021-22385
|
2024-11-21 14:50 |
2021-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195316
|
9.8 |
CRITICAL
Network
|
rocket.chat
|
rocket.chat
|
A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which could result in a NoSQL injection, potentially leading to RCE.
|
NVD-CWE-Other
|
CVE-2021-22910
|
2024-11-21 14:50 |
2021-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195317
|
7.8 |
HIGH
Local
|
citrix
|
xendesktop xenapp virtual_apps_and_desktops
|
A vulnerability has been identified in Citrix Virtual Apps and Desktops that could, if exploited, allow a user of a Windows VDA that has either Citrix Profile Management or Citrix Profile Management …
|
NVD-CWE-Other
|
CVE-2021-22928
|
2024-11-21 14:50 |
2021-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195318
|
8.1 |
HIGH
Network
|
citrix
|
application_delivery_controller_firmware netscaler_gateway gateway
|
A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session.
|
CWE-384
Session Fixation
|
CVE-2021-22927
|
2024-11-21 14:50 |
2021-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195319
|
7.5 |
HIGH
Network
|
haxx netapp oracle siemens splunk
|
curl snapcenter oncommand_workflow_automation oncommand_insight clustered_data_ontap solidfire hci_management_node active_iq_unified_manager peoplesoft_enterprise_peopletools<…
|
libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CURLOPT_SSLCERT` option (`--cert` with the command line tool).When libcurl is bui…
|
CWE-295
Improper Certificate Validation
|
CVE-2021-22926
|
2024-11-21 14:50 |
2021-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195320
|
5.3 |
MEDIUM
Network
|
haxx fedoraproject netapp apple oracle siemens splunk
|
curl fedora cloud_backup clustered_data_ontap solidfire hci_management_node macos mac_os_x peoplesoft_enterprise_peopletools mysql_server sinec_infrastructure_network_se…
|
curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parse…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2021-22925
|
2024-11-21 14:50 |
2021-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|