|
195551
|
5.4 |
MEDIUM
Network
|
tecnick
|
tcexam
|
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_select_mediafile.php with a filename beggining with a period will be rendered as text/html. An att…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20112
|
2024-11-21 14:45 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195552
|
5.4 |
MEDIUM
Network
|
tecnick
|
tcexam
|
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_filemanager.php with a filename beggining with a period will be rendered as text/html. An attacker…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20111
|
2024-11-21 14:45 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195553
|
6.5 |
MEDIUM
Local
|
tenable
|
nessus
|
Nessus Agent versions 8.2.5 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus administrator user to upload a specially crafted file that could lead to …
|
NVD-CWE-noinfo
|
CVE-2021-20106
|
2024-11-21 14:45 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195554
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_assetexplorer
|
Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP addres…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2021-20110
|
2024-11-21 14:45 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195555
|
7.5 |
HIGH
Network
|
zohocorp
|
manageengine_assetexplorer
|
Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allo…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-20109
|
2024-11-21 14:45 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195556
|
7.5 |
HIGH
Network
|
zohocorp
|
manageengine_assetexplorer
|
Manage Engine Asset Explorer Agent 1.0.34 listens on port 9000 for incoming commands over HTTPS from Manage Engine Server. The HTTPS certificates are not verified which allows any arbitrary user on t…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2021-20108
|
2024-11-21 14:45 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195557
|
7.5 |
HIGH
Network
|
qualcomm
|
apq8053_firmware aqt1000_firmware ar8031_firmware ar8035_firmware csra6620_firmware csra6640_firmware csrb31024_firmware msm8953_firmware qca6175a_firmware qca6310_firmware…
|
Possible out of bound read due to lack of length check of FT sub-elements in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdrag…
|
CWE-20 CWE-125
Improper Input Validation Out-of-bounds Read
|
CVE-2021-1970
|
2024-11-21 14:45 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195558
|
9.8 |
CRITICAL
Network
|
qualcomm
|
aqt1000_firmware ar9380_firmware csr8811_firmware ipq4018_firmware ipq4019_firmware ipq4028_firmware ipq4029_firmware ipq5010_firmware ipq5018_firmware ipq5028_firmware …
|
Possible buffer overflow due to lack of parameter length check during MBSSID scan IE parse in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wired Infrast…
|
CWE-20 CWE-120
Improper Input Validation Classic Buffer Overflow
|
CVE-2021-1965
|
2024-11-21 14:45 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195559
|
7.8 |
HIGH
Local
|
qualcomm
|
aqt1000_firmware ar8031_firmware ar8035_firmware csra6620_firmware csra6640_firmware fsm10055_firmware fsm10056_firmware qca6391_firmware qca6420_firmware qca6430_firmware<…
|
Use after free can occur due to improper handling of response from firmware in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon V…
|
CWE-416
Use After Free
|
CVE-2021-1940
|
2024-11-21 14:45 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195560
|
6.7 |
MEDIUM
Local
|
qualcomm
|
aqt1000_firmware ar8031_firmware ar8035_firmware csra6620_firmware csra6640_firmware csrb31024_firmware fsm10055_firmware fsm10056_firmware qca6174a_firmware qca6310_firmwa…
|
Possible buffer overflow due to improper validation of buffer length while processing fast boot commands in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snap…
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-1931
|
2024-11-21 14:45 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|