|
195291
|
6.7 |
MEDIUM
Local
|
gnu redhat fedoraproject netapp
|
grub2 enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux enterprise_linux_server_tus enterprise_linux_server_eus fedora ontap_select_deploy_administration_…
|
A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a heap-allocated buffer by calling certain commands with a large number of specific …
|
CWE-787
Out-of-bounds Write
|
CVE-2021-20225
|
2024-11-21 14:46 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195292
|
3.2 |
LOW
Local
|
qemu fedoraproject debian
|
qemu fedora debian_linux
|
An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameter…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2021-20203
|
2024-11-21 14:46 |
2021-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195293
|
6.8 |
MEDIUM
Adjacent
|
mongodb quarkus
|
java_driver quarkus
|
Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KMS server’s certificate. This vulnerability in comb…
|
CWE-295
Improper Certificate Validation
|
CVE-2021-20328
|
2024-11-21 14:46 |
2021-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195294
|
6.8 |
MEDIUM
Adjacent
|
mongodb
|
libmongocrypt
|
A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate. This vulnerability in combination with a privileged network pos…
|
CWE-295
Improper Certificate Validation
|
CVE-2021-20327
|
2024-11-21 14:46 |
2021-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195295
|
7.5 |
HIGH
Network
|
contec
|
sv-cpt-mc310_firmware
|
Missing authentication for critical function in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to alter the setting information without the access privileges via unspecified vecto…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-20662
|
2024-11-21 14:46 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195296
|
8.1 |
HIGH
Network
|
contec
|
sv-cpt-mc310_firmware
|
Directory traversal vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows authenticated attackers to delete arbitrary files and/or directories on the server via unspecified vectors.
|
CWE-22
Path Traversal
|
CVE-2021-20661
|
2024-11-21 14:46 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195297
|
6.1 |
MEDIUM
Network
|
contec
|
sv-cpt-mc310_firmware
|
Cross-site scripting vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to inject an arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20660
|
2024-11-21 14:46 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195298
|
8.8 |
HIGH
Network
|
contec
|
sv-cpt-mc310_firmware
|
SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecified vectors. If the file is PHP script, an attacker may execute arbitrary code.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-20659
|
2024-11-21 14:46 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195299
|
9.8 |
CRITICAL
Network
|
contec
|
sv-cpt-mc310_firmware
|
SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server privilege via unspecified vectors.
|
CWE-78
OS Command
|
CVE-2021-20658
|
2024-11-21 14:46 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195300
|
5.4 |
MEDIUM
Network
|
contec
|
sv-cpt-mc310_firmware
|
Improper access control vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to obtain and/or alter the setting information without the access privilege v…
|
NVD-CWE-Other
|
CVE-2021-20657
|
2024-11-21 14:46 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|