|
195091
|
7.8 |
HIGH
Local
|
schneider-electric
|
interactive_graphical_scada_system
|
A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which…
|
-
|
CVE-2021-22710
|
2024-11-21 14:50 |
2021-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195092
|
7.8 |
HIGH
Local
|
schneider-electric
|
interactive_graphical_scada_system
|
A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which…
|
-
|
CVE-2021-22709
|
2024-11-21 14:50 |
2021-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195093
|
4.8 |
MEDIUM
Network
|
nextcloud fedoraproject
|
nextcloud_server fedora
|
Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in `OC.Notification.show`.
|
CWE-79
Cross-site Scripting
|
CVE-2021-22878
|
2024-11-21 14:50 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195094
|
6.5 |
MEDIUM
Network
|
nextcloud fedoraproject
|
nextcloud_server fedora
|
A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration when not already configured yet.
|
CWE-862
Missing Authorization
|
CVE-2021-22877
|
2024-11-21 14:50 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195095
|
7.5 |
HIGH
Network
|
nodejs fedoraproject netapp oracle siemens
|
node.js fedora snapcenter oncommand_workflow_automation oncommand_insight active_iq_unified_manager e-series_performance_analyzer peoplesoft_enterprise_peopletools graalvm …
|
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordi…
|
NVD-CWE-Other
|
CVE-2021-22884
|
2024-11-21 14:50 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195096
|
7.5 |
HIGH
Network
|
nodejs fedoraproject netapp oracle siemens
|
node.js fedora e-series_performance_analyzer peoplesoft_enterprise_peopletools graalvm nosql_database mysql_cluster jd_edwards_enterpriseone_tools sinec_infrastructure_network…
|
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of …
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2021-22883
|
2024-11-21 14:50 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195097
|
9.8 |
CRITICAL
Network
|
rockwellautomation
|
factorytalk_services_platform rslogix_5000 studio_5000_logix_designer
|
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactL…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2021-22681
|
2024-11-21 14:50 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195098
|
7.8 |
HIGH
Local
|
fatek
|
fvdesigner
|
Fatek FvDesigner Version 1.5.76 and prior is vulnerable to an out-of-bounds write while processing project files, allowing an attacker to craft a special project file that may permit arbitrary code e…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-22683
|
2024-11-21 14:50 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195099
|
7.8 |
HIGH
Local
|
fatek
|
fvdesigner
|
An uninitialized pointer may be exploited in Fatek FvDesigner Version 1.5.76 and prior while the application is processing project files, allowing an attacker to craft a special project file that may…
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2021-22670
|
2024-11-21 14:50 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195100
|
7.8 |
HIGH
Local
|
fatek
|
fvdesigner
|
Fatek FvDesigner Version 1.5.76 and prior is vulnerable to a stack-based buffer overflow while project files are being processed, allowing an attacker to craft a special project file that may permit …
|
CWE-787
Out-of-bounds Write
|
CVE-2021-22666
|
2024-11-21 14:50 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|