|
195031
|
9.8 |
CRITICAL
Network
|
ps-visitor_project
|
ps-visitor
|
This affects all versions of package ps-visitor. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of t…
|
CWE-78
OS Command
|
CVE-2021-23374
|
2024-11-21 14:51 |
2021-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195032
|
7.0 |
HIGH
Local
|
linux fedoraproject debian netapp broadcom
|
linux_kernel fedora debian_linux cloud_backup solidfire_\&_hci_management_node brocade_fabric_operating_system h410c_firmware h300s_firmware h500s_firmware h700s_firmwa…
|
A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_des…
|
CWE-362
Race Condition
|
CVE-2021-23133
|
2024-11-21 14:51 |
2021-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195033
|
7.5 |
HIGH
Network
|
mongo-express_project
|
mongo-express
|
All versions of package mongo-express are vulnerable to Denial of Service (DoS) when exporting an empty collection as CSV, due to an unhandled exception, leading to a crash.
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2021-23372
|
2024-11-21 14:51 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195034
|
10.0 |
CRITICAL
Network
|
eaton
|
intelligent_power_manager
|
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated remote code execution vulnerability. IPM software does not sanitize the date provided via coverterCheckList action…
|
CWE-94
Code Injection
|
CVE-2021-23281
|
2024-11-21 14:51 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195035
|
9.9 |
CRITICAL
Network
|
eaton
|
intelligent_power_manager intelligent_power_manager_virtual_appliance intelligent_power_protector
|
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file upload vulnerability. IPM’s maps_srv.js allows an attacker to upload a malicious NodeJS file using up…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-23280
|
2024-11-21 14:51 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195036
|
10.0 |
CRITICAL
Network
|
eaton
|
intelligent_power_manager intelligent_power_manager_virtual_appliance intelligent_power_protector
|
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated arbitrary file delete vulnerability induced due to improper input validation in meta_driver_srv.js class with save…
|
CWE-20
Improper Input Validation
|
CVE-2021-23279
|
2024-11-21 14:51 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195037
|
9.6 |
CRITICAL
Network
|
eaton
|
intelligent_power_manager intelligent_power_manager_virtual_appliance intelligent_power_protector
|
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file delete vulnerability induced due to improper input validation at server/maps_srv.js with action remov…
|
NVD-CWE-noinfo
|
CVE-2021-23278
|
2024-11-21 14:51 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195038
|
10.0 |
CRITICAL
Network
|
eaton
|
intelligent_power_manager intelligent_power_manager_virtual_appliance intelligent_power_protector
|
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated eval injection vulnerability. The software does not neutralize code syntax from users before using in the dynamic …
|
CWE-94
Code Injection
|
CVE-2021-23277
|
2024-11-21 14:51 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195039
|
8.8 |
HIGH
Network
|
eaton
|
intelligent_power_manager intelligent_power_manager_virtual_appliance intelligent_power_protector
|
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated SQL injection. A malicious user can send a specially crafted packet to exploit the vulnerability. Successful exploit…
|
CWE-89
SQL Injection
|
CVE-2021-23276
|
2024-11-21 14:51 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195040
|
7.5 |
HIGH
Network
|
gargoyle-router
|
gargoyle
|
In Gargoyle OS 1.12.0, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and its upstream ISP's router. This occurs when a link prefix ro…
|
CWE-834
Excessive Iteration
|
CVE-2021-23270
|
2024-11-21 14:51 |
2021-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|