|
195111
|
7.8 |
HIGH
Local
|
luxion siemens
|
keyshot_network_rendering keyvr keyshot_viewer keyshot solid_edge_se2020_firmware solid_edge_se2021_firmware
|
Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10.1 are vulnerable to…
|
-
|
CVE-2021-22647
|
2024-11-21 14:50 |
2021-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195112
|
7.8 |
HIGH
Local
|
luxion siemens
|
keyshot_network_rendering keyvr keyshot_viewer keyshot solid_edge_se2020_firmware solid_edge_se2021_firmware
|
Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10.1 are vulnerable to…
|
-
|
CVE-2021-22643
|
2024-11-21 14:50 |
2021-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195113
|
7.8 |
HIGH
Local
|
luxion siemens
|
keyshot_network_rendering keyvr keyshot_viewer keyshot solid_edge_se2020_firmware solid_edge_se2021_firmware
|
Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10.1 are vulnerable to…
|
NVD-CWE-Other
|
CVE-2021-22645
|
2024-11-21 14:50 |
2021-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195114
|
7.5 |
HIGH
Network
|
schneider-electric
|
powerlogic_ion7400_firmware powerlogic_ion7650_firmware powerlogic_ion8600_firmware powerlogic_ion8650_firmware powerlogic_ion8800_firmware powerlogic_ion9000_firmware powerlogic_pm…
|
A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affec…
|
-
|
CVE-2021-22703
|
2024-11-21 14:50 |
2021-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195115
|
7.5 |
HIGH
Network
|
schneider-electric
|
powerlogic_ion7400_firmware powerlogic_ion7650_firmware powerlogic_ion7700_firmware powerlogic_ion7300_firmware powerlogic_ion8600_firmware powerlogic_ion8650_firmware powerlogic_io…
|
A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION7700/73xx, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notifica…
|
-
|
CVE-2021-22702
|
2024-11-21 14:50 |
2021-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195116
|
4.5 |
MEDIUM
Network
|
schneider-electric
|
powerlogic_ion7400_firmware powerlogic_ion7650_firmware powerlogic_ion8600_firmware powerlogic_ion8650_firmware powerlogic_ion8800_firmware powerlogic_ion9000_firmware powerlogic_pm…
|
A CWE-352: Cross-Site Request Forgery vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that c…
|
-
|
CVE-2021-22701
|
2024-11-21 14:50 |
2021-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195117
|
9.8 |
CRITICAL
Network
|
hr_portal_project
|
hr_portal
|
The specific function of HR Portal of Soar Cloud System accepts any type of object to be deserialized. Attackers can send malicious serialized objects to execute arbitrary commands.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-22855
|
2024-11-21 14:50 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195118
|
7.5 |
HIGH
Network
|
hr_portal_project
|
hr_portal
|
The HR Portal of Soar Cloud System fails to filter specific parameters. Remote attackers can inject SQL syntax and obtain all data in the database without privilege.
|
CWE-89
SQL Injection
|
CVE-2021-22854
|
2024-11-21 14:50 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195119
|
5.4 |
MEDIUM
Network
|
hr_portal_project
|
hr_portal
|
The HR Portal of Soar Cloud System fails to manage access control. While obtaining user ID, remote attackers can access sensitive data via a specific data packet, such as user’s login information, fu…
|
NVD-CWE-Other
|
CVE-2021-22853
|
2024-11-21 14:50 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195120
|
7.5 |
HIGH
Network
|
google
|
gerrit
|
Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not automatically dispose of the session. Over multiple git actions, this can lead …
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2021-22553
|
2024-11-21 14:50 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|