|
195271
|
6.1 |
MEDIUM
Network
|
aterm
|
wg2600hp_firmware
|
Cross-site scripting vulnerability in Aterm WF800HP firmware Ver1.0.9 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20620
|
2024-11-21 14:46 |
2021-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195272
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rhapsody_design_manager rational_engineering_lifecycle_manager rhapsody_model_manager engineering_workflow_management collaborative_lifecycle_management eng…
|
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potential…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20357
|
2024-11-21 14:46 |
2021-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195273
|
8.1 |
HIGH
Network
|
fasterxml netapp apache debian oracle
|
jackson-databind oncommand_insight service_level_manager oncommand_api_services active_iq_unified_manager nifi debian_linux commerce_guided_search_and_experience_manager
|
A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidential…
|
-
|
CVE-2021-20190
|
2024-11-21 14:46 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195274
|
6.1 |
MEDIUM
Network
|
weseek
|
growi
|
Cross-site scripting vulnerability in GROWI (v4.2 Series) versions prior to v4.2.3 allows remote attackers to inject an arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20619
|
2024-11-21 14:46 |
2021-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195275
|
9.8 |
CRITICAL
Network
|
acmailer
|
acmailer_db acmailer
|
Privilege chaining vulnerability in acmailer ver. 4.0.2 and earlier, and acmailer DB ver. 1.1.4 and earlier allows remote attackers to bypass authentication and to gain an administrative privilege wh…
|
CWE-269
Improper Privilege Management
|
CVE-2021-20618
|
2024-11-21 14:46 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195276
|
9.8 |
CRITICAL
Network
|
acmailer
|
acmailer acmailer_db
|
Improper access control vulnerability in acmailer ver. 4.0.1 and earlier, and acmailer DB ver. 1.1.3 and earlier allows remote attackers to execute an arbitrary OS command, or gain an administrative …
|
NVD-CWE-Other
|
CVE-2021-20617
|
2024-11-21 14:46 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195277
|
7.8 |
HIGH
Local
|
skygroup
|
skysea_client_view
|
Untrusted search path vulnerability in the installer of SKYSEA Client View Ver.1.020.05b to Ver.16.001.01g allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2021-20616
|
2024-11-21 14:46 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195278
|
7.5 |
HIGH
Network
|
sonicwall
|
global_management_system
|
SonicWall GMS is vulnerable to file path manipulation resulting that an unauthenticated attacker can gain access to web directory containing application's binaries and configuration files.
|
CWE-22
Path Traversal
|
CVE-2021-20030
|
2024-11-21 14:45 |
2022-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195279
|
7.8 |
HIGH
Local
|
sonicwall
|
global_vpn_client
|
SonicWall Global VPN Client 4.10.7.1117 installer (32-bit and 64-bit) and earlier versions have a DLL Search Order Hijacking vulnerability in one of the installer components. Successful exploitation …
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2021-20051
|
2024-11-21 14:45 |
2022-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195280
|
7.8 |
HIGH
Local
|
qualcomm
|
ar8035_firmware csr8811_firmware ipq6000_firmware ipq6005_firmware ipq6010_firmware ipq6018_firmware ipq6028_firmware qca4024_firmware qca6390_firmware qca6391_firmware …
|
Improper cleaning of secure memory between authenticated users can lead to face authentication bypass in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapd…
|
CWE-287
Improper Authentication
|
CVE-2021-1950
|
2024-11-21 14:45 |
2022-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|