|
195571
|
8.1 |
HIGH
Network
|
machform
|
machform
|
Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments uploaded with forms through upload.php.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-20104
|
2024-11-21 14:45 |
2021-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195572
|
6.1 |
MEDIUM
Network
|
machform
|
machform
|
Machform prior to version 16 is vulnerable to stored cross-site scripting due to insufficient sanitization of file attachments uploaded with forms through upload.php.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20103
|
2024-11-21 14:45 |
2021-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195573
|
8.8 |
HIGH
Network
|
machform
|
machform
|
Machform prior to version 16 is vulnerable to cross-site request forgery due to a lack of CSRF tokens in place.
|
CWE-352
Origin Validation Error
|
CVE-2021-20102
|
2024-11-21 14:45 |
2021-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195574
|
6.1 |
MEDIUM
Network
|
machform
|
machform
|
Machform prior to version 16 is vulnerable to HTTP host header injection due to improperly validated host headers. This could cause a victim to receive malformed content.
|
CWE-74
Injection
|
CVE-2021-20101
|
2024-11-21 14:45 |
2021-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195575
|
6.7 |
MEDIUM
Local
|
tenable
|
nessus
|
Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticated, local administrator to run specific Windows ex…
|
NVD-CWE-noinfo
|
CVE-2021-20100
|
2024-11-21 14:45 |
2021-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195576
|
6.7 |
MEDIUM
Local
|
tenable
|
nessus
|
Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticated, local administrator to run specific Windows ex…
|
NVD-CWE-noinfo
|
CVE-2021-20099
|
2024-11-21 14:45 |
2021-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195577
|
7.5 |
HIGH
Network
|
sonicwall
|
sonicos sonicosv
|
A vulnerability in SonicOS where the HTTP server response leaks partial memory by sending a crafted HTTP request, this can potentially lead to an internal sensitive data disclosure vulnerability.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2021-20019
|
2024-11-21 14:45 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195578
|
7.5 |
HIGH
Network
|
wibu siemens
|
codemeter pss_cape sicam_230_firmware
|
A denial of service vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to crash the CodeMeter Runtime Server.
|
CWE-125
Out-of-bounds Read
|
CVE-2021-20094
|
2024-11-21 14:45 |
2021-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195579
|
9.1 |
CRITICAL
Network
|
wibu siemens
|
codemeter pss_cape sicam_230_firmware sinema_remote_connect_server simatic_information_server sinec_infrastructure_network_services simatic_pcs_neo simit_simulation_platform s…
|
A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to disclose heap memory contents or crash the CodeMeter R…
|
CWE-125
Out-of-bounds Read
|
CVE-2021-20093
|
2024-11-21 14:45 |
2021-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195580
|
7.5 |
HIGH
Network
|
sonicwall
|
sonicos
|
A buffer overflow vulnerability in SonicOS allows a remote attacker to cause a Denial of Service (DoS) by sending a specially crafted request. This vulnerability affects SonicOS Gen5, Gen6, Gen7 plat…
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-20027
|
2024-11-21 14:45 |
2021-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|