|
195691
|
7.8 |
HIGH
Local
|
racom
|
m\!dge_firmware
|
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for privilege escalation via configd.
|
CWE-269
Improper Privilege Management
|
CVE-2021-20075
|
2024-11-21 14:45 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195692
|
8.8 |
HIGH
Network
|
racom
|
m\!dge_firmware
|
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows users to escape the provided command line interface and execute arbitrary OS commands.
|
CWE-78
OS Command
|
CVE-2021-20074
|
2024-11-21 14:45 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195693
|
8.8 |
HIGH
Network
|
racom
|
m\!dge_firmware
|
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for cross-site request forgeries.
|
CWE-352
Origin Validation Error
|
CVE-2021-20073
|
2024-11-21 14:45 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195694
|
7.2 |
HIGH
Network
|
racom
|
m\!dge_firmware
|
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to arbitrarily access and delete files via an authenticated directory traveral.
|
CWE-22
Path Traversal
|
CVE-2021-20072
|
2024-11-21 14:45 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195695
|
4.8 |
MEDIUM
Network
|
racom
|
m\!dge_firmware
|
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scriptings attacks via the sms.php dialogs.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20071
|
2024-11-21 14:45 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195696
|
4.8 |
MEDIUM
Network
|
racom
|
m\!dge_firmware
|
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scriptings attacks via the virtualization.php dialogs.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20070
|
2024-11-21 14:45 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195697
|
4.8 |
MEDIUM
Network
|
racom
|
m\!dge_firmware
|
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scripting attacks via the regionalSettings.php dialogs.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20069
|
2024-11-21 14:45 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195698
|
4.8 |
MEDIUM
Network
|
racom
|
m\!dge_firmware
|
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scripting attacks via the error handling functionality of web pages.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20068
|
2024-11-21 14:45 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195699
|
5.3 |
MEDIUM
Network
|
racom
|
m\!dge_firmware
|
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to view sensitive syslog events without authentication.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-20067
|
2024-11-21 14:45 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195700
|
5.6 |
MEDIUM
Network
|
jsdom_project
|
jsdom
|
JSDom improperly allows the loading of local resources, which allows for local files to be manipulated by a malicious web page when script execution is enabled.
|
NVD-CWE-noinfo
|
CVE-2021-20066
|
2024-11-21 14:45 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|