|
195901
|
4.8 |
MEDIUM
Network
|
redhat netapp
|
undertow oncommand_workflow_automation active_iq_unified_manager
|
A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid c…
|
CWE-444
HTTP Request Smuggling
|
CVE-2021-20220
|
2024-11-21 14:46 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195902
|
8.1 |
HIGH
Network
|
redhat
|
openshift_installer
|
A flaw was found in the OpenShift Installer before version v0.9.0-master.0.20210125200451-95101da940b0. During installation of OpenShift Container Platform 4 clusters, bootstrap nodes are provisioned…
|
-
|
CVE-2021-20198
|
2024-11-21 14:46 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195903
|
7.5 |
HIGH
Network
|
stunnel
|
stunnel
|
A flaw was found in stunnel before 5.57, where it improperly validates client certificates when it is configured to use both redirect and verifyChain options. This flaw allows an attacker with a cert…
|
-
|
CVE-2021-20230
|
2024-11-21 14:46 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195904
|
7.8 |
HIGH
Local
|
linux netapp
|
linux_kernel cloud_backup
|
A use-after-free flaw was found in the io_uring in Linux kernel, where a local attacker with a user privilege could cause a denial of service problem on the system The issue results from the lack of …
|
-
|
CVE-2021-20226
|
2024-11-21 14:46 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195905
|
9.8 |
CRITICAL
Network
|
mitsubishielectric
|
melfa-works rt_toolbox2 ezsocket fr_configurator fr_configurator_sw3 gx_configurator-dp gx_configurator-qp gx_explorer gx_iec_developer gx_works2 gx_works3 m_commdtm-…
|
Improper handling of length parameter inconsistency vulnerability in Mitsubishi Electric FA Engineering Software(CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2021-20588
|
2024-11-21 14:46 |
2021-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195906
|
9.8 |
CRITICAL
Network
|
mitsubishielectric
|
melfa-works rt_toolbox2 ezsocket fr_configurator fr_configurator_sw3 gx_configurator-dp gx_configurator-qp gx_explorer gx_iec_developer gx_works2 gx_works3 m_commdtm-…
|
Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Da…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-20587
|
2024-11-21 14:46 |
2021-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195907
|
5.4 |
MEDIUM
Network
|
ibm
|
maximo_for_civil_infrastructure
|
IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functional…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20446
|
2024-11-21 14:46 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195908
|
6.5 |
MEDIUM
Network
|
ibm
|
maximo_for_civil_infrastructure
|
IBM Maximo for Civil Infrastructure 7.6.2 could allow a user to obtain sensitive information due to insecure storeage of authentication credentials. IBM X-Force ID: 196621.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2021-20445
|
2024-11-21 14:46 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195909
|
6.1 |
MEDIUM
Network
|
ibm
|
maximo_for_civil_infrastructure
|
IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functional…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20444
|
2024-11-21 14:46 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195910
|
8.8 |
HIGH
Network
|
ibm
|
maximo_for_civil_infrastructure
|
IBM Maximo for Civil Infrastructure 7.6.2 includes executable functionality (such as a library) from a source that is outside of the intended control sphere. IBM X-Force ID: 196619.
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2021-20443
|
2024-11-21 14:46 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|