|
194951
|
7.5 |
HIGH
Network
|
cloudfoundry
|
capi-release cf-deployment
|
Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerability allowing unauthenticated attackers to cause denial of service by using REST HTTP requ…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2021-22101
|
2024-11-21 14:49 |
2021-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194952
|
7.5 |
HIGH
Network
|
vmware
|
vrealize_operations_tenant
|
Releases prior to VMware vRealize Operations Tenant App 8.6 contain an Information Disclosure Vulnerability.
|
NVD-CWE-noinfo
|
CVE-2021-22034
|
2024-11-21 14:49 |
2021-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194953
|
6.5 |
MEDIUM
Network
|
vmware
|
vrealize_automation vrealize_orchestrator
|
VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling. A malicious actor may be able to redirect victim to an attacker controlled doma…
|
CWE-200
Information Exposure
|
CVE-2021-22036
|
2024-11-21 14:49 |
2021-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194954
|
4.3 |
MEDIUM
Network
|
vmware
|
cloud_foundation vrealize_log_insight vrealize_suite_lifecycle_manager
|
VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulnerability in interactive analytics export function. An authenticated malicious actor with non-admini…
|
CWE-74
Injection
|
CVE-2021-22035
|
2024-11-21 14:49 |
2021-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194955
|
2.7 |
LOW
Network
|
vmware
|
vrealize_suite_lifecycle_manager cloud_foundation vrealize_operations
|
Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulnerability.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-22033
|
2024-11-21 14:49 |
2021-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194956
|
9.0 |
CRITICAL
Network
|
anker
|
eufy_homebase_2_firmware
|
A use-after-free vulnerability exists in the pushMuxer CreatePushThread functionality of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to remote code execution.
|
CWE-416
Use After Free
|
CVE-2021-21941
|
2024-11-21 14:49 |
2021-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194957
|
10.0 |
CRITICAL
Network
|
anker
|
eufy_homebase_2_firmware
|
A heap-based buffer overflow vulnerability exists in the pushMuxer processRtspInfo functionality of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted network packet can lead to a heap buffer overfl…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-21940
|
2024-11-21 14:49 |
2021-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194958
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user ac…
|
CWE-269
Improper Privilege Management
|
CVE-2021-22263
|
2024-11-21 14:49 |
2021-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194959
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. Under spe…
|
NVD-CWE-noinfo
|
CVE-2021-22264
|
2024-11-21 14:49 |
2021-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194960
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 with Jira Cloud integ…
|
CWE-863
Incorrect Authorization
|
CVE-2021-22262
|
2024-11-21 14:49 |
2021-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|