|
195081
|
7.5 |
HIGH
Network
|
fortinet
|
fortisandbox fortiauthenticator
|
An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6; and FortiAuthenticator b…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2021-22124
|
2024-11-21 14:49 |
2021-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195082
|
7.8 |
HIGH
Local
|
codesys
|
development_system
|
A unsafe deserialization vulnerability exists in the ObjectManager.plugin ProfileInformation.ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafte…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-21866
|
2024-11-21 14:49 |
2021-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195083
|
7.8 |
HIGH
Local
|
codesys
|
development_system
|
A unsafe deserialization vulnerability exists in the PackageManagement.plugin ExtensionMethods.Clone() functionality of CODESYS GmbH CODESYS Development System 3.5.16. A specially crafted file can le…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-21865
|
2024-11-21 14:49 |
2021-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195084
|
7.8 |
HIGH
Local
|
codesys
|
development_system
|
A unsafe deserialization vulnerability exists in the ComponentModel ComponentManager.StartupCultureSettings functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially cra…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-21864
|
2024-11-21 14:49 |
2021-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195085
|
6.5 |
MEDIUM
Network
|
elastic oracle
|
elasticsearch communications_cloud_native_core_automated_test_suite
|
In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with t…
|
CWE-674
Uncontrolled Recursion
|
CVE-2021-22144
|
2024-11-21 14:49 |
2021-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195086
|
7.5 |
HIGH
Network
|
cloudfoundry
|
user_account_and_authentication cf-deployment
|
In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in response when deletion request of an identity provider( IdP) of type “oauth 1.0” was sent t…
|
NVD-CWE-noinfo
|
CVE-2021-22001
|
2024-11-21 14:49 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195087
|
7.5 |
HIGH
Network
|
elastic
|
elasticsearch
|
All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting the anonymous user has no permissions and is unab…
|
NVD-CWE-Other
|
CVE-2021-22146
|
2024-11-21 14:49 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195088
|
6.5 |
MEDIUM
Network
|
elastic oracle
|
elasticsearch communications_cloud_native_core_automated_test_suite
|
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2021-22145
|
2024-11-21 14:49 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195089
|
7.5 |
HIGH
Network
|
wireshark debian
|
wireshark debian_linux
|
Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2021-22235
|
2024-11-21 14:49 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195090
|
7.2 |
HIGH
Network
|
fortinet
|
fortisandbox
|
An instance of improper neutralization of special elements in the sniffer module of FortiSandbox before 3.2.2 may allow an authenticated administrator to execute commands on the underlying system's s…
|
CWE-78
OS Command
|
CVE-2021-22125
|
2024-11-21 14:49 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|