|
195311
|
4.8 |
MEDIUM
Network
|
gitlab
|
gitlab
|
A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting f…
|
CWE-79
Cross-site Scripting
|
CVE-2021-22261
|
2024-11-21 14:49 |
2021-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195312
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses
|
NVD-CWE-noinfo
|
CVE-2021-22258
|
2024-11-21 14:49 |
2021-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195313
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. The route…
|
NVD-CWE-noinfo
|
CVE-2021-22257
|
2024-11-21 14:49 |
2021-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195314
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API.
|
NVD-CWE-noinfo
|
CVE-2021-22259
|
2024-11-21 14:49 |
2021-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195315
|
9.4 |
CRITICAL
Network
|
abb busch-jaeger
|
mybuildings mybusch-jaeger
|
The vulnerability origins in the commissioning process where an attacker of the ControlTouch can enter a serial number in a specific way to transfer the device virtually into her/his my.busch-jaeger.…
|
NVD-CWE-noinfo
|
CVE-2021-22272
|
2024-11-21 14:49 |
2021-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195316
|
5.5 |
MEDIUM
Local
|
abb
|
system_access_point_2.0_firmware system_access_point_127v_firmware wl-system_access_point_127v_firmware wl-system_access_point_firmware wl-system_access_point_2.0_firmware
|
The vulnerability allows a successful attacker to bypass the integrity check of FW uploaded to the free@home System Access Point.
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2021-22276
|
2024-11-21 14:49 |
2021-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195317
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-3040_firmware
|
An information disclosure vulnerability exists in the WiFi Smart Mesh functionality of D-LINK DIR-3040 1.13B03. A specially-crafted network request can lead to command execution. An attacker can conn…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2021-21913
|
2024-11-21 14:49 |
2021-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195318
|
5.5 |
MEDIUM
Local
|
vmware
|
vcenter_server cloud_foundation
|
The vCenter Server contains a denial-of-service vulnerability in the Analytics service. Successful exploitation of this issue may allow an attacker to create a denial-of-service condition on vCenter …
|
NVD-CWE-noinfo
|
CVE-2021-22020
|
2024-11-21 14:49 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195319
|
7.5 |
HIGH
Network
|
vmware
|
vcenter_server cloud_foundation
|
The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 5480 on vCenter Server may exploit this issue by sending a s…
|
NVD-CWE-noinfo
|
CVE-2021-22019
|
2024-11-21 14:49 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195320
|
6.5 |
MEDIUM
Network
|
vmware
|
vcenter_server cloud_foundation
|
The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious actor with network access to port 9087 on vCenter Server may exploit t…
|
NVD-CWE-noinfo
|
CVE-2021-22018
|
2024-11-21 14:49 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|