|
196881
|
6.1 |
MEDIUM
Network
|
tecnick
|
tcexam
|
A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3. The paths provided in the f, d, and dir parameters in tce_filemanager.php were not properly validated and could cause reflec…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20115
|
2024-11-21 14:45 |
2021-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196882
|
9.8 |
CRITICAL
Network
|
sonicwall
|
sma_210_firmware sma_410_firmware sma_500v_firmware sra_4600_firmware sra_1600_firmware sra_va_firmware
|
Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running all 8.x firmware and…
|
CWE-89
SQL Injection
|
CVE-2021-20028
|
2024-11-21 14:45 |
2021-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196883
|
7.5 |
HIGH
Network
|
tecnick
|
tcexam
|
When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which included sensitive database backup files.
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2021-20114
|
2024-11-21 14:45 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196884
|
5.3 |
MEDIUM
Network
|
tecnick
|
tcexam
|
An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1. If a password reset request was made for an email address that was not registered with a user then we would be presented…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2021-20113
|
2024-11-21 14:45 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196885
|
5.4 |
MEDIUM
Network
|
tecnick
|
tcexam
|
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_select_mediafile.php with a filename beggining with a period will be rendered as text/html. An att…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20112
|
2024-11-21 14:45 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196886
|
5.4 |
MEDIUM
Network
|
tecnick
|
tcexam
|
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_filemanager.php with a filename beggining with a period will be rendered as text/html. An attacker…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20111
|
2024-11-21 14:45 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196887
|
6.5 |
MEDIUM
Local
|
tenable
|
nessus
|
Nessus Agent versions 8.2.5 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus administrator user to upload a specially crafted file that could lead to …
|
NVD-CWE-noinfo
|
CVE-2021-20106
|
2024-11-21 14:45 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196888
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_assetexplorer
|
Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP addres…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2021-20110
|
2024-11-21 14:45 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196889
|
7.5 |
HIGH
Network
|
zohocorp
|
manageengine_assetexplorer
|
Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allo…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-20109
|
2024-11-21 14:45 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196890
|
7.5 |
HIGH
Network
|
zohocorp
|
manageengine_assetexplorer
|
Manage Engine Asset Explorer Agent 1.0.34 listens on port 9000 for incoming commands over HTTPS from Manage Engine Server. The HTTPS certificates are not verified which allows any arbitrary user on t…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2021-20108
|
2024-11-21 14:45 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|