|
194591
|
6.5 |
MEDIUM
Network
|
apache
|
airflow
|
Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configurations including sensitive information even when `…
|
NVD-CWE-Other
|
CVE-2021-26559
|
2024-11-21 14:56 |
2021-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194592
|
9.8 |
CRITICAL
Network
|
phpgurukul
|
teachers_record_management_system
|
Teachers Record Management System 1.0 is affected by a SQL injection vulnerability in 'searchteacher' POST parameter in search-teacher.php. This vulnerability can be exploited by a remote unauthentic…
|
CWE-89
SQL Injection
|
CVE-2021-26822
|
2024-11-21 14:56 |
2021-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194593
|
9.9 |
CRITICAL
Network
|
nedi
|
nedi
|
NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parameter. This allows an attacker to obtain access to t…
|
CWE-863
Incorrect Authorization
|
CVE-2021-26753
|
2024-11-21 14:56 |
2021-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194594
|
8.8 |
HIGH
Network
|
nedi
|
nedi
|
NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /Nodes-Traffic.php via the md or ag HTTP GET parameter. This allows an attack…
|
CWE-78
OS Command
|
CVE-2021-26752
|
2024-11-21 14:56 |
2021-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194595
|
8.8 |
HIGH
Network
|
nedi
|
nedi
|
NeDi 1.9C allows an authenticated user to perform a SQL Injection in the Monitoring History function on the endpoint /Monitoring-History.php via the det HTTP GET parameter. This allows an attacker to…
|
CWE-89
SQL Injection
|
CVE-2021-26751
|
2024-11-21 14:56 |
2021-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194596
|
8.8 |
HIGH
Network
|
smartfoxserver
|
smartfoxserver
|
An issue was discovered in SmartFoxServer 2.17.0. An attacker can execute arbitrary Python code, and bypass the javashell.py protection mechanism, by creating /config/ConsoleModuleUnlock.txt and edit…
|
CWE-94
Code Injection
|
CVE-2021-26551
|
2024-11-21 14:56 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194597
|
5.5 |
MEDIUM
Local
|
smartfoxserver
|
smartfoxserver
|
An issue was discovered in SmartFoxServer 2.17.0. Cleartext password disclosure can occur via /config/server.xml.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2021-26550
|
2024-11-21 14:56 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194598
|
5.4 |
MEDIUM
Network
|
smartfoxserver
|
smartfoxserver
|
An XSS issue was discovered in SmartFoxServer 2.17.0. Input passed to the AdminTool console is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTM…
|
CWE-79
Cross-site Scripting
|
CVE-2021-26549
|
2024-11-21 14:56 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194599
|
6.5 |
MEDIUM
Adjacent
|
intel debian opensuse
|
connman debian_linux leap
|
gdhcp in ConnMan before 1.39 could be used by network-adjacent attackers to leak sensitive stack information, allowing further exploitation of bugs in gdhcp.
|
NVD-CWE-noinfo
|
CVE-2021-26676
|
2024-11-21 14:56 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194600
|
8.8 |
HIGH
Adjacent
|
intel debian opensuse
|
connman debian_linux leap
|
A stack-based buffer overflow in dnsproxy in ConnMan before 1.39 could be used by network adjacent attackers to execute code.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-26675
|
2024-11-21 14:56 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|