|
194851
|
7.5 |
HIGH
Local
|
nvidia
|
geforce_gtx_950 geforce_gtx_960 geforce_gtx_970 geforce_gtx_980 geforce_gtx_titan_x jetson_nano jetson_tx1 quadro_m1000m quadro_m1200 quadro_m2000 quadro_m2000m quadr…
|
NVIDIA GPU and Tegra hardware contain a vulnerability in an internal microcontroller, which may allow a user with elevated privileges to generate valid microcode by identifying, exploiting, and loadi…
|
NVD-CWE-noinfo
|
CVE-2021-23201
|
2024-11-21 14:51 |
2021-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194852
|
9.8 |
CRITICAL
Network
|
algolia
|
algoliasearch-helper
|
The package algoliasearch-helper before 3.6.2 are vulnerable to Prototype Pollution due to use of the merge function in src/SearchParameters/index.jsSearchParameters._parseNumbers without any protect…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-23433
|
2024-11-21 14:51 |
2021-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194853
|
7.5 |
HIGH
Network
|
concretecms
|
concrete_cms
|
Concrete CMS (formerly concrete5) versions 8.5.6 and below and version 9.0.0 allow local IP importing causing the system to be vulnerable toa. SSRF attacks on the private LAN servers by reading files…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-22970
|
2024-11-21 14:51 |
2021-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194854
|
7.5 |
HIGH
Network
|
concretecms
|
concrete_cms
|
In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowed to Add Message to a Conversation.To remediate this, a check was added to veri…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2021-22967
|
2024-11-21 14:51 |
2021-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194855
|
7.5 |
HIGH
Network
|
pulsesecure ivanti
|
pulse_connect_secure connect_secure
|
A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial of service when a malformed request is sent to the device.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2021-22965
|
2024-11-21 14:51 |
2021-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194856
|
5.3 |
MEDIUM
Network
|
concretecms
|
concrete_cms
|
Concrete CMS (formerly concrete5) versions below 8.5.7 has a SSRF mitigation bypass using DNS Rebind attack giving an attacker the ability to fetch cloud IAAS (ex AWS) IAM keys.To fix this Concrete C…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-22969
|
2024-11-21 14:51 |
2021-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194857
|
7.2 |
HIGH
Network
|
concretecms
|
concrete_cms
|
A bypass of adding remote files in Concrete CMS (previously concrete5) File Manager leads to remote code execution in Concrete CMS (concrete5) versions 8.5.6 and below.The external file upload featur…
|
CWE-330 CWE-434
Use of Insufficiently Random Values Unrestricted Upload of File with Dangerous Type
|
CVE-2021-22968
|
2024-11-21 14:51 |
2021-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194858
|
8.8 |
HIGH
Network
|
concretecms
|
concrete_cms
|
Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below. If a group is granted "view" permissions on the bulkupdate page, then users in that group can escalate…
|
CWE-863
Incorrect Authorization
|
CVE-2021-22966
|
2024-11-21 14:51 |
2021-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194859
|
7.5 |
HIGH
Network
|
concretecms
|
concrete_cms
|
Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) prior to version 8.5.7. Concrete CMS now checks to see if a file has a password …
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2021-22951
|
2024-11-21 14:51 |
2021-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194860
|
7.8 |
HIGH
Local
|
gallagher
|
command_centre
|
Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary code as the account that runs the Controller Service. This issue affects: Gall…
|
CWE-428
Unquoted Search Path or Element
|
CVE-2021-23197
|
2024-11-21 14:51 |
2021-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|