|
194861
|
8.0 |
HIGH
Adjacent
|
eaton
|
intelligent_power_manager
|
Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to CSV Formula Injection. This issue affects: Eaton Intelligent Power Ma…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2021-23286
|
2024-11-21 14:51 |
2022-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194862
|
4.8 |
MEDIUM
Network
|
eaton
|
intelligent_power_manager
|
Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to reflected Cross-site Scripting vulnerability. This issue affects: Eat…
|
CWE-79
Cross-site Scripting
|
CVE-2021-23285
|
2024-11-21 14:51 |
2022-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194863
|
4.8 |
MEDIUM
Network
|
eaton
|
intelligent_power_manager_infrastructure
|
Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to Stored Cross-site Scripting vulnerability. This issue affects: Eaton …
|
CWE-79
Cross-site Scripting
|
CVE-2021-23284
|
2024-11-21 14:51 |
2022-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194864
|
4.8 |
MEDIUM
Adjacent
|
eaton
|
intelligent_power_protector
|
The vulnerability exists due to insufficient validation of input from certain resources by the IPP software. The attacker would need access to the local Subnet and an administrator interaction to com…
|
CWE-79
Cross-site Scripting
|
CVE-2021-23288
|
2024-11-21 14:51 |
2022-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194865
|
5.4 |
MEDIUM
Network
|
eaton
|
intelligent_power_manager
|
The vulnerability exists due to insufficient validation of input of certain resources within the IPM software. This issue affects: Intelligent Power Manager (IPM 1) versions prior to 1.70.
|
CWE-79
Cross-site Scripting
|
CVE-2021-23287
|
2024-11-21 14:51 |
2022-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194866
|
9.8 |
CRITICAL
Network
|
oppo
|
quick_app
|
A command injection vulerability found in quick game engine allows arbitrary remote code in quick app. Allows remote attacke0rs to gain arbitrary code execution in quick game engine
|
CWE-77
Command Injection
|
CVE-2021-23247
|
2024-11-21 14:51 |
2022-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194867
|
7.2 |
HIGH
Network
|
bosch
|
autodome_ip_4000i_firmware autodome_ip_5000i_firmware autodome_ip_starlight_5000i_firmware autodome_ip_starlight_7000i_firmware dinion_ip_3000i_firmware dinion_ip_bullet_4000i_firmware…
|
A specially crafted TCP/IP packet may cause the camera recovery image web interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only…
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-23851
|
2024-11-21 14:51 |
2022-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194868
|
7.2 |
HIGH
Network
|
bosch
|
autodome_ip_4000i_firmware autodome_ip_5000i_firmware autodome_ip_starlight_5000i_firmware autodome_ip_starlight_7000i_firmware dinion_ip_3000i_firmware dinion_ip_bullet_4000i_firmware…
|
A specially crafted TCP/IP packet may cause a camera recovery image telnet interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can onl…
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-23850
|
2024-11-21 14:51 |
2022-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194869
|
4.8 |
MEDIUM
Network
|
ampforwp
|
accelerated_mobile_pages
|
Multiple Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) vulnerabilities discovered in AMP for WP – Accelerated Mobile Pages WordPress plugin (versions <= 1.0.77.32).
|
-
|
CVE-2021-23209
|
2024-11-21 14:51 |
2022-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194870
|
4.8 |
MEDIUM
Network
|
ampforwp
|
accelerated_mobile_pages
|
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in AMP for WP – Accelerated Mobile Pages plugin <= 1.0.77.31 versions.
|
-
|
CVE-2021-23150
|
2024-11-21 14:51 |
2022-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|