|
195071
|
7.5 |
HIGH
Network
|
apache oracle
|
cxf business_intelligence communications_session_route_manager communications_session_report_manager communications_element_manager communications_diameter_intelligence_hub
|
CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR))…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-22696
|
2024-11-21 14:50 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195072
|
3.7 |
LOW
Network
|
haxx fedoraproject netapp broadcom debian siemens oracle splunk
|
libcurl fedora solidfire hci_management_node hci_storage_node fabric_operating_system debian_linux sinec_infrastructure_network_services communications_billing_and_revenue_man…
|
curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2021-22890
|
2024-11-21 14:50 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195073
|
5.3 |
MEDIUM
Network
|
haxx fedoraproject netapp broadcom debian siemens oracle splunk
|
libcurl fedora solidfire hci_management_node hci_storage_node hci_compute_node fabric_operating_system debian_linux sinec_infrastructure_network_services communications_bil…
|
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip o…
|
CWE-200
Information Exposure
|
CVE-2021-22876
|
2024-11-21 14:50 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195074
|
8.8 |
HIGH
Network
|
google
|
exposure_notifications_verification_server
|
A privilege escalation vulnerability impacting the Google Exposure Notification Verification Server (versions prior to 0.23.1), allows an attacker who (1) has UserWrite permissions and (2) is using a…
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-22538
|
2024-11-21 14:50 |
2021-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195075
|
6.1 |
MEDIUM
Network
|
rocket.chat
|
rocket.chat
|
Rocket.Chat before 3.11, 3.10.5, 3.9.7, 3.8.8 is vulnerable to persistent cross-site scripting (XSS) using nested markdown tags allowing a remote attacker to inject arbitrary JavaScript in a message.…
|
CWE-79
Cross-site Scripting
|
CVE-2021-22886
|
2024-11-21 14:50 |
2021-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195076
|
7.5 |
HIGH
Network
|
microfocus
|
access_manager
|
Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage.
|
NVD-CWE-noinfo
|
CVE-2021-22506
|
2024-11-21 14:50 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195077
|
6.1 |
MEDIUM
Network
|
revive-adserver
|
revive_adserver
|
Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `statsBreakdown` parameter of stats.php (and possibly other scripts) due to single quotes not being escaped. An att…
|
CWE-79
Cross-site Scripting
|
CVE-2021-22889
|
2024-11-21 14:50 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195078
|
6.1 |
MEDIUM
Network
|
revive-adserver
|
revive_adserver
|
Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `status` parameter of campaign-zone-zones.php. An attacker could trick a user with access to the user interface of …
|
CWE-79
Cross-site Scripting
|
CVE-2021-22888
|
2024-11-21 14:50 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195079
|
8.6 |
HIGH
Network
|
rockwellautomation
|
micrologix_1400_firmware
|
Rockwell Automation MicroLogix 1400 Version 21.6 and below may allow a remote unauthenticated attacker to send a specially crafted Modbus packet allowing the attacker to retrieve or modify random val…
|
-
|
CVE-2021-22659
|
2024-11-21 14:50 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195080
|
7.5 |
HIGH
Network
|
microfocus
|
access_manager
|
Authentication Bypass Vulnerability in Micro Focus Access Manager Product, affects all version prior to version 4.5.3.3. The vulnerability could cause information leakage.
|
CWE-287
Improper Authentication
|
CVE-2021-22496
|
2024-11-21 14:50 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|