|
195451
|
7.8 |
HIGH
Local
|
vmware
|
thinapp
|
VMware Thinapp version 5.x prior to 5.2.10 contain a DLL hijacking vulnerability due to insecure loading of DLLs. A malicious actor with non-administrative privileges may exploit this vulnerability t…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2021-22000
|
2024-11-21 14:49 |
2021-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195452
|
7.5 |
HIGH
Network
|
vmware
|
cloud_foundation esxi
|
OpenSLP as used in ESXi has a denial-of-service vulnerability due a heap out-of-bounds read issue. A malicious actor with network access to port 427 on ESXi may be able to trigger a heap out-of-bound…
|
CWE-125
Out-of-bounds Read
|
CVE-2021-21995
|
2024-11-21 14:49 |
2021-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195453
|
9.8 |
CRITICAL
Network
|
vmware
|
cloud_foundation esxi
|
SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on ESXi may exploit this issue to bypass SFCB authenti…
|
CWE-287
Improper Authentication
|
CVE-2021-21994
|
2024-11-21 14:49 |
2021-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195454
|
8.8 |
HIGH
Network
|
fortinet
|
fortimail
|
Multiple instances of incorrect calculation of buffer size in the Webmail and Administrative interface of FortiMail before 6.4.5 may allow an authenticated attacker with regular webmail access to tri…
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-22129
|
2024-11-21 14:49 |
2021-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195455
|
8.8 |
HIGH
Network
|
webkitgtk
|
webkitgtk
|
An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.3 x64. A specially crafted HTML web page can cause a use-after-free condition, resulting in remote code execution.…
|
CWE-416
Use After Free
|
CVE-2021-21806
|
2024-11-21 14:49 |
2021-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195456
|
9.8 |
CRITICAL
Network
|
accusoft
|
imagegear
|
A stack-based buffer overflow vulnerability exists in the PDF process_fontname functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to code execution. An attacker can…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-21821
|
2024-11-21 14:49 |
2021-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195457
|
9.8 |
CRITICAL
Network
|
accusoft
|
imagegear
|
An integer overflow vulnerability exists in the DICOM parse_dicom_meta_info functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to a stack-based buffer overflow. An …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2021-21807
|
2024-11-21 14:49 |
2021-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195458
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details
|
CWE-862
Missing Authorization
|
CVE-2021-22233
|
2024-11-21 14:49 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195459
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown
|
CWE-79
Cross-site Scripting
|
CVE-2021-22225
|
2024-11-21 14:49 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195460
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim
|
CWE-352
Origin Validation Error
|
CVE-2021-22224
|
2024-11-21 14:49 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|