|
196671
|
8.8 |
HIGH
Adjacent
|
gryphonconnect
|
gryphon_tower_firmware
|
An unauthenticated command injection vulnerability exists in the parameters of operation 10 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same n…
|
CWE-78
OS Command
|
CVE-2021-20140
|
2024-11-21 14:46 |
2021-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196672
|
6.1 |
MEDIUM
Network
|
ibm netapp
|
cognos_analytics oncommand_insight
|
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20493
|
2024-11-21 14:46 |
2021-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196673
|
7.5 |
HIGH
Network
|
ibm netapp
|
cognos_analytics oncommand_insight
|
IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196339.
|
CWE-521
Weak Password Requirements
|
CVE-2021-20470
|
2024-11-21 14:46 |
2021-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196674
|
7.5 |
HIGH
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196074.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2021-20400
|
2024-11-21 14:46 |
2021-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196675
|
7.5 |
HIGH
Network
|
mitsubishi
|
melsec_iq-r_r00_cpu_firmware melsec_iq-r_r01_cpu_firmware melsec_iq-r_r02_cpu_firmware melsec_iq-r_r04_cpu_firmware melsec_iq-r_r08_cpu_firmware melsec_iq-r_r120_cpu_firmware melsec…
|
Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, MELSEC iQ-R Series R08/16/32/120SFCPU, MELSEC iQ-R Series R…
|
CWE-20
Improper Input Validation
|
CVE-2021-20611
|
2024-11-21 14:46 |
2021-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196676
|
7.5 |
HIGH
Network
|
mitsubishi
|
melsec_iq-r_r00_cpu_firmware melsec_iq-r_r01_cpu_firmware melsec_iq-r_r02_cpu_firmware melsec_iq-r_r04_cpu_firmware melsec_iq-r_r08_cpu_firmware melsec_iq-r_r120_cpu_firmware melsec…
|
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, MELSEC iQ-R Series R08/16/32/120S…
|
NVD-CWE-Other
|
CVE-2021-20610
|
2024-11-21 14:46 |
2021-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196677
|
7.5 |
HIGH
Network
|
mitsubishi
|
melsec_iq-r_r00_cpu_firmware melsec_iq-r_r01_cpu_firmware melsec_iq-r_r02_cpu_firmware melsec_iq-r_r04_cpu_firmware melsec_iq-r_r08_cpu_firmware melsec_iq-r_r120_cpu_firmware melsec…
|
Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, MELSEC iQ-R Series R08/16/32/120SFCPU, MELSEC iQ-R …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2021-20609
|
2024-11-21 14:46 |
2021-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196678
|
7.5 |
HIGH
Network
|
mitsubishielectric
|
gt_softgot2000 got_simple_gs2110-wtbd_firmware got_simple_gs2107-wtbd_firmware got2000_gt2104-rtbd_firmware got2000_gt2103-pmbd_firmware got2000_gt2103-pmbds_firmware got2000_gt2103…
|
Improper input validation vulnerability in GOT2000 series GT27 model all versions, GOT2000 series GT25 model all versions, GOT2000 series GT23 model all versions, GOT2000 series GT21 model all versio…
|
CWE-20
Improper Input Validation
|
CVE-2021-20601
|
2024-11-21 14:46 |
2021-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196679
|
5.3 |
MEDIUM
Network
|
ibm
|
planning_analytics
|
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2021-20526
|
2024-11-21 14:46 |
2021-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196680
|
7.5 |
HIGH
Network
|
mitsubishielectric
|
r08sfcpu_firmware r16sfcpu_firmware r32sfcpu_firmware r120sfcpu_firmware r08psfcpu_firmware r16psfcpu_firmware r32psfcpu_firmware r120psfcpu_firmware
|
Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information vulnerability in MELSEC iQ-R series Safety CPU R08/16/32/120SFCPU firmware versions "26" and prior and M…
|
-
|
CVE-2021-20599
|
2024-11-21 14:46 |
2021-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|