|
196311
|
7.5 |
HIGH
Network
|
rubyonrails
|
rails
|
The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible denial of service vulnerability in the Mime type parser of A…
|
NVD-CWE-noinfo
|
CVE-2021-22902
|
2024-11-21 14:50 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196312
|
8.1 |
HIGH
Network
|
haxx oracle netapp siemens splunk
|
curl mysql_server essbase communications_cloud_native_core_network_slice_selection_function communications_cloud_native_core_network_repository_function communications_cloud_native_cor…
|
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use…
|
CWE-416
Use After Free
|
CVE-2021-22901
|
2024-11-21 14:50 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196313
|
4.3 |
MEDIUM
Network
|
nextcloud
|
nextcloud
|
Nextcloud Mail before 1.9.5 suffers from improper access control due to a missing permission check allowing other authenticated users to create mail aliases for other users.
|
CWE-862
Missing Authorization
|
CVE-2021-22896
|
2024-11-21 14:50 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196314
|
5.9 |
MEDIUM
Network
|
nextcloud debian
|
desktop debian_linux
|
Nextcloud Desktop Client before 3.3.1 is vulnerable to improper certificate validation due to lack of SSL certificate verification when using the "Register with a Provider" flow.
|
CWE-295
Improper Certificate Validation
|
CVE-2021-22895
|
2024-11-21 14:50 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196315
|
4.3 |
MEDIUM
Network
|
schneider-electric
|
easergy_t300_firmware
|
A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 with firmware V2.7.1 and older that could expose files or directory content when access from an att…
|
-
|
CVE-2021-22769
|
2024-11-21 14:50 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196316
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
powerlogic_egx100_firmware powerlogic_egx300_firmware
|
A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code executi…
|
-
|
CVE-2021-22768
|
2024-11-21 14:50 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196317
|
3.1 |
LOW
Network
|
haxx debian fedoraproject oracle siemens splunk
|
curl debian_linux fedora mysql_server essbase communications_cloud_native_core_network_slice_selection_function communications_cloud_native_core_network_repository_function commu…
|
curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers…
|
CWE-909
Missing Initialization of Resource
|
CVE-2021-22898
|
2024-11-21 14:50 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196318
|
5.3 |
MEDIUM
Network
|
haxx oracle netapp siemens splunk
|
curl mysql_server essbase communications_cloud_native_core_network_slice_selection_function communications_cloud_native_core_network_repository_function communications_cloud_native_cor…
|
curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The s…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2021-22897
|
2024-11-21 14:50 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196319
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
powerlogic_egx100_firmware powerlogic_egx300_firmware
|
A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code executi…
|
-
|
CVE-2021-22767
|
2024-11-21 14:50 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196320
|
7.5 |
HIGH
Network
|
schneider-electric
|
powerlogic_egx100_firmware powerlogic_egx300_firmware
|
A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service via a specially crafte…
|
-
|
CVE-2021-22766
|
2024-11-21 14:50 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|