|
194581
|
5.5 |
MEDIUM
Local
|
xen
|
xen
|
xen/arm: Boot modules are not scrubbed The bootloader will load boot modules (e.g. kernel, initramfs...) in a temporary area before they are copied by Xen to each domain memory. To ensure sensitive d…
|
NVD-CWE-noinfo
|
CVE-2021-28693
|
2024-11-21 15:00 |
2021-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194582
|
7.1 |
HIGH
Local
|
xen
|
xen
|
inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such commands. In the current implementation in Xen, a…
|
CWE-269
Improper Privilege Management
|
CVE-2021-28692
|
2024-11-21 15:00 |
2021-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194583
|
7.8 |
HIGH
Local
|
tibco
|
spotfire_server spotfire_statistics_services spotfire_analytics_platform enterprise_runtime_for_r
|
The TIBCO Spotfire Server and TIBCO Enterprise Runtime for R components of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBC…
|
NVD-CWE-noinfo
|
CVE-2021-28830
|
2024-11-21 15:00 |
2021-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194584
|
6.5 |
MEDIUM
Network
|
xen
|
xen
|
x86: TSX Async Abort protections not restored after S3 This issue relates to the TSX Async Abort speculative security vulnerability. Please see https://xenbits.xen.org/xsa/advisory-305.html for detai…
|
NVD-CWE-noinfo
|
CVE-2021-28690
|
2024-11-21 15:00 |
2021-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194585
|
7.8 |
HIGH
Local
|
linux netapp
|
linux_kernel cloud_backup h410c_firmware h300s_firmware h500s_firmware h700s_firmware h300e_firmware h500e_firmware h700e_firmware h410s_firmware
|
Guest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to disable the interface and terminate the receive kernel thread associated with q…
|
CWE-416
Use After Free
|
CVE-2021-28691
|
2024-11-21 15:00 |
2021-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194586
|
5.5 |
MEDIUM
Local
|
dovecot fedoraproject
|
dovecot fedora
|
Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled locatio…
|
CWE-22
Path Traversal
|
CVE-2021-29157
|
2024-11-21 15:00 |
2021-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194587
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_adselfservice_plus
|
Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.
|
CWE-78
OS Command
|
CVE-2021-28958
|
2024-11-21 15:00 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194588
|
9.8 |
CRITICAL
Network
|
qnap
|
qts
|
A command injection vulnerability has been reported to affect QNAP NAS running legacy versions of QTS. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised…
|
-
|
CVE-2021-28800
|
2024-11-21 15:00 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194589
|
4.8 |
MEDIUM
Network
|
get-simple
|
getsimplecms
|
Cross Site Scripting vulnerability in GetSimpleCMS 3.3.16 in admin/upload.php by adding comments or jpg and other file header information to the content of xla, pages, and gzip files,
|
CWE-79
Cross-site Scripting
|
CVE-2021-28977
|
2024-11-21 15:00 |
2021-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194590
|
7.2 |
HIGH
Network
|
get-simple
|
getsimplecms
|
Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-28976
|
2024-11-21 15:00 |
2021-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|