|
195801
|
9.8 |
CRITICAL
Network
|
ge
|
reason_dr60_firmware
|
The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components on the Reason DR60 (all firmware versions prior to 02A04.1).
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2021-27440
|
2024-11-21 14:57 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195802
|
8.8 |
HIGH
Network
|
ge
|
reason_dr60_firmware
|
The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components on the Reason DR60 (all firmware versions prior to 02A04.1).
|
CWE-94 CWE-798
Code Injection Use of Hard-coded Credentials
|
CVE-2021-27438
|
2024-11-21 14:57 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195803
|
5.9 |
MEDIUM
Network
|
netop
|
vision_pro
|
Improper Authorization vulnerability in Netop Vision Pro up to and including to 9.7.1 allows an attacker to replay network traffic.
|
CWE-863
Incorrect Authorization
|
CVE-2021-27195
|
2024-11-21 14:57 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195804
|
8.8 |
HIGH
Adjacent
|
netop
|
vision_pro
|
Cleartext transmission of sensitive information in Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to gather credentials including Windows login usernames and pass…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2021-27194
|
2024-11-21 14:57 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195805
|
9.8 |
CRITICAL
Network
|
netop
|
vision_pro
|
Incorrect default permissions vulnerability in the API of Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to read and write files on the remote machine with system…
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-27193
|
2024-11-21 14:57 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195806
|
7.8 |
HIGH
Local
|
netop
|
vision_pro
|
Local privilege escalation vulnerability in Windows clients of Netop Vision Pro up to and including 9.7.1 allows a local user to gain administrator privileges whilst using the clients.
|
CWE-269
Improper Privilege Management
|
CVE-2021-27192
|
2024-11-21 14:57 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195807
|
7.5 |
HIGH
Network
|
doctor_appointment_system_project
|
doctor_appointment_system
|
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.
|
CWE-89
SQL Injection
|
CVE-2021-27320
|
2024-11-21 14:57 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195808
|
7.5 |
HIGH
Network
|
doctor_appointment_system_project
|
doctor_appointment_system
|
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via email parameter.
|
CWE-89
SQL Injection
|
CVE-2021-27319
|
2024-11-21 14:57 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195809
|
7.5 |
HIGH
Network
|
doctor_appointment_system_project
|
doctor_appointment_system
|
Blind SQL injection in contactus.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via lastname parameter.
|
CWE-89
SQL Injection
|
CVE-2021-27316
|
2024-11-21 14:57 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195810
|
7.5 |
HIGH
Network
|
doctor_appointment_system_project
|
doctor_appointment_system
|
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via the comment parameter.
|
CWE-89
SQL Injection
|
CVE-2021-27315
|
2024-11-21 14:57 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|