|
196111
|
7.8 |
HIGH
Local
|
amd
|
epyc_7763_firmware epyc_7713p_firmware epyc_7713_firmware epyc_7663_firmware epyc_7643_firmware epyc_75f3_firmware epyc_7543p_firmware epyc_7543_firmware epyc_7513_firmware
|
Failure to validate inputs in SMM may allow an attacker to create a mishandled error leaving the DRTM UApp in a partially initialized state potentially resulting in loss of memory integrity.
|
CWE-665
Improper Initialization
|
CVE-2021-26353
|
2024-11-21 14:56 |
2022-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196112
|
5.5 |
MEDIUM
Local
|
amd
|
ryzen_5_2600_firmware ryzen_5_2600x_firmware ryzen_5_2700x_firmware ryzen_5_2700_firmware ryzen_5_3600_firmware ryzen_5_3600x_firmware ryzen_7_3700x_firmware ryzen_7_3800x_firmwa…
|
Insufficient bound checks in System Management Unit (SMU) PCIe Hot Plug table may result in access/updates from/to invalid address space that could result in denial of service.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2021-26352
|
2024-11-21 14:56 |
2022-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196113
|
7.1 |
HIGH
Local
|
amd
|
epyc_7763_firmware epyc_7713p_firmware epyc_7713_firmware epyc_7663_firmware epyc_7643_firmware epyc_75f3_firmware epyc_7543p_firmware epyc_7543_firmware epyc_7513_firmware
|
Failure to verify SEV-ES TMR is not in MMIO space, SEV-ES FW could result in a potential loss of integrity or availability.
|
NVD-CWE-noinfo
|
CVE-2021-26332
|
2024-11-21 14:56 |
2022-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196114
|
7.8 |
HIGH
Local
|
amd
|
epyc_7763_firmware epyc_7713p_firmware epyc_7713_firmware epyc_7663_firmware epyc_7643_firmware epyc_75f3_firmware epyc_7543p_firmware epyc_7543_firmware epyc_7513_firmware
|
A bug with the SEV-ES TMR may lead to a potential loss of memory integrity for SNP-active VMs.
|
NVD-CWE-noinfo
|
CVE-2021-26324
|
2024-11-21 14:56 |
2022-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196115
|
8.8 |
HIGH
Network
|
tobesoft
|
xplatform
|
A path traversal vulnerability in XPLATFORM's runtime archive function could lead to arbitrary file creation. When the .xzip archive file is decompressed, an arbitrary file can be d in the parent pat…
|
CWE-22
Path Traversal
|
CVE-2021-26629
|
2024-11-21 14:56 |
2022-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196116
|
6.1 |
MEDIUM
Network
|
maxb
|
maxboard
|
Insufficient script validation of the admin page enables XSS, which causes unauthorized users to steal admin privileges. When uploading file in a specific menu, the verification of the files is insuf…
|
CWE-79
Cross-site Scripting
|
CVE-2021-26628
|
2024-11-21 14:56 |
2022-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196117
|
7.5 |
HIGH
Network
|
qcp
|
qcp200w_firmware
|
Real-time image information exposure is caused by insufficient authentication for activated RTSP port. This vulnerability could allow to remote attackers to send the RTSP requests using ffplay comman…
|
CWE-287
Improper Authentication
|
CVE-2021-26627
|
2024-11-21 14:56 |
2022-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196118
|
8.8 |
HIGH
Network
|
tobesoft
|
xplatform
|
Improper input validation vulnerability in XPLATFORM's execBrowser method can cause execute arbitrary commands. IF the second parameter value of the execBrowser function is ‘default’, the first param…
|
CWE-20
Improper Input Validation
|
CVE-2021-26626
|
2024-11-21 14:56 |
2022-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196119
|
8.8 |
HIGH
Network
|
tobesoft
|
nexacro
|
Insufficient Verification of input Data leading to arbitrary file download and execute was discovered in Nexacro platform. This vulnerability is caused by an automatic update function that does not v…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2021-26625
|
2024-11-21 14:56 |
2022-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196120
|
8.8 |
HIGH
Network
|
escanav
|
escan_anti-virus
|
An local privilege escalation vulnerability due to a "runasroot" command in eScan Anti-Virus. This vulnerability is due to invalid arguments and insufficient execution conditions related to "runasroo…
|
CWE-20
Improper Input Validation
|
CVE-2021-26624
|
2024-11-21 14:56 |
2022-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|