|
196231
|
9.8 |
CRITICAL
Network
|
vembu
|
bdr_suite offsite_dr
|
In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 the http API located at /sgwebservice_o.php action logFilePath allows an attacker to write arbitrary files in the context of the web serve…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-26473
|
2024-11-21 14:56 |
2021-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196232
|
9.8 |
CRITICAL
Network
|
vembu
|
bdr_suite offsite_dr
|
In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 installed on Windows, the http API located at /consumerweb/secure/download.php. Using this command argument an unauthenticated attacker ca…
|
CWE-78
OS Command
|
CVE-2021-26472
|
2024-11-21 14:56 |
2021-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196233
|
9.8 |
CRITICAL
Network
|
vembu
|
bdr_suite offsite_dr
|
In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1, the http API located at /sgwebservice_o.php accepts a command argument. Using this command argument an unauthenticated attacker can execu…
|
NVD-CWE-noinfo
|
CVE-2021-26471
|
2024-11-21 14:56 |
2021-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196234
|
6.1 |
MEDIUM
Network
|
hp
|
oneview_for_vmware_vcenter
|
A security vulnerability in HPE OneView for VMware vCenter (OV4VC) could be exploited remotely to allow Cross-Site Scripting. HPE has released the following software update to resolve the vulnerabili…
|
CWE-79
Cross-site Scripting
|
CVE-2021-26584
|
2024-11-21 14:56 |
2021-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196235
|
9.8 |
CRITICAL
Network
|
merge-deep_project netapp
|
merge-deep e-series_performance_analyzer
|
The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in t…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-26707
|
2024-11-21 14:56 |
2021-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196236
|
7.2 |
HIGH
Network
|
amd
|
epyc_7251 epyc_7261 epyc_7281 epyc_7301 epyc_7351 epyc_7351p epyc_7371 epyc_7401 epyc_7401p epyc_7451 epyc_7501 epyc_7551 epyc_7551p epyc_7601 epyc_7763 e…
|
In the AMD SEV/SEV-ES feature, memory can be rearranged in the guest address space that is not detected by the attestation mechanism which could be used by a malicious hypervisor to potentially lead …
|
CWE-77
Command Injection
|
CVE-2021-26311
|
2024-11-21 14:56 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196237
|
7.2 |
HIGH
Network
|
microsoft
|
skype_for_business_server lync_server
|
Skype for Business and Lync Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2021-26422
|
2024-11-21 14:56 |
2021-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196238
|
6.5 |
MEDIUM
Network
|
microsoft
|
skype_for_business_server lync_server
|
Skype for Business and Lync Spoofing Vulnerability
|
NVD-CWE-noinfo
|
CVE-2021-26421
|
2024-11-21 14:56 |
2021-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196239
|
7.5 |
HIGH
Network
|
microsoft
|
internet_explorer
|
Scripting Engine Memory Corruption Vulnerability
|
CWE-787
Out-of-bounds Write
|
CVE-2021-26419
|
2024-11-21 14:56 |
2021-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196240
|
7.5 |
HIGH
Network
|
jetbrains
|
teamcity
|
In the TeamCity IntelliJ plugin before 2020.2.2.85899, DoS was possible.
|
NVD-CWE-noinfo
|
CVE-2021-26310
|
2024-11-21 14:56 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|