|
194261
|
4.9 |
MEDIUM
Network
|
hitach
|
vantara
|
A tenant administrator Hitachi Content Platform (HCP) may modify the configuration in another tenant without authorization, potentially allowing unauthorized access to data in the other tenant. Also,…
|
CWE-862
Missing Authorization
|
CVE-2021-28052
|
2024-11-21 14:59 |
2022-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194262
|
7.2 |
HIGH
Network
|
osgeo
|
geonetwork
|
A privileged attacker in GeoNetwork before 3.12.0 and 4.x before 4.0.4 can use the directory harvester before-script to execute arbitrary OS commands remotely on the hosting infrastructure. A User Ad…
|
CWE-78
OS Command
|
CVE-2021-28398
|
2024-11-21 14:59 |
2022-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194263
|
6.5 |
MEDIUM
Network
|
arista
|
eos
|
This advisory documents the impact of an internally found vulnerability in Arista EOS for security ACL bypass. The impact of this vulnerability is that the security ACL drop rule might be bypassed if…
|
NVD-CWE-Other
|
CVE-2021-28511
|
2024-11-21 14:59 |
2022-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194264
|
6.1 |
MEDIUM
Network
|
arista
|
terminattr eos
|
This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols. The impact of this vulnerability i…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2021-28509
|
2024-11-21 14:59 |
2022-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194265
|
6.1 |
MEDIUM
Network
|
arista
|
terminattr eos
|
This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols. The impact of this vulnerability i…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2021-28508
|
2024-11-21 14:59 |
2022-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194266
|
6.1 |
MEDIUM
Network
|
identityserver4.admin_project
|
identityserver4.admin
|
A cross-site scripting (XSS) vulnerability in Skoruba IdentityServer4.Admin before 2.0.0 via unencoded value passed to the data-secret-value parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-28290
|
2024-11-21 14:59 |
2022-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194267
|
7.5 |
HIGH
Network
|
arista
|
eos
|
On affected Arista EOS platforms, if a VXLAN match rule exists in an IPv4 access-list that is applied to the ingress of an L2 or an L3 port/SVI, the VXLAN rule and subsequent ACL rules in that access…
|
CWE-863
Incorrect Authorization
|
CVE-2021-28505
|
2024-11-21 14:59 |
2022-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194268
|
4.3 |
MEDIUM
Network
|
apache debian fedoraproject apple
|
subversion debian_linux fedora macos
|
Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a…
|
-
|
CVE-2021-28544
|
2024-11-21 14:59 |
2022-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194269
|
9.8 |
CRITICAL
Network
|
horizontcms_project
|
horizontcms
|
File upload vulnerability in HorizontCMS before 1.0.0-beta.3 via uploading a .htaccess and *.hello files using the Media Files upload functionality. The original file upload vulnerability (CVE-2020-2…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-28428
|
2024-11-21 14:59 |
2022-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194270
|
7.5 |
HIGH
Network
|
arista
|
eos
|
On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol then that rule and subsequent rules ( rules decla…
|
CWE-863
Incorrect Authorization
|
CVE-2021-28504
|
2024-11-21 14:59 |
2022-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|