|
194361
|
3.3 |
LOW
Local
|
hcltechsw
|
hcl_commerce
|
HCL Commerce is affected by an Insufficient Session Expiration vulnerability. After the session expires, in some circumstances, parts of the application are still accessible.
|
CWE-613
Insufficient Session Expiration
|
CVE-2021-27751
|
2024-11-21 14:58 |
2022-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194362
|
9.8 |
CRITICAL
Network
|
philips
|
vue_pacs vue_motion speech myvue
|
Philips Vue PACS versions 12.2.x.x and prior does not follow certain coding rules for development, which can lead to resultant weaknesses or increase the severity of the associated vulnerabilities.
|
NVD-CWE-noinfo
|
CVE-2021-27501
|
2024-11-21 14:58 |
2022-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194363
|
9.8 |
CRITICAL
Network
|
philips
|
vue_pacs vue_motion speech myvue
|
Philips Vue PACS versions 12.2.x.x and prior does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
|
NVD-CWE-Other
|
CVE-2021-27497
|
2024-11-21 14:58 |
2022-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194364
|
6.5 |
MEDIUM
Network
|
philips
|
vue_pacs vue_motion speech myvue
|
Philips Vue PACS versions 12.2.x.x and prior does not ensure or incorrectly ensures structured messages or data are well formed and that certain security properties are met before being read from an …
|
NVD-CWE-Other
|
CVE-2021-27493
|
2024-11-21 14:58 |
2022-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194365
|
9.8 |
CRITICAL
Network
|
rockwellautomation
|
factorytalk_assetcentre
|
A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute ar…
|
CWE-78
OS Command
|
CVE-2021-27476
|
2024-11-21 14:58 |
2022-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194366
|
8.6 |
HIGH
Local
|
rockwellautomation
|
connected_components_workbench
|
Rockwell Automation Connected Components Workbench v12.00.00 and prior does not limit the objects that can be deserialized. This vulnerability allows attackers to craft a malicious serialized object …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-27475
|
2024-11-21 14:58 |
2022-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194367
|
7.5 |
HIGH
Network
|
rockwellautomation
|
factorytalk_assetcentre
|
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulnerability may allow a remote, unauthenticated attac…
|
NVD-CWE-Other
|
CVE-2021-27474
|
2024-11-21 14:58 |
2022-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194368
|
9.8 |
CRITICAL
Network
|
rockwellautomation
|
factorytalk_assetcentre
|
A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticate…
|
CWE-89
SQL Injection
|
CVE-2021-27472
|
2024-11-21 14:58 |
2022-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194369
|
9.8 |
CRITICAL
Network
|
rockwellautomation
|
factorytalk_assetcentre
|
A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a rem…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-27470
|
2024-11-21 14:58 |
2022-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194370
|
8.2 |
HIGH
Local
|
rockwellautomation
|
connected_components_workbench
|
Rockwell Automation Connected Components Workbench v12.00.00 and prior does not sanitize paths specified within the .ccwarc archive file during extraction. This type of vulnerability is also commonly…
|
CWE-22
Path Traversal
|
CVE-2021-27473
|
2024-11-21 14:58 |
2022-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|