|
194381
|
9.8 |
CRITICAL
Network
|
broadcom
|
fabric_operating_system
|
Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x contain documented hard-coded credentials, which could allow attackers to gain acces…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2021-27797
|
2024-11-21 14:58 |
2022-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194382
|
6.5 |
MEDIUM
Network
|
broadcom
|
fabric_operating_system
|
A vulnerability in Brocade Fabric OS versions before Brocade Fabric OS v8.0.1b, v7.4.1d could allow an authenticated attacker within the restricted shell environment (rbash) as either the “user” or “…
|
NVD-CWE-noinfo
|
CVE-2021-27796
|
2024-11-21 14:58 |
2022-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194383
|
5.5 |
MEDIUM
Local
|
hcltech
|
hcl_sametime
|
"Sametime Android potential path traversal vulnerability when using File class"
|
CWE-22
Path Traversal
|
CVE-2021-27755
|
2024-11-21 14:58 |
2022-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194384
|
5.5 |
MEDIUM
Local
|
hcltech
|
hcl_sametime
|
"Sametime Android PathTraversal Vulnerability"
|
CWE-22
Path Traversal
|
CVE-2021-27753
|
2024-11-21 14:58 |
2022-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194385
|
7.8 |
HIGH
Local
|
alpsalpine
|
touchpad_driver
|
Alps Alpine Touchpad Driver 10.3201.101.215 is vulnerable to DLL Injection.
|
NVD-CWE-Other
|
CVE-2021-27971
|
2024-11-21 14:58 |
2022-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194386
|
7.8 |
HIGH
Local
|
pega
|
infinity
|
Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2021-27654
|
2024-11-21 14:58 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194387
|
7.5 |
HIGH
Network
|
apache
|
kylin
|
All request mappings in `StreamingCoordinatorController.java` handling `/kylin/api/streaming_coordinator/*` REST API endpoints did not include any security checks, which allowed an unauthenticated us…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-27738
|
2024-11-21 14:58 |
2022-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194388
|
9.8 |
CRITICAL
Network
|
mesalabs
|
amegaview
|
Mesa Labs AmegaView Versions 3.0 uses default cookies that could be set to bypass authentication to the web application, which may allow an attacker to gain access.
|
-
|
CVE-2021-27453
|
2024-11-21 14:58 |
2021-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194389
|
9.8 |
CRITICAL
Network
|
mesalabs
|
amegaview
|
Mesa Labs AmegaView Versions 3.0 and prior’s passcode is generated by an easily reversible algorithm, which may allow an attacker to gain access to the device.
|
-
|
CVE-2021-27451
|
2024-11-21 14:58 |
2021-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194390
|
8.8 |
HIGH
Network
|
mesalabs
|
amegaview
|
Mesa Labs AmegaView Versions 3.0 and prior has a command injection vulnerability that can be exploited to execute commands in the web server.
|
CWE-77
Command Injection
|
CVE-2021-27449
|
2024-11-21 14:58 |
2021-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|