|
194391
|
9.8 |
CRITICAL
Network
|
mesalabs
|
amegaview
|
Mesa Labs AmegaView version 3.0 is vulnerable to a command injection, which may allow an attacker to remotely execute arbitrary code.
|
-
|
CVE-2021-27447
|
2024-11-21 14:58 |
2021-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194392
|
7.8 |
HIGH
Local
|
mesalabs
|
amegaview
|
Mesa Labs AmegaView Versions 3.0 and prior has insecure file permissions that could be exploited to escalate privileges on the device.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2021-27445
|
2024-11-21 14:58 |
2021-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194393
|
5.3 |
MEDIUM
Network
|
fatpipeinc
|
ipvpn_firmware mpvpn_firmware warp_firmware
|
A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote attacker to access at lea…
|
CWE-862
Missing Authorization
|
CVE-2021-27858
|
2024-11-21 14:58 |
2021-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194394
|
9.8 |
CRITICAL
Network
|
fatpipeinc
|
ipvpn_firmware mpvpn_firmware warp_firmware
|
FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 includes an account named "cmuser" that has administrative privileges and no password. Older versions of FatPipe s…
|
NVD-CWE-Other
|
CVE-2021-27856
|
2024-11-21 14:58 |
2021-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194395
|
8.8 |
HIGH
Network
|
fatpipeinc
|
ipvpn_firmware warp_firmware mpvpn_firmware
|
FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote, authenticated attacker with read-only privileges to grant themselves administrative privileges. O…
|
NVD-CWE-Other
|
CVE-2021-27855
|
2024-11-21 14:58 |
2021-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194396
|
8.8 |
HIGH
Network
|
fatpipeinc
|
ipvpn_firmware mpvpn_firmware warp_firmware
|
A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows an authenticated, remote attacker …
|
CWE-862
Missing Authorization
|
CVE-2021-27859
|
2024-11-21 14:58 |
2021-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194397
|
7.5 |
HIGH
Network
|
fatpipeinc
|
ipvpn_firmware mpvpn_firmware warp_firmware
|
A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote, unauthenticated attacker…
|
CWE-862
Missing Authorization
|
CVE-2021-27857
|
2024-11-21 14:58 |
2021-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194398
|
8.1 |
HIGH
Network
|
pluck-cms
|
pluck
|
In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-27984
|
2024-11-21 14:58 |
2021-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194399
|
9.8 |
CRITICAL
Network
|
max-3000
|
maxsite_cms
|
Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page.
|
NVD-CWE-noinfo
|
CVE-2021-27983
|
2024-11-21 14:58 |
2021-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194400
|
8.8 |
HIGH
Network
|
fatpipeinc
|
ipvpn_firmware warp_firmware mpvpn_firmware
|
A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-27860
|
2024-11-21 14:58 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|