|
194571
|
4.9 |
MEDIUM
Network
|
asus
|
asmb9-ikvm_firmware rs720a-e9-rs24-e_firmware rs700a-e9-rs4_firmware rs700-e9-rs4_firmware esc4000_g4x_firmware rs700-e9-rs12_firmware rs100-e10-pi2_firmware rs300-e10-ps4_firmwa…
|
The specific function in ASUS BMC’s firmware Web management page (Generate new certificate function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. …
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-28190
|
2024-11-21 14:59 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194572
|
5.9 |
MEDIUM
Network
|
cohesity
|
cohesity_dataplatform
|
A man-in-the-middle vulnerability in Cohesity DataPlatform support channel in version 6.3 up to 6.3.1g, 6.4 up to 6.4.1c and 6.5.1 through 6.5.1b. Missing server authentication in impacted versions c…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-28124
|
2024-11-21 14:59 |
2021-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194573
|
9.8 |
CRITICAL
Network
|
cohesity
|
cohesity_dataplatform
|
Undocumented Default Cryptographic Key Vulnerability in Cohesity DataPlatform version 6.3 prior 6.3.1g, 6.4 up to 6.4.1c and 6.5.1 through 6.5.1b. The ssh key can provide an attacker access to the li…
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2021-28123
|
2024-11-21 14:59 |
2021-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194574
|
6.7 |
MEDIUM
Network
|
okta
|
access_gateway
|
A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (with admin access to the Okta Access Gateway UI) to execute O…
|
CWE-78
OS Command
|
CVE-2021-28113
|
2024-11-21 14:59 |
2021-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194575
|
5.4 |
MEDIUM
Network
|
devolutions
|
remote_desktop_manager
|
Cross-Site Scripting (XSS) in Administrative Reports in Devolutions Remote Desktop Manager before 2021.1 allows remote authenticated users to inject arbitrary web script or HTML via multiple input fi…
|
CWE-79
Cross-site Scripting
|
CVE-2021-28047
|
2024-11-21 14:59 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194576
|
7.5 |
HIGH
Network
|
eclipse oracle jenkins netapp
|
jetty communications_services_gatekeeper autovue_for_agile_product_lifecycle_management siebel_core_-_automation communications_element_manager communications_cloud_native_core_policy<…
|
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2021-28165
|
2024-11-21 14:59 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194577
|
5.3 |
MEDIUM
Network
|
eclipse netapp oracle
|
jetty santricity_cloud_connector snapcenter e-series_performance_analyzer e-series_santricity_web_services virtual_storage_console storage_replication_adapter_for_clustered_data_ont…
|
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF direc…
|
NVD-CWE-Other
|
CVE-2021-28164
|
2024-11-21 14:59 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194578
|
6.5 |
MEDIUM
Network
|
adobe
|
acrobat acrobat_dc acrobat_reader acrobat_reader_dc
|
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are missing support for an integrity check. An unauthenticated attacker…
|
-
|
CVE-2021-28546
|
2024-11-21 14:59 |
2021-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194579
|
8.1 |
HIGH
Network
|
adobe
|
acrobat acrobat_dc acrobat_reader acrobat_reader_dc
|
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are missing support for an integrity check. An unauthenticated attacker…
|
-
|
CVE-2021-28545
|
2024-11-21 14:59 |
2021-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194580
|
2.7 |
LOW
Network
|
eclipse fedoraproject apache netapp oracle
|
jetty fedora solr ignite santricity_cloud_connector snapcenter e-series_performance_analyzer e-series_santricity_web_services virtual_storage_console storage_replication_ad…
|
In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a sta…
|
CWE-59
Link Following
|
CVE-2021-28163
|
2024-11-21 14:59 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|