|
194581
|
7.5 |
HIGH
Network
|
pbootcms
|
pbootcms
|
PbootCMS 3.0.4 contains a SQL injection vulnerability through index.php via the search parameter that can reveal sensitive information through adding an admin account.
|
CWE-89
SQL Injection
|
CVE-2021-28245
|
2024-11-21 14:59 |
2021-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194582
|
7.8 |
HIGH
Local
|
ca
|
ehealth_performance_manager
|
CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a setuid (and/or setgid) file. When a component is run as an argument of the runpicEhealth executable, the scri…
|
CWE-269
Improper Privilege Management
|
CVE-2021-28250
|
2024-11-21 14:59 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194583
|
8.8 |
HIGH
Local
|
ca
|
ehealth_performance_manager
|
CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. To exploit the vulnerability, the ehealth user must create a malici…
|
CWE-426
Untrusted Search Path
|
CVE-2021-28249
|
2024-11-21 14:59 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194584
|
7.5 |
HIGH
Network
|
broadcom
|
ehealth
|
CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is able to perform an arbitrary number of /web/frames/ authentica…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2021-28248
|
2024-11-21 14:59 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194585
|
5.4 |
MEDIUM
Network
|
ca
|
ehealth_performance_manager
|
CA eHealth Performance Manager through 6.3.2.12 is affected by Cross Site Scripting (XSS). The impact is: An authenticated remote user is able to inject arbitrary web script or HTML due to incorrect …
|
CWE-79
Cross-site Scripting
|
CVE-2021-28247
|
2024-11-21 14:59 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194586
|
7.8 |
HIGH
Local
|
broadcom
|
ehealth
|
CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. A regular user must create a malicious library in the writable RPAT…
|
CWE-426
Untrusted Search Path
|
CVE-2021-28246
|
2024-11-21 14:59 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194587
|
7.5 |
HIGH
Network
|
contiki-os
|
contiki
|
An issue was discovered in Contiki through 3.0. When sending an ICMPv6 error message because of invalid extension header options in an incoming IPv6 packet, there is an attempt to remove the RPL exte…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2021-28362
|
2024-11-21 14:59 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194588
|
5.5 |
MEDIUM
Local
|
netflix
|
priam
|
Priam uses File.createTempFile, which gives the permissions on that file -rw-r--r--. An attacker with read access to the local filesystem can read anything written there by the Priam process.
|
NVD-CWE-noinfo
|
CVE-2021-28100
|
2024-11-21 14:59 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194589
|
4.4 |
MEDIUM
Local
|
netflix
|
hollow
|
In Netflix OSS Hollow, since the Files.exists(parent) is run before creating the directories, an attacker can pre-create these directories with wide permissions. Additionally, since an insecure sourc…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2021-28099
|
2024-11-21 14:59 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194590
|
7.5 |
HIGH
Network
|
grafana
|
grafana
|
One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication. This allows any unauthenticate…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-28148
|
2024-11-21 14:59 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|