|
194801
|
9.8 |
CRITICAL
Network
|
sap
|
netweaver_application_server_abap netweaver_abap
|
SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about internal and external RFC user in consistent and …
|
CWE-287
Improper Authentication
|
CVE-2021-27610
|
2024-11-21 14:58 |
2021-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194802
|
7.5 |
HIGH
Network
|
zoll
|
defibrillator_dashboard
|
ZOLL Defibrillator Dashboard, v prior to 2.2,The application allows users to store their passwords in a recoverable format, which could allow an attacker to retrieve the credentials from the web brow…
|
-
|
CVE-2021-27485
|
2024-11-21 14:58 |
2021-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194803
|
7.8 |
HIGH
Local
|
zoll
|
defibrillator_dashboard
|
ZOLL Defibrillator Dashboard, v prior to 2.2,The affected products contain insecure filesystem permissions that could allow a lower privilege user to escalate privileges to an administrative level us…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2021-27483
|
2024-11-21 14:58 |
2021-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194804
|
5.4 |
MEDIUM
Network
|
zoll
|
defibrillator_dashboard
|
ZOLL Defibrillator Dashboard, v prior to 2.2,The affected product’s web application could allow a low privilege user to inject parameters to contain malicious scripts to be executed by higher privile…
|
-
|
CVE-2021-27479
|
2024-11-21 14:58 |
2021-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194805
|
8.8 |
HIGH
Network
|
zoll
|
defibrillator_dashboard
|
ZOLL Defibrillator Dashboard, v prior to 2.2, The web application allows a non-administrative user to upload a malicious file. This file could allow an attacker to remotely execute arbitrary commands.
|
-
|
CVE-2021-27489
|
2024-11-21 14:58 |
2021-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194806
|
5.5 |
MEDIUM
Local
|
zoll
|
defibrillator_dashboard
|
ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products contain credentials stored in plaintext. This could allow an attacker to gain access to sensitive information.
|
-
|
CVE-2021-27487
|
2024-11-21 14:58 |
2021-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194807
|
5.5 |
MEDIUM
Local
|
zoll
|
defibrillator_dashboard
|
ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products utilize an encryption key in the data exchange process, which is hardcoded. This could allow an attacker to gain access to sensitiv…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2021-27481
|
2024-11-21 14:58 |
2021-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194808
|
5.4 |
MEDIUM
Network
|
hitachiabb-powergrids
|
ellipse_asset_performance_management
|
Cross-site Scripting (XSS) vulnerability in the main dashboard of Ellipse APM versions allows an authenticated user or integrated application to inject malicious data into the application that can th…
|
CWE-79
Cross-site Scripting
|
CVE-2021-27887
|
2024-11-21 14:58 |
2021-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194809
|
5.5 |
MEDIUM
Local
|
sap
|
3d_visual_enterprise_viewer
|
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of the application and becoming temporarily unavaila…
|
CWE-20
Improper Input Validation
|
CVE-2021-27643
|
2024-11-21 14:58 |
2021-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194810
|
5.5 |
MEDIUM
Local
|
sap
|
3d_visual_enterprise_viewer
|
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavaila…
|
CWE-20
Improper Input Validation
|
CVE-2021-27642
|
2024-11-21 14:58 |
2021-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|