|
195471
|
7.5 |
HIGH
Network
|
cpanel
|
cpanel
|
cPanel before 92.0.9 allows a Reseller to bypass the suspension lock (SEC-578).
|
NVD-CWE-Other
|
CVE-2021-26266
|
2024-11-21 14:56 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195472
|
6.5 |
MEDIUM
Network
|
intel
|
openvino
|
Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Toolkit may allow an authenticated user to potentially enable denial of service via network access.
|
CWE-20
Improper Input Validation
|
CVE-2021-26251
|
2024-11-21 14:55 |
2022-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195473
|
6.3 |
MEDIUM
Network
|
kubernetes
|
kubernetes
|
Kube-proxy
on Windows can unintentionally forward traffic to local processes
listening on the same port (“spec.ports[*].port”) as a LoadBalancer
Service when the LoadBalancer controller
does not …
|
NVD-CWE-noinfo
|
CVE-2021-25736
|
2024-11-21 14:55 |
2023-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195474
|
7.2 |
HIGH
Network
|
supermicro-cms_project
|
supermicro-cms
|
An issue was discovered in pcmt superMicro-CMS version 3.11, allows authenticated attackers to execute arbitrary code via the font_type parameter to setup.php.
|
NVD-CWE-noinfo
|
CVE-2021-25857
|
2024-11-21 14:55 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195475
|
4.9 |
MEDIUM
Network
|
supermicro-cms_project
|
supermicro-cms
|
An issue was discovered in pcmt superMicro-CMS version 3.11, allows attackers to delete files via crafted image file in images.php.
|
NVD-CWE-noinfo
|
CVE-2021-25856
|
2024-11-21 14:55 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195476
|
5.3 |
MEDIUM
Local
|
qpdf_project
|
qpdf
|
An issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file to Pl_ASCII85Decoder::write parameter in libqpdf.
|
CWE-416
Use After Free
|
CVE-2021-25786
|
2024-11-21 14:55 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195477
|
6.1 |
MEDIUM
Network
|
emby
|
emby
|
Emby Server versions < 4.6.0.50 is vulnerable to Cross Site Scripting (XSS) vulnerability via a crafted GET request to /web.
|
CWE-79
Cross-site Scripting
|
CVE-2021-25828
|
2024-11-21 14:55 |
2023-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195478
|
9.8 |
CRITICAL
Network
|
emby
|
emby
|
Emby Server < 4.7.12.0 is vulnerable to a login bypass attack by setting the X-Forwarded-For header to a local IP-address.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2021-25827
|
2024-11-21 14:55 |
2023-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195479
|
7.8 |
HIGH
Local
|
kubernetes
|
kubernetes
|
Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true.
|
NVD-CWE-noinfo
|
CVE-2021-25749
|
2024-11-21 14:55 |
2023-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195480
|
6.5 |
MEDIUM
Network
|
kubernetes
|
ingress-nginx
|
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the `spec.rules[].http.paths[].path` …
|
NVD-CWE-noinfo
|
CVE-2021-25748
|
2024-11-21 14:55 |
2023-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|