|
195641
|
7.5 |
HIGH
Network
|
jetbrains
|
teamcity
|
In the TeamCity IntelliJ plugin before 2020.2.2.85899, DoS was possible.
|
NVD-CWE-noinfo
|
CVE-2021-26310
|
2024-11-21 14:56 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195642
|
3.3 |
LOW
Local
|
jetbrains
|
teamcity
|
Information disclosure in the TeamCity plugin for IntelliJ before 2020.2.2.85899 was possible because a local temporary file had Insecure Permissions.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2021-26309
|
2024-11-21 14:56 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195643
|
9.8 |
CRITICAL
Network
|
hp
|
ilo_amplifier_pack
|
A potential security vulnerability was identified in HPE iLO Amplifier Pack. The vulnerabilities could be remotely exploited to allow remote code execution.
|
NVD-CWE-noinfo
|
CVE-2021-26583
|
2024-11-21 14:56 |
2021-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195644
|
8.8 |
HIGH
Network
|
wayfair
|
git-parse
|
The "gitDiff" function in Wayfair git-parse <=1.0.4 has a command injection vulnerability. Clients of the git-parse library are unlikely to be aware of this, so they might unwittingly write code that…
|
CWE-78
OS Command
|
CVE-2021-26543
|
2024-11-21 14:56 |
2021-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195645
|
6.5 |
MEDIUM
Network
|
centreon
|
centreon_web
|
Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validation by changing any file extension to ".gif", then uploading it in the "Administr…
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-26804
|
2024-11-21 14:56 |
2021-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195646
|
7.8 |
HIGH
Local
|
gog
|
galaxy
|
GalaxyClient version 2.0.28.9 loads unsigned DLLs such as zlib1.dll, libgcc_s_dw2-1.dll and libwinpthread-1.dll from PATH, which allows an attacker to potentially run code locally through unsigned DL…
|
CWE-426
Untrusted Search Path
|
CVE-2021-26807
|
2024-11-21 14:56 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195647
|
9.8 |
CRITICAL
Network
|
hametech
|
hame_sd1_wi-fi_firmware
|
An access control vulnerability in Hame SD1 Wi-Fi firmware <=V.20140224154640 allows an attacker to get system administrator through an open Telnet service.
|
CWE-521
Weak Password Requirements
|
CVE-2021-26797
|
2024-11-21 14:56 |
2021-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195648
|
9.1 |
CRITICAL
Network
|
apache quarkus oracle
|
maven quarkus financial_services_analytical_applications_infrastructure goldengate_big_data_and_application_adapters
|
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over …
|
CWE-346
Origin Validation Error
|
CVE-2021-26291
|
2024-11-21 14:56 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195649
|
9.1 |
CRITICAL
Network
|
tribalsystems
|
zenario
|
SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is accomplished via the `ID` input field of ajax.php in the `Pugin libra…
|
CWE-89
SQL Injection
|
CVE-2021-26830
|
2024-11-21 14:56 |
2021-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195650
|
6.1 |
MEDIUM
Network
|
hp
|
icewall_sso_dgfw
|
A security vulnerability in HPE IceWall SSO Domain Gateway Option (Dgfw) module version 10.0 on RHEL 5/6/7, version 10.0 on HP-UX 11i v3, version 10.0 on Windows and 11.0 on Windows could be exploite…
|
CWE-79
Cross-site Scripting
|
CVE-2021-26582
|
2024-11-21 14:56 |
2021-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|