|
199421
|
5.3 |
MEDIUM
Network
|
uap-core_project
|
uap-core
|
uap-core in an open-source npm package which contains the core of BrowserScope's original user agent string parser. In uap-core before version 0.11.0, some regexes are vulnerable to regular expressio…
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2021-21317
|
2024-11-21 14:48 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199422
|
7.8 |
HIGH
Local
|
less-openui5_project
|
less-openui5
|
less-openui5 is an npm package which enables building OpenUI5 themes with Less.js. In less-openui5 before version 0.10., when processing theming resources (i.e. `*.less` files) with less-openui5 that…
|
-
|
CVE-2021-21316
|
2024-11-21 14:48 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199423
|
7.8 |
HIGH
Local
|
systeminformation apache
|
systeminformation cordova
|
The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation b…
|
CWE-78
OS Command
|
CVE-2021-21315
|
2024-11-21 14:48 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199424
|
8.1 |
HIGH
Network
|
dell
|
emc_avamar_server emc_integrated_data_protection_appliance
|
Dell EMC Avamar Server, versions 19.3 and 19.4 contain an Improper Authorization vulnerability in the web UI. A remote low privileged attacker could potentially exploit this vulnerability, to gain un…
|
NVD-CWE-Other
|
CVE-2021-21511
|
2024-11-21 14:48 |
2021-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199425
|
7.5 |
HIGH
Network
|
php debian netapp oracle
|
php debian_linux clustered_data_ontap communications_diameter_signaling_router
|
In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a SOAP server, a malicious SOAP server could return malformed XML data as a respo…
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-21702
|
2024-11-21 14:48 |
2021-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199426
|
9.8 |
CRITICAL
Network
|
dell
|
emc_powerscale_onefs
|
Dell PowerScale OneFS versions 8.1.0 – 9.1.0 contain a "use of SSH key past account expiration" vulnerability. A user on the network with the ISI_PRIV_AUTH_SSH RBAC privilege that has an expired acco…
|
CWE-287
Improper Authentication
|
CVE-2021-21502
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199427
|
9.1 |
CRITICAL
Network
|
sap
|
scimono
|
In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system.
|
CWE-74
Injection
|
CVE-2021-21479
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199428
|
6.1 |
MEDIUM
Network
|
sap
|
web_dynpro_abap
|
SAP Web Dynpro ABAP allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.
|
CWE-601
Open Redirect
|
CVE-2021-21478
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199429
|
9.9 |
CRITICAL
Network
|
sap
|
commerce
|
SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attacker with this privilege will be able to inject mali…
|
CWE-94
Code Injection
|
CVE-2021-21477
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199430
|
6.1 |
MEDIUM
Network
|
sap
|
ui5
|
SAP UI5 versions before 1.38.49, 1.52.49, 1.60.34, 1.71.31, 1.78.18, 1.84.5, 1.85.4, 1.86.1 allows an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerab…
|
CWE-601
Open Redirect
|
CVE-2021-21476
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|