|
194671
|
5.0 |
MEDIUM
Local
|
hcltechsw
|
hcl_commerce
|
HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerability requires the victim to first perform a particular operation on the website.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2021-27785
|
2024-11-21 14:58 |
2022-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194672
|
9.8 |
CRITICAL
Network
|
hcltech
|
onetest_server
|
Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that identifies the domain that is making the initial …
|
CWE-697
Incorrect Comparison
|
CVE-2021-27786
|
2024-11-21 14:58 |
2022-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194673
|
4.8 |
MEDIUM
Network
|
acquia
|
mautic
|
A cross-site scripting (XSS) vulnerability in the installer component of Mautic before 4.3.0 allows admins to inject executable javascript
|
CWE-79
Cross-site Scripting
|
CVE-2021-27914
|
2024-11-21 14:58 |
2022-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194674
|
4.8 |
MEDIUM
Network
|
hcltech
|
traveler
|
HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could ex…
|
CWE-79
Cross-site Scripting
|
CVE-2021-27778
|
2024-11-21 14:58 |
2022-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194675
|
4.8 |
MEDIUM
Network
|
hcltech
|
modern_client_management bigfix_mobile
|
The Master operator may be able to embed script tag in HTML with alert pop-up display cookie.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27781
|
2024-11-21 14:58 |
2022-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194676
|
5.3 |
MEDIUM
Network
|
hcltech
|
modern_client_management bigfix_mobile
|
The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.
|
NVD-CWE-noinfo
|
CVE-2021-27780
|
2024-11-21 14:58 |
2022-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194677
|
6.5 |
MEDIUM
Network
|
hcltech
|
bigfix_modern_client_management bigfix_mobile
|
User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed.
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2021-27783
|
2024-11-21 14:58 |
2022-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194678
|
9.1 |
CRITICAL
Network
|
hcltech
|
versionvault_express
|
VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on communications with the server.
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2021-27779
|
2024-11-21 14:58 |
2022-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194679
|
5.5 |
MEDIUM
Local
|
xpdfreader
|
xpdf
|
There is a Null Pointer Dereference vulnerability in the XFAScanner::scanNode() function in XFAScanner.cc in xpdf 4.03.
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-27548
|
2024-11-21 14:58 |
2022-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194680
|
9.8 |
CRITICAL
Network
|
weintek
|
cmt-svr-100_firmware cmt-svr-102_firmware cmt-svr-200_firmware cmt-svr-202_firmware cmt-g01_firmware cmt-g02_firmware cmt-g03_firmware cmt-g04_firmware cmt3071_firmware cmt…
|
The Weintek cMT product line is vulnerable to code injection, which may allow an unauthenticated remote attacker to execute commands with root privileges on the operation system.
|
CWE-94
Code Injection
|
CVE-2021-27446
|
2024-11-21 14:58 |
2022-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|