|
195271
|
6.1 |
MEDIUM
Network
|
margox
|
braft-editor
|
Cross Site Scripting (XSS) vulnerability in margox braft-editor version 2.3.8, allows remote attackers to execute arbitrary code via the embed media feature.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27524
|
2024-11-21 14:58 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195272
|
9.8 |
CRITICAL
Network
|
open-falcon
|
dashboard
|
An issue was discovered in open-falcon dashboard version 0.2.0, allows remote attackers to gain, modify, and delete sensitive information via crafted POST request to register interface.
|
NVD-CWE-noinfo
|
CVE-2021-27523
|
2024-11-21 14:58 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195273
|
7.5 |
HIGH
Network
|
mercurycom
|
mac1200r_firmware
|
A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-static/ URL.
|
CWE-22
Path Traversal
|
CVE-2021-27825
|
2024-11-21 14:58 |
2023-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195274
|
7.5 |
HIGH
Network
|
hcltech
|
hcl_launch_container_image
|
The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys and certificates. Th…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2021-27784
|
2024-11-21 14:58 |
2022-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195275
|
4.7 |
MEDIUM
Adjacent
|
ieee ietf
|
ieee_802.2 p802.1q
|
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length and Ethernet to Wifi frame conversion (and optionally VLAN0 headers).
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2021-27862
|
2024-11-21 14:58 |
2022-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195276
|
4.7 |
MEDIUM
Adjacent
|
ieee ietf
|
ieee_802.2 p802.1q
|
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length (and optionally VLAN0 headers)
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2021-27861
|
2024-11-21 14:58 |
2022-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195277
|
4.7 |
MEDIUM
Adjacent
|
ieee ietf
|
ieee_802.2 p802.1q
|
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using combinations of VLAN 0 headers, LLC/SNAP headers, and converting frames from Ethernet to Wifi and its reverse.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2021-27854
|
2024-11-21 14:58 |
2022-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195278
|
4.7 |
MEDIUM
Adjacent
|
ieee ietf cisco
|
ieee_802.2 p802.1q catalyst_6503-e_firmware catalyst_6504-e_firmware catalyst_6506-e_firmware catalyst_6509-e_firmware catalyst_6509-neb-a_firmware catalyst_6509-v-e_firmware …
|
Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2021-27853
|
2024-11-21 14:58 |
2022-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195279
|
5.4 |
MEDIUM
Network
|
hcltech
|
hcl_digital_experience
|
User input included in error response, which could be used in a phishing attack.
|
CWE-20
Improper Input Validation
|
CVE-2021-27774
|
2024-11-21 14:58 |
2022-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195280
|
9.8 |
CRITICAL
Network
|
publiccms
|
publiccms
|
Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-27693
|
2024-11-21 14:58 |
2022-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|