|
190981
|
9.8 |
CRITICAL
Network
|
connectwise
|
automate
|
An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.
|
CWE-611
XXE
|
CVE-2021-35066
|
2024-11-21 15:11 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190982
|
4.8 |
MEDIUM
Network
|
checksec
|
canopy
|
CheckSec Canopy before 3.5.2 allows XSS attacks against the login page via the LOGIN_PAGE_DISCLAIMER parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-34815
|
2024-11-21 15:11 |
2021-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190983
|
7.5 |
HIGH
Network
|
synology
|
calendar
|
Use of hard-coded credentials vulnerability in php component in Synology Calendar before 2.4.0-0761 allows remote attackers to obtain sensitive information via unspecified vectors.
|
-
|
CVE-2021-34812
|
2024-11-21 15:11 |
2021-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190984
|
4.3 |
MEDIUM
Network
|
synology
|
download_station
|
Server-Side Request Forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to access intranet resources via unspec…
|
-
|
CVE-2021-34811
|
2024-11-21 15:11 |
2021-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190985
|
8.8 |
HIGH
Network
|
synology
|
download_station
|
Improper privilege management vulnerability in cgi component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to execute arbitrary code via unspecified vectors.
|
-
|
CVE-2021-34810
|
2024-11-21 15:11 |
2021-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190986
|
8.8 |
HIGH
Network
|
synology
|
download_station
|
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in task management component in Synology Download Station before 3.8.16-3566 allows remote authentica…
|
-
|
CVE-2021-34809
|
2024-11-21 15:11 |
2021-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190987
|
5.3 |
MEDIUM
Network
|
synology
|
media_server
|
Server-Side Request Forgery (SSRF) vulnerability in cgi component in Synology Media Server before 1.8.3-2881 allows remote attackers to access intranet resources via unspecified vectors.
|
-
|
CVE-2021-34808
|
2024-11-21 15:11 |
2021-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190988
|
7.5 |
HIGH
Network
|
quassel-irc fedoraproject
|
quassel fedora
|
Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local system.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2021-34825
|
2024-11-21 15:11 |
2021-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190989
|
9.8 |
CRITICAL
Network
|
matrix
|
olm
|
Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup from the homeserver) because olm_pk_decrypt has …
|
CWE-787
Out-of-bounds Write
|
CVE-2021-34813
|
2024-11-21 15:11 |
2021-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190990
|
7.8 |
HIGH
Local
|
teamviewer
|
teamviewer
|
TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2021-34803
|
2024-11-21 15:11 |
2021-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|