|
196791
|
6.5 |
MEDIUM
Network
|
centreon
|
centreon_web
|
Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validation by changing any file extension to ".gif", then uploading it in the "Administr…
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-26804
|
2024-11-21 14:56 |
2021-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196792
|
7.8 |
HIGH
Local
|
gog
|
galaxy
|
GalaxyClient version 2.0.28.9 loads unsigned DLLs such as zlib1.dll, libgcc_s_dw2-1.dll and libwinpthread-1.dll from PATH, which allows an attacker to potentially run code locally through unsigned DL…
|
CWE-426
Untrusted Search Path
|
CVE-2021-26807
|
2024-11-21 14:56 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196793
|
9.8 |
CRITICAL
Network
|
hametech
|
hame_sd1_wi-fi_firmware
|
An access control vulnerability in Hame SD1 Wi-Fi firmware <=V.20140224154640 allows an attacker to get system administrator through an open Telnet service.
|
CWE-521
Weak Password Requirements
|
CVE-2021-26797
|
2024-11-21 14:56 |
2021-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196794
|
9.1 |
CRITICAL
Network
|
apache quarkus oracle
|
maven quarkus financial_services_analytical_applications_infrastructure goldengate_big_data_and_application_adapters
|
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over …
|
CWE-346
Origin Validation Error
|
CVE-2021-26291
|
2024-11-21 14:56 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196795
|
9.1 |
CRITICAL
Network
|
tribalsystems
|
zenario
|
SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is accomplished via the `ID` input field of ajax.php in the `Pugin libra…
|
CWE-89
SQL Injection
|
CVE-2021-26830
|
2024-11-21 14:56 |
2021-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196796
|
6.1 |
MEDIUM
Network
|
hp
|
icewall_sso_dgfw
|
A security vulnerability in HPE IceWall SSO Domain Gateway Option (Dgfw) module version 10.0 on RHEL 5/6/7, version 10.0 on HP-UX 11i v3, version 10.0 on Windows and 11.0 on Windows could be exploite…
|
CWE-79
Cross-site Scripting
|
CVE-2021-26582
|
2024-11-21 14:56 |
2021-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196797
|
6.1 |
MEDIUM
Network
|
priority-software
|
priority_enterprise_management_system
|
Cross Site Scripting (XSS) in the "Reset Password" page form of Priority Enterprise Management System v8.00 allows attackers to execute javascript on behalf of the victim by sending a malicious URL o…
|
CWE-79
Cross-site Scripting
|
CVE-2021-26832
|
2024-11-21 14:56 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196798
|
7.5 |
HIGH
Network
|
tp-link
|
tl-wr2041\+_firmware
|
Buffer Overflow in TP-Link WR2041 v1 firmware for the TL-WR2041+ router allows remote attackers to cause a Denial-of-Service (DoS) by sending an HTTP request with a very long "ssid" parameter to the …
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-26827
|
2024-11-21 14:56 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196799
|
6.1 |
MEDIUM
Network
|
jitsi
|
meet
|
Cross Site Scripting (XSS) in the Jitsi Meet 2.7 through 2.8.3 plugin for Moodle via the "sessionpriv.php" module. This allows attackers to craft a malicious URL, which when clicked on by users, can …
|
CWE-79
Cross-site Scripting
|
CVE-2021-26812
|
2024-11-21 14:56 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196800
|
5.5 |
MEDIUM
Local
|
tsmuxer_project
|
tsmuxer
|
Buffer Overflow in tsMuxer 2.6.16 allows attackers to cause a Denial of Service (DoS) by running the application with a malicious WAV file.
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-26805
|
2024-11-21 14:56 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|