|
190861
|
6.1 |
MEDIUM
Network
|
cisco
|
identity_services_engine
|
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an attacker to conduct a cross-site scripting (XSS) attack against a user o…
|
CWE-79
Cross-site Scripting
|
CVE-2021-34738
|
2024-11-21 15:11 |
2021-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190862
|
7.5 |
HIGH
Network
|
cisco
|
unified_computing_system
|
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to cause the web-based management interf…
|
CWE-20
Improper Input Validation
|
CVE-2021-34736
|
2024-11-21 15:11 |
2021-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190863
|
7.5 |
HIGH
Network
|
proofpoint
|
spam_engine
|
Proofpoint Spam Engine before 8.12.0-2106240000 has a Security Control Bypass.
|
NVD-CWE-noinfo
|
CVE-2021-34814
|
2024-11-21 15:11 |
2021-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190864
|
5.3 |
MEDIUM
Network
|
openwaygroup
|
way4
|
/way4acs/enroll in OpenWay WAY4 ACS before 1.2.278-2693 allows unauthenticated attackers to leverage response differences to discover whether a specific payment card number is stored in the system.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2021-35060
|
2024-11-21 15:11 |
2021-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190865
|
6.1 |
MEDIUM
Network
|
openwaygroup
|
way4
|
OpenWay WAY4 ACS before 1.2.278-2693 allows XSS via the /way4acs/enroll action parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-35059
|
2024-11-21 15:11 |
2021-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190866
|
8.1 |
HIGH
Network
|
meross
|
msg100_firmware
|
Meross MSG100 devices before 3.2.3 allow an attacker to replay the same data or similar data (e.g., an attacker who sniffs a Close message can transmit an acceptable Open message).
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2021-35067
|
2024-11-21 15:11 |
2021-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190867
|
7.5 |
HIGH
Network
|
cisco
|
ata_190_firmware ata_191_firmware ata_192_firmware
|
Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perform a command injection attack resulting in remote code execution or cause a deni…
|
NVD-CWE-Other
|
CVE-2021-34735
|
2024-11-21 15:11 |
2021-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190868
|
8.8 |
HIGH
Network
|
cisco
|
ata_190_firmware ata_191_firmware ata_192_firmware
|
Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perform a command injection attack resulting in remote code execution or cause a deni…
|
CWE-78
OS Command
|
CVE-2021-34710
|
2024-11-21 15:11 |
2021-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190869
|
7.0 |
HIGH
Local
|
cisco
|
anyconnect_secure_mobility_client
|
A vulnerability in the shared library loading mechanism of Cisco AnyConnect Secure Mobility Client for Linux and Mac OS could allow an authenticated, local attacker to perform a shared library hijack…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2021-34788
|
2024-11-21 15:11 |
2021-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190870
|
4.3 |
MEDIUM
Network
|
cisco
|
dna_center
|
A vulnerability in the API endpoints for Cisco DNA Center could allow an authenticated, remote attacker to gain access to sensitive information that should be restricted. The attacker must have valid…
|
NVD-CWE-Other
|
CVE-2021-34782
|
2024-11-21 15:11 |
2021-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|