|
191481
|
8.8 |
HIGH
Network
|
chinamobile
|
an_lianbao_wf-1_firmware
|
China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRMesh/set_ZRMesh which receives parameters by POST request, and the parameter mesh_enable and mesh_device have a command inje…
|
CWE-77
Command Injection
|
CVE-2021-33965
|
2024-11-21 15:09 |
2022-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191482
|
8.8 |
HIGH
Network
|
chinamobile
|
an_lianbao_wf-1_firmware
|
China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRRuleFilter/set_firewall_level which receives parameters by POST request, and the parameter firewall_level has a command inje…
|
CWE-77
Command Injection
|
CVE-2021-33964
|
2024-11-21 15:09 |
2022-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191483
|
8.8 |
HIGH
Network
|
owncloud
|
files_antivirus
|
The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploaded to a public share) are supposed to be deleted upon detect…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-33828
|
2024-11-21 15:09 |
2022-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191484
|
7.2 |
HIGH
Network
|
owncloud
|
files_antivirus
|
The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings.
|
CWE-78
OS Command
|
CVE-2021-33827
|
2024-11-21 15:09 |
2022-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191485
|
9.8 |
CRITICAL
Network
|
chinamobile
|
an_lianbao_wf-1_firmware
|
China Mobile An Lianbao WF-1 v1.0.1 router web interface through /api/ZRMacClone/mac_addr_clone receives parameters by POST request, and the parameter macType has a command injection vulnerability. A…
|
CWE-77
Command Injection
|
CVE-2021-33963
|
2024-11-21 15:09 |
2022-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191486
|
9.8 |
CRITICAL
Network
|
chinamobileltd
|
an_lianbao_wf_firmware-1
|
China Mobile An Lianbao WF-1 router v1.0.1 is affected by an OS command injection vulnerability in the web interface /api/ZRUsb/pop_usb_device component.
|
CWE-78
OS Command
|
CVE-2021-33962
|
2024-11-21 15:09 |
2022-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191487
|
7.1 |
HIGH
Network
|
ultimaker
|
ultimaker_s3_firmware ultimaker_s5_firmware ultimaker_3_firmware
|
In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5.2.16, the local webserver can be used for clickjacking. This includes the sett…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2021-34087
|
2024-11-21 15:09 |
2022-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191488
|
8.8 |
HIGH
Network
|
ultimaker
|
ultimaker_s3_firmware ultimaker_s5_firmware ultimaker_3_firmware
|
In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5.2.16, the local webserver hosts APIs vulnerable to CSRF. They do not verify in…
|
CWE-352
Origin Validation Error
|
CVE-2021-34086
|
2024-11-21 15:09 |
2022-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191489
|
5.3 |
MEDIUM
Network
|
numpy oracle
|
numpy communications_cloud_native_core_policy
|
An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor sta…
|
CWE-697
Incorrect Comparison
|
CVE-2021-34141
|
2024-11-21 15:09 |
2021-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191490
|
5.4 |
MEDIUM
Network
|
microsoft
|
clarity
|
There is a Cross-Site Scripting vulnerability in Microsoft Clarity version 0.3. The XSS payload executes whenever the user changes the clarity configuration in Microsoft Clarity version 0.3. The payl…
|
CWE-79
Cross-site Scripting
|
CVE-2021-33850
|
2024-11-21 15:09 |
2021-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|