| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-22930 | Cri | 0.67 | 9.8 | 0.36 | Oct 7, 2021 | Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior. | ||
| CVE-2021-32172 | Cri | 0.72 | 9.8 | 0.66 | Oct 7, 2021 | Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin. | ||
| CVE-2020-21653 | Cri | 0.59 | 9.1 | 0.01 | Oct 6, 2021 | Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploited via the sj() method. | ||
| CVE-2020-21652 | Cri | 0.64 | 9.8 | 0.03 | Oct 6, 2021 | Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the addqq() method. | ||
| CVE-2020-21651 | Cri | 0.64 | 9.8 | 0.03 | Oct 6, 2021 | Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\point.php, which can be exploited via the add() method. | ||
| CVE-2020-21648 | Cri | 0.59 | 9.1 | 0.01 | Oct 6, 2021 | WDJA CMS v1.5.2 contains an arbitrary file deletion vulnerability in the component admin/cache/manage.php. | ||
| CVE-2021-41128 | Cri | 0.59 | 9.1 | 0.01 | Oct 6, 2021 | Hygeia is an application for collecting and processing personal and case data in connection with communicable diseases. In affected versions all CSV Exports (Statistics & BAG MED) contain a CSV Injection Vulnerability. Users of the system are able to submit formula as exported… | ||
| CVE-2021-38923 | Cri | 0.59 | 9.1 | 0.01 | Oct 6, 2021 | IBM PowerVM Hypervisor FW1010 could allow a privileged user to gain access to another VM due to assigning duplicate WWPNs. IBM X-Force ID: 210162. | ||
| CVE-2021-29908 | Cri | 0.64 | 9.8 | 0.02 | Oct 6, 2021 | The IBM TS7700 Management Interface is vulnerable to unauthenticated access. By accessing a specially-crafted URL, an attacker may gain administrative access to the Management Interface without authentication. IBM X-Force ID: 207747. | ||
| CVE-2021-29903 | Cri | 0.64 | 9.8 | 0.01 | Oct 6, 2021 | IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID:… | ||
| CVE-2021-29798 | Cri | 0.64 | 9.8 | 0.01 | Oct 6, 2021 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID:… | ||
| CVE-2021-3625 | Cri | 0.63 | 9.6 | 0.02 | Oct 5, 2021 | Buffer overflow in Zephyr USB DFU DNLOAD. Zephyr versions >= v2.5.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-c3gr-hgvr-f363 | ||
| CVE-2021-39226 | Cri | 0.77 | 9.8 | 1.00 | KEV | Oct 5, 2021 | Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /api/snapshots/:key. If the snapshot… | |
| CVE-2021-41553 | Cri | 0.64 | 9.8 | 0.01 | Oct 5, 2021 | In ARCHIBUS Web Central 21.3.3.815 (a version from 2014), the Web Application in /archibus/login.axvw assign a session token that could be already in use by another user. It was therefore possible to access the application through a user whose credentials were not known, without… | ||
| CVE-2021-41773 | Cri | 0.86 | 9.8 | 1.00 | KEV | Oct 5, 2021 | A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the… | |
| CVE-2021-23857 | Cri | 0.65 | 10.0 | 0.01 | Oct 4, 2021 | Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this allows an attacker to subsequently login to the system. | ||
| CVE-2021-23856 | Cri | 0.65 | 10.0 | 0.01 | Oct 4, 2021 | The web server is vulnerable to reflected XSS and therefore an attacker might be able to execute scripts on a client’s computer by sending the client a manipulated URL. | ||
| CVE-2021-41592 | Cri | 0.61 | 9.4 | 0.02 | Oct 4, 2021 | Blockstream c-lightning through 0.10.1 allows loss of funds because of dust HTLC exposure. | ||
| CVE-2021-41591 | Cri | 0.61 | 9.4 | 0.02 | Oct 4, 2021 | ACINQ Eclair before 0.6.3 allows loss of funds because of dust HTLC exposure. | ||
| CVE-2021-35296 | Cri | 0.64 | 9.8 | 0.02 | Oct 4, 2021 | An issue in the administrator authentication panel of PTCL HG150-Ub v3.0 allows attackers to bypass authentication via modification of the cookie value and Response Path. | ||
| CVE-2021-41868 | Cri | 0.64 | 9.8 | 0.02 | Oct 4, 2021 | OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to upload files on a non-public node when using the --receive functionality. | ||
| CVE-2021-38823 | Cri | 0.64 | 9.8 | 0.02 | Oct 4, 2021 | The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue. A signout from an admin account does not invalidate an admin session that is opened in a different browser. | ||
| CVE-2021-37333 | Cri | 0.64 | 9.8 | 0.01 | Oct 4, 2021 | Laravel Booking System Booking Core 2.0 is vulnerable to Session Management. A password change at sandbox.bookingcore.org/user/profile/change-password does not invalidate a session that is opened in a different browser. | ||
| CVE-2021-41511 | Cri | 0.64 | 9.8 | 0.03 | Oct 4, 2021 | The username and password field of login in Lodging Reservation Management System V1 can give access to any user by using SQL injection to bypass authentication. | ||
| CVE-2021-40323 | Cri | 0.64 | 9.8 | 0.87 | Oct 4, 2021 | Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection. | ||
| CVE-2021-41862 | Cri | 0.64 | 9.8 | 0.02 | Oct 2, 2021 | AviatorScript through 5.2.7 allows code execution via an expression that is encoded with Byte Code Engineering Library (BCEL). | ||
| CVE-2020-21012 | Cri | 0.64 | 9.8 | 0.04 | Oct 1, 2021 | Sourcecodester Hotel and Lodge Management System 2.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the email parameter to the edit page for Customer, Room, Currency, Room Booking Details, or Tax Details. | ||
| CVE-2021-41647 | Cri | 0.59 | 9.1 | 0.02 | Oct 1, 2021 | An un-authenticated error-based and time-based blind SQL injection vulnerability exists in Kaushik Jadhav Online Food Ordering Web App 1.0. An attacker can exploit the vulnerable "username" parameter in login.php and retrieve sensitive database information, as well as add an… | ||
| CVE-2021-3825 | Cri | 0.63 | 9.6 | 0.02 | Oct 1, 2021 | On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to the configurations API could get valid LDAP credentials. | ||
| CVE-2021-41649 | Cri | 0.68 | 9.8 | 0.52 | Oct 1, 2021 | An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input. | ||
| CVE-2021-40960 | Cri | 0.64 | 9.8 | 0.10 | Oct 1, 2021 | Galera WebTemplate 1.0 is affected by a directory traversal vulnerability that could reveal information from /etc/passwd and /etc/shadow. | ||
| CVE-2021-41110 | Cri | 0.59 | 9.1 | 0.03 | Oct 1, 2021 | cwlviewer is a web application to view and share Common Workflow Language workflows. Versions prior to 1.3.1 contain a Deserialization of Untrusted Data vulnerability. Commit number f6066f09edb70033a2ce80200e9fa9e70a5c29de (dated 2021-09-30) contains a patch. There are no… | ||
| CVE-2020-20797 | Cri | 0.64 | 9.8 | 0.01 | Sep 30, 2021 | FlameCMS 3.3.5 contains a time-based blind SQL injection vulnerability in /account/register.php. | ||
| CVE-2020-20796 | Cri | 0.64 | 9.8 | 0.01 | Sep 30, 2021 | FlameCMS 3.3.5 contains a SQL injection vulnerability in /master/article.php via the "Id" parameter. | ||
| CVE-2021-33583 | Cri | 0.64 | 9.8 | 0.01 | Sep 30, 2021 | REINER timeCard 6.05.07 installs a Microsoft SQL Server with an sa password that is hardcoded in the TCServer.jar file. | ||
| CVE-2021-41288 | Cri | 0.70 | 9.8 | 0.80 | Sep 30, 2021 | Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API. | ||
| CVE-2021-20578 | Cri | 0.64 | 9.8 | 0.01 | Sep 30, 2021 | IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized actions due to improper or missing authentication controls. IBM X-Force ID: 199282. | ||
| CVE-2021-41729 | Cri | 0.59 | 9.1 | 0.01 | Sep 30, 2021 | BaiCloud-cms v2.5.7 is affected by an arbitrary file deletion vulnerability, which allows an attacker to delete arbitrary files on the server through /user/ppsave.php. | ||
| CVE-2021-41301 | Cri | 0.64 | 9.8 | 0.02 | Sep 30, 2021 | ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. This will enable the unauthenticated attacker to remotely disclose sensitive information and help her in authentication bypass,… | ||
| CVE-2021-41300 | Cri | 0.64 | 9.8 | 0.01 | Sep 30, 2021 | ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page and obtain privilege with full functionality. | ||
| CVE-2021-41299 | Cri | 0.64 | 9.8 | 0.02 | Sep 30, 2021 | ECOA BAS controller is vulnerable to hard-coded credentials within its Linux distribution image, thus remote attackers can obtain administrator’s privilege without logging in. | ||
| CVE-2021-41296 | Cri | 0.64 | 9.8 | 0.01 | Sep 30, 2021 | ECOA BAS controller uses weak set of default administrative credentials that can be easily guessed in remote password attacks and gain full control of the system. | ||
| CVE-2021-41294 | Cri | 0.59 | 9.1 | 0.01 | Sep 30, 2021 | ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files deletion. Using the specific GET parameter, unauthenticated attackers can remotely delete arbitrary files on the affected device and cause denial of service scenario. | ||
| CVE-2021-41292 | Cri | 0.64 | 9.8 | 0.01 | Sep 30, 2021 | ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can remotely bypass authentication and disclose sensitive information and circumvent physical access controls in smart homes and buildings and manipulate… | ||
| CVE-2021-41290 | Cri | 0.64 | 9.8 | 0.02 | Sep 30, 2021 | ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, unauthenticated attackers can remotely set arbitrary values for location and content type and gain the possibility to execute arbitrary code on the affected… | ||
| CVE-2021-41616 | Cri | 0.64 | 9.8 | 0.03 | Sep 30, 2021 | Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL data type of BINARY, VARBINARY, LONGVARBINARY, or BLOB between databases using the ddlutils features. The BinaryObjectsHelper class was insecure and used… | ||
| CVE-2020-18685 | Cri | 0.64 | 9.8 | 0.01 | Sep 30, 2021 | Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of unchecked prerequisites related to TCP or UDP ports, or group or table IDs. | ||
| CVE-2020-18684 | Cri | 0.64 | 9.8 | 0.01 | Sep 30, 2021 | Floodlight through 1.2 has an integer overflow in checkFlow in StaticFlowEntryPusherResource.java via priority or port number. | ||
| CVE-2020-18683 | Cri | 0.64 | 9.8 | 0.01 | Sep 30, 2021 | Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of undefined fields mishandling. | ||
| CVE-2021-35943 | Cri | 0.64 | 9.8 | 0.01 | Sep 29, 2021 | Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password, per RFC4513. |
- risk 0.67cvss 9.8epss 0.36
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.
- risk 0.72cvss 9.8epss 0.66
Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin.
- risk 0.59cvss 9.1epss 0.01
Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploited via the sj() method.
- risk 0.64cvss 9.8epss 0.03
Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the addqq() method.
- risk 0.64cvss 9.8epss 0.03
Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\point.php, which can be exploited via the add() method.
- risk 0.59cvss 9.1epss 0.01
WDJA CMS v1.5.2 contains an arbitrary file deletion vulnerability in the component admin/cache/manage.php.
- risk 0.59cvss 9.1epss 0.01
Hygeia is an application for collecting and processing personal and case data in connection with communicable diseases. In affected versions all CSV Exports (Statistics & BAG MED) contain a CSV Injection Vulnerability. Users of the system are able to submit formula as exported…
- risk 0.59cvss 9.1epss 0.01
IBM PowerVM Hypervisor FW1010 could allow a privileged user to gain access to another VM due to assigning duplicate WWPNs. IBM X-Force ID: 210162.
- risk 0.64cvss 9.8epss 0.02
The IBM TS7700 Management Interface is vulnerable to unauthenticated access. By accessing a specially-crafted URL, an attacker may gain administrative access to the Management Interface without authentication. IBM X-Force ID: 207747.
- risk 0.64cvss 9.8epss 0.01
IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID:…
- risk 0.64cvss 9.8epss 0.01
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID:…
- risk 0.63cvss 9.6epss 0.02
Buffer overflow in Zephyr USB DFU DNLOAD. Zephyr versions >= v2.5.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-c3gr-hgvr-f363
- risk 0.77cvss 9.8epss 1.00
Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /api/snapshots/:key. If the snapshot…
- risk 0.64cvss 9.8epss 0.01
In ARCHIBUS Web Central 21.3.3.815 (a version from 2014), the Web Application in /archibus/login.axvw assign a session token that could be already in use by another user. It was therefore possible to access the application through a user whose credentials were not known, without…
- risk 0.86cvss 9.8epss 1.00
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the…
- risk 0.65cvss 10.0epss 0.01
Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this allows an attacker to subsequently login to the system.
- risk 0.65cvss 10.0epss 0.01
The web server is vulnerable to reflected XSS and therefore an attacker might be able to execute scripts on a client’s computer by sending the client a manipulated URL.
- risk 0.61cvss 9.4epss 0.02
Blockstream c-lightning through 0.10.1 allows loss of funds because of dust HTLC exposure.
- risk 0.61cvss 9.4epss 0.02
ACINQ Eclair before 0.6.3 allows loss of funds because of dust HTLC exposure.
- risk 0.64cvss 9.8epss 0.02
An issue in the administrator authentication panel of PTCL HG150-Ub v3.0 allows attackers to bypass authentication via modification of the cookie value and Response Path.
- risk 0.64cvss 9.8epss 0.02
OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to upload files on a non-public node when using the --receive functionality.
- risk 0.64cvss 9.8epss 0.02
The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue. A signout from an admin account does not invalidate an admin session that is opened in a different browser.
- risk 0.64cvss 9.8epss 0.01
Laravel Booking System Booking Core 2.0 is vulnerable to Session Management. A password change at sandbox.bookingcore.org/user/profile/change-password does not invalidate a session that is opened in a different browser.
- risk 0.64cvss 9.8epss 0.03
The username and password field of login in Lodging Reservation Management System V1 can give access to any user by using SQL injection to bypass authentication.
- risk 0.64cvss 9.8epss 0.87
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.
- risk 0.64cvss 9.8epss 0.02
AviatorScript through 5.2.7 allows code execution via an expression that is encoded with Byte Code Engineering Library (BCEL).
- risk 0.64cvss 9.8epss 0.04
Sourcecodester Hotel and Lodge Management System 2.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the email parameter to the edit page for Customer, Room, Currency, Room Booking Details, or Tax Details.
- risk 0.59cvss 9.1epss 0.02
An un-authenticated error-based and time-based blind SQL injection vulnerability exists in Kaushik Jadhav Online Food Ordering Web App 1.0. An attacker can exploit the vulnerable "username" parameter in login.php and retrieve sensitive database information, as well as add an…
- risk 0.63cvss 9.6epss 0.02
On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to the configurations API could get valid LDAP credentials.
- risk 0.68cvss 9.8epss 0.52
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.
- risk 0.64cvss 9.8epss 0.10
Galera WebTemplate 1.0 is affected by a directory traversal vulnerability that could reveal information from /etc/passwd and /etc/shadow.
- risk 0.59cvss 9.1epss 0.03
cwlviewer is a web application to view and share Common Workflow Language workflows. Versions prior to 1.3.1 contain a Deserialization of Untrusted Data vulnerability. Commit number f6066f09edb70033a2ce80200e9fa9e70a5c29de (dated 2021-09-30) contains a patch. There are no…
- risk 0.64cvss 9.8epss 0.01
FlameCMS 3.3.5 contains a time-based blind SQL injection vulnerability in /account/register.php.
- risk 0.64cvss 9.8epss 0.01
FlameCMS 3.3.5 contains a SQL injection vulnerability in /master/article.php via the "Id" parameter.
- risk 0.64cvss 9.8epss 0.01
REINER timeCard 6.05.07 installs a Microsoft SQL Server with an sa password that is hardcoded in the TCServer.jar file.
- risk 0.70cvss 9.8epss 0.80
Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.
- risk 0.64cvss 9.8epss 0.01
IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized actions due to improper or missing authentication controls. IBM X-Force ID: 199282.
- risk 0.59cvss 9.1epss 0.01
BaiCloud-cms v2.5.7 is affected by an arbitrary file deletion vulnerability, which allows an attacker to delete arbitrary files on the server through /user/ppsave.php.
- risk 0.64cvss 9.8epss 0.02
ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. This will enable the unauthenticated attacker to remotely disclose sensitive information and help her in authentication bypass,…
- risk 0.64cvss 9.8epss 0.01
ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page and obtain privilege with full functionality.
- risk 0.64cvss 9.8epss 0.02
ECOA BAS controller is vulnerable to hard-coded credentials within its Linux distribution image, thus remote attackers can obtain administrator’s privilege without logging in.
- risk 0.64cvss 9.8epss 0.01
ECOA BAS controller uses weak set of default administrative credentials that can be easily guessed in remote password attacks and gain full control of the system.
- risk 0.59cvss 9.1epss 0.01
ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files deletion. Using the specific GET parameter, unauthenticated attackers can remotely delete arbitrary files on the affected device and cause denial of service scenario.
- risk 0.64cvss 9.8epss 0.01
ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can remotely bypass authentication and disclose sensitive information and circumvent physical access controls in smart homes and buildings and manipulate…
- risk 0.64cvss 9.8epss 0.02
ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, unauthenticated attackers can remotely set arbitrary values for location and content type and gain the possibility to execute arbitrary code on the affected…
- risk 0.64cvss 9.8epss 0.03
Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL data type of BINARY, VARBINARY, LONGVARBINARY, or BLOB between databases using the ddlutils features. The BinaryObjectsHelper class was insecure and used…
- risk 0.64cvss 9.8epss 0.01
Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of unchecked prerequisites related to TCP or UDP ports, or group or table IDs.
- risk 0.64cvss 9.8epss 0.01
Floodlight through 1.2 has an integer overflow in checkFlow in StaticFlowEntryPusherResource.java via priority or port number.
- risk 0.64cvss 9.8epss 0.01
Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of undefined fields mishandling.
- risk 0.64cvss 9.8epss 0.01
Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password, per RFC4513.