Show filters
58 Total Results
Displaying 1-10 of 58
Sort by:
Attacker Value
Unknown
CVE-2021-22957
Disclosure Date: November 24, 2021 (last updated February 23, 2025)
A Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allows a malicious actor who has convinced a privileged user to access a URL with malicious code to take over said user’s account.This vulnerability is fixed in UniFi Protect application Version 1.20.0 and later.
0
Attacker Value
Unknown
CVE-2021-35233
Disclosure Date: October 19, 2021 (last updated February 23, 2025)
The HTTP TRACK & TRACE methods were enabled in Kiwi Syslog Server 9.7.1 and earlier. These methods are intended for diagnostic purposes only. If enabled, the web server will respond to requests that use these methods by returning exact HTTP request that was received in the response to the client. This may lead to the disclosure of sensitive information such as internal authentication headers appended by reverse proxies.
0
Attacker Value
Unknown
CVE-2021-31381
Disclosure Date: October 13, 2021 (last updated February 23, 2025)
A configuration weakness in the JBoss Application Server (AppSvr) component of Juniper Networks SRC Series allows a remote attacker to send a specially crafted query to cause the web server to delete files which may allow the attacker to disrupt the integrity and availability of the system.
0
Attacker Value
Unknown
CVE-2021-31380
Disclosure Date: October 13, 2021 (last updated February 23, 2025)
A configuration weakness in the JBoss Application Server (AppSvr) component of Juniper Networks SRC Series allows a remote attacker to send a specially crafted query to cause the web server to disclose sensitive information in the HTTP response which allows the attacker to obtain sensitive information.
0
Attacker Value
Unknown
CVE-2021-20032
Disclosure Date: August 10, 2021 (last updated February 23, 2025)
SonicWall Analytics 2.5 On-Prem is vulnerable to Java Debug Wire Protocol (JDWP) interface security misconfiguration vulnerability which potentially leads to Remote Code Execution. This vulnerability impacts Analytics On-Prem 2.5.2518 and earlier.
0
Attacker Value
Unknown
CVE-2021-21532
Disclosure Date: March 31, 2021 (last updated February 22, 2025)
Dell Wyse ThinOS 8.6 MR9 contains remediation for an improper management server validation vulnerability that could be potentially exploited to redirect a client to an attacker-controlled management server, thus allowing the attacker to change the device configuration or certificate file.
0
Attacker Value
Unknown
CVE-2021-0222
Disclosure Date: January 13, 2021 (last updated February 22, 2025)
A vulnerability in Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) to the device by sending certain crafted protocol packets from an adjacent device with invalid payloads to the device. These crafted packets, which should be discarded, are instead replicated and sent to the RE. Over time, a Denial of Service (DoS) occurs. Continued receipt of these crafted protocol packets will cause an extended Denial of Service (DoS) condition, which may cause wider traffic impact due to protocol flapping. An indication of compromise is to check "monitor interface traffic" on the ingress and egress port packet counts. For each ingress packet, two duplicate packets are seen on egress. This issue can be triggered by IPv4 and IPv6 packets. This issue affects all traffic through the device. This issue affects: Juniper Networks Junos OS: 14.1X53 versions prior to 14.1X53-D53 on EX4300, QFX3500, QFX5100, EX4600; 15.1 versions prior to 15.1R7-S6 on EX4300, QFX3500, QFX5100, …
0
Attacker Value
Unknown
CVE-2020-8351
Disclosure Date: November 30, 2020 (last updated February 22, 2025)
A privilege escalation vulnerability was reported in Lenovo PCManager prior to version 3.0.50.9162 that could allow an authenticated user to execute code with elevated privileges.
0
Attacker Value
Unknown
CVE-2020-8353
Disclosure Date: November 11, 2020 (last updated February 22, 2025)
Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) feature of Intel AMT enabled. This could allow an administrative user with local access to configure Intel AMT.
0
Attacker Value
Unknown
CVE-2020-16247
Disclosure Date: September 18, 2020 (last updated February 22, 2025)
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
0