Show filters
186 Total Results
Displaying 101-110 of 186
Sort by:
Attacker Value
Unknown

CVE-2020-19275

Disclosure Date: May 12, 2021 (last updated February 22, 2025)
An Information Disclosure vulnerability exists in dhcms 2017-09-18 when entering invalid characters after the normal interface, which causes an error that will leak the physical path.
Attacker Value
Unknown

CVE-2021-31341

Disclosure Date: May 12, 2021 (last updated February 22, 2025)
Uploading a table mapping using a manipulated XML file results in an exception that could expose information about the application-server and the used XML-framework on the Mendix Database Replication Module (All versions prior to v7.0.1).
Attacker Value
Unknown

CVE-2021-31339

Disclosure Date: May 12, 2021 (last updated February 22, 2025)
A vulnerability has been identified in Mendix Excel Importer Module (All versions < V9.0.3). Uploading a manipulated XML File results in an exception that could expose information about the Application-Server and the used XML-Framework.
Attacker Value
Unknown

CVE-2020-4536

Disclosure Date: May 10, 2021 (last updated February 22, 2025)
IBM OpenPages GRC Platform 8.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 182907.
Attacker Value
Unknown

CVE-2021-21421

Disclosure Date: April 01, 2021 (last updated February 22, 2025)
node-etsy-client is a NodeJs Etsy ReST API Client. Applications that are using node-etsy-client and reporting client error to the end user will offer api key value too This is fixed in node-etsy-client v0.3.0 and later.
Attacker Value
Unknown

CVE-2021-21416

Disclosure Date: April 01, 2021 (last updated February 22, 2025)
django-registration is a user registration package for Django. The django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data, with the result that sensitive data could be included in error reports rather than removed automatically by Django. Triggering this requires: A site is using django-registration < 3.1.2, The site has detailed error reports (such as Django's emailed error reports to site staff/developers) enabled and a server-side error (HTTP 5xx) occurs during an attempt by a user to register an account. Under these conditions, recipients of the detailed error report will see all submitted data from the account-registration attempt, which may include the user's proposed credentials (such as a password).
Attacker Value
Unknown

CVE-2021-3393

Disclosure Date: April 01, 2021 (last updated February 22, 2025)
An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read.
Attacker Value
Unknown

CVE-2021-20289

Disclosure Date: March 26, 2021 (last updated February 22, 2025)
A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or query values to the matching JAX-RS resource method's parameter value. The highest threat from this vulnerability is to data confidentiality.
Attacker Value
Unknown

CVE-2021-22169

Disclosure Date: March 24, 2021 (last updated February 22, 2025)
An issue was identified in GitLab EE 13.4 or later which leaked internal IP address via error messages.
Attacker Value
Unknown

CVE-2021-22193

Disclosure Date: March 24, 2021 (last updated February 22, 2025)
An issue has been discovered in GitLab affecting all versions starting with 7.1. A member of a private group was able to validate the use of a specific name for private project.