Show filters
638 Total Results
Displaying 41-50 of 638
Sort by:
Attacker Value
Unknown

CVE-2021-43528

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level privileges, but could be used as a stepping stone to further an attack with other vulnerabilities. This vulnerability affects Thunderbird < 91.4.0.
Attacker Value
Unknown

CVE-2021-37941

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious file to an application running with the APM Java agent. Using this vector, a malicious or compromised user account could use the agent to run commands at a higher level of permissions than they possess. This vulnerability affects users that have set up the agent via the attacher cli 3, the attach API 2, as well as users that have enabled the profiling_inferred_spans_enabled option
Attacker Value
Unknown

CVE-2021-25515

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
An improper usage of implicit intent in SemRewardManager prior to SMR Dec-2021 Release 1 allows attackers to access BSSID.
Attacker Value
Unknown

CVE-2021-25513

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
An improper privilege management vulnerability in Apps Edge application prior to SMR Dec-2021 Release 1 allows unauthorized access to some device data on the lockscreen.
Attacker Value
Unknown

CVE-2021-45729

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
The Privilege Escalation vulnerability discovered in the WP Google Map WordPress plugin (versions <= 1.8.0) allows authenticated low-role users to create, edit, and delete maps.
Attacker Value
Unknown

CVE-2021-44021

Disclosure Date: December 03, 2021 (last updated February 23, 2025)
An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar to but not identical to CVE-2021-44019 and 44020.
Attacker Value
Unknown

CVE-2021-44020

Disclosure Date: December 03, 2021 (last updated February 23, 2025)
An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar to but not identical to CVE-2021-44019 and 44021.
Attacker Value
Unknown

CVE-2021-44019

Disclosure Date: December 03, 2021 (last updated February 23, 2025)
An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar to but not identical to CVE-2021-44020 and 44021.
Attacker Value
Unknown

CVE-2021-43793

Disclosure Date: December 01, 2021 (last updated February 23, 2025)
Discourse is an open source discussion platform. In affected versions a vulnerability in the Polls feature allowed users to vote multiple times in a single-option poll. The problem is patched in the latest tests-passed, beta and stable versions of Discourse
0
Attacker Value
Unknown

CVE-2021-43211

Disclosure Date: November 24, 2021 (last updated February 23, 2025)
Windows 10 Update Assistant Elevation of Privilege Vulnerability
0