Show filters
230 Total Results
Displaying 111-120 of 230
Sort by:
Attacker Value
Unknown

CVE-2021-33723

Disclosure Date: October 12, 2021 (last updated February 23, 2025)
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could change the user profile of any user without proper authorization. With this, the attacker could change the password of any user in the affected system.
Attacker Value
Unknown

CVE-2021-36311

Disclosure Date: October 11, 2021 (last updated February 23, 2025)
Dell EMC Networker versions prior to 19.5 contain an Improper Authorization vulnerability. Any local malicious user with networker user privileges may exploit this vulnerability to upload malicious file to unauthorized locations and execute it.
Attacker Value
Unknown

CVE-2021-41974

Disclosure Date: October 08, 2021 (last updated February 23, 2025)
Tad Book3 editing book page does not perform identity verification. Remote attackers can use the vulnerability to view and modify arbitrary content of books without permission.
Attacker Value
Unknown

CVE-2021-41564

Disclosure Date: October 08, 2021 (last updated February 23, 2025)
Tad Honor viewing book list function is vulnerable to authorization bypass, thus remote attackers can use special parameters to delete articles arbitrarily without logging in.
Attacker Value
Unknown

CVE-2021-41975

Disclosure Date: October 08, 2021 (last updated February 23, 2025)
TadTools special page is vulnerable to authorization bypass, thus remote attackers can use the specific parameter to delete arbitrary files in the system without logging in.
Attacker Value
Unknown

CVE-2021-41568

Disclosure Date: October 08, 2021 (last updated February 23, 2025)
Tad Web is vulnerable to authorization bypass, thus remote attackers can exploit the vulnerability to use the original function of viewing bulletin boards and uploading files in the system.
Attacker Value
Unknown

CVE-2021-41976

Disclosure Date: October 08, 2021 (last updated February 23, 2025)
Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function to amend the folder names in the book list without logging in.
Attacker Value
Unknown

CVE-2021-38486

Disclosure Date: October 07, 2021 (last updated February 23, 2025)
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 cloud portal allows for self-registration of the affected product without any requirements to create an account, which may allow an attacker to have full control over the product and execute code within the internal network to which the product is connected.
Attacker Value
Unknown

CVE-2021-39317

Disclosure Date: October 06, 2021 (last updated February 23, 2025)
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the affected products. The complete list of affected products and their versions are below: WordPress Plugin: AccessPress Demo Importer <=1.0.6 WordPress Themes: accesspress-basic <= 3.2.1 accesspress-lite <= 2.92 accesspress-mag <= 2.6.5 accesspress-parallax <= 4.5 accesspress-root <= 2.5 accesspress-store <= 2.4.9 agency-lite <= 1.1.6 arrival <= 1.4.2 bingle <= 1.0.4 bloger <= 1.2.6 brovy <= 1.3 construction-lite <= 1.2.5 doko <= 1.0.27 edict-lite <= 1.1.4 eightlaw-lite <= 2.1.5 eightmedi-lite <= 2.1.8 eight-sec <= 1.1.4 eightstore-lite <= 1.2.5 enlighten <= 1.3.5 fotography <= 2.4.0 opstore <= 1.4.3 parallaxsome <= 1.3.6 punte <= 1.1.2 revolve <= 1.3.1 ripple <= 1.2.0 sakala …
Attacker Value
Unknown

CVE-2021-25499

Disclosure Date: October 06, 2021 (last updated February 23, 2025)
Intent redirection vulnerability in SamsungAccountSDKSigninActivity of Galaxy Store prior to version 4.5.32.4 allows attacker to access content provider of Galaxy Store.