Show filters
138 Total Results
Displaying 31-40 of 138
Sort by:
Attacker Value
Unknown

CVE-2021-25459

Disclosure Date: September 09, 2021 (last updated February 23, 2025)
An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockchainTZService.
Attacker Value
Unknown

CVE-2021-25460

Disclosure Date: September 09, 2021 (last updated February 23, 2025)
An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate BlockchainTZService.
Attacker Value
Unknown

CVE-2021-3049

Disclosure Date: September 08, 2021 (last updated February 23, 2025)
An improper authorization vulnerability in the Palo Alto Networks Cortex XSOAR server enables an authenticated network-based attacker with investigation read permissions to download files from incident investigations of which they are aware but are not a part of. This issue impacts: All Cortex XSOAR 5.5.0 builds; Cortex XSOAR 6.1.0 builds earlier than 12099345. This issue does not impact Cortex XSOAR 6.2.0 versions.
Attacker Value
Unknown

CVE-2021-34434

Disclosure Date: August 30, 2021 (last updated February 23, 2025)
In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked when a durable client is offline, then existing subscriptions for that client are not revoked.
Attacker Value
Unknown

CVE-2021-27663

Disclosure Date: August 30, 2021 (last updated February 23, 2025)
A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access to the system without adequate authorization. This issue affects: Johnson Controls CEM Systems AC2000 10.1; 10.2; 10.3; 10.4; 10.5.
Attacker Value
Unknown

CVE-2021-3616

Disclosure Date: August 17, 2021 (last updated February 23, 2025)
A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device information, alter firmware content and device configuration. This vulnerability is the same as CNVD-2020-68651.
Attacker Value
Unknown

CVE-2021-37705

Disclosure Date: August 13, 2021 (last updated February 23, 2025)
OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incomplete authorization check allows an authenticated user from any Azure Active Directory tenant to make authorized API calls to a vulnerable OneFuzz instance. To be vulnerable, a OneFuzz deployment must be both version 2.12.0 or greater and deployed with the non-default --multi_tenant_domain option. This can result in read/write access to private data such as software vulnerability and crash information, security testing tools and proprietary code and symbols. Via authorized API calls, this also enables tampering with existing data and unauthorized code execution on Azure compute resources. This issue is resolved starting in release 2.31.0, via the addition of application-level check of the bearer token's `issuer` against an administrator-configured allowlist. As a workaround users can restrict access to the tenant of a deployed OneFuzz instance < 2.31.0 by redeploying i…
Attacker Value
Unknown

CVE-2021-36037

Disclosure Date: August 10, 2021 (last updated February 23, 2025)
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vulnerability. An authenticated attacker could leverage this vulnerability to achieve sensitive information disclosure.
0
Attacker Value
Unknown

CVE-2021-36029

Disclosure Date: August 10, 2021 (last updated February 23, 2025)
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vulnerability. An attacker with admin privileges could leverage this vulnerability to achieve remote code execution.
Attacker Value
Unknown

CVE-2021-36276

Disclosure Date: August 02, 2021 (last updated February 23, 2025)
Dell DBUtilDrv2.sys driver (versions 2.5 and 2.6) contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.