Show filters
145 Total Results
Displaying 41-50 of 145
Sort by:
Attacker Value
Unknown
CVE-2021-34434
Disclosure Date: August 30, 2021 (last updated February 23, 2025)
In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked when a durable client is offline, then existing subscriptions for that client are not revoked.
0
Attacker Value
Unknown
CVE-2021-27663
Disclosure Date: August 30, 2021 (last updated February 23, 2025)
A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access to the system without adequate authorization. This issue affects: Johnson Controls CEM Systems AC2000 10.1; 10.2; 10.3; 10.4; 10.5.
0
Attacker Value
Unknown
CVE-2021-3616
Disclosure Date: August 17, 2021 (last updated February 23, 2025)
A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device information, alter firmware content and device configuration. This vulnerability is the same as CNVD-2020-68651.
0
Attacker Value
Unknown
CVE-2021-37705
Disclosure Date: August 13, 2021 (last updated February 23, 2025)
OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incomplete authorization check allows an authenticated user from any Azure Active Directory tenant to make authorized API calls to a vulnerable OneFuzz instance. To be vulnerable, a OneFuzz deployment must be both version 2.12.0 or greater and deployed with the non-default --multi_tenant_domain option. This can result in read/write access to private data such as software vulnerability and crash information, security testing tools and proprietary code and symbols. Via authorized API calls, this also enables tampering with existing data and unauthorized code execution on Azure compute resources. This issue is resolved starting in release 2.31.0, via the addition of application-level check of the bearer token's `issuer` against an administrator-configured allowlist. As a workaround users can restrict access to the tenant of a deployed OneFuzz instance < 2.31.0 by redeploying i…
0
Attacker Value
Unknown
CVE-2021-36037
Disclosure Date: August 10, 2021 (last updated February 23, 2025)
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vulnerability. An authenticated attacker could leverage this vulnerability to achieve sensitive information disclosure.
0
Attacker Value
Unknown
CVE-2021-36029
Disclosure Date: August 10, 2021 (last updated February 23, 2025)
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vulnerability. An attacker with admin privileges could leverage this vulnerability to achieve remote code execution.
0
Attacker Value
Unknown
CVE-2021-36276
Disclosure Date: August 02, 2021 (last updated February 23, 2025)
Dell DBUtilDrv2.sys driver (versions 2.5 and 2.6) contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.
0
Attacker Value
Unknown
CVE-2021-35964
Disclosure Date: July 19, 2021 (last updated February 23, 2025)
The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remote attackers to execute the management function without logging in, access members’ information, modify and delete the courses in system, thus causing users fail to access the learning content.
0
Attacker Value
Unknown
CVE-2021-32688
Disclosure Date: July 12, 2021 (last updated February 23, 2025)
Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens for authentication purposes. These tokens are supposed to be granted to a specific applications (e.g. DAV sync clients), and can also be configured by the user to not have any filesystem access. Due to a lacking permission check, the tokens were able to change their own permissions in versions prior to 19.0.13, 20.0.11, and 21.0.3. Thus fileystem limited tokens were able to grant themselves access to the filesystem. The issue is patched in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds aside from upgrading.
0
Attacker Value
Unknown
CVE-2021-25433
Disclosure Date: July 08, 2021 (last updated February 23, 2025)
Improper authorization vulnerability in Tizen factory reset policy prior to Firmware update JUL-2021 Release allows untrusted applications to perform factory reset using dbus signal.
0