Show filters
204 Total Results
Displaying 81-90 of 204
Sort by:
Attacker Value
Unknown

CVE-2021-42332

Disclosure Date: October 15, 2021 (last updated February 23, 2025)
The “List View” function of ShinHer StudyOnline System is not under authority control. After logging in with user’s privilege, remote attackers can access the content of other users’ message boards by crafting URL parameters.
0
Attacker Value
Unknown

CVE-2021-42330

Disclosure Date: October 15, 2021 (last updated February 23, 2025)
The “Teacher Edit” function of ShinHer StudyOnline System does not perform authority control. After logging in with user’s privilege, remote attackers can access and edit other users’ credential and personal information by crafting URL parameters.
0
Attacker Value
Unknown

CVE-2021-31384

Disclosure Date: October 13, 2021 (last updated February 23, 2025)
Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in Juniper Networks Junos OS on SRX Series whereby an attacker who attempts to access J-Web administrative interfaces can successfully do so from any device interface regardless of the web-management configuration and filter rules which may otherwise protect access to J-Web. This issue affects: Juniper Networks Junos OS SRX Series 20.4 version 20.4R1 and later versions prior to 20.4R2-S1, 20.4R3; 21.1 versions prior to 21.1R1-S1, 21.1R2. This issue does not affect Juniper Networks Junos OS versions prior to 20.4R1.
Attacker Value
Unknown

CVE-2021-41137

Disclosure Date: October 13, 2021 (last updated February 23, 2025)
Minio is a Kubernetes native application for cloud storage. All users on release `RELEASE.2021-10-10T16-53-30Z` are affected by a vulnerability that involves bypassing policy restrictions on regular users. Normally, checkKeyValid() should return owner true for rootCreds. In the affected version, policy restriction did not work properly for users who did not have service (svc) or security token service (STS) accounts. This issue is fixed in `RELEASE.2021-10-13T00-23-17Z`. A downgrade back to release `RELEASE.2021-10-08T23-58-24Z` is available as a workaround.
0
Attacker Value
Unknown

CVE-2021-33723

Disclosure Date: October 12, 2021 (last updated February 23, 2025)
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could change the user profile of any user without proper authorization. With this, the attacker could change the password of any user in the affected system.
Attacker Value
Unknown

CVE-2021-36311

Disclosure Date: October 11, 2021 (last updated February 23, 2025)
Dell EMC Networker versions prior to 19.5 contain an Improper Authorization vulnerability. Any local malicious user with networker user privileges may exploit this vulnerability to upload malicious file to unauthorized locations and execute it.
Attacker Value
Unknown

CVE-2021-41974

Disclosure Date: October 08, 2021 (last updated February 23, 2025)
Tad Book3 editing book page does not perform identity verification. Remote attackers can use the vulnerability to view and modify arbitrary content of books without permission.
Attacker Value
Unknown

CVE-2021-41564

Disclosure Date: October 08, 2021 (last updated February 23, 2025)
Tad Honor viewing book list function is vulnerable to authorization bypass, thus remote attackers can use special parameters to delete articles arbitrarily without logging in.
Attacker Value
Unknown

CVE-2021-41975

Disclosure Date: October 08, 2021 (last updated February 23, 2025)
TadTools special page is vulnerable to authorization bypass, thus remote attackers can use the specific parameter to delete arbitrary files in the system without logging in.
Attacker Value
Unknown

CVE-2021-41568

Disclosure Date: October 08, 2021 (last updated February 23, 2025)
Tad Web is vulnerable to authorization bypass, thus remote attackers can exploit the vulnerability to use the original function of viewing bulletin boards and uploading files in the system.