Show filters
556 Total Results
Displaying 21-30 of 556
Sort by:
Attacker Value
Unknown

CVE-2021-24527

Disclosure Date: August 16, 2021 (last updated February 23, 2025)
The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way the reset key is checked. Furthermore, the admin will not be notified of such change by email for example.
Attacker Value
Unknown

CVE-2021-36949

Disclosure Date: August 12, 2021 (last updated February 23, 2025)
Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability
0
Attacker Value
Unknown

CVE-2021-36921

Disclosure Date: August 12, 2021 (last updated February 23, 2025)
AIMANAGER before B115 on MONITORAPP Application Insight Web Application Firewall (AIWAF) devices with Manager 2.1.0 has Improper Authentication. An attacker can gain administrative access by modifying the response to an authentication check request.
Attacker Value
Unknown

CVE-2021-27794

Disclosure Date: August 12, 2021 (last updated February 23, 2025)
A vulnerability in the authentication mechanism of Brocade Fabric OS versions before Brocade Fabric OS v.9.0.1a, v8.2.3a and v7.4.2h could allow a user to Login with empty password, and invalid password through telnet, ssh and REST.
Attacker Value
Unknown

CVE-2021-3046

Disclosure Date: August 11, 2021 (last updated February 23, 2025)
An improper authentication vulnerability exists in Palo Alto Networks PAN-OS software that enables a SAML authenticated attacker to impersonate any other user in the GlobalProtect Portal and GlobalProtect Gateway when they are configured to use SAML authentication. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.19; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14; PAN-OS 9.1 versions earlier than PAN-OS 9.1.9; PAN-OS 10.0 versions earlier than PAN-OS 10.0.5. PAN-OS 10.1 versions are not impacted.
Attacker Value
Unknown

CVE-2021-37172

Disclosure Date: August 10, 2021 (last updated February 23, 2025)
A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (V4.5.0). Affected devices fail to authenticate against configured passwords when provisioned using TIA Portal V13. This could allow an attacker using TIA Portal V13 or later versions to bypass authentication and download arbitrary programs to the PLC. The vulnerability does not occur when TIA Portal V13 SP1 or any later version was used to provision the device.
Attacker Value
Unknown

CVE-2014-9320

Disclosure Date: August 09, 2021 (last updated February 23, 2025)
SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and consequently gain SYSTEM privileges via vectors involving CORBA calls, aka SAP Note 2039905.
Attacker Value
Unknown

CVE-2021-20598

Disclosure Date: August 06, 2021 (last updated February 23, 2025)
Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R08/16/32/120SFCPU all versions, R08/16/32/120PSFCPU all versions) allows a remote unauthenticated attacker to lockout a legitimate user by continuously trying login with incorrect password.
Attacker Value
Unknown

CVE-2021-37545

Disclosure Date: August 06, 2021 (last updated February 23, 2025)
In JetBrains TeamCity before 2021.1.1, insufficient authentication checks for agent requests were made.
Attacker Value
Unknown

CVE-2021-32579

Disclosure Date: August 05, 2021 (last updated February 23, 2025)
Acronis True Image prior to 2021 Update 4 for Windows and Acronis True Image prior to 2021 Update 5 for macOS allowed an unauthenticated attacker (who has a local code execution ability) to tamper with the micro-service API.