Show filters
658 Total Results
Displaying 31-40 of 658
Sort by:
Attacker Value
Unknown

CVE-2021-38376

Disclosure Date: November 22, 2021 (last updated February 23, 2025)
OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.
Attacker Value
Unknown

CVE-2021-42338

Disclosure Date: November 19, 2021 (last updated February 23, 2025)
4MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to bypass authentication by code injection in cookie, and arbitrarily manipulate the system or interrupt services by upload and execution of arbitrary files.
0
Attacker Value
Unknown

CVE-2021-33087

Disclosure Date: November 17, 2021 (last updated February 23, 2025)
Improper authentication in the installer for the Intel(R) NUC M15 Laptop Kit Management Engine driver pack before version 15.0.10.1508 may allow an authenticated user to potentially enable denial of service via local access.
Attacker Value
Unknown

CVE-2021-0096

Disclosure Date: November 17, 2021 (last updated February 23, 2025)
Improper authentication in the software installer for the Intel(R) NUC HDMI Firmware Update Tool for NUC7i3DN, NUC7i5DN, NUC7i7DN before version 1.78.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2021-37580

Disclosure Date: November 16, 2021 (last updated February 23, 2025)
A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue affected Apache ShenYu 2.3.0 and 2.4.0
Attacker Value
Unknown

CVE-2021-3788

Disclosure Date: November 12, 2021 (last updated February 23, 2025)
An exposed debug interface was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access unauthorized access to the device.
Attacker Value
Unknown

CVE-2021-43203

Disclosure Date: November 09, 2021 (last updated February 23, 2025)
In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly.
Attacker Value
Unknown

CVE-2021-24647

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username
Attacker Value
Unknown

CVE-2021-31602

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The Security Model has different layers of Access Control. One of these layers is the applicationContext security, which is defined in the applicationContext-spring-security.xml file. The default configuration allows an unauthenticated user with no previous knowledge of the platform settings to extract pieces of information without possessing valid credentials.
Attacker Value
Unknown

CVE-2021-42072

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
An issue was discovered in Barrier before 2.4.0. The barriers component (aka the server-side implementation of Barrier) does not sufficiently verify the identify of connecting clients. Clients can thus exploit weaknesses in the provided protocol to cause denial-of-service or stage further attacks that could lead to information leaks or integrity corruption.