Show filters
233 Total Results
Displaying 171-180 of 233
Sort by:
Attacker Value
Unknown

CVE-2020-28900

Disclosure Date: May 24, 2021 (last updated February 22, 2025)
Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_to_latest.sh.
Attacker Value
Unknown

CVE-2021-22339

Disclosure Date: May 20, 2021 (last updated February 22, 2025)
There is a denial of service vulnerability in some versions of ManageOne. In specific scenarios, due to the insufficient verification of the parameter, an attacker may craft some specific parameter. Successful exploit may cause some services abnormal.
Attacker Value
Unknown

CVE-2020-24395

Disclosure Date: May 20, 2021 (last updated February 22, 2025)
The USB firmware update script of homee Brain Cube v2 (2.28.2 and 2.28.4) devices allows an attacker with physical access to install compromised firmware. This occurs because of insufficient validation of the firmware image file and can lead to code execution on the device.
Attacker Value
Unknown

CVE-2021-30005

Disclosure Date: May 11, 2021 (last updated February 22, 2025)
In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.
Attacker Value
Unknown

CVE-2021-29239

Disclosure Date: May 03, 2021 (last updated February 22, 2025)
CODESYS Development System 3 before 3.5.17.0 displays or executes malicious documents or files embedded in libraries without first checking their validity.
Attacker Value
Unknown

CVE-2021-31783

Disclosure Date: April 26, 2021 (last updated February 22, 2025)
show_default.php in the LocalFilesEditor extension before 11.4.0.1 for Piwigo allows Local File Inclusion because the file parameter is not validated with a proper regular-expression check.
Attacker Value
Unknown

CVE-2021-29462

Disclosure Date: April 20, 2021 (last updated February 22, 2025)
The Portable SDK for UPnP Devices is an SDK for development of UPnP device and control point applications. The server part of pupnp (libupnp) appears to be vulnerable to DNS rebinding attacks because it does not check the value of the `Host` header. This can be mitigated by using DNS revolvers which block DNS-rebinding attacks. The vulnerability is fixed in version 1.14.6 and later.
Attacker Value
Unknown

CVE-2021-20271

Disclosure Date: March 26, 2021 (last updated February 22, 2025)
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity, confidentiality, and system availability.
Attacker Value
Unknown

CVE-2021-1403

Disclosure Date: March 24, 2021 (last updated February 22, 2025)
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site WebSocket hijacking (CSWSH) attack and cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient HTTP protections in the web UI on an affected device. An attacker could exploit this vulnerability by persuading an authenticated user of the web UI to follow a crafted link. A successful exploit could allow the attacker to corrupt memory on the affected device, forcing it to reload and causing a DoS condition.
Attacker Value
Unknown

CVE-2021-21320

Disclosure Date: March 02, 2021 (last updated February 22, 2025)
matrix-react-sdk is an npm package which is a Matrix SDK for React Javascript. In matrix-react-sdk before version 3.15.0, the user content sandbox can be abused to trick users into opening unexpected documents. The content is opened with a `blob` origin that cannot access Matrix user data, so messages and secrets are not at risk. This has been fixed in version 3.15.0.