Show filters
89 Total Results
Displaying 31-40 of 89
Sort by:
Attacker Value
Unknown

CVE-2021-39175

Disclosure Date: August 30, 2021 (last updated February 23, 2025)
HedgeDoc is a platform to write and share markdown. In versions prior to 1.9.0, an unauthenticated attacker can inject arbitrary JavaScript into the speaker-notes of the slide-mode feature by embedding an iframe hosting the malicious code into the slides or by embedding the HedgeDoc instance into another page. The problem is patched in version 1.9.0. There are no known workarounds aside from upgrading.
Attacker Value
Unknown

CVE-2021-30596

Disclosure Date: August 26, 2021 (last updated February 23, 2025)
Incorrect security UI in Navigation in Google Chrome on Android prior to 92.0.4515.131 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Attacker Value
Unknown

CVE-2021-39270

Disclosure Date: August 18, 2021 (last updated February 23, 2025)
In Ping Identity RSA SecurID Integration Kit before 3.2, user impersonation can occur.
Attacker Value
Unknown

CVE-2021-37705

Disclosure Date: August 13, 2021 (last updated February 23, 2025)
OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incomplete authorization check allows an authenticated user from any Azure Active Directory tenant to make authorized API calls to a vulnerable OneFuzz instance. To be vulnerable, a OneFuzz deployment must be both version 2.12.0 or greater and deployed with the non-default --multi_tenant_domain option. This can result in read/write access to private data such as software vulnerability and crash information, security testing tools and proprietary code and symbols. Via authorized API calls, this also enables tampering with existing data and unauthorized code execution on Azure compute resources. This issue is resolved starting in release 2.31.0, via the addition of application-level check of the bearer token's `issuer` against an administrator-configured allowlist. As a workaround users can restrict access to the tenant of a deployed OneFuzz instance < 2.31.0 by redeploying i…
Attacker Value
Unknown

CVE-2021-21229

Disclosure Date: April 30, 2021 (last updated February 22, 2025)
Incorrect security UI in downloads in Google Chrome on Android prior to 90.0.4430.93 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Attacker Value
Unknown

CVE-2021-21209

Disclosure Date: April 26, 2021 (last updated February 22, 2025)
Inappropriate implementation in storage in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Attacker Value
Unknown

CVE-2021-21211

Disclosure Date: April 26, 2021 (last updated February 22, 2025)
Inappropriate implementation in Navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Attacker Value
Unknown

CVE-2021-31718

Disclosure Date: April 25, 2021 (last updated February 22, 2025)
The server in npupnp before 4.1.4 is affected by DNS rebinding in the embedded web server (including UPnP SOAP and GENA endpoints), leading to remote code execution.
Attacker Value
Unknown

CVE-2021-26291

Disclosure Date: April 23, 2021 (last updated February 22, 2025)
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior. See this link for more information about repository management: https://maven.apache.org/repository-management.html
Attacker Value
Unknown

CVE-2021-28048

Disclosure Date: April 14, 2021 (last updated February 22, 2025)
An overly permissive CORS policy in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows a remote attacker to leak cross-origin data via a crafted HTML page.