Show filters
136 Total Results
Displaying 21-30 of 136
Sort by:
Attacker Value
Unknown

CVE-2021-39916

Disclosure Date: December 13, 2021 (last updated February 23, 2025)
Lack of an access control check in the External Status Check feature allowed any authenticated user to retrieve the configuration of any External Status Check in GitLab EE starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.
Attacker Value
Unknown

CVE-2021-3964

Disclosure Date: December 01, 2021 (last updated February 23, 2025)
elgg is vulnerable to Authorization Bypass Through User-Controlled Key
Attacker Value
Unknown

CVE-2021-3992

Disclosure Date: December 01, 2021 (last updated February 23, 2025)
kimai2 is vulnerable to Improper Access Control
Attacker Value
Unknown

CVE-2021-24892

Disclosure Date: November 23, 2021 (last updated February 23, 2025)
Insecure Direct Object Reference in edit function of Advanced Forms (Free & Pro) before 1.6.9 allows authenticated remote attacker to change arbitrary user's email address and request for reset password, which could lead to take over of WordPress's administrator account. To exploit this vulnerability, an attacker must register to obtain a valid WordPress's user and use such user to authenticate with WordPress in order to exploit the vulnerable edit function.
Attacker Value
Unknown

CVE-2021-22967

Disclosure Date: November 19, 2021 (last updated February 23, 2025)
In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowed to Add Message to a Conversation.To remediate this, a check was added to verify a user has permissions to view files before attaching the files to a message in "add / edit message”.Concrete CMS security team gave this a CVSS v3.1 score of 4.3 AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NCredit for discovery Adrian H
Attacker Value
Unknown

CVE-2021-22951

Disclosure Date: November 19, 2021 (last updated February 23, 2025)
Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) prior to version 8.5.7. Concrete CMS now checks to see if a file has a password in view_inline and, if it does, the file is not rendered.For version 8.5.6, the following mitigations were put in place a. restricting file types for view_inline to images only b. putting a warning in the file manager to advise users.Credit for discovery: "Solar Security Research Team"Concrete CMS security team CVSS scoring is 5.3: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NThis fix is also in Concrete version 9.0.0
Attacker Value
Unknown

CVE-2021-36329

Disclosure Date: November 19, 2021 (last updated February 23, 2025)
Dell EMC Streaming Data Platform versions before 1.3 contain an Indirect Object Reference Vulnerability. A remote malicious user may potentially exploit this vulnerability to gain sensitive information.
Attacker Value
Unknown

CVE-2021-3380

Disclosure Date: November 10, 2021 (last updated February 23, 2025)
Insecure direct object reference (IDOR) vulnerability in ICREM H8 SSRMS allows attackers to disclose sensitive information via the Print Invoice Functionality.
Attacker Value
Unknown

CVE-2021-24840

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of its REST endpoint, without any validation. As a result, private and scheduled posts could be retrieved via a crafted request.
Attacker Value
Unknown

CVE-2021-39225

Disclosure Date: October 25, 2021 (last updated February 23, 2025)
Nextcloud is an open-source, self-hosted productivity platform. A missing permission check in Nextcloud Deck before 1.2.9, 1.4.5 and 1.5.3 allows another authenticated users to access Deck cards of another user. It is recommended that the Nextcloud Deck App is upgraded to 1.2.9, 1.4.5 or 1.5.3. There are no known workarounds aside from upgrading.