Show filters
27 Total Results
Displaying 1-10 of 27
Sort by:
Attacker Value
Very High

CVE-2020-15505

Disclosure Date: July 07, 2020 (last updated February 21, 2025)
A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0; and Sentry versions 9.7.2 and earlier, and 9.8.0; and Monitor and Reporting Database (RDB) version 2.0.0.1 and earlier that allows remote attackers to execute arbitrary code via unspecified vectors.
Attacker Value
Very High

CVE-2021-40539

Disclosure Date: September 07, 2021 (last updated February 23, 2025)
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.
Attacker Value
Unknown

CVE-2021-40856

Disclosure Date: December 13, 2021 (last updated February 23, 2025)
Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring.
Attacker Value
Unknown

CVE-2021-39156

Disclosure Date: August 24, 2021 (last updated February 23, 2025)
Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. Istio 1.11.0, 1.10.3 and below, and 1.9.7 and below contain a remotely exploitable vulnerability where an HTTP request with `#fragment` in the path may bypass Istio’s URI path based authorization policies. Patches are available in Istio 1.11.1, Istio 1.10.4 and Istio 1.9.8. As a work around a Lua filter may be written to normalize the path.
Attacker Value
Unknown

CVE-2021-37212

Disclosure Date: August 09, 2021 (last updated February 23, 2025)
The bulletin function of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the bulletin ID in specific Url parameters and access and modify bulletin particular content.
Attacker Value
Unknown

CVE-2021-37213

Disclosure Date: August 09, 2021 (last updated February 23, 2025)
The check-in record page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID and date in specific parameters to access particular employee’s check-in record.
Attacker Value
Unknown

CVE-2021-37214

Disclosure Date: August 09, 2021 (last updated February 23, 2025)
The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID in specific parameters to arbitrary access employee's data, modify it, and then obtain administrator privilege and execute arbitrary command.
Attacker Value
Unknown

CVE-2021-37215

Disclosure Date: August 09, 2021 (last updated February 23, 2025)
The employee management page of Flygo contains an Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attacker can manipulate the user data and then over-write another employee’s user data by specifying that employee’s ID in the API parameter.
Attacker Value
Unknown

CVE-2021-22924

Disclosure Date: August 05, 2021 (last updated February 23, 2025)
libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing wrong connections.File paths are, or can be, case sensitive on many systems but not all, and caneven vary depending on used file systems.The comparison also didn't include the 'issuer cert' which a transfer can setto qualify how to verify the server certificate.
Attacker Value
Unknown

CVE-2021-37144

Disclosure Date: July 30, 2021 (last updated February 23, 2025)
CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion. This occurs in PHP when the unlink() function is called and user input might affect portions of or the whole affected parameter, which represents the path of the file to remove, without sufficient sanitization.