Show filters
384 Total Results
Displaying 31-40 of 384
Sort by:
Attacker Value
Unknown
CVE-2021-43034
Disclosure Date: December 06, 2021 (last updated February 23, 2025)
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A world writable file allowed local users to execute arbitrary code as the user apache, leading to privilege escalation.
0
Attacker Value
Unknown
CVE-2022-23132
Disclosure Date: December 01, 2021 (last updated February 23, 2025)
During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix Proxy or Server processes can bypass file read, write and execute permissions check on the file system level
0
Attacker Value
Unknown
CVE-2021-40101
Disclosure Date: November 30, 2021 (last updated February 23, 2025)
An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password.
0
Attacker Value
Unknown
CVE-2021-44230
Disclosure Date: November 30, 2021 (last updated February 23, 2025)
PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows has weak file permissions for the embedded H2 database, which might lead to privilege escalation. This issue can be exploited by an adversary who has already compromised a valid Windows account on the server via separate means. In this scenario, the compromised account may have inherited read access to sensitive configuration, database, and log files.
0
Attacker Value
Unknown
CVE-2021-43998
Disclosure Date: November 30, 2021 (last updated February 23, 2025)
HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multiple entity aliases exist for a specified entity and mount combination, potentially resulting in incorrect policy enforcement. Fixed in Vault and Vault Enterprise 1.7.6, 1.8.5, and 1.9.0.
0
Attacker Value
Unknown
CVE-2021-42115
Disclosure Date: November 30, 2021 (last updated February 23, 2025)
Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an unauthenticated remote attacker to escalate privileges from unauthenticated to authenticated user via stealing and injecting the session- independent and static cookie UID.
0
Attacker Value
Unknown
CVE-2021-43359
Disclosure Date: November 30, 2021 (last updated February 23, 2025)
Sunnet eHRD has broken access control vulnerability, which allows a remote attacker to access account management page after being authenticated as a general user, then perform privilege escalation to execute arbitrary code and control the system or interrupt services.
0
Attacker Value
Unknown
CVE-2021-24703
Disclosure Date: November 23, 2021 (last updated February 23, 2025)
The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are already installed.
0
Attacker Value
Unknown
CVE-2021-39235
Disclosure Date: November 19, 2021 (last updated February 23, 2025)
In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated users with valid READ block token can do any write operation on the same block.
0
Attacker Value
Unknown
CVE-2021-0064
Disclosure Date: November 17, 2021 (last updated February 23, 2025)
Insecure inherited permissions in the Intel(R) PROSet/Wireless WiFi software installer for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.
0