Show filters
981 Total Results
Displaying 671-680 of 981
Sort by:
Attacker Value
Unknown
CVE-2021-22148
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Elastic Enterprise Search App Search versions before 7.14.0 was vulnerable to an issue where API keys were not bound to the same engines as their creator. This could lead to a less privileged user gaining access to unauthorized engines.
0
Attacker Value
Unknown
CVE-2021-3706
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
adminlte is vulnerable to Sensitive Cookie Without 'HttpOnly' Flag
0
Attacker Value
Unknown
CVE-2021-35508
Disclosure Date: September 01, 2021 (last updated February 23, 2025)
NMSAccess32.exe in TeraRecon AQNetClient 4.4.13 allows attackers to execute a malicious binary with SYSTEM privileges via a low-privileged user account. To exploit this, a low-privileged user must change the service configuration or overwrite the binary service.
0
Attacker Value
Unknown
CVE-2020-18121
Disclosure Date: August 30, 2021 (last updated February 23, 2025)
A configuration issue in Indexhibit 2.1.5 allows authenticated attackers to modify .php files, leading to getshell.
0
Attacker Value
Unknown
CVE-2021-38154
Disclosure Date: August 29, 2021 (last updated February 23, 2025)
Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access, allow remote attackers to modify an e-mail address setting, and thus cause the device to send sensitive information through e-mail to the attacker. For example, an incoming FAX may be sent through e-mail to the attacker. This occurs when a PIN is not required for General User Mode, as exploited in the wild in August 2021.
0
Attacker Value
Unknown
CVE-2021-30964
Disclosure Date: August 24, 2021 (last updated February 23, 2025)
An inherited permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPadOS 15.2. A malicious application may be able to bypass Privacy preferences.
0
Attacker Value
Unknown
CVE-2021-30892
Disclosure Date: August 24, 2021 (last updated February 23, 2025)
An inherited permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. A malicious application may be able to modify protected parts of the file system.
0
Attacker Value
Unknown
CVE-2021-30920
Disclosure Date: August 24, 2021 (last updated February 23, 2025)
A permissions issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.0.1. A local attacker may be able to read sensitive information.
0
Attacker Value
Unknown
CVE-2021-38557
Disclosure Date: August 24, 2021 (last updated February 23, 2025)
raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions. The www-data account can execute /etc/raspap/hostapd/enablelog.sh as root with no password; however, the www-data account can also overwrite /etc/raspap/hostapd/enablelog.sh with any executable content.
0
Attacker Value
Unknown
CVE-2021-38475
Disclosure Date: August 19, 2021 (last updated February 23, 2025)
The database connection to the server is performed by calling a specific API, which could allow an unprivileged user to gain SYSDBA permissions.
0