Show filters
376 Total Results
Displaying 51-60 of 376
Sort by:
Attacker Value
Unknown
CVE-2021-43998
Disclosure Date: November 30, 2021 (last updated February 23, 2025)
HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multiple entity aliases exist for a specified entity and mount combination, potentially resulting in incorrect policy enforcement. Fixed in Vault and Vault Enterprise 1.7.6, 1.8.5, and 1.9.0.
0
Attacker Value
Unknown
CVE-2021-42115
Disclosure Date: November 30, 2021 (last updated February 23, 2025)
Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an unauthenticated remote attacker to escalate privileges from unauthenticated to authenticated user via stealing and injecting the session- independent and static cookie UID.
0
Attacker Value
Unknown
CVE-2021-43359
Disclosure Date: November 30, 2021 (last updated February 23, 2025)
Sunnet eHRD has broken access control vulnerability, which allows a remote attacker to access account management page after being authenticated as a general user, then perform privilege escalation to execute arbitrary code and control the system or interrupt services.
0
Attacker Value
Unknown
CVE-2021-24703
Disclosure Date: November 23, 2021 (last updated February 23, 2025)
The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are already installed.
0
Attacker Value
Unknown
CVE-2021-39235
Disclosure Date: November 19, 2021 (last updated February 23, 2025)
In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated users with valid READ block token can do any write operation on the same block.
0
Attacker Value
Unknown
CVE-2021-0064
Disclosure Date: November 17, 2021 (last updated February 23, 2025)
Insecure inherited permissions in the Intel(R) PROSet/Wireless WiFi software installer for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2021-33094
Disclosure Date: November 17, 2021 (last updated February 23, 2025)
Insecure inherited permissions in the installer for the Intel(R) NUC M15 Laptop Kit Keyboard LED Service driver pack before version 1.0.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2021-33093
Disclosure Date: November 17, 2021 (last updated February 23, 2025)
Insecure inherited permissions in the installer for the Intel(R) NUC M15 Laptop Kit Serial IO driver pack before version 30.100.2104.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2021-33091
Disclosure Date: November 17, 2021 (last updated February 23, 2025)
Insecure inherited permissions in the installer for the Intel(R) NUC M15 Laptop Kit audio driver pack before version 1.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2021-42955
Disclosure Date: November 17, 2021 (last updated February 23, 2025)
Zoho Remote Access Plus Server Windows Desktop binary fixed in version 10.1.2132 is affected by an unauthorized password reset vulnerability. Because of the designed password reset mechanism, any non-admin Windows user can reset the password of the Remote Access Plus Server Admin account.
0