Show filters
424 Total Results
Displaying 71-80 of 424
Sort by:
Attacker Value
Unknown

CVE-2021-3557

Disclosure Date: February 16, 2022 (last updated February 23, 2025)
A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created ServiceAccount argocd-argocd-server, the unprivileged user is able to read all resources of the cluster including all secrets which might enable privilege escalations. The highest threat from this vulnerability is to data confidentiality.
Attacker Value
Unknown

CVE-2021-44521

Disclosure Date: February 11, 2022 (last updated February 23, 2025)
When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on the host. The attacker would need to have enough permissions to create user defined functions in the cluster to be able to exploit this. Note that this configuration is documented as unsafe, and will continue to be considered unsafe after this CVE.
Attacker Value
Unknown

CVE-2022-0483

Disclosure Date: February 11, 2022 (last updated February 23, 2025)
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (Windows) before build 53
Attacker Value
Unknown

CVE-2022-0532

Disclosure Date: February 09, 2022 (last updated February 23, 2025)
An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kernel namespace.
Attacker Value
Unknown

CVE-2021-39992

Disclosure Date: February 09, 2022 (last updated February 23, 2025)
There is an improper security permission configuration vulnerability on ACPU.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
Attacker Value
Unknown

CVE-2021-4199

Disclosure Date: February 05, 2022 (last updated February 23, 2025)
Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling component BDReinit.exe as used in Bitdefender Total Security, Internet Security, Antivirus Plus, Endpoint Security Tools for Windows allows a remote attacker to escalate local privileges to SYSTEM. This issue affects: Bitdefender Total Security versions prior to 26.0.10.45. Bitdefender Internet Security versions prior to 26.0.10.45. Bitdefender Antivirus Plus versions prior to 26.0.10.45. Bitdefender Endpoint Security Tools for Windows versions prior to 7.4.3.146.
Attacker Value
Unknown

CVE-2021-29396

Disclosure Date: February 04, 2022 (last updated February 23, 2025)
Systemic Insecure Permissions in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to use various functionalities without authentication.
Attacker Value
Unknown

CVE-2022-0338

Disclosure Date: January 25, 2022 (last updated February 23, 2025)
Insertion of Sensitive Information into Log File in Conda loguru prior to 0.5.3.
Attacker Value
Unknown

CVE-2021-22284

Disclosure Date: January 24, 2022 (last updated February 23, 2025)
Incorrect Permission Assignment for Critical Resource vulnerability in OPC Server for AC 800M allows an attacker to execute arbitrary code in the node running the AC800M OPC Server.
Attacker Value
Unknown

CVE-2022-0277

Disclosure Date: January 20, 2022 (last updated February 23, 2025)
Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11.