Show filters
216 Total Results
Displaying 11-20 of 216
Sort by:
Attacker Value
Unknown

CVE-2020-29605

Disclosure Date: January 29, 2021 (last updated February 22, 2025)
An issue was discovered in MantisBT before 2.24.4. Due to insufficient access-level checks, any logged-in user allowed to perform Group Actions can get access to the Summary fields of private Issues via bug_arr[]= in a crafted bug_actiongroup_page.php URL. (The target Issues can have Private view status, or belong to a private Project.)
Attacker Value
Unknown

CVE-2020-1725

Disclosure Date: January 28, 2021 (last updated February 22, 2025)
A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changing the role mappings in Keycloak and after expiration of the previous access token.
Attacker Value
Unknown

CVE-2021-3337

Disclosure Date: January 28, 2021 (last updated February 22, 2025)
The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading restrictions by clicking on reply or quote in the postbit.
Attacker Value
Unknown

CVE-2021-26025

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDStd!zlibVersion+0x0000000000004e5e via a crafted BMP image.
Attacker Value
Unknown

CVE-2021-26026

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDStd!JPEGTransW+0x000000000000c7f4 via a crafted BMP image.
Attacker Value
Unknown

CVE-2020-9492

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification.
Attacker Value
Unknown

CVE-2021-1305

Disclosure Date: January 20, 2021 (last updated February 22, 2025)
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and view information that they are not authorized to access. For more information about these vulnerabilities, see the Details section of this advisory.
Attacker Value
Unknown

CVE-2021-1270

Disclosure Date: January 20, 2021 (last updated February 22, 2025)
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the Details section of this advisory.
Attacker Value
Unknown

CVE-2021-1269

Disclosure Date: January 20, 2021 (last updated February 22, 2025)
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the Details section of this advisory.
Attacker Value
Unknown

CVE-2020-4873

Disclosure Date: January 18, 2021 (last updated February 22, 2025)
IBM Planning Analytics 2.0 could allow an attacker to obtain sensitive information due to an overly permissive CORS policy. IBM X-Force ID: 190836.