Show filters
216 Total Results
Displaying 11-20 of 216
Sort by:
Attacker Value
Unknown
CVE-2020-29605
Disclosure Date: January 29, 2021 (last updated February 22, 2025)
An issue was discovered in MantisBT before 2.24.4. Due to insufficient access-level checks, any logged-in user allowed to perform Group Actions can get access to the Summary fields of private Issues via bug_arr[]= in a crafted bug_actiongroup_page.php URL. (The target Issues can have Private view status, or belong to a private Project.)
0
Attacker Value
Unknown
CVE-2020-1725
Disclosure Date: January 28, 2021 (last updated February 22, 2025)
A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changing the role mappings in Keycloak and after expiration of the previous access token.
0
Attacker Value
Unknown
CVE-2021-3337
Disclosure Date: January 28, 2021 (last updated February 22, 2025)
The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading restrictions by clicking on reply or quote in the postbit.
0
Attacker Value
Unknown
CVE-2021-26025
Disclosure Date: January 26, 2021 (last updated February 22, 2025)
PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDStd!zlibVersion+0x0000000000004e5e via a crafted BMP image.
0
Attacker Value
Unknown
CVE-2021-26026
Disclosure Date: January 26, 2021 (last updated February 22, 2025)
PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDStd!JPEGTransW+0x000000000000c7f4 via a crafted BMP image.
0
Attacker Value
Unknown
CVE-2020-9492
Disclosure Date: January 26, 2021 (last updated February 22, 2025)
In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification.
0
Attacker Value
Unknown
CVE-2021-1305
Disclosure Date: January 20, 2021 (last updated February 22, 2025)
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and view information that they are not authorized to access. For more information about these vulnerabilities, see the Details section of this advisory.
0
Attacker Value
Unknown
CVE-2021-1270
Disclosure Date: January 20, 2021 (last updated February 22, 2025)
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the Details section of this advisory.
0
Attacker Value
Unknown
CVE-2021-1269
Disclosure Date: January 20, 2021 (last updated February 22, 2025)
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the Details section of this advisory.
0
Attacker Value
Unknown
CVE-2020-4873
Disclosure Date: January 18, 2021 (last updated February 22, 2025)
IBM Planning Analytics 2.0 could allow an attacker to obtain sensitive information due to an overly permissive CORS policy. IBM X-Force ID: 190836.
0