Show filters
467 Total Results
Displaying 31-40 of 467
Sort by:
Attacker Value
Unknown
CVE-2021-24788
Disclosure Date: November 08, 2021 (last updated February 23, 2025)
The Batch Cat WordPress plugin through 0.3 defines 3 custom AJAX actions, which both require authentication but are available for all roles. As a result, any authenticated user (including simple subscribers) can add/set/delete arbitrary categories to posts.
0
Attacker Value
Unknown
CVE-2021-24783
Disclosure Date: November 08, 2021 (last updated February 23, 2025)
The Post Expirator WordPress plugin before 2.6.0 does not have proper capability checks in place, which could allow users with a role as low as Contributor to schedule deletion of arbitrary posts.
0
Attacker Value
Unknown
CVE-2021-22051
Disclosure Date: November 08, 2021 (last updated February 23, 2025)
Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream services. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.5+, 2.2.x users should upgrade to 2.2.10.RELEASE or newer.
0
Attacker Value
Unknown
CVE-2021-41230
Disclosure Date: November 05, 2021 (last updated February 23, 2025)
Pomerium is an open source identity-aware access proxy. In affected versions changes to the OIDC claims of a user after initial login are not reflected in policy evaluation when using `allowed_idp_claims` as part of policy. If using `allowed_idp_claims` and a user's claims are changed, Pomerium can make incorrect authorization decisions. This issue has been resolved in v0.15.6. For users unable to upgrade clear data on `databroker` service by clearing redis or restarting the in-memory databroker to force claims to be updated.
0
Attacker Value
Unknown
CVE-2021-25506
Disclosure Date: November 05, 2021 (last updated February 23, 2025)
Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service.
0
Attacker Value
Unknown
CVE-2021-39904
Disclosure Date: November 05, 2021 (last updated February 23, 2025)
An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a Merge Request creator to resolve discussions and apply suggestions after a project owner has locked the Merge Request
0
Attacker Value
Unknown
CVE-2021-39902
Disclosure Date: November 04, 2021 (last updated February 23, 2025)
Incorrect Authorization in GitLab CE/EE 13.4 or above allows a user with guest membership in a project to modify the severity of an incident.
0
Attacker Value
Unknown
CVE-2021-21693
Disclosure Date: November 04, 2021 (last updated February 23, 2025)
When creating temporary files, agent-to-controller access to create those files is only checked after they've been created in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
0
Attacker Value
Unknown
CVE-2021-24717
Disclosure Date: November 01, 2021 (last updated February 23, 2025)
The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or perform privilege escalation via Ajax actions.
0
Attacker Value
Unknown
CVE-2021-24757
Disclosure Date: November 01, 2021 (last updated February 23, 2025)
The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX action (available to both unauthenticated and authenticated users), which could allow unauthenticated users to upload images.
0