Show filters
468 Total Results
Displaying 11-20 of 468
Sort by:
Attacker Value
Unknown
CVE-2020-10199
Disclosure Date: April 01, 2020 (last updated February 21, 2025)
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
0
Attacker Value
Very High
CVE-2020-8135
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external network or otherwise interact with internal systems.
0
Attacker Value
High
CVE-2020-0646
Disclosure Date: January 14, 2020 (last updated February 21, 2025)
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.
0
Attacker Value
Unknown
CVE-2024-34068
Disclosure Date: May 03, 2024 (last updated February 23, 2025)
Pterodactyl wings is the server control plane for Pterodactyl Panel. An authenticated user who has access to a game server is able to bypass the previously implemented access control (GHSA-6rg3-8h8x-5xfv) that prevents accessing internal endpoints of the node hosting Wings in the pull endpoint. This would allow malicious users to potentially access resources on local networks that would otherwise be inaccessible. This issue has been addressed in version 1.11.2 and users are advised to upgrade. Users unable to upgrade may enable the `api.disable_remote_download` option as a workaround.
0
Attacker Value
Unknown
CVE-2021-44659
Disclosure Date: December 22, 2021 (last updated February 23, 2025)
Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve a Server Side Request Forgery (SSRF). NOTE: the vendor's position is that the observed behavior is not a vulnerability, because the product's design allows an admin to configure outbound requests
0
Attacker Value
Unknown
CVE-2021-43987
Disclosure Date: December 21, 2021 (last updated February 23, 2025)
An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web interface, which cannot be deleted or changed through the regular web interface.
0
Attacker Value
Unknown
CVE-2021-43989
Disclosure Date: December 21, 2021 (last updated February 23, 2025)
mySCADA myPRO Versions 8.20.0 and prior stores passwords using MD5, which may allow an attacker to crack the previously retrieved password hashes.
0
Attacker Value
Unknown
CVE-2021-42809
Disclosure Date: December 20, 2021 (last updated February 23, 2025)
Improper Access Control of Dynamically-Managed Code Resources (DLL) in Thales Sentinel Protection Installer could allow the execution of arbitrary code.
0
Attacker Value
Unknown
CVE-2021-22056
Disclosure Date: December 20, 2021 (last updated February 23, 2025)
VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary origins and read the full response.
0
Attacker Value
Unknown
CVE-2021-22054
Disclosure Date: December 17, 2021 (last updated February 23, 2025)
VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.
0