Show filters
16,122 Total Results
Displaying 31-40 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown
CVE-2021-45896
Disclosure Date: December 27, 2021 (last updated February 23, 2025)
Nokia FastMile 3TG00118ABAD52 devices allow privilege escalation by an authenticated user via is_ctc_admin=1 to login_web_app.cgi and use of Import Config File.
0
Attacker Value
Unknown
CVE-2021-23244
Disclosure Date: December 27, 2021 (last updated February 23, 2025)
ColorOS pregrant dangerous permissions to apps which are listed in a whitelist xml named default-grant-permissions.But some apps in whitelist is not installed, attacker can disguise app with the same package name to obtain dangerous permission.
0
Attacker Value
Unknown
CVE-2021-45338
Disclosure Date: December 27, 2021 (last updated February 23, 2025)
Multiple privilege escalation vulnerabilities in Avast Antivirus prior to 20.4 allow a local user to gain elevated privileges by calling unnecessarily powerful internal methods of the main antivirus service which could lead to the (1) arbitrary file delete, (2) write and (3) reset security.
0
Attacker Value
Unknown
CVE-2021-25991
Disclosure Date: December 27, 2021 (last updated February 23, 2025)
In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme.
0
Attacker Value
Unknown
CVE-2021-20050
Disclosure Date: December 23, 2021 (last updated February 23, 2025)
An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, potentially exposing configuration meta-data.
0
Attacker Value
Unknown
CVE-2021-38020
Disclosure Date: December 23, 2021 (last updated February 23, 2025)
Insufficient policy enforcement in contacts picker in Google Chrome on Android prior to 96.0.4664.45 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2021-21953
Disclosure Date: December 22, 2021 (last updated February 23, 2025)
An authentication bypass vulnerability exists in the process_msg() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted man-in-the-middle attack can lead to increased privileges.
0
Attacker Value
Unknown
CVE-2021-35243
Disclosure Date: December 22, 2021 (last updated February 23, 2025)
The HTTP PUT and DELETE methods were enabled in the Web Help Desk web server (12.7.7 and earlier), allowing users to execute dangerous HTTP requests. The HTTP PUT method is normally used to upload data that is saved on the server with a user-supplied URL. While the DELETE method requests that the origin server removes the association between the target resource and its current functionality. Improper use of these methods may lead to a loss of integrity.
0
Attacker Value
Unknown
CVE-2021-45289
Disclosure Date: December 21, 2021 (last updated February 23, 2025)
A vulnerability exists in GPAC 1.0.1 due to an omission of security-relevant Information, which could cause a Denial of Service. The program terminates with signal SIGKILL.
0
Attacker Value
Unknown
CVE-2021-44877
Disclosure Date: December 21, 2021 (last updated February 23, 2025)
Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to Incorrect Access Control. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. A broken access control vulnerability has been found while using a temporary generated token in order to consume api resources. The vulnerability allows an unauthenticated attacker to use an api endpoint to generate a temporary JWT token that is designed to reference the correct tenant prior to authentication, to request system configuration parameters using direct api requests. The correct exploitation of this vulnerability causes sensitive information exposure. In case the tenant has an smtp credential set, the full credential information is disclosed.
0