Show filters
249 Total Results
Displaying 111-120 of 249
Sort by:
Attacker Value
Unknown

CVE-2019-17567

Disclosure Date: June 10, 2021 (last updated February 22, 2025)
Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.
Attacker Value
Unknown

CVE-2021-22222

Disclosure Date: June 07, 2021 (last updated February 22, 2025)
Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet injection or crafted capture file
Attacker Value
Unknown

CVE-2021-31903

Disclosure Date: May 11, 2021 (last updated February 22, 2025)
In JetBrains YouTrack before 2021.1.9819, a pull request's title was sanitized insufficiently, leading to XSS.
Attacker Value
Unknown

CVE-2021-31905

Disclosure Date: May 11, 2021 (last updated November 28, 2024)
In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible.
Attacker Value
Unknown

CVE-2021-27733

Disclosure Date: May 11, 2021 (last updated February 22, 2025)
In JetBrains YouTrack before 2020.6.6441, stored XSS was possible via an issue attachment.
Attacker Value
Unknown

CVE-2021-31902

Disclosure Date: May 11, 2021 (last updated February 22, 2025)
In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly.
Attacker Value
Unknown

CVE-2021-21633

Disclosure Date: March 30, 2021 (last updated February 22, 2025)
A cross-site request forgery (CSRF) vulnerability in Jenkins OWASP Dependency-Track Plugin 3.1.0 and earlier allows attackers to connect to an attacker-specified URL, capturing credentials stored in Jenkins.
Attacker Value
Unknown

CVE-2021-21632

Disclosure Date: March 30, 2021 (last updated February 22, 2025)
A missing permission check in Jenkins OWASP Dependency-Track Plugin 3.1.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL, capturing credentials stored in Jenkins.
Attacker Value
Unknown

CVE-2021-25122

Disclosure Date: March 01, 2021 (last updated February 22, 2025)
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.
Attacker Value
Unknown

CVE-2021-25329

Disclosure Date: March 01, 2021 (last updated November 08, 2023)
The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.