Show filters
545 Total Results
Displaying 161-170 of 545
Sort by:
Attacker Value
Unknown

CVE-2021-23430

Disclosure Date: August 24, 2021 (last updated February 23, 2025)
All versions of package startserver are vulnerable to Directory Traversal due to missing sanitization.
Attacker Value
Unknown

CVE-2021-32827

Disclosure Date: August 16, 2021 (last updated February 23, 2025)
MockServer is open source software which enables easy mocking of any system you integrate with via HTTP or HTTPS. An attacker that can trick a victim into visiting a malicious site while running MockServer locally, will be able to run arbitrary code on the MockServer machine. With an overly broad default CORS configuration MockServer allows any site to send cross-site requests. Additionally, MockServer allows you to create dynamic expectations using Javascript or Velocity templates. Both engines may allow an attacker to execute arbitrary code on-behalf of MockServer. By combining these two issues (Overly broad CORS configuration + Script injection), an attacker could serve a malicious page so that if a developer running MockServer visits it, they will get compromised. For more details including a PoC see the referenced GHSL-2021-059.
Attacker Value
Unknown

CVE-2021-38384

Disclosure Date: August 10, 2021 (last updated February 23, 2025)
Serverless Offline 8.0.0 returns a 403 HTTP status code for a route that has a trailing / character, which might cause a developer to implement incorrect access control, because the actual behavior within the Amazon AWS environment is a 200 HTTP status code (i.e., possibly greater than expected permissions).
Attacker Value
Unknown

CVE-2021-37573

Disclosure Date: August 09, 2021 (last updated February 23, 2025)
A reflected cross-site scripting (XSS) vulnerability in the web server TTiny Java Web Server and Servlet Container (TJWS) <=1.115 allows an adversary to inject malicious code on the server's "404 Page not Found" error page
Attacker Value
Unknown

CVE-2021-3169

Disclosure Date: July 23, 2021 (last updated February 23, 2025)
An issue in Jumpserver before 2.6.2, before 2.5.4, before 2.4.5 allows attackers to create a connection token through an API which does not have access control and use it to access sensitive assets.
Attacker Value
Unknown

CVE-2020-18102

Disclosure Date: May 10, 2021 (last updated February 22, 2025)
Cross Site Scripting (XSS) in Hotels_Server v1.0 allows remote attackers to execute arbitrary code by injecting crafted commands the data fields in the component "/controller/publishHotel.php".
Attacker Value
Unknown

CVE-2021-29247

Disclosure Date: May 05, 2021 (last updated February 22, 2025)
BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the HTTPOnly flag for a cookie.
Attacker Value
Unknown

CVE-2021-29246

Disclosure Date: May 05, 2021 (last updated February 22, 2025)
BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achieve code execution. The attacker must craft a malicious plugin file with special characters to upload the file outside of the restricted directory.
Attacker Value
Unknown

CVE-2021-29245

Disclosure Date: May 05, 2021 (last updated February 22, 2025)
BTCPay Server through 1.0.7.0 uses a weak method Next to produce pseudo-random values to generate a legacy API key.
Attacker Value
Unknown

CVE-2021-29248

Disclosure Date: May 05, 2021 (last updated February 22, 2025)
BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the Secure flag for a cookie.