Show filters
318 Total Results
Displaying 171-180 of 318
Sort by:
Attacker Value
Unknown
CVE-2021-27786
Disclosure Date: June 07, 2022 (last updated February 23, 2025)
Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that identifies the domain that is making the initial request and defines the protocol between a browser and server to see if the request is allowed. An attacker can take advantage of this and possibly carry out privileged actions and access sensitive information when the Access-Control-Allow-Credentials is enabled.
0
Attacker Value
Unknown
CVE-2021-27778
Disclosure Date: May 31, 2022 (last updated February 23, 2025)
HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerability to execute a malicious script to access any cookies, session tokens, or other sensitive information retained by the browser and used with that site.
0
Attacker Value
Unknown
CVE-2022-29334
Disclosure Date: May 24, 2022 (last updated February 23, 2025)
An issue in H v1.0 allows attackers to bypass authentication via a session replay attack.
0
Attacker Value
Unknown
CVE-2021-27783
Disclosure Date: May 19, 2022 (last updated February 23, 2025)
User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed.
0
Attacker Value
Unknown
CVE-2021-27780
Disclosure Date: May 09, 2022 (last updated February 23, 2025)
The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.
0
Attacker Value
Unknown
CVE-2021-27781
Disclosure Date: May 09, 2022 (last updated February 23, 2025)
The Master operator may be able to embed script tag in HTML with alert pop-up display cookie.
0
Attacker Value
Unknown
CVE-2021-27779
Disclosure Date: April 30, 2022 (last updated February 23, 2025)
VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on communications with the server.
0
Attacker Value
Unknown
CVE-2021-27758
Disclosure Date: April 28, 2022 (last updated February 23, 2025)
There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after attacker spam to login and system blocked victim's account.
0
Attacker Value
Unknown
CVE-2021-27759
Disclosure Date: April 28, 2022 (last updated February 23, 2025)
This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intentionally. An attacker can cause a victim's browser to emit an HTTP request to an arbitrary URL in the application.
0
Attacker Value
Unknown
CVE-2021-27762
Disclosure Date: April 21, 2022 (last updated October 07, 2023)
Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web responses
0