Show filters
597 Total Results
Displaying 181-190 of 597
Sort by:
Attacker Value
Unknown
CVE-2021-22535
Disclosure Date: September 28, 2021 (last updated February 23, 2025)
Unauthorized information security disclosure vulnerability on Micro Focus Directory and Resource Administrator (DRA) product, affecting all DRA versions prior to 10.1 Patch 1. The vulnerability could lead to unauthorized information disclosure.
0
Attacker Value
Unknown
CVE-2021-24663
Disclosure Date: September 20, 2021 (last updated February 23, 2025)
The Simple Schools Staff Directory WordPress plugin through 1.1 does not validate uploaded logo pictures to ensure that are indeed images, allowing high privilege users such as admin to upload arbitrary file like PHP, leading to RCE
0
Attacker Value
Unknown
CVE-2021-36949
Disclosure Date: August 12, 2021 (last updated February 23, 2025)
Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability
0
Attacker Value
Unknown
CVE-2021-33900
Disclosure Date: July 26, 2021 (last updated February 23, 2025)
While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any configured SASL confidentiality layer was not applied. This issue affects Apache Directory Studio version 2.0.0.v20210213-M16 and prior versions.
0
Attacker Value
Unknown
CVE-2021-3514
Disclosure Date: May 28, 2021 (last updated February 22, 2025)
When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash.
0
Attacker Value
Unknown
CVE-2021-24179
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator import files. As the plugin also did not validate uploaded files, it could lead to RCE.
0
Attacker Value
Unknown
CVE-2021-24250
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from lack of sanitisation in the label of the Form Fields, leading to Authenticated Stored Cross-Site Scripting issues across various pages of the plugin.
0
Attacker Value
Unknown
CVE-2021-24248
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 did not properly check for imported files, forbidding certain extension via a blacklist approach, allowing administrator to import an archive with a .php4 inside for example, leading to RCE
0
Attacker Value
Unknown
CVE-2021-24249
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator export files, which could then be downloaded by the attacker to get access to PII, such as email, home addresses etc
0
Attacker Value
Unknown
CVE-2021-24251
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator update arbitrary payment history, such as change their status (from pending to completed to example)
0