Show filters
506 Total Results
Displaying 241-250 of 506
Sort by:
Attacker Value
Unknown
CVE-2019-5640
Disclosure Date: November 17, 2021 (last updated February 23, 2025)
Rapid7 Nexpose versions prior to 6.6.114 suffer from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the inspect element browser feature to remove the login panel and view the details available in the last webpage visited by previous user
0
Attacker Value
Unknown
CVE-2021-29213
Disclosure Date: November 01, 2021 (last updated November 28, 2024)
A potential local bypass of security restrictions vulnerability has been identified in HPE ProLiant DL20 Gen10, HPE ProLiant ML30 Gen10, and HPE ProLiant MicroServer Gen10 Plus server's system ROMs prior to version 2.52. The vulnerability could be locally exploited to cause disclosure of sensitive information, denial of service (DoS), and/or compromise system integrity.
0
Attacker Value
Unknown
CVE-2021-41116
Disclosure Date: October 05, 2021 (last updated February 23, 2025)
Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs and WSL are not affected. The issue has been resolved in composer versions 1.10.23 and 2.1.9. There are no workarounds for this issue.
0
Attacker Value
Unknown
CVE-2021-24495
Disclosure Date: August 09, 2021 (last updated February 23, 2025)
The Marmoset Viewer WordPress plugin before 1.9.3 does not property sanitize, validate or escape the 'id' parameter before outputting back in the page, leading to a reflected Cross-Site Scripting issue.
0
Attacker Value
Unknown
CVE-2021-31868
Disclosure Date: August 04, 2021 (last updated February 23, 2025)
Rapid7 Nexpose version 6.6.95 and earlier allows authenticated users of the Security Console to view and edit any ticket in the legacy ticketing feature, regardless of the assignment of the ticket. This issue was resolved in version 6.6.96, released on August 4, 2021.
0
Attacker Value
Unknown
CVE-2021-29061
Disclosure Date: June 21, 2021 (last updated February 22, 2025)
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Vfsjfilechooser2 version 0.2.9 and below which occurs when the application attempts to validate crafted URIs.
0
Attacker Value
Unknown
CVE-2021-31642
Disclosure Date: June 01, 2021 (last updated February 22, 2025)
A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC. The vulnerability can be explored by sending an unexpected integer (> 32 bits) on the page parameter that will crash the web portal and making it unavailable until a reboot of the device.
0
Attacker Value
Unknown
CVE-2021-31643
Disclosure Date: June 01, 2021 (last updated February 22, 2025)
An XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and Webpass due to a lack of sanitization on the component if.cgi - username parameter.
0
Attacker Value
Unknown
CVE-2020-26140
Disclosure Date: May 11, 2021 (last updated February 22, 2025)
An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration.
0
Attacker Value
Unknown
CVE-2020-26139
Disclosure Date: May 11, 2021 (last updated February 22, 2025)
An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to exploit other vulnerabilities in connected clients.
0