Show filters
1,713 Total Results
Displaying 431-440 of 1,713
Sort by:
Attacker Value
Unknown
CVE-2021-44019
Disclosure Date: December 03, 2021 (last updated February 23, 2025)
An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar to but not identical to CVE-2021-44020 and 44021.
0
Attacker Value
Unknown
CVE-2021-33086
Disclosure Date: November 17, 2021 (last updated February 23, 2025)
Out-of-bounds write in firmware for some Intel(R) NUCs may allow an authenticated user to potentially enable denial of service via local access.
0
Attacker Value
Unknown
CVE-2021-31599
Disclosure Date: November 08, 2021 (last updated February 23, 2025)
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. A reports (.prpt) file allows the inclusion of BeanShell scripts to ease the production of complex reports. An authenticated user can run arbitrary code.
0
Attacker Value
Unknown
CVE-2021-31601
Disclosure Date: November 08, 2021 (last updated February 23, 2025)
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. They implement a series of web services using the SOAP protocol to allow scripting interaction with the backend server. An authenticated user (regardless of privileges) can list all databases connection details and credentials.
0
Attacker Value
Unknown
CVE-2021-31602
Disclosure Date: November 08, 2021 (last updated February 23, 2025)
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The Security Model has different layers of Access Control. One of these layers is the applicationContext security, which is defined in the applicationContext-spring-security.xml file. The default configuration allows an unauthenticated user with no previous knowledge of the platform settings to extract pieces of information without possessing valid credentials.
0
Attacker Value
Unknown
CVE-2021-31600
Disclosure Date: November 08, 2021 (last updated February 23, 2025)
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. They implement a series of web services using the SOAP protocol to allow scripting interaction with the backend server. An authenticated user (regardless of privileges) can list all valid usernames.
0
Attacker Value
Unknown
CVE-2021-29753
Disclosure Date: November 04, 2021 (last updated February 23, 2025)
IBM Business Automation Workflow 18. 19, 20, 21, and IBM Business Process Manager 8.5 and d8.6 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
0
Attacker Value
Unknown
CVE-2020-36503
Disclosure Date: November 01, 2021 (last updated February 23, 2025)
The Connections Business Directory WordPress plugin before 9.7 does not validate or sanitise some connections' fields, which could lead to a CSV injection issue
0
Attacker Value
Unknown
CVE-2021-24794
Disclosure Date: November 01, 2021 (last updated February 23, 2025)
The Connections Business Directory WordPress plugin before 10.4.3 does not escape the Address settings when creating an Entry, which could allow high privilege users to perform Cross-Site Scripting when the unfiltered_html capability is disallowed.
0
Attacker Value
Unknown
CVE-2021-42104
Disclosure Date: October 21, 2021 (last updated February 23, 2025)
Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar to but not identical to CVE-2021-42105, 42106 and 42107.
0