Show filters
174 Total Results
Displaying 51-60 of 174
Sort by:
Attacker Value
Unknown

CVE-2021-24489

Disclosure Date: October 25, 2021 (last updated February 23, 2025)
The Request a Quote WordPress plugin before 2.3.9 does not sanitise, validate or escape some of its settings in the admin dashboard, leading to authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed.
Attacker Value
Unknown

CVE-2021-40371

Disclosure Date: October 25, 2021 (last updated February 23, 2025)
Gridpro Request Management for Windows Azure Pack before 2.0.7912 allows Directory Traversal for remote code execution, as demonstrated by ..\\ in a scriptName JSON value to ServiceManagerTenant/GetVisibilityMap.
Attacker Value
Unknown

CVE-2021-38562

Disclosure Date: October 18, 2021 (last updated February 23, 2025)
Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a timing attack against lib/RT/REST2/Middleware/Auth.pm.
Attacker Value
Unknown

CVE-2021-24420

Disclosure Date: July 12, 2021 (last updated February 23, 2025)
The Request a Quote WordPress plugin before 2.3.4 did not sanitise and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting issues when the quote is output in the 'All Quotes" table.
Attacker Value
Unknown

CVE-2021-21674

Disclosure Date: June 30, 2021 (last updated October 26, 2023)
A missing permission check in Jenkins requests-plugin Plugin 2.2.6 and earlier allows attackers with Overall/Read permission to view the list of pending requests.
Attacker Value
Unknown

CVE-2021-21675

Disclosure Date: June 30, 2021 (last updated February 22, 2025)
A cross-site request forgery (CSRF) vulnerability in Jenkins requests-plugin Plugin 2.2.12 and earlier allows attackers to create requests and/or have administrators apply pending requests.
Attacker Value
Unknown

CVE-2021-21676

Disclosure Date: June 30, 2021 (last updated February 22, 2025)
Jenkins requests-plugin Plugin 2.2.7 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to send test emails to an attacker-specified email address.
Attacker Value
Unknown

CVE-2021-29476

Disclosure Date: April 27, 2021 (last updated February 22, 2025)
Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been patched and users of `Requests` 1.6.0, 1.6.1 and 1.7.0 should update to version 1.8.0.
Attacker Value
Unknown

CVE-2021-31597

Disclosure Date: April 23, 2021 (last updated February 22, 2025)
The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.
Attacker Value
Unknown

CVE-2021-28470

Disclosure Date: April 13, 2021 (last updated November 28, 2024)
Visual Studio Code GitHub Pull Requests and Issues Extension Remote Code Execution Vulnerability
0