Show filters
165 Total Results
Displaying 91-100 of 165
Sort by:
Attacker Value
Unknown
CVE-2021-24545
Disclosure Date: October 11, 2021 (last updated February 23, 2025)
The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone visit a post in the frontend made by such user. As a result, user with a role as low as author could perform Cross-Site Scripting attacks against users, which could potentially lead to privilege escalation when an admin view the related post/s.
0
Attacker Value
Unknown
CVE-2021-36754
Disclosure Date: July 30, 2021 (last updated February 23, 2025)
PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE 65535) that causes an out-of-bounds exception.
0
Attacker Value
Unknown
CVE-2021-34477
Disclosure Date: July 14, 2021 (last updated February 23, 2025)
Visual Studio Code .NET Runtime Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2021-21623
Disclosure Date: March 18, 2021 (last updated February 22, 2025)
An incorrect permission check in Jenkins Matrix Authorization Strategy Plugin 2.6.5 and earlier allows attackers with Item/Read permission on nested items to access them, even if they lack Item/Read permission for parent folders.
0
Attacker Value
Unknown
CVE-2021-21624
Disclosure Date: March 18, 2021 (last updated February 22, 2025)
An incorrect permission check in Jenkins Role-based Authorization Strategy Plugin 3.1 and earlier allows attackers with Item/Read permission on nested items to access them, even if they lack Item/Read permission for parent folders.
0
Attacker Value
Unknown
CVE-2020-35724
Disclosure Date: January 11, 2021 (last updated February 22, 2025)
Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the Error.jsp file via the err parameter (or indirectly via the cpr, tcp, or abs parameter). NOTE: This vulnerability only affects products that are no longer supported by the maintainer
0
Attacker Value
Unknown
CVE-2020-35206
Disclosure Date: January 11, 2021 (last updated February 22, 2025)
Reflected XSS in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious code into the browser via a specially crafted link to the cConn.jsp file via the ur parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
0
Attacker Value
Unknown
CVE-2020-35721
Disclosure Date: January 11, 2021 (last updated February 22, 2025)
Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the BrowseAssets.do file via the title parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
0
Attacker Value
Unknown
CVE-2020-35719
Disclosure Date: January 11, 2021 (last updated February 22, 2025)
Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the /WebCM/Applications/Search/index.jsp file via the added parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
0
Attacker Value
Unknown
CVE-2020-35205
Disclosure Date: January 11, 2021 (last updated February 22, 2025)
Server Side Request Forgery (SSRF) in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to scan internal ports and make outbound connections via the initFile.jsp file. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
0