Show filters
165 Total Results
Displaying 91-100 of 165
Sort by:
Attacker Value
Unknown

CVE-2021-24545

Disclosure Date: October 11, 2021 (last updated February 23, 2025)
The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone visit a post in the frontend made by such user. As a result, user with a role as low as author could perform Cross-Site Scripting attacks against users, which could potentially lead to privilege escalation when an admin view the related post/s.
Attacker Value
Unknown

CVE-2021-36754

Disclosure Date: July 30, 2021 (last updated February 23, 2025)
PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE 65535) that causes an out-of-bounds exception.
Attacker Value
Unknown

CVE-2021-34477

Disclosure Date: July 14, 2021 (last updated February 23, 2025)
Visual Studio Code .NET Runtime Elevation of Privilege Vulnerability
0
Attacker Value
Unknown

CVE-2021-21623

Disclosure Date: March 18, 2021 (last updated February 22, 2025)
An incorrect permission check in Jenkins Matrix Authorization Strategy Plugin 2.6.5 and earlier allows attackers with Item/Read permission on nested items to access them, even if they lack Item/Read permission for parent folders.
Attacker Value
Unknown

CVE-2021-21624

Disclosure Date: March 18, 2021 (last updated February 22, 2025)
An incorrect permission check in Jenkins Role-based Authorization Strategy Plugin 3.1 and earlier allows attackers with Item/Read permission on nested items to access them, even if they lack Item/Read permission for parent folders.
Attacker Value
Unknown

CVE-2020-35724

Disclosure Date: January 11, 2021 (last updated February 22, 2025)
Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the Error.jsp file via the err parameter (or indirectly via the cpr, tcp, or abs parameter). NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Attacker Value
Unknown

CVE-2020-35206

Disclosure Date: January 11, 2021 (last updated February 22, 2025)
Reflected XSS in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious code into the browser via a specially crafted link to the cConn.jsp file via the ur parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Attacker Value
Unknown

CVE-2020-35721

Disclosure Date: January 11, 2021 (last updated February 22, 2025)
Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the BrowseAssets.do file via the title parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Attacker Value
Unknown

CVE-2020-35719

Disclosure Date: January 11, 2021 (last updated February 22, 2025)
Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the /WebCM/Applications/Search/index.jsp file via the added parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Attacker Value
Unknown

CVE-2020-35205

Disclosure Date: January 11, 2021 (last updated February 22, 2025)
Server Side Request Forgery (SSRF) in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to scan internal ports and make outbound connections via the initFile.jsp file. NOTE: This vulnerability only affects products that are no longer supported by the maintainer