Total
2555 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2021-28146 | 1 Grafana | 1 Grafana | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
|
The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.
|
|||||
| CVE-2021-27793 | 1 Broadcom | 1 Fabric Operating System | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
|
ntermittent authorization failure in aaa tacacs+ with Brocade Fabric OS versions before Brocade Fabric OS v9.0.1b and after 9.0.0, also in Brocade Fabric OS before Brocade Fabric OS v8.2.3a and after v8.2.0 could cause a user with a valid account to be unable to log into the switch.
|
|||||
| CVE-2021-27661 | 1 Johnsoncontrols | 2 F4-snc, F4-snc Firmware | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
Successful exploitation of this vulnerability could give an authenticated Facility Explorer SNC Series Supervisory Controller (F4-SNC) user an unintended level of access to the controller’s file system, allowing them to access or modify system files by sending specifically crafted web messages to the F4-SNC.
|
|||||
| CVE-2021-27509 | 1 Visualware | 1 Myconnection Server | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
In Visualware MyConnection Server before 11.0b build 5382, each published report is not associated with its own access code.
|
|||||
| CVE-2021-27225 | 1 Dataiku | 1 Data Science Studio | 2024-11-21 | 5.5 MEDIUM | 5.4 MEDIUM |
|
In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects that they are not authorized to access.
|
|||||
| CVE-2021-27195 | 2 Microsoft, Netop | 2 Windows, Vision Pro | 2024-11-21 | 5.0 MEDIUM | 5.9 MEDIUM |
|
Improper Authorization vulnerability in Netop Vision Pro up to and including to 9.7.1 allows an attacker to replay network traffic.
|
|||||
| CVE-2021-27177 | 1 Fiberhome | 2 Hg6245d, Hg6245d Firmware | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to bypass authentication by sending the decoded value of the GgpoZWxwCmxpc3QKd2hvCg== string to the telnet server.
|
|||||
| CVE-2021-27099 | 1 Cncf | 1 Spire | 2024-11-21 | 4.9 MEDIUM | 6.8 MEDIUM |
|
In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the path provided through the agent ID templating feature, which may allow the issuance of an arbitrary SPIFFE ID within the same trust domain, if the attacker controls the value of an EC2 tag prior to attestation, and the attestor is configured for agent ID templating where the tag value is the last element in the path. This issue has been fixed in SPIRE versions 0.11.3 and 0.12.1
|
|||||
| CVE-2021-27086 | 1 Microsoft | 3 Windows 10, Windows Server 2016, Windows Server 2019 | 2024-11-21 | 4.6 MEDIUM | 7.8 HIGH |
|
Windows Services and Controller App Elevation of Privilege Vulnerability
|
|||||
| CVE-2021-26964 | 1 Arubanetworks | 1 Airwave | 2024-11-21 | 5.5 MEDIUM | 7.1 HIGH |
|
A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an authenticated remote attacker to improperly access and modify devices and management user details. A successful exploit would consist of an attacker using a lower privileged account to change management user or device details. This could allow the attacker to escalate privileges and ...
Show More |
|||||
| CVE-2021-26845 | 1 Hitachienergy | 1 Esoms | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
Information Exposure vulnerability in Hitachi ABB Power Grids eSOMS allows unauthorized user to gain access to report data if the URL used to access the report is discovered. This issue affects: Hitachi ABB Power Grids eSOMS 6.0 versions prior to 6.0.4.2.2; 6.1 versions prior to 6.1.4; 6.3 versions prior to 6.3.
|
|||||
| CVE-2021-26753 | 1 Nedi | 1 Nedi | 2024-11-21 | 6.5 MEDIUM | 9.9 CRITICAL |
|
NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all application data.
|
|||||
| CVE-2021-26718 | 1 Kaspersky | 1 Internet Security | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus protection.
|
|||||
| CVE-2021-26273 | 1 Ninjarmm | 1 Ninjarmm | 2024-11-21 | 4.6 MEDIUM | 7.8 HIGH |
|
The Agent in NinjaRMM 5.0.909 has Incorrect Access Control.
|
|||||
| CVE-2021-26040 | 1 Joomla | 1 Joomla\! | 2024-11-21 | 6.4 MEDIUM | 9.1 CRITICAL |
|
An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before executing a file deletion command.
|
|||||
| CVE-2021-26027 | 1 Joomla | 1 Joomla\! | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
|
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Incorrect ACL checks could allow unauthorized change of the category for an article.
|
|||||
| CVE-2021-26026 | 1 Acdsee | 1 Photo Studio 2021 | 2024-11-21 | 6.8 MEDIUM | 7.8 HIGH |
|
PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDStd!JPEGTransW+0x000000000000c7f4 via a crafted BMP image.
|
|||||
| CVE-2021-26025 | 1 Acdsee | 1 Photo Studio 2021 | 2024-11-21 | 6.8 MEDIUM | 7.8 HIGH |
|
PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDStd!zlibVersion+0x0000000000004e5e via a crafted BMP image.
|
|||||
| CVE-2021-25954 | 1 Dolibarr | 1 Dolibarr | 2024-11-21 | 4.0 MEDIUM | 4.3 MEDIUM |
|
In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthorized actor. A low privileged attacker can modify the Private Note which only an administrator has rights to do, the affected field is at “/adherents/note.php?id=1” endpoint.
|
|||||
| CVE-2021-25777 | 1 Jetbrains | 1 Teamcity | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
|
In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly.
|
|||||
| CVE-2021-25774 | 1 Jetbrains | 1 Teamcity | 2024-11-21 | 4.0 MEDIUM | 4.3 MEDIUM |
|
In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user.
|
|||||
| CVE-2021-25506 | 1 Samsung | 1 Health | 2024-11-21 | 2.1 LOW | 4.0 MEDIUM |
|
Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service.
|
|||||
| CVE-2021-25418 | 1 Samsung | 1 Internet | 2024-11-21 | 4.4 MEDIUM | 7.8 HIGH |
|
Improper component protection vulnerability in Samsung Internet prior to version 14.0.1.62 allows untrusted applications to execute arbitrary activity in specific condition.
|
|||||
| CVE-2021-25410 | 1 Google | 1 Android | 2024-11-21 | 3.6 LOW | 7.1 HIGH |
|
Improper access control of a component in CallBGProvider prior to SMR JUN-2021 Release 1 allows local attackers to access arbitrary files with an escalated privilege.
|
|||||
| CVE-2021-25406 | 1 Samsung | 1 Gear S | 2024-11-21 | 3.3 LOW | 6.5 MEDIUM |
|
Information exposure vulnerability in Gear S Plugin prior to version 2.2.05.20122441 allows unstrusted applications to access connected BT device information.
|
|||||
| CVE-2021-25356 | 1 Google | 1 Android | 2024-11-21 | 7.2 HIGH | 7.1 HIGH |
|
An improper caller check vulnerability in Managed Provisioning prior to SMR APR-2021 Release 1 allows unprivileged application to install arbitrary application, grant device admin permission and then delete several installed application.
|
|||||
| CVE-2021-25097 | 1 Creativityjuice | 1 Labtools | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
|
The LabTools WordPress plugin through 1.0 does not have proper authorisation and CSRF check in place when deleting publications, allowing any authenticated users, such as subscriber to delete arbitrary publication
|
|||||
| CVE-2021-24947 | 1 Thinkupthemes | 1 Responsive Vector Maps | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
|
The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in the rvm_import_regions AJAX action, allowing any authenticated user, such as subscriber, to read arbitrary files on the web server
|
|||||
| CVE-2021-24917 | 1 Wpserveur | 1 Wps Hide Login | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.
|
|||||
| CVE-2021-24905 | 1 Vsourz | 1 Advanced Cf7 Db | 2024-11-21 | 6.0 MEDIUM | 8.0 HIGH |
|
The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX action, and does not validate the file to be deleted, allowing any authenticated user to delete arbitrary files on the web server. For example, removing the wp-config.php allows attackers to trigger WordPress setup again, gain administrator privileges and execute arbitrary code or display arbitrary content to the users.
|
|||||
| CVE-2021-24872 | 1 Get Custom Field Values Project | 1 Get Custom Field Values | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
|
The Get Custom Field Values WordPress plugin before 4.0 allows users with a role as low as Contributor to access other posts metadata without validating the permissions. Eg. contributors can access admin posts metadata.
|
|||||
| CVE-2021-24851 | 1 Insert Pages Project | 1 Insert Pages | 2024-11-21 | 4.0 MEDIUM | 4.3 MEDIUM |
|
The Insert Pages WordPress plugin before 3.7.0 allows users with a role as low as Contributor to access content and metadata from arbitrary posts/pages regardless of their author and status (ie private), using a shortcode. Password protected posts/pages are not affected by such issue.
|
|||||
| CVE-2021-24842 | 1 Bulk Datetime Change Project | 1 Bulk Datetime Change | 2024-11-21 | 5.5 MEDIUM | 5.4 MEDIUM |
|
The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contributor roles to 1) list private post titles of other users and 2) change the posted date of other users' posts.
|
|||||
| CVE-2021-24824 | 1 Custom Content Shortcode Project | 1 Custom Content Shortcode | 2024-11-21 | 4.0 MEDIUM | 4.3 MEDIUM |
|
The [field] shortcode included with the Custom Content Shortcode WordPress plugin before 4.0.1, allows authenticated users with a role as low as contributor, to access arbitrary post metadata. This could lead to sensitive data disclosure, for example when used in combination with WooCommerce, the email address of orders can be retrieved
|
|||||
| CVE-2021-24819 | 1 Page\/post Content Shortcode Project | 1 Page\/post Content Shortcode | 2024-11-21 | 4.0 MEDIUM | 4.3 MEDIUM |
|
The Page/Post Content Shortcode WordPress plugin through 1.0 does not have proper authorisation in place, allowing users with a role as low as contributor to access draft/private/password protected/trashed posts/pages they should not be allowed to, including posts created by other users such as admins and editors.
|
|||||
| CVE-2021-24788 | 1 Batch Cat Project | 1 Batch Cat | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
|
The Batch Cat WordPress plugin through 0.3 defines 3 custom AJAX actions, which both require authentication but are available for all roles. As a result, any authenticated user (including simple subscribers) can add/set/delete arbitrary categories to posts.
|
|||||
| CVE-2021-24783 | 1 Publishpress | 1 Post Expirator | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
|
The Post Expirator WordPress plugin before 2.6.0 does not have proper capability checks in place, which could allow users with a role as low as Contributor to schedule deletion of arbitrary posts.
|
|||||
| CVE-2021-24770 | 1 Stylishpricelist | 1 Stylish Price List | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
|
The Stylish Price List WordPress plugin before 6.9.1 does not perform capability checks in its spl_upload_ser_img AJAX action (available to authenticated users), which could allow any authenticated users, such as subscriber, to upload arbitrary images.
|
|||||
| CVE-2021-24757 | 1 Stylishpricelist | 1 Stylish Price List | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
|
The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX action (available to both unauthenticated and authenticated users), which could allow unauthenticated users to upload images.
|
|||||
| CVE-2021-24742 | 1 Radiustheme | 1 Logo Slider And Showcase | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
|
The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugin's settings via the rtWLSSettings AJAX action because it uses a nonce for authorisation instead of a capability check.
|
|||||