|
199881
|
6.5 |
MEDIUM
Network
|
elastic
|
elasticsearch
|
Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized …
|
CWE-862
Missing Authorization
|
CVE-2021-22147
|
2024-11-21 14:49 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199882
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later.
|
CWE-863
Incorrect Authorization
|
CVE-2021-22239
|
2024-11-21 14:49 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199883
|
8.8 |
HIGH
Network
|
ribbonsoft fedoraproject debian
|
dxflib extra_packages_for_enterprise_linux fedora debian_linux
|
A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can …
|
-
|
CVE-2021-21897
|
2024-11-21 14:49 |
2021-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199884
|
6.4 |
MEDIUM
Local
|
saltstack fedoraproject
|
salt fedora
|
An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This …
|
CWE-362
Race Condition
|
CVE-2021-22004
|
2024-11-21 14:49 |
2021-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199885
|
7.5 |
HIGH
Network
|
saltstack fedoraproject debian
|
salt fedora debian_linux
|
An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.
|
NVD-CWE-noinfo
|
CVE-2021-21996
|
2024-11-21 14:49 |
2021-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199886
|
7.5 |
HIGH
Network
|
vmware
|
identity_manager workspace_one_access cloud_foundation vrealize_suite_lifecycle_manager
|
VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute forc…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2021-22003
|
2024-11-21 14:49 |
2021-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199887
|
9.8 |
CRITICAL
Network
|
vmware
|
identity_manager workspace_one_access cloud_foundation vrealize_suite_lifecycle_manager
|
VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network…
|
CWE-287
Improper Authentication
|
CVE-2021-22002
|
2024-11-21 14:49 |
2021-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199888
|
7.5 |
HIGH
Network
|
vmware
|
workspace_one_uem_console
|
VMware Workspace ONE UEM REST API contains a denial of service vulnerability. A malicious actor with access to /API/system/admins/session could cause an API denial of service due to improper rate lim…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2021-22029
|
2024-11-21 14:49 |
2021-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199889
|
9.8 |
CRITICAL
Network
|
att
|
xmill
|
A memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs’ Xmill 0.7. A specially crafted XML file can lead to a heap buffer overflow. An attacker can…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2021-21811
|
2024-11-21 14:49 |
2021-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199890
|
5.4 |
MEDIUM
Network
|
vmware
|
vrealize_log_insight cloud_foundation
|
VMware vRealize Log Insight (8.x prior to 8.4) contains a Cross Site Scripting (XSS) vulnerability due to improper user input validation. An attacker with user privileges may be able to inject a mali…
|
CWE-79
Cross-site Scripting
|
CVE-2021-22021
|
2024-11-21 14:49 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|