|
197371
|
5.3 |
MEDIUM
Network
|
moodle fedoraproject
|
moodle fedora
|
When creating a user account, it was possible to verify the account without having access to the verification email link/secret in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
|
-
|
CVE-2021-20282
|
2024-11-21 14:46 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197372
|
5.3 |
MEDIUM
Network
|
moodle fedoraproject
|
moodle fedora
|
It was possible for some users without permission to view other users' full names to do so via the online users block in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
|
CWE-863
Incorrect Authorization
|
CVE-2021-20281
|
2024-11-21 14:46 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197373
|
5.4 |
MEDIUM
Network
|
moodle fedoraproject
|
moodle fedora
|
Text-based feedback answers required additional sanitizing to prevent stored XSS and blind SSRF risks in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
|
-
|
CVE-2021-20280
|
2024-11-21 14:46 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197374
|
5.4 |
MEDIUM
Network
|
moodle fedoraproject
|
moodle fedora
|
The ID number user profile field required additional sanitizing to prevent a stored XSS risk in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20279
|
2024-11-21 14:46 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197375
|
2.7 |
LOW
Network
|
redhat
|
libnbd enterprise_linux
|
A flaw was found in libnbd 1.7.3. An assertion failure in nbd_unlocked_opt_go in ilb/opt.c may lead to denial of service.
|
-
|
CVE-2021-20286
|
2024-11-21 14:46 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197376
|
4.3 |
MEDIUM
Network
|
ibm
|
api_connect
|
IBM API Connect 10.0.0.0, and 2018.4.1.0 through 2018.4.1.13 does not restrict member registration to the intended recepient. An attacker who is a valid user in the user registry used by API Manager …
|
NVD-CWE-noinfo
|
CVE-2021-20440
|
2024-11-21 14:46 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197377
|
8.1 |
HIGH
Network
|
dogtagpki redhat fedoraproject
|
dogtagpki enterprise_linux certificate_system fedora
|
A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoke…
|
-
|
CVE-2021-20179
|
2024-11-21 14:46 |
2021-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197378
|
9.8 |
CRITICAL
Network
|
gnu redhat fedoraproject
|
gnutls enterprise_linux fedora
|
A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potential consequences.
|
-
|
CVE-2021-20232
|
2024-11-21 14:46 |
2021-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197379
|
9.8 |
CRITICAL
Network
|
gnu redhat fedoraproject netapp
|
gnutls enterprise_linux fedora active_iq_unified_manager e-series_performance_analyzer
|
A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.
|
-
|
CVE-2021-20231
|
2024-11-21 14:46 |
2021-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197380
|
7.8 |
HIGH
Local
|
ntt-tx
|
magicconnect
|
Untrusted search path vulnerability in Installer of MagicConnect Client program distributed before 2021 March 1 allows an attacker to gain privileges and via a Trojan horse DLL in an unspecified dire…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2021-20674
|
2024-11-21 14:46 |
2021-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|