|
196401
|
4.3 |
MEDIUM
Network
|
jenkins
|
xebialabs_xl_deploy
|
A missing permission check in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins.
|
-
|
CVE-2021-21662
|
2024-11-21 14:48 |
2021-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196402
|
4.3 |
MEDIUM
Network
|
jenkins
|
kubernetes
|
Jenkins Kubernetes CLI Plugin 1.10.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credenti…
|
-
|
CVE-2021-21661
|
2024-11-21 14:48 |
2021-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196403
|
7.2 |
HIGH
Network
|
zte
|
zxhn_hs562_firmware
|
A smart camera product of ZTE is impacted by a permission and access control vulnerability. Due to the defect of user permission management by the cloud-end app, users whose sharing permissions have …
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-21736
|
2024-11-21 14:48 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196404
|
6.5 |
MEDIUM
Network
|
zte
|
zxhn_h168n_firmware
|
A ZTE product has an information leak vulnerability. Due to improper permission settings, an attacker with ordinary user permissions could exploit this vulnerability to obtain some sensitive user inf…
|
CWE-281
Improper Preservation of Permissions
|
CVE-2021-21735
|
2024-11-21 14:48 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196405
|
6.1 |
MEDIUM
Network
|
sap
|
netweaver_application_server_abap
|
SAP NetWeaver AS for ABAP (Web Survey), versions - 700, 702, 710, 711, 730, 731, 750, 750, 752, 75A, 75F, does not sufficiently encode input and output parameters which results in reflected cross sit…
|
CWE-79
Cross-site Scripting
|
CVE-2021-21490
|
2024-11-21 14:48 |
2021-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196406
|
6.3 |
MEDIUM
Network
|
sap
|
netweaver_application_server_abap
|
SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, contains function module SRM_RFC_SUBMIT_REPORT which fails to validate authorizati…
|
CWE-862
Missing Authorization
|
CVE-2021-21473
|
2024-11-21 14:48 |
2021-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196407
|
4.4 |
MEDIUM
Local
|
dell
|
emc_networker
|
Dell EMC NetWorker, 18.x, 19.1.x, 19.2.x 19.3.x, 19.4 and 19.4.0.1, contains an Information Disclosure vulnerability. A local administrator of the gstd system may potentially exploit this vulnerabili…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2021-21558
|
2024-11-21 14:48 |
2021-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196408
|
5.3 |
MEDIUM
Adjacent
|
dell
|
emc_networker
|
Dell EMC NetWorker, versions 18.x, 19.1.x, 19.2.x 19.3.x, 19.4, and 19.4.0.1 contain an Improper Certificate Validation vulnerability in the client (NetWorker Management Console) components which use…
|
CWE-295
Improper Certificate Validation
|
CVE-2021-21559
|
2024-11-21 14:48 |
2021-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196409
|
6.5 |
MEDIUM
Network
|
zte
|
zxa10_f821_firmware zxa10_f822_firmware zxa10_f819_firmware zxa10_f832_firmware zxa10_f839_firmware zxa10_f809_firmware zxa10_f822p_firmware zxa10_f832v2_firmware
|
Some PON MDU devices of ZTE stored sensitive information in plaintext, and users with login authority can obtain it by inputing command. This affects: ZTE PON MDU device ZXA10 F821 V1.7.0P3T22, ZXA10…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2021-21734
|
2024-11-21 14:48 |
2021-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196410
|
5.4 |
MEDIUM
Network
|
jenkins
|
markdown_formatter
|
Jenkins Markdown Formatter Plugin 0.1.0 and earlier does not sanitize crafted link target URLs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with the abilit…
|
CWE-79
Cross-site Scripting
|
CVE-2021-21660
|
2024-11-21 14:48 |
2021-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|