|
193761
|
7.5 |
HIGH
Network
|
jetbrains
|
intellij_idea
|
In JetBrains IntelliJ IDEA before 2021.1, DoS was possible because of unbounded resource allocation.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2021-30504
|
2024-11-21 15:04 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193762
|
7.5 |
HIGH
Network
|
apache
|
tapestry
|
Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specially-constructed URL. This was caused by an incompl…
|
CWE-863
Incorrect Authorization
|
CVE-2021-30638
|
2024-11-21 15:04 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193763
|
9.8 |
CRITICAL
Network
|
symantec
|
security_analytics
|
An input validation flaw in the Symantec Security Analytics web UI 7.2 prior 7.2.7, 8.1, prior to 8.1.3-NSR3, 8.2, prior to 8.2.1-NSR2 or 8.2.2 allows a remote, unauthenticated attacker to execute ar…
|
CWE-78
OS Command
|
CVE-2021-30642
|
2024-11-21 15:04 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193764
|
5.3 |
MEDIUM
Network
|
sonatype
|
nexus_repository_manager
|
Sonatype Nexus Repository Manager 3.x before 3.30.1 allows a remote attacker to get a list of files and directories that exist in a UI-related folder via directory traversal (no customer-specific dat…
|
CWE-22
Path Traversal
|
CVE-2021-30635
|
2024-11-21 15:04 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193765
|
9.8 |
CRITICAL
Network
|
simple_glasgow_haskell_compiler_project
|
simple_glasgow_haskell_compiler
|
The unofficial vscode-ghc-simple (aka Simple Glasgow Haskell Compiler) extension before 0.2.3 for Visual Studio Code allows remote code execution via a crafted workspace configuration with replComman…
|
NVD-CWE-noinfo
|
CVE-2021-30502
|
2024-11-21 15:04 |
2021-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193766
|
5.7 |
MEDIUM
Network
|
telegram
|
telegram
|
The Telegram app 7.6.2 for iOS allows remote authenticated users to cause a denial of service (application crash) if the victim pastes an attacker-supplied message (e.g., in the Persian language) int…
|
NVD-CWE-noinfo
|
CVE-2021-30496
|
2024-11-21 15:04 |
2021-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193767
|
2.7 |
LOW
Network
|
zulip
|
zulip_server
|
In the topic moving API in Zulip Server 3.x before 3.4, organization administrators were able to move messages to streams in other organizations hosted by the same Zulip installation.
|
NVD-CWE-noinfo
|
CVE-2021-30487
|
2024-11-21 15:04 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193768
|
5.3 |
MEDIUM
Network
|
zulip
|
zulip_server
|
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the all_public_streams API feature resulted in guest users being able to receive message traffic to public streams t…
|
CWE-269
Improper Privilege Management
|
CVE-2021-30479
|
2024-11-21 15:04 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193769
|
4.3 |
MEDIUM
Network
|
zulip
|
zulip_server
|
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the can_forge_sender permission (previously is_api_super_user) resulted in users with this permission being able to …
|
CWE-269
Improper Privilege Management
|
CVE-2021-30478
|
2024-11-21 15:04 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193770
|
4.3 |
MEDIUM
Network
|
zulip
|
zulip_server
|
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of replies to messages sent by outgoing webhooks to private streams meant that an outgoing webhook bot could be used to…
|
NVD-CWE-noinfo
|
CVE-2021-30477
|
2024-11-21 15:04 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|