|
197991
|
4.3 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not properly check that a newly created view has an allowed name, allowing attackers with View/Create permission to create views with invalid o…
|
-
|
CVE-2021-21640
|
2024-11-21 14:48 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197992
|
4.3 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not validate the type of object created after loading the data submitted to the `config.xml` REST API endpoint of a node, allowing attackers wi…
|
-
|
CVE-2021-21639
|
2024-11-21 14:48 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197993
|
7.5 |
HIGH
Network
|
syncthing
|
syncthing
|
Syncthing is a continuous file synchronization program. In Syncthing before version 1.15.0, the relay server `strelaysrv` can be caused to crash and exit by sending a relay message with a negative le…
|
-
|
CVE-2021-21404
|
2024-11-21 14:48 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197994
|
8.1 |
HIGH
Network
|
projen_project
|
projen
|
`projen` is a project generation tool that synthesizes project configuration files such as `package.json`, `tsconfig.json`, `.gitignore`, GitHub Workflows, `eslint`, `jest`, and more, from a well-typ…
|
-
|
CVE-2021-21423
|
2024-11-21 14:48 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197995
|
4.3 |
MEDIUM
Network
|
dell
|
wyse_management_suite
|
Wyse Management Suite versions up to 3.2 contains a vulnerability wherein a malicious authenticated user can cause a denial of service in the job status retrieval page, also affecting other users tha…
|
CWE-20
Improper Input Validation
|
CVE-2021-21533
|
2024-11-21 14:48 |
2021-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197996
|
6.3 |
MEDIUM
Adjacent
|
dell
|
wyse_thinos
|
Dell Wyse ThinOS 8.6 MR9 contains remediation for an improper management server validation vulnerability that could be potentially exploited to redirect a client to an attacker-controlled management …
|
CWE-20
Improper Input Validation
|
CVE-2021-21532
|
2024-11-21 14:48 |
2021-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197997
|
5.5 |
MEDIUM
Local
|
dell
|
system_update
|
Dell System Update (DSU) 1.9 and earlier versions contain a denial of service vulnerability. A local authenticated malicious user with low privileges may potentially exploit this vulnerability to cau…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2021-21529
|
2024-11-21 14:48 |
2021-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197998
|
6.5 |
MEDIUM
Network
|
wire
|
wire-webapp
|
wire-webapp is an open-source front end for Wire, a secure collaboration platform. In wire-webapp before version 2021-03-15-production.0, when being prompted to enter the app-lock passphrase, the typ…
|
CWE-200
Information Exposure
|
CVE-2021-21400
|
2024-11-21 14:48 |
2021-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197999
|
6.5 |
MEDIUM
Network
|
node-etsy-client_project
|
node-etsy-client
|
node-etsy-client is a NodeJs Etsy ReST API Client. Applications that are using node-etsy-client and reporting client error to the end user will offer api key value too This is fixed in node-etsy-clie…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2021-21421
|
2024-11-21 14:48 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198000
|
7.8 |
HIGH
Local
|
stripe
|
stripe
|
vscode-stripe is an extension for Visual Studio Code. A vulnerability in Stripe for Visual Studio Code extension exists when it loads an untrusted source-code repository containing malicious settings…
|
NVD-CWE-noinfo
|
CVE-2021-21420
|
2024-11-21 14:48 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|