|
197191
|
8.8 |
HIGH
Network
|
jenkins
|
templating_engine
|
Jenkins Templating Engine Plugin 2.1 and earlier does not protect its pipeline configurations using Script Security Plugin, allowing attackers with Job/Configure permission to execute arbitrary code …
|
-
|
CVE-2021-21646
|
2024-11-21 14:48 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197192
|
4.3 |
MEDIUM
Network
|
jenkins
|
config_file_provider
|
Jenkins Config File Provider Plugin 3.7.0 and earlier does not perform permission checks in several HTTP endpoints, attackers with Overall/Read permission to enumerate configuration file IDs.
|
-
|
CVE-2021-21645
|
2024-11-21 14:48 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197193
|
5.4 |
MEDIUM
Network
|
jenkins
|
config_file_provider
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Config File Provider Plugin 3.7.0 and earlier allows attackers to delete configuration files corresponding to an attacker-specified ID.
|
CWE-352
Origin Validation Error
|
CVE-2021-21644
|
2024-11-21 14:48 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197194
|
6.5 |
MEDIUM
Network
|
jenkins
|
config_file_provider
|
Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpoints, allowing attackers with global Job/Configure permission to enumerate syst…
|
-
|
CVE-2021-21643
|
2024-11-21 14:48 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197195
|
8.1 |
HIGH
Network
|
jenkins
|
config_file_provider
|
Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
CWE-611
XXE
|
CVE-2021-21642
|
2024-11-21 14:48 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197196
|
6.7 |
MEDIUM
Local
|
dell
|
powerscale_onefs
|
Dell PowerScale OneFS 8.1.0 - 9.1.0 contains a privilege escalation in SmartLock compliance mode that may allow compadmin to execute arbitrary commands as root.
|
CWE-78
OS Command
|
CVE-2021-21526
|
2024-11-21 14:48 |
2021-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197197
|
7.5 |
HIGH
Network
|
filecoin
|
lotus
|
Lotus is an Implementation of the Filecoin protocol written in Go. BLS signature validation in lotus uses blst library method VerifyCompressed. This method accepts signatures in 2 forms: "serialized"…
|
-
|
CVE-2021-21405
|
2024-11-21 14:48 |
2021-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197198
|
7.5 |
HIGH
Network
|
ampache
|
ampache
|
Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated access to Ampache using the subsonic API. To successfully make the attack you …
|
CWE-287
Improper Authentication
|
CVE-2021-21399
|
2024-11-21 14:48 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197199
|
7.8 |
HIGH
Local
|
accusoft
|
imagegear
|
An out-of-bounds write vulnerability exists in the JPG format SOF marker processing of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to memory corruption. An attacker can provi…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-21784
|
2024-11-21 14:48 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197200
|
4.3 |
MEDIUM
Network
|
sap
|
netweaver_application_server_java
|
SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate logon group in URLs, resulting in a content spoofing vulnerabi…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2021-21492
|
2024-11-21 14:48 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|