|
196991
|
6.5 |
MEDIUM
Network
|
jenkins
|
config_file_provider
|
Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpoints, allowing attackers with global Job/Configure permission to enumerate syst…
|
-
|
CVE-2021-21643
|
2024-11-21 14:48 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196992
|
8.1 |
HIGH
Network
|
jenkins
|
config_file_provider
|
Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
CWE-611
XXE
|
CVE-2021-21642
|
2024-11-21 14:48 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196993
|
6.7 |
MEDIUM
Local
|
dell
|
powerscale_onefs
|
Dell PowerScale OneFS 8.1.0 - 9.1.0 contains a privilege escalation in SmartLock compliance mode that may allow compadmin to execute arbitrary commands as root.
|
CWE-78
OS Command
|
CVE-2021-21526
|
2024-11-21 14:48 |
2021-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196994
|
7.5 |
HIGH
Network
|
filecoin
|
lotus
|
Lotus is an Implementation of the Filecoin protocol written in Go. BLS signature validation in lotus uses blst library method VerifyCompressed. This method accepts signatures in 2 forms: "serialized"…
|
-
|
CVE-2021-21405
|
2024-11-21 14:48 |
2021-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196995
|
7.5 |
HIGH
Network
|
ampache
|
ampache
|
Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated access to Ampache using the subsonic API. To successfully make the attack you …
|
CWE-287
Improper Authentication
|
CVE-2021-21399
|
2024-11-21 14:48 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196996
|
7.8 |
HIGH
Local
|
accusoft
|
imagegear
|
An out-of-bounds write vulnerability exists in the JPG format SOF marker processing of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to memory corruption. An attacker can provi…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-21784
|
2024-11-21 14:48 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196997
|
4.3 |
MEDIUM
Network
|
sap
|
netweaver_application_server_java
|
SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate logon group in URLs, resulting in a content spoofing vulnerabi…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2021-21492
|
2024-11-21 14:48 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196998
|
6.5 |
MEDIUM
Network
|
sap
|
netweaver_application_server_java
|
An unauthorized attacker may be able to entice an administrator to invoke telnet commands of an SAP NetWeaver Application Server for Java that allow the attacker to gain NTLM hashes of a privileged u…
|
NVD-CWE-noinfo
|
CVE-2021-21485
|
2024-11-21 14:48 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196999
|
4.9 |
MEDIUM
Network
|
sap
|
solution_manager
|
Under certain conditions SAP Solution Manager, version - 720, allows a high privileged attacker to get access to sensitive information which has a direct serious impact beyond the exploitable compone…
|
NVD-CWE-noinfo
|
CVE-2021-21483
|
2024-11-21 14:48 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197000
|
8.3 |
HIGH
Adjacent
|
sap
|
netweaver_master_data_management
|
SAP NetWeaver Master Data Management, versions - 710, 710.750, allows a malicious unauthorized user with access to the MDM Server subnet to find the password using a brute force method. If successful…
|
NVD-CWE-noinfo
|
CVE-2021-21482
|
2024-11-21 14:48 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|