|
196861
|
8.8 |
HIGH
Network
|
elastic
|
enterprise_search
|
Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alternate route. Using this vulnerability, an authenticated att…
|
CWE-862
Missing Authorization
|
CVE-2021-22149
|
2024-11-21 14:49 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196862
|
8.8 |
HIGH
Network
|
elastic
|
enterprise_search
|
Elastic Enterprise Search App Search versions before 7.14.0 was vulnerable to an issue where API keys were not bound to the same engines as their creator. This could lead to a less privileged user ga…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2021-22148
|
2024-11-21 14:49 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196863
|
6.5 |
MEDIUM
Network
|
elastic
|
elasticsearch
|
Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized …
|
CWE-862
Missing Authorization
|
CVE-2021-22147
|
2024-11-21 14:49 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196864
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later.
|
CWE-863
Incorrect Authorization
|
CVE-2021-22239
|
2024-11-21 14:49 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196865
|
8.8 |
HIGH
Network
|
ribbonsoft fedoraproject debian
|
dxflib extra_packages_for_enterprise_linux fedora debian_linux
|
A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can …
|
-
|
CVE-2021-21897
|
2024-11-21 14:49 |
2021-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196866
|
6.4 |
MEDIUM
Local
|
saltstack fedoraproject
|
salt fedora
|
An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This …
|
CWE-362
Race Condition
|
CVE-2021-22004
|
2024-11-21 14:49 |
2021-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196867
|
7.5 |
HIGH
Network
|
saltstack fedoraproject debian
|
salt fedora debian_linux
|
An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.
|
NVD-CWE-noinfo
|
CVE-2021-21996
|
2024-11-21 14:49 |
2021-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196868
|
7.5 |
HIGH
Network
|
vmware
|
identity_manager workspace_one_access cloud_foundation vrealize_suite_lifecycle_manager
|
VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute forc…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2021-22003
|
2024-11-21 14:49 |
2021-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196869
|
9.8 |
CRITICAL
Network
|
vmware
|
identity_manager workspace_one_access cloud_foundation vrealize_suite_lifecycle_manager
|
VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network…
|
CWE-287
Improper Authentication
|
CVE-2021-22002
|
2024-11-21 14:49 |
2021-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196870
|
7.5 |
HIGH
Network
|
vmware
|
workspace_one_uem_console
|
VMware Workspace ONE UEM REST API contains a denial of service vulnerability. A malicious actor with access to /API/system/admins/session could cause an API denial of service due to improper rate lim…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2021-22029
|
2024-11-21 14:49 |
2021-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|