|
195981
|
6.5 |
MEDIUM
Network
|
kubernetes
|
kubernetes
|
A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Adm…
|
NVD-CWE-Other
|
CVE-2021-25735
|
2024-11-21 14:55 |
2021-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195982
|
7.5 |
HIGH
Network
|
apache
|
ofbiz
|
In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle errors at multiple locations but leaks out sensitive table info which may aid the attacker for further recon…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2021-25958
|
2024-11-21 14:55 |
2021-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195983
|
9.8 |
CRITICAL
Network
|
atlassian
|
confluence_server confluence_data_center
|
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data…
|
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2021-26084
|
2024-11-21 14:55 |
2021-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195984
|
9.1 |
CRITICAL
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before executing a file deletion command.
|
CWE-863
Incorrect Authorization
|
CVE-2021-26040
|
2024-11-21 14:55 |
2021-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195985
|
8.8 |
HIGH
Network
|
dolibarr
|
dolibarr
|
In “Dolibarr” application, v2.8.1 to v13.0.2 are vulnerable to account takeover via password reset functionality. A low privileged attacker can reset the password of any user in the application using…
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2021-25957
|
2024-11-21 14:55 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195986
|
7.2 |
HIGH
Network
|
dolibarr
|
dolibarr dolibarr_erp\/crm
|
In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to validate already existing “Login” name, while renaming…
|
NVD-CWE-Other
|
CVE-2021-25956
|
2024-11-21 14:55 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195987
|
5.3 |
MEDIUM
Network
|
atlassian
|
jira_server jira_data_center
|
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions a…
|
CWE-22
Path Traversal
|
CVE-2021-26086
|
2024-11-21 14:55 |
2021-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195988
|
9.0 |
CRITICAL
Network
|
dolibarr
|
dolibarr
|
In “Dolibarr ERP CRM”, WYSIWYG Editor module, v2.8.1 to v13.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the “Private Note…
|
CWE-79
Cross-site Scripting
|
CVE-2021-25955
|
2024-11-21 14:55 |
2021-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195989
|
7.5 |
HIGH
Network
|
siemens
|
automation_license_manager
|
A vulnerability has been identified in Automation License Manager 5 (All versions), Automation License Manager 6 (All versions < V6.0 SP9 Update 2). Sending specially crafted packets to port 4410/tcp…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2021-25659
|
2024-11-21 14:55 |
2021-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195990
|
4.3 |
MEDIUM
Network
|
dolibarr
|
dolibarr
|
In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthorized actor. A low privileged attacker can modify the Private Note which only an…
|
CWE-863
Incorrect Authorization
|
CVE-2021-25954
|
2024-11-21 14:55 |
2021-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|