|
195421
|
6.1 |
MEDIUM
Network
|
jenkins
|
cas
|
Jenkins CAS Plugin 1.6.0 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.
|
-
|
CVE-2021-21673
|
2024-11-21 14:48 |
2021-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195422
|
4.3 |
MEDIUM
Network
|
jenkins
|
selenium_html_report
|
Jenkins Selenium HTML report Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
CWE-611
XXE
|
CVE-2021-21672
|
2024-11-21 14:48 |
2021-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195423
|
7.5 |
HIGH
Network
|
jenkins
|
jenkins
|
Jenkins 2.299 and earlier, LTS 2.289.1 and earlier does not invalidate the previous session on login.
|
-
|
CVE-2021-21671
|
2024-11-21 14:48 |
2021-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195424
|
4.3 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.299 and earlier, LTS 2.289.1 and earlier allows users to cancel queue items and abort builds of jobs for which they have Item/Cancel permission even when they do not have Item/Read permissi…
|
-
|
CVE-2021-21670
|
2024-11-21 14:48 |
2021-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195425
|
7.5 |
HIGH
Local
|
dell
|
alienware_m15_r6_firmware chengming_3990_firmware chengming_3991_firmware g15_5510_firmware g15_5511_firmware g3_3500_firmware g5_5500_firmware g7_7500_firmware g7_7700_firmwa…
|
Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary co…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-21574
|
2024-11-21 14:48 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195426
|
7.5 |
HIGH
Local
|
dell
|
alienware_m15_r6_firmware chengming_3990_firmware chengming_3991_firmware g15_5510_firmware g15_5511_firmware g3_3500_firmware g5_5500_firmware g7_7500_firmware g7_7700_firmwa…
|
Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary co…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-21573
|
2024-11-21 14:48 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195427
|
7.5 |
HIGH
Local
|
dell
|
alienware_m15_r6_firmware chengming_3990_firmware chengming_3991_firmware g15_5510_firmware g15_5511_firmware g3_3500_firmware g5_5500_firmware g7_7500_firmware g7_7700_firmwa…
|
Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary co…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-21572
|
2024-11-21 14:48 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195428
|
6.5 |
MEDIUM
Network
|
dell
|
alienware_m15_r6_firmware chengming_3990_firmware chengming_3991_firmware g15_5510_firmware g15_5511_firmware g3_3500_firmware g5_5500_firmware g7_7500_firmware g7_7700_firmwa…
|
Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability. A remote unauthenticated attacker may explo…
|
CWE-295
Improper Certificate Validation
|
CVE-2021-21571
|
2024-11-21 14:48 |
2021-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195429
|
7.5 |
HIGH
Network
|
zte
|
zxv10_b860h_v5.0_firmware
|
A smart STB product of ZTE is impacted by a permission and access control vulnerability. Due to insufficient protection of system application, attackers could use this vulnerability to tamper with th…
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-21737
|
2024-11-21 14:48 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195430
|
6.1 |
MEDIUM
Network
|
mongo-express_project
|
mongo-express
|
mongo-express is a web-based MongoDB admin interface, written with Node.js and express. 1: As mentioned in this issue: https://github.com/mongo-express/mongo-express/issues/577, when the content of a…
|
-
|
CVE-2021-21422
|
2024-11-21 14:48 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|