|
195841
|
7.5 |
HIGH
Network
|
chainsafe
|
ethermint
|
Cosmos Network Ethermint <= v0.4.0 is affected by cache lifecycle inconsistency in the EVM module. Due to the inconsistency between the Storage caching cycle and the Tx processing cycle, Storage chan…
|
NVD-CWE-noinfo
|
CVE-2021-25837
|
2024-11-21 14:55 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195842
|
7.5 |
HIGH
Network
|
chainsafe
|
ethermint
|
Cosmos Network Ethermint <= v0.4.0 is affected by cache lifecycle inconsistency in the EVM module. The bytecode set in a FAILED transaction wrongfully remains in memory(stateObject.code) and is furth…
|
NVD-CWE-noinfo
|
CVE-2021-25836
|
2024-11-21 14:55 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195843
|
7.5 |
HIGH
Network
|
chainsafe
|
ethermint
|
Cosmos Network Ethermint <= v0.4.0 is affected by a cross-chain transaction replay vulnerability in the EVM module. Since ethermint uses the same chainIDEpoch and signature schemes with ethereum for …
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2021-25835
|
2024-11-21 14:55 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195844
|
7.5 |
HIGH
Network
|
chainsafe
|
ethermint
|
Cosmos Network Ethermint <= v0.4.0 is affected by a transaction replay vulnerability in the EVM module. If the victim sends a very large nonce transaction, the attacker can replay the transaction thr…
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2021-25834
|
2024-11-21 14:55 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195845
|
5.3 |
MEDIUM
Network
|
nagios
|
favorites
|
The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possible to create favorites for any other user account.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2021-26024
|
2024-11-21 14:55 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195846
|
6.1 |
MEDIUM
Network
|
nagios
|
favorites
|
The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2021-26023
|
2024-11-21 14:55 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195847
|
5.3 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2020.2.1, permissions during user deletion were checked improperly.
|
NVD-CWE-Other
|
CVE-2021-25778
|
2024-11-21 14:55 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195848
|
5.3 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly.
|
CWE-863
Incorrect Authorization
|
CVE-2021-25777
|
2024-11-21 14:55 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195849
|
7.5 |
HIGH
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters.
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2021-25776
|
2024-11-21 14:55 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195850
|
3.8 |
LOW
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.
|
NVD-CWE-noinfo
|
CVE-2021-25775
|
2024-11-21 14:55 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|