|
195011
|
7.5 |
HIGH
Network
|
chainsafe
|
ethermint
|
Cosmos Network Ethermint <= v0.4.0 is affected by a transaction replay vulnerability in the EVM module. If the victim sends a very large nonce transaction, the attacker can replay the transaction thr…
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2021-25834
|
2024-11-21 14:55 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195012
|
5.3 |
MEDIUM
Network
|
nagios
|
favorites
|
The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possible to create favorites for any other user account.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2021-26024
|
2024-11-21 14:55 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195013
|
6.1 |
MEDIUM
Network
|
nagios
|
favorites
|
The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2021-26023
|
2024-11-21 14:55 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195014
|
5.3 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2020.2.1, permissions during user deletion were checked improperly.
|
NVD-CWE-Other
|
CVE-2021-25778
|
2024-11-21 14:55 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195015
|
5.3 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly.
|
CWE-863
Incorrect Authorization
|
CVE-2021-25777
|
2024-11-21 14:55 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195016
|
7.5 |
HIGH
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters.
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2021-25776
|
2024-11-21 14:55 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195017
|
3.8 |
LOW
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.
|
NVD-CWE-noinfo
|
CVE-2021-25775
|
2024-11-21 14:55 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195018
|
4.3 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user.
|
CWE-863
Incorrect Authorization
|
CVE-2021-25774
|
2024-11-21 14:55 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195019
|
6.1 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
JetBrains TeamCity before 2020.2 was vulnerable to reflected XSS on several pages.
|
CWE-79
Cross-site Scripting
|
CVE-2021-25773
|
2024-11-21 14:55 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195020
|
5.3 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2020.2.2, TeamCity server DoS was possible via server integration.
|
NVD-CWE-noinfo
|
CVE-2021-25772
|
2024-11-21 14:55 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|