|
199611
|
8.8 |
HIGH
Local
|
iobit
|
advanced_systemcare_ultimate
|
A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write requests. During IOCTL 0x9c40a0d8, the first dword passed in t…
|
NVD-CWE-Other
|
CVE-2021-21787
|
2024-11-21 14:48 |
2021-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199612
|
7.8 |
HIGH
Local
|
iobit
|
advanced_systemcare_ultimate
|
A privilege escalation vulnerability exists in the IOCTL 0x9c406144 handling of IOBit Advanced SystemCare Ultimate 14.2.0.220. A specially crafted I/O request packet (IRP) can lead to increased privi…
|
CWE-269
Improper Privilege Management
|
CVE-2021-21786
|
2024-11-21 14:48 |
2021-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199613
|
8.8 |
HIGH
Local
|
iobit
|
advanced_systemcare_ultimate
|
A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write requests. During IOCTL 0x9c40a0dc, the first dword passed in t…
|
NVD-CWE-Other
|
CVE-2021-21788
|
2024-11-21 14:48 |
2021-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199614
|
4.3 |
MEDIUM
Network
|
jenkins
|
requests
|
Jenkins requests-plugin Plugin 2.2.7 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to send test emails to an attacker-specified …
|
CWE-862
Missing Authorization
|
CVE-2021-21676
|
2024-11-21 14:48 |
2021-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199615
|
6.5 |
MEDIUM
Network
|
jenkins
|
requests
|
A cross-site request forgery (CSRF) vulnerability in Jenkins requests-plugin Plugin 2.2.12 and earlier allows attackers to create requests and/or have administrators apply pending requests.
|
CWE-352
Origin Validation Error
|
CVE-2021-21675
|
2024-11-21 14:48 |
2021-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199616
|
4.3 |
MEDIUM
Network
|
jenkins
|
requests
|
A missing permission check in Jenkins requests-plugin Plugin 2.2.6 and earlier allows attackers with Overall/Read permission to view the list of pending requests.
|
-
|
CVE-2021-21674
|
2024-11-21 14:48 |
2021-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199617
|
6.1 |
MEDIUM
Network
|
jenkins
|
cas
|
Jenkins CAS Plugin 1.6.0 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.
|
-
|
CVE-2021-21673
|
2024-11-21 14:48 |
2021-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199618
|
4.3 |
MEDIUM
Network
|
jenkins
|
selenium_html_report
|
Jenkins Selenium HTML report Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
CWE-611
XXE
|
CVE-2021-21672
|
2024-11-21 14:48 |
2021-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199619
|
7.5 |
HIGH
Network
|
jenkins
|
jenkins
|
Jenkins 2.299 and earlier, LTS 2.289.1 and earlier does not invalidate the previous session on login.
|
-
|
CVE-2021-21671
|
2024-11-21 14:48 |
2021-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199620
|
4.3 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.299 and earlier, LTS 2.289.1 and earlier allows users to cancel queue items and abort builds of jobs for which they have Item/Cancel permission even when they do not have Item/Read permissi…
|
-
|
CVE-2021-21670
|
2024-11-21 14:48 |
2021-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|