|
198731
|
6.5 |
MEDIUM
Network
|
vmware
|
vcenter_server cloud_foundation
|
The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing. A malicious actor with non-administrative user access to the vCenter Server vSphere Client (HTML5) or…
|
NVD-CWE-noinfo
|
CVE-2021-21992
|
2024-11-21 14:49 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198732
|
7.8 |
HIGH
Local
|
vmware
|
vcenter_server cloud_foundation
|
The vCenter Server contains a local privilege escalation vulnerability due to the way it handles session tokens. A malicious actor with non-administrative user access on vCenter Server host may explo…
|
NVD-CWE-noinfo
|
CVE-2021-21991
|
2024-11-21 14:49 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198733
|
8.8 |
HIGH
Network
|
elastic
|
enterprise_search
|
Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alternate route. Using this vulnerability, an authenticated att…
|
CWE-862
Missing Authorization
|
CVE-2021-22149
|
2024-11-21 14:49 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198734
|
8.8 |
HIGH
Network
|
elastic
|
enterprise_search
|
Elastic Enterprise Search App Search versions before 7.14.0 was vulnerable to an issue where API keys were not bound to the same engines as their creator. This could lead to a less privileged user ga…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2021-22148
|
2024-11-21 14:49 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198735
|
6.5 |
MEDIUM
Network
|
elastic
|
elasticsearch
|
Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized …
|
CWE-862
Missing Authorization
|
CVE-2021-22147
|
2024-11-21 14:49 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198736
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later.
|
CWE-863
Incorrect Authorization
|
CVE-2021-22239
|
2024-11-21 14:49 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198737
|
8.8 |
HIGH
Network
|
ribbonsoft fedoraproject debian
|
dxflib extra_packages_for_enterprise_linux fedora debian_linux
|
A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can …
|
-
|
CVE-2021-21897
|
2024-11-21 14:49 |
2021-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198738
|
6.4 |
MEDIUM
Local
|
saltstack fedoraproject
|
salt fedora
|
An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This …
|
CWE-362
Race Condition
|
CVE-2021-22004
|
2024-11-21 14:49 |
2021-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198739
|
7.5 |
HIGH
Network
|
saltstack fedoraproject debian
|
salt fedora debian_linux
|
An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.
|
NVD-CWE-noinfo
|
CVE-2021-21996
|
2024-11-21 14:49 |
2021-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198740
|
7.5 |
HIGH
Network
|
vmware
|
identity_manager workspace_one_access cloud_foundation vrealize_suite_lifecycle_manager
|
VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute forc…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2021-22003
|
2024-11-21 14:49 |
2021-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|