Latest CVE Feed
-
4.3
MEDIUMCVE-2024-39411
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass securi... Read more
- Published: Aug. 14, 2024
- Modified: Aug. 14, 2024
-
4.3
MEDIUMCVE-2021-37963
Side-channel information leakage in DevTools in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to bypass site isolation via a crafted HTML page.... Read more
- Published: Oct. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-39911
An improper access control flaw in all versions of GitLab CE/EE starting from 13.9 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 exposes private email address of Issue and Merge Requests as... Read more
Affected Products : gitlab- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-39936
Improper access control in GitLab CE/EE affecting all versions starting from 10.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker in possession of a deploy token to access a p... Read more
Affected Products : gitlab- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-39904
An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a Merge Request creator t... Read more
Affected Products : gitlab- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-39918
Incorrect Authorization in GitLab EE affecting all versions starting from 11.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows a user to add comments to a vulnerability which cannot be ac... Read more
Affected Products : gitlab- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-39931
An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.11 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under specific condition an unauthorised project member was... Read more
Affected Products : gitlab- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-34800
Jenkins Build Notifications Plugin 1.5.0 and earlier stores tokens unencrypted in its global configuration files on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.... Read more
Affected Products : build_notifications- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-39927
Server side request forgery protections in GitLab CE/EE versions between 8.4 and 14.4.4, between 14.5.0 and 14.5.2, and between 14.6.0 and 14.6.1 would fail to protect against attacks sending requests to localhost on port 80 or 443 if GitLab was configure... Read more
Affected Products : gitlab- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-37867
Mattermost Boards plugin v0.10.0 and earlier fails to protect email addresses of all users via one of the Boards APIs, which allows authenticated and unauthorized users to access this information resulting in sensitive & private information disclosure.... Read more
Affected Products : mattermost_boards- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-39865
Adobe Framemaker versions 2019 Update 8 (and earlier) and 2020 Release Update 2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mi... Read more
Affected Products : framemaker- Published: Sep. 29, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-34803
Jenkins OpsGenie Plugin 1.9 and earlier stores API keys unencrypted in its global configuration file and in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission (config.xml), or access to the Jenki... Read more
Affected Products : opsgenie- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-36371
Emissary-Ingress (formerly Ambassador API Gateway) through 1.13.9 allows attackers to bypass client certificate requirements (i.e., mTLS cert_required) on backend upstreams when more than one TLSContext is defined and at least one configuration exists tha... Read more
Affected Products : emissary-ingress- Published: Jul. 09, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-36349
Dell EMC Data Protection Central versions 19.5 and prior contain a Server Side Request Forgery vulnerability in the DPC DNS client processing. A remote malicious user could potentially exploit this vulnerability, allowing port scanning of external hosts.... Read more
- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-30156
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Special:Contributions can leak that a "hidden" user exists.... Read more
- Published: Apr. 09, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-31443
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malici... Read more
- Published: May. 07, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-33210
An issue was discovered in Fimer Aurora Vision before 2.97.10. An attacker can (in the WebUI) obtain plant information without authentication by reading the response of APIs from a kiosk view of a plant.... Read more
Affected Products : aurora_vision- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-50776
Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier stores PaaSLane authentication tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller... Read more
Affected Products : paaslane_estimate- Published: Dec. 13, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-33215
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The API allows Directory Traversal.... Read more
Affected Products : ruckus_iot_controller- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-3660
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar atta... Read more
- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024