Exploit Database

149,752 exploits tracked across all sources.

Sort: Activity Stars
CVE-2021-39109 WRITEUP HIGH
Atlassian Atlasboard < 1.1.9 - Path Traversal via renderWidgetResource
The renderWidgetResource resource in Atlasian Atlasboard before version 1.1.9 allows remote attackers to read arbitrary files via a path traversal vulnerability.
CVSS 7.5
CVE-2021-39890 WRITEUP LOW
GitLab 14.1.1-14.1.6 - Two-Factor Authentication Bypass via Basic Authentication
It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.
CVSS 3.1
CVE-2021-39900 WRITEUP LOW
GitLab 10.8.0-14.1.6 - Information Disclosure via SendEntry Rails Log Exposure
Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in object-storage with a temporary availability via Rails logs.
CVSS 2.0
CVE-2021-39920 WRITEUP HIGH
Wireshark 3.4.0-3.4.9 - Denial of Service via IPPUSB Dissector NULL Pointer Dereference
NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file
CVSS 7.5
CVE-2021-39921 WRITEUP HIGH
Wireshark 3.2.0-3.2.17 and 3.4.0-3.4.9 - Denial of Service via Modbus Dissector NULL Pointer Dereference
NULL pointer exception in the Modbus dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
CVSS 7.5
CVE-2021-39922 WRITEUP HIGH
Wireshark 3.2.0-3.2.17 and 3.4.0-3.4.9 - Denial of Service via C12.22 Dissector Buffer Overflow
Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
CVSS 7.5
CVE-2021-39923 WRITEUP HIGH
Wireshark 3.2.0-3.2.17 and 3.4.0-3.4.9 - Denial of Service via PNRP Dissector Large Loop
Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
CVSS 7.5
CVE-2021-39924 WRITEUP HIGH
Wireshark 3.2.0-3.2.17 and 3.4.0-3.4.9 - Denial of Service via Bluetooth DHT Dissector
Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
CVSS 7.5
CVE-2021-39925 WRITEUP HIGH
Wireshark 3.2.0-3.2.17 and 3.4.0-3.4.9 - Denial of Service via Bluetooth SDP Dissector Buffer Overflow
Buffer overflow in the Bluetooth SDP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
CVSS 7.5
CVE-2021-39926 WRITEUP HIGH
Wireshark 3.4.0-3.4.9 - Denial of Service via Bluetooth HCI_ISO Dissector Buffer Overflow
Buffer overflow in the Bluetooth HCI_ISO dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file
CVSS 7.5
CVE-2021-39928 WRITEUP HIGH
Wireshark 3.2.0-3.2.17 and 3.4.0-3.4.9 - Denial of Service via IEEE 802.11 Dissector
NULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
CVSS 7.5
CVE-2021-39929 WRITEUP HIGH
Wireshark 3.2.0-3.2.17 and 3.4.0-3.4.9 - Denial of Service via Bluetooth DHT Dissector
Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
CVSS 7.5
CVE-2021-39932 WRITEUP MEDIUM
GitLab 11.0-14.3.5, 14.4-14.4.3, 14.5-14.5.1 - Denial of Service via Diff Feature
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Using large payloads, the diff feature could be used to trigger high load time for users reviewing code changes.
CVSS 4.3
CVE-2021-39933 WRITEUP MEDIUM
GitLab 12.10-14.3.5, 14.4-14.4.3, 14.5-14.5.1 - Denial of Service via Inefficient Regular Expression
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression used for handling user input (notes, comments, etc) was susceptible to catastrophic backtracking that could cause a DOS attack.
CVSS 4.3
CVE-2021-39934 WRITEUP MEDIUM
GitLab 12.10-14.3.5, 14.4-14.4.3, 14.5-14.5.1 - Unauthorized Service Desk Email Address Disclosure
Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.
CVSS 4.3
CVE-2021-39935 WRITEUP MEDIUM
GitLab 10.5-14.3.5, 14.4-14.4.3, 14.5-14.5.1 - Unauthenticated Server-Side Request Forgery via CI Lint API
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API
CVSS 6.8
CVE-2021-39936 WRITEUP LOW
GitLab 10.7-14.3.5, 14.4-14.4.3, 14.5-14.5.1 - Incorrect Authorization via Deploy Token
Improper access control in GitLab CE/EE affecting all versions starting from 10.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker in possession of a deploy token to access a project's disabled wiki.
CVSS 3.5
CVE-2021-39937 WRITEUP MEDIUM
GitLab < 14.3.6, 14.4-14.4.4, 14.5-14.5.2 - Improper Privilege Management via Access Memoization Collision
A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, leads to potential elevated privileges in groups and projects under rare circumstances
CVSS 5.9
CVE-2021-39938 WRITEUP LOW
GitLab 8.15.0-14.3.5, 14.4.0-14.4.3, 14.5.0-14.5.1 - Denial of Service via Deploy Slash Command Regex
A vulnerable regular expression pattern in GitLab CE/EE since version 8.15 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to cause uncontrolled resource consumption leading to Denial of Service via specially crafted deploy Slash commands
CVSS 3.1
CVE-2021-39939 WRITEUP MEDIUM
GitLab Runner 13.7-14.3.5, 14.4-14.4.3, 14.5-14.5.1 - Uncontrolled Resource Consumption via Crafted Docker Image
An uncontrolled resource consumption vulnerability in GitLab Runner affecting all versions starting from 13.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker triggering a job with a specially crafted docker image to exhaust resources on runner manager
CVSS 6.5
CVE-2021-39940 WRITEUP MEDIUM
GitLab 13.2-14.3.5, 14.4-14.4.3, 14.5-14.5.1 - Regular Expression Denial of Service in Maven Package Registry
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package registry is vulnerable to a regular expression denial of service when a specifically crafted string is sent.
CVSS 4.3
CVE-2021-39941 WRITEUP LOW
GitLab 12.0-14.3.6, 14.4-14.4.4, 14.5-14.5.2 - Unauthenticated Exposure of Sensitive Information via Default Branch Name
An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to see the default branch name for projects that restrict access to the repository to project members
CVSS 3.7
CVE-2021-39944 WRITEUP HIGH
GitLab 11.0-14.3.5, 14.4-14.4.3, 14.5-14.5.1 - Privilege Escalation via Project Import
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A permissions validation flaw allowed group members with a developer role to elevate their privilege to a maintainer on projects they import
CVSS 7.1
CVE-2021-39945 WRITEUP LOW
GitLab 9.4.0-14.3.5, 14.4.0-14.4.3, 14.5.0-14.5.1 - Incorrect Authorization in Merge Request Approval
Improper access control in the GitLab CE/EE API affecting all versions starting from 9.4 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an author of a Merge Request to approve the Merge Request even after having their project access revoked
CVSS 2.7
CVE-2021-39947 WRITEUP MEDIUM
GitLab Runner <14.5.2 - Buffer Overflow
In specific circumstances, trace file buffers in GitLab Runner versions up to 14.3.4, 14.4 to 14.4.2, and 14.5 to 14.5.2 would re-use the file descriptor 0 for multiple traces and mix the output of several jobs
CVSS 5.3