LiveActive security incident?Get immediate response
CVE archive

April 2021

Browse CVE records published in April 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2026 matching CVEs · Page 18 of 41.

Unknown · CVSS Not scored

CVE-2021-43442: A Logic Flaw vulnerability exists in i3 International Inc Annexxus Camera V5.2.0 build 150317 (Ax46), V5.0....

A Logic Flaw vulnerability exists in i3 International Inc Annexxus Camera V5.2.0 build 150317 (Ax46), V5.0.9 build 151106 (Ax68), and V5.0.9 build 150615 (Ax78) due to a failure to allow the creation of more than one administrator account; however, this can be bypassed by parameter maniulation using PUT and DELETE and by calling the 'UserPermission' endpoint with the ID of created account and set it to 'admin' userType, successfully adding a second administrative account.

Published Apr 11, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-43286: An issue was discovered in ThoughtWorks GoCD before 21.3.0.

An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker with privileges to create a new pipeline on a GoCD server can abuse a command-line injection in the Git URL "Test Connection" feature to execute arbitrary code.

Published Apr 14, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-43290: An issue was discovered in ThoughtWorks GoCD before 21.3.0.

An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into a directory of a GoCD server. They can control the filename but the directory is placed inside of a directory that they can't control.

Published Apr 14, 2022 · Updated Aug 4, 2024