CVE Feed

    Dashboard / CVE

    4.4
    Medium

    CVE-2021-0666

    Last Modified: 21 Nov 2024

    In apusys, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672086; Issue ID: ALPS05672086.

    Published: 18 Nov 2021
    4.4
    Medium

    CVE-2021-0665

    Last Modified: 21 Nov 2024

    In apusys, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672113; Issue ID: ALPS05672113.

    Published: 18 Nov 2021
    6.7
    Medium

    CVE-2021-0664

    Last Modified: 21 Nov 2024

    In ccu, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05827158; Issue ID: ALPS05827158.

    Published: 18 Nov 2021
    4.4
    Medium

    CVE-2021-0659

    Last Modified: 21 Nov 2024

    In apusys, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05687559; Issue ID: ALPS05687559.

    Published: 18 Nov 2021
    6.7
    Medium

    CVE-2021-0658

    Last Modified: 21 Nov 2024

    In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05672107.

    Published: 18 Nov 2021
    6.7
    Medium

    CVE-2021-0657

    Last Modified: 21 Nov 2024

    In apusys, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672103; Issue ID: ALPS05672103.

    Published: 18 Nov 2021
    6.7
    Medium

    CVE-2021-0656

    Last Modified: 21 Nov 2024

    In edma driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05709376; Issue ID: ALPS05709376.

    Published: 18 Nov 2021
    6.7
    Medium

    CVE-2021-0655

    Last Modified: 21 Nov 2024

    In mdlactl driver, there is a possible memory corruption due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05673424; Issue ID: ALPS05673424.

    Published: 18 Nov 2021
    6.7
    Medium

    CVE-2021-0629

    Last Modified: 21 Nov 2024

    In mdlactl driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05776625; Issue ID: ALPS05776625.

    Published: 18 Nov 2021
    5.5
    Medium

    CVE-2021-0624

    Last Modified: 21 Nov 2024

    In flv extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05594988; Issue ID: ALPS05594988.

    Published: 18 Nov 2021
    5.5
    Medium

    CVE-2021-0623

    Last Modified: 21 Nov 2024

    In asf extractor, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489178; Issue ID: ALPS05585817.

    Published: 18 Nov 2021
    5.5
    Medium

    CVE-2021-0622

    Last Modified: 21 Nov 2024

    In asf extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489178; Issue ID: ALPS05561388.

    Published: 18 Nov 2021
    5.5
    Medium

    CVE-2021-0621

    Last Modified: 21 Nov 2024

    In asf extractor, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489178; Issue ID: ALPS05561383.

    Published: 18 Nov 2021
    5.5
    Medium

    CVE-2021-0620

    Last Modified: 21 Nov 2024

    In asf extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489178; Issue ID: ALPS05561381.

    Published: 18 Nov 2021
    5.5
    Medium

    CVE-2021-0619

    Last Modified: 21 Nov 2024

    In ape extractor, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05561395; Issue ID: ALPS05561395.

    Published: 18 Nov 2021
    5.5
    Medium

    CVE-2021-0672

    Last Modified: 21 Nov 2024

    In Browser app, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-199678035

    Published: 18 Nov 2021
    8.8
    High

    CVE-2021-36909

    Last Modified: 28 Mar 2025

    Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authenticated user to wipe the entire database regardless of their authorization. It leads to a complete website reset and takeover.

    Published: 18 Nov 2021
    8.8
    High

    CVE-2021-36908

    Last Modified: 28 Mar 2025

    Cross-Site Request Forgery (CSRF) vulnerability in WebFactory Ltd. WP Reset PRO plugin <= 5.98 versions.

    Published: 18 Nov 2021
    4.4
    Medium

    CVE-2021-27026

    Last Modified: 21 Nov 2024

    A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged

    Published: 18 Nov 2021
    8.1
    High

    CVE-2021-27024

    Last Modified: 21 Nov 2024

    A flaw was discovered in Continuous Delivery for Puppet Enterprise (CD4PE) that results in a user with lower privileges being able to access a Puppet Enterprise API token. This issue is resolved in CD4PE 4.10.0

    Published: 18 Nov 2021
    6.9
    Medium

    CVE-2021-43549

    Last Modified: 21 Nov 2024

    A remote authenticated attacker with write access to a PI Server could trick a user into interacting with a PI Web API endpoint and redirect them to a malicious website. As a result, a victim may disclose sensitive information to the attacker or be provided with false information.

    Published: 18 Nov 2021
    7.8
    High

    CVE-2021-3984

    Last Modified: 21 Nov 2024

    vim is vulnerable to Heap-based Buffer Overflow

    Published: 18 Nov 2021
    6.5
    Medium

    CVE-2021-43998

    Last Modified: 21 Nov 2024

    HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multiple entity aliases exist for a specified entity and mount combination, potentially resulting in incorrect policy enforcement. Fixed in Vault and Vault Enterprise 1.7.6, 1.8.5, and 1.9.0.

    Published: 18 Nov 2021
    7.5
    High

    CVE-2021-43612

    Last Modified: 13 Feb 2025

    In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bounds heap read via short SONMP packets.

    Published: 18 Nov 2021
    10
    Critical

    CVE-2021-41277

    Last Modified: 24 Oct 2025

    Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the application.

    Published: 17 Nov 2021
    9.3
    Critical

    CVE-2021-41274

    Last Modified: 21 Nov 2024

    solidus_auth_devise provides authentication services for the Solidus webstore framework, using the Devise gem. In affected versions solidus_auth_devise is subject to a CSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of `solidus_auth_devise` are affected if `protect_from_forgery` method is both: Executed whether as: A `before_action` callback (the default) or A `prepend_before_action` (option `prepend: true` given) before the `:load_object` hook in `Spree::UserController` (most likely order to find). Configured to use `:null_session` or `:reset_session` strategies (`:null_session` is the default in case the no strategy is given, but `rails --new` generated skeleton use `:exception`). Users should promptly update to `solidus_auth_devise` version `2.5.4`. Users unable to update should if possible, change their strategy to `:exception`. Please see the linked GHSA for more workaround details.

    Published: 17 Nov 2021
    9.3
    Critical

    CVE-2021-41275

    Last Modified: 21 Nov 2024

    spree_auth_devise is an open source library which provides authentication and authorization services for use with the Spree storefront framework by using an underlying Devise authentication framework. In affected versions spree_auth_devise is subject to a CSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of spree_auth_devise are affected if protect_from_forgery method is both: Executed whether as: A before_action callback (the default). A prepend_before_action (option prepend: true given) before the :load_object hook in Spree::UserController (most likely order to find). Configured to use :null_session or :reset_session strategies (:null_session is the default in case the no strategy is given, but rails --new generated skeleton use :exception). Users are advised to update their spree_auth_devise gem. For users unable to update it may be possible to change your strategy to :exception. Please see the linked GHSA for more workaround details. ### Impact CSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of `spree_auth_devise` are affected if `protect_from_forgery` method is both: * Executed whether as: * A before_action callback (the default) * A prepend_before_action (option prepend: true given) before the :load_object hook in Spree::UserController (most likely order to find). * Configured to use :null_session or :reset_session strategies (:null_session is the default in case the no strategy is given, but rails --new generated skeleton use :exception). That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch �� ### Patches Spree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 ### Workarounds If possible, change your strategy to :exception: ```ruby class ApplicationController < ActionController::Base protect_from_forgery with: :exception end ``` Add the following to`config/application.rb `to at least run the `:exception` strategy on the affected controller: ```ruby config.after_initialize do Spree::UsersController.protect_from_forgery with: :exception end ``` ### References https://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2

    Published: 17 Nov 2021
    6.2
    Medium

    CVE-2021-0182

    Last Modified: 21 Nov 2024

    Uncontrolled resource consumption in the Intel(R) HAXM software before version 7.6.6 may allow an unauthenticated user to potentially enable information disclosure via local access.

    Published: 17 Nov 2021
    8.4
    High

    CVE-2021-0180

    Last Modified: 21 Nov 2024

    Uncontrolled resource consumption in the Intel(R) HAXM software before version 7.6.6 may allow an unauthenticated user to potentially enable privilege escalation via local access.

    Published: 17 Nov 2021
    6.7
    Medium

    CVE-2021-0186

    Last Modified: 21 Nov 2024

    Improper input validation in the Intel(R) SGX SDK applications compiled for SGX2 enabled processors may allow a privileged user to potentially escalation of privilege via local access.

    Published: 17 Nov 2021
    7.8
    High

    CVE-2020-8741

    Last Modified: 21 Nov 2024

    Improper permissions in the installer for the Intel(R) Thunderbolt(TM) non-DCH driver, all versions, for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Nov 2021
    7.5
    High

    CVE-2021-0013

    Last Modified: 21 Nov 2024

    Improper input validation for Intel(R) EMA before version 1.5.0 may allow an unauthenticated user to potentially enable denial of service via network access.

    Published: 17 Nov 2021
    5.7
    Medium

    CVE-2021-0053

    Last Modified: 21 Nov 2024

    Improper initialization in firmware for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi in Windows 10 may allow an authenticated user to potentially enable information disclosure via adjacent access.

    Published: 17 Nov 2021
    6.5
    Medium

    CVE-2021-0079

    Last Modified: 21 Nov 2024

    Improper input validation in software for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi in Windows 10 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 17 Nov 2021
    5.5
    Medium

    CVE-2021-0075

    Last Modified: 21 Nov 2024

    Out-of-bounds write in firmware for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and some Killer(TM) WiFi in Windows 10 may allow a privileged user to potentially enable denial of service via local access.

    Published: 17 Nov 2021
    6.5
    Medium

    CVE-2021-0069

    Last Modified: 21 Nov 2024

    Improper input validation in firmware for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and some Killer(TM) WiFi in Windows 10 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 17 Nov 2021
    4.3
    Medium

    CVE-2021-41273

    Last Modified: 21 Nov 2024

    Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. Due to improperly configured CSRF protections on two routes, a malicious user could execute a CSRF-based attack against the following endpoints: Sending a test email and Generating a node auto-deployment token. At no point would any data be exposed to the malicious user, this would simply trigger email spam to an administrative user, or generate a single auto-deployment token unexpectedly. This token is not revealed to the malicious user, it is simply created unexpectedly in the system. This has been addressed in release `1.6.6`. Users may optionally manually apply the fixes released in v1.6.6 to patch their own systems.

    Published: 17 Nov 2021
    7.8
    High

    CVE-2021-0082

    Last Modified: 21 Nov 2024

    Uncontrolled search path in software installer for Intel(R) PROSet/Wireless WiFi in Windows 10 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Nov 2021
    8.8
    High

    CVE-2021-0071

    Last Modified: 21 Nov 2024

    Improper input validation in firmware for some Intel(R) PROSet/Wireless WiFi in UEFI may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

    Published: 17 Nov 2021
    8.1
    High

    CVE-2021-0078

    Last Modified: 21 Nov 2024

    Improper input validation in software for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi in Windows 10 may allow an unauthenticated user to potentially enable denial of service or information disclosure via adjacent access.

    Published: 17 Nov 2021
    6.5
    Medium

    CVE-2021-0063

    Last Modified: 21 Nov 2024

    Improper input validation in firmware for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi in Windows 10 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 17 Nov 2021
    6.7
    Medium

    CVE-2021-0135

    Last Modified: 21 Nov 2024

    Improper input validation in the Intel(R) Ethernet Diagnostic Driver for Windows before version 1.4.0.10 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 17 Nov 2021
    5.5
    Medium

    CVE-2021-0110

    Last Modified: 21 Nov 2024

    Improper access control in some Intel(R) Thunderbolt(TM) Windows DCH Drivers before version 1.41.1054.0 may allow unauthenticated user to potentially enable denial of service via local access.

    Published: 17 Nov 2021
    4.4
    Medium

    CVE-2021-0148

    Last Modified: 21 Nov 2024

    Insertion of information into log file in firmware for some Intel(R) SSD DC may allow a privileged user to potentially enable information disclosure via local access.

    Published: 17 Nov 2021
    5.5
    Medium

    CVE-2021-33073

    Last Modified: 21 Nov 2024

    Uncontrolled resource consumption in the Intel(R) Distribution of OpenVINOâ„¢ Toolkit before version 2021.4 may allow an unauthenticated user to potentially enable denial of service via local access.

    Published: 17 Nov 2021
    5.5
    Medium

    CVE-2021-0152

    Last Modified: 21 Nov 2024

    Improper verification of cryptographic signature in the installer for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products in Windows 10 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 17 Nov 2021
    7.8
    High

    CVE-2021-0151

    Last Modified: 21 Nov 2024

    Improper access control in the installer for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products in Windows 10 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Nov 2021
    7.8
    High

    CVE-2021-0065

    Last Modified: 21 Nov 2024

    Incorrect default permissions in the Intel(R) PROSet/Wireless WiFi software installer for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Nov 2021
    7.8
    High

    CVE-2021-0064

    Last Modified: 21 Nov 2024

    Insecure inherited permissions in the Intel(R) PROSet/Wireless WiFi software installer for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Nov 2021
    9.8
    Critical

    CVE-2021-43996

    Last Modified: 21 Nov 2024

    The Ignition component before 1.16.15, and 2.0.x before 2.0.6, for Laravel has a "fix variable names" feature that can lead to incorrect access control.

    Published: 17 Nov 2021