CVE Feed

    Dashboard / CVE

    4.4
    Medium

    CVE-2021-0199

    Last Modified: 21 Nov 2024

    Improper input validation in the firmware for the Intel(R) Ethernet Network Controller E810 before version 1.6.0.6 may allow a privileged user to potentially enable a denial of service via local access.

    Published: 17 Nov 2021
    4.4
    Medium

    CVE-2021-0198

    Last Modified: 21 Nov 2024

    Improper access control in the firmware for the Intel(R) Ethernet Network Controller E810 before version 1.5.5.6 may allow a privileged user to potentially enable a denial of service via local access.

    Published: 17 Nov 2021
    4.4
    Medium

    CVE-2021-0197

    Last Modified: 21 Nov 2024

    Protection mechanism failure in the firmware for the Intel(R) Ethernet Network Controller E810 before version 1.5.5.6 may allow a privileged user to enable a denial of service via local access.

    Published: 17 Nov 2021
    8.2
    High

    CVE-2021-41165

    Last Modified: 21 Nov 2024

    CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.

    Published: 17 Nov 2021
    6.7
    Medium

    CVE-2021-0200

    Last Modified: 21 Nov 2024

    Out-of-bounds write in the firmware for Intel(R) Ethernet 700 Series Controllers before version 8.2 may allow a privileged user to potentially enable an escalation of privilege via local access.

    Published: 17 Nov 2021
    6.7
    Medium

    CVE-2021-33059

    Last Modified: 21 Nov 2024

    Improper input validation in the Intel(R) Administrative Tools for Intel(R) Network Adapters driver for Windows before version 1.4.0.15, may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 17 Nov 2021
    7.8
    High

    CVE-2021-33058

    Last Modified: 21 Nov 2024

    Improper access control in the installer Intel(R)Administrative Tools for Intel(R) Network Adaptersfor Windowsbefore version 1.4.0.21 may allow an unauthenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Nov 2021
    7.8
    High

    CVE-2021-33062

    Last Modified: 21 Nov 2024

    Incorrect default permissions in the software installer for the Intel(R) VTune(TM) Profiler before version 2021.3.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Nov 2021
    7.8
    High

    CVE-2021-33063

    Last Modified: 21 Nov 2024

    Uncontrolled search path in the Intel(R) RealSense(TM) D400 Series UWP driver for Windows 10 before version 6.1.160.22 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Nov 2021
    7.8
    High

    CVE-2021-33118

    Last Modified: 21 Nov 2024

    Improper access control in the software installer for the Intel(R) Serial IO driver for Intel(R) NUC 11 Gen before version 30.100.2104.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Nov 2021
    7.8
    High

    CVE-2021-33071

    Last Modified: 21 Nov 2024

    Incorrect default permissions in the installer for the Intel(R) oneAPI Rendering Toolkit before version 2021.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Nov 2021
    6.6
    Medium

    CVE-2021-33097

    Last Modified: 21 Nov 2024

    Time-of-check time-of-use vulnerability in the Crypto API Toolkit for Intel(R) SGX may allow a privileged user to potentially enable escalation of privilege via network access.

    Published: 17 Nov 2021
    5.5
    Medium

    CVE-2021-0120

    Last Modified: 21 Nov 2024

    Improper initialization in the installer for some Intel(R) Graphics DCH Drivers for Windows 10 before version 27.20.100.9316 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 17 Nov 2021
    7.8
    High

    CVE-2021-0121

    Last Modified: 21 Nov 2024

    Improper access control in the installer for some Intel(R) Iris(R) Xe MAX Dedicated Graphics Drivers for Windows 10 before version 27.20.100.9466 may allow authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Nov 2021
    5.5
    Medium

    CVE-2021-33086

    Last Modified: 21 Nov 2024

    Out-of-bounds write in firmware for some Intel(R) NUCs may allow an authenticated user to potentially enable denial of service via local access.

    Published: 17 Nov 2021
    7.8
    High

    CVE-2021-33090

    Last Modified: 21 Nov 2024

    Incorrect default permissionsin the software installer for the Intel(R) NUC HDMI Firmware Update Tool for NUC10i3FN, NUC10i5FN, NUC10i7FN before version 1.78.2.0.7 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Nov 2021
    7.8
    High

    CVE-2021-33089

    Last Modified: 21 Nov 2024

    Improper access control in the software installer for the Intel(R) NUC HDMI Firmware Update Tool for NUC8i3BE, NUC8i5BE, NUC8i7BE before version 1.78.4.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Nov 2021
    7.8
    High

    CVE-2021-0096

    Last Modified: 21 Nov 2024

    Improper authentication in the software installer for the Intel(R) NUC HDMI Firmware Update Tool for NUC7i3DN, NUC7i5DN, NUC7i7DN before version 1.78.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Nov 2021
    5.5
    Medium

    CVE-2021-33087

    Last Modified: 21 Nov 2024

    Improper authentication in the installer for the Intel(R) NUC M15 Laptop Kit Management Engine driver pack before version 15.0.10.1508 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 17 Nov 2021
    7.8
    High

    CVE-2021-33095

    Last Modified: 21 Nov 2024

    Unquoted search path in the installer for the Intel(R) NUC M15 Laptop Kit Keyboard LED Service driver pack before version 1.0.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Nov 2021
    7.8
    High

    CVE-2021-33094

    Last Modified: 21 Nov 2024

    Insecure inherited permissions in the installer for the Intel(R) NUC M15 Laptop Kit Keyboard LED Service driver pack before version 1.0.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Nov 2021
    7.8
    High

    CVE-2021-33093

    Last Modified: 21 Nov 2024

    Insecure inherited permissions in the installer for the Intel(R) NUC M15 Laptop Kit Serial IO driver pack before version 30.100.2104.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Nov 2021
    7.8
    High

    CVE-2021-33092

    Last Modified: 21 Nov 2024

    Incorrect default permissions in the installer for the Intel(R) NUC M15 Laptop Kit HID Event Filter driver pack before version 2.2.1.383 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Nov 2021
    7.8
    High

    CVE-2021-33091

    Last Modified: 21 Nov 2024

    Insecure inherited permissions in the installer for the Intel(R) NUC M15 Laptop Kit audio driver pack before version 1.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Nov 2021
    7.8
    High

    CVE-2021-33088

    Last Modified: 21 Nov 2024

    Incorrect default permissions in the installer for the Intel(R) NUC M15 Laptop Kit Integrated Sensor Hub driver pack before version 5.4.1.4449 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Nov 2021
    7.8
    High

    CVE-2021-33106

    Last Modified: 21 Nov 2024

    Integer overflow in the Safestring library maintained by Intel(R) may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Nov 2021
    4.8
    Medium

    CVE-2021-42361

    Last Modified: 14 Feb 2025

    The Contact Form Email WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and escaping via the name parameter found in the ~/trunk/cp-admin-int-list.inc.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.3.24. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

    Published: 17 Nov 2021
    5.3
    Medium

    CVE-2021-43979

    Last Modified: 21 Nov 2024

    Styra Open Policy Agent (OPA) Gatekeeper through 3.7.0 mishandles concurrency, sometimes resulting in incorrect access control. The data replication mechanism allows policies to access the Kubernetes cluster state. During data replication, OPA/Gatekeeper does not wait for the replication to finish before processing a request, which might cause inconsistencies between the replicated resources in OPA/Gatekeeper and the resources actually present in the cluster. Inconsistency can later be reflected in a policy bypass. NOTE: the vendor disagrees that this is a vulnerability, because Kubernetes states are only eventually consistent

    Published: 17 Nov 2021
    3.1
    Low

    CVE-2021-43553

    Last Modified: 21 Nov 2024

    PI Vision could disclose information to a user with insufficient privileges for an AF attribute that is the child of another attribute and is configured as a Limits property.

    Published: 17 Nov 2021
    6.5
    Medium

    CVE-2021-43551

    Last Modified: 21 Nov 2024

    A remote attacker with write access to PI Vision could inject code into a display. Unauthorized information disclosure, modification, or deletion is possible if a victim views or interacts with the infected display using Microsoft Internet Explorer. The impact affects PI System data and other data accessible with victim's user permissions.

    Published: 17 Nov 2021
    7.2
    High

    CVE-2021-35528

    Last Modified: 21 Nov 2024

    Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Operations, Counterparty Settlement and Billing (CSB) allows an attacker to execute a modified signed Java Applet JAR file. A successful exploitation may lead to data extraction or modification of data inside the application. This issue affects: Hitachi Energy Retail Operations 5.7.3 and prior versions. Hitachi Energy Counterparty Settlement and Billing (CSB) 5.7.3 prior versions.

    Published: 17 Nov 2021
    7.6
    High

    CVE-2021-42360

    Last Modified: 14 Feb 2025

    On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability, which includes Contributor-level users, to import blocks onto any page using the astra-page-elementor-batch-process AJAX action. An attacker could craft and host a block containing malicious JavaScript on a server they controlled, and then use it to overwrite any post or page by sending an AJAX request with the action set to astra-page-elementor-batch-process and the url parameter pointed to their remotely-hosted malicious block, as well as an id parameter containing the post or page to overwrite. Any post or page that had been built with Elementor, including published pages, could be overwritten by the imported block, and the malicious JavaScript in the imported block would then be executed in the browser of any visitors to that page.

    Published: 17 Nov 2021
    8.8
    High

    CVE-2021-42362

    Last Modified: 21 Nov 2024

    The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can be used to obtain remote code execution, in versions up to and including 5.3.2.

    Published: 17 Nov 2021
    6.1
    Medium

    CVE-2021-43977

    Last Modified: 21 Nov 2024

    SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows XSS.

    Published: 17 Nov 2021
    9.8
    Critical

    CVE-2021-32234

    Last Modified: 21 Nov 2024

    SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows remote code execution.

    Published: 17 Nov 2021
    7.5
    High

    CVE-2021-40745

    Last Modified: 23 Apr 2025

    Adobe Campaign version 21.2.1 (and earlier) is affected by a Path Traversal vulnerability that could lead to reading arbitrary server files. By leveraging an exposed XML file, an unauthenticated attacker can enumerate other files on the server.

    Published: 17 Nov 2021
    6.5
    Medium

    CVE-2021-42250

    Last Modified: 21 Nov 2024

    Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs.

    Published: 17 Nov 2021
    5.5
    Medium

    CVE-2021-38959

    Last Modified: 21 Nov 2024

    IBM SPSS Statistics for Windows 24.0, 25.0, 26.0, 27.0, 27.0.1, and 28.0 could allow a local user to cause a denial of service by writing arbitrary files to admin protected directories on the system. IBM X-Force ID: 212046.

    Published: 17 Nov 2021
    6.2
    Medium

    CVE-2021-29861

    Last Modified: 21 Nov 2024

    IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in EFS to expose sensitive information. IBM X-Force ID: 206085.

    Published: 17 Nov 2021
    6.2
    Medium

    CVE-2021-29860

    Last Modified: 21 Nov 2024

    IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the libc.a library to expose sensitive information. IBM X-Force ID: 206084.

    Published: 17 Nov 2021
    3.3
    Low

    CVE-2021-3981

    Last Modified: 13 Feb 2025

    A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set allowing non privileged users to read its content. This represents a low severity confidentiality issue, as those users can eventually read any encrypted passwords present in grub.cfg. This flaw affects grub2 2.06 and previous versions. This issue has been fixed in grub upstream but no version with the fix is currently released.

    Published: 17 Nov 2021
    7.3
    High

    CVE-2021-42955

    Last Modified: 21 Nov 2024

    Zoho Remote Access Plus Server Windows Desktop binary fixed in version 10.1.2132 is affected by an unauthorized password reset vulnerability. Because of the designed password reset mechanism, any non-admin Windows user can reset the password of the Remote Access Plus Server Admin account.

    Published: 17 Nov 2021
    7.8
    High

    CVE-2021-42954

    Last Modified: 21 Nov 2024

    Zoho Remote Access Plus Server Windows Desktop Binary fixed from 10.1.2121.1 is affected by incorrect access control. The installation directory is vulnerable to weak file permissions by allowing full control for Windows Everyone user group (non-admin or any guest users), thereby allowing privilege escalation, unauthorized password reset, stealing of sensitive data, access to credentials in plaintext, access to registry values, tampering with configuration files, etc.

    Published: 17 Nov 2021
    7.8
    High

    CVE-2021-42956

    Last Modified: 21 Nov 2024

    Zoho Remote Access Plus Server Windows Desktop Binary fixed in 10.1.2132.6 is affected by a sensitive information disclosure vulnerability. Due to improper privilege management, the process launches as the logged in user, so memory dump can be done by non-admin also. Remotely, an attacker can dump all sensitive information including DB Connection string, entire IT infrastructure details, commands executed by IT admin including credentials, secrets, private keys and more.

    Published: 17 Nov 2021
    5
    Medium

    CVE-2021-32600

    Last Modified: 21 Nov 2024

    An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, 6.0.x and 5.6.x may allow a local and authenticated user assigned to a specific VDOM to retrieve other VDOMs information such as the admin account list and the network interface list.

    Published: 17 Nov 2021
    9.8
    Critical

    CVE-2021-41931

    Last Modified: 21 Nov 2024

    The Company's Recruitment Management System in id=2 of the parameter from view_vacancy app on-page appears to be vulnerable to SQL injection. The payloads 19424269' or '1309'='1309 and 39476597' or '2917'='2923 were each submitted in the id parameter. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

    Published: 17 Nov 2021
    4.8
    Medium

    CVE-2021-24856

    Last Modified: 21 Nov 2024

    The Shared Files WordPress plugin before 1.6.61 does not sanitise and escape the Download Counter Text settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 17 Nov 2021
    5.4
    Medium

    CVE-2021-24854

    Last Modified: 21 Nov 2024

    The QR Redirector WordPress plugin before 1.6.1 does not sanitise and escape some of the QR Redirect fields, which could allow users with a role as low as Contributor perform Stored Cross-Site Scripting attacks.

    Published: 17 Nov 2021
    4.3
    Medium

    CVE-2021-24853

    Last Modified: 21 Nov 2024

    The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector settings via the qr_save_bulk AJAX action, which could allow any authenticated user, such as subscriber to change the redirect response status code of arbitrary QR Redirects

    Published: 17 Nov 2021
    6.5
    Medium

    CVE-2021-24852

    Last Modified: 21 Nov 2024

    The MouseWheel Smooth Scroll WordPress plugin before 5.7 does not have CSRF check in place on its settings page, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 17 Nov 2021