CVE Feed

    Dashboard / CVE

    9.1
    Critical

    CVE-2021-22373

    Last Modified: 21 Nov 2024

    There is a Defects Introduced in the Design Process Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service integrity and availability.

    Published: 30 Jun 2021
    8.4
    High

    CVE-2021-22376

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to bypass user restrictions.

    Published: 30 Jun 2021
    7.5
    High

    CVE-2021-22372

    Last Modified: 21 Nov 2024

    There is a Security Features Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 30 Jun 2021
    7.5
    High

    CVE-2021-22370

    Last Modified: 21 Nov 2024

    There is a Credentials Management Errors Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 30 Jun 2021
    9.8
    Critical

    CVE-2021-22375

    Last Modified: 21 Nov 2024

    There is a Key Management Errors Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confidentiality,availability and integrity.

    Published: 30 Jun 2021
    7.1
    High

    CVE-2021-22326

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Privilege Dropping / Lowering Errors vulnerability. Local attackers may exploit this vulnerability to obtain Kernel space read/write capability.

    Published: 30 Jun 2021
    9.1
    Critical

    CVE-2021-22380

    Last Modified: 21 Nov 2024

    There is a Cleartext Transmission of Sensitive Information Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confidentiality and availability.

    Published: 30 Jun 2021
    5.5
    Medium

    CVE-2021-3630

    Last Modified: 21 Nov 2024

    An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText.cpp via a crafted djvu file which may lead to crash and segmentation fault. This flaw affects DjVuLibre versions prior to 3.5.28.

    Published: 30 Jun 2021
    6.5
    Medium

    CVE-2021-20461

    Last Modified: 21 Nov 2024

    IBM Cognos Analytics 10.0 and 11.1 is susceptible to a weakness in the implementation of the System Appearance configuration setting. An attacker could potentially bypass business logic to modify the appearance and behavior of the application. IBM X-Force ID: 196770.

    Published: 30 Jun 2021
    5.4
    Medium

    CVE-2021-20107

    Last Modified: 21 Nov 2024

    There exists an unauthenticated BLE Interface in Sloan SmartFaucets including Optima EAF, Optima ETF/EBF, BASYS EFX, and Flushometers including SOLIS. The vulnerability allows for unauthenticated kinetic effects and information disclosure on the faucets. It is possible to use the Bluetooth Low Energy (BLE) connectivity to read and write to many BLE characteristics on the device. Some of these control the flow of water, the sensitivity of the sensors, and information about maintenance.

    Published: 30 Jun 2021
    7.5
    High

    CVE-2021-28993

    Last Modified: 21 Nov 2024

    Plixer Scrutinizer 19.0.2 is affected by: SQL Injection. The impact is: obtain sensitive information (remote).

    Published: 30 Jun 2021
    9.8
    Critical

    CVE-2021-27903

    Last Modified: 21 Nov 2024

    An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's session).

    Published: 30 Jun 2021
    6.1
    Medium

    CVE-2021-27902

    Last Modified: 21 Nov 2024

    An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a potential XSS vulnerability existed in connection with front-end forms that accepted user uploads.

    Published: 30 Jun 2021
    5.4
    Medium

    CVE-2021-35956

    Last Modified: 21 Nov 2024

    Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote authenticated attackers to introduce arbitrary JavaScript via the Sensor Description, Email (from/to/cc), System Name, and System Location fields.

    Published: 30 Jun 2021
    7.5
    High

    CVE-2021-25951

    Last Modified: 21 Nov 2024

    XXE vulnerability in 'XML2Dict' version 0.2.2 allows an attacker to cause a denial of service.

    Published: 30 Jun 2021
    6.1
    Medium

    CVE-2021-31721

    Last Modified: 21 Nov 2024

    Chevereto before 3.17.1 allows Cross Site Scripting (XSS) via an image title at the image upload stage.

    Published: 30 Jun 2021
    9.8
    Critical

    CVE-2021-30648

    Last Modified: 21 Nov 2024

    The Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles are susceptible to an authentication bypass vulnerability. An unauthenticated attacker can execute arbitrary CLI commands, view/modify the appliance configuration and policy, and shutdown/restart the appliance.

    Published: 30 Jun 2021
    5.5
    Medium

    CVE-2021-28693

    Last Modified: 21 Nov 2024

    xen/arm: Boot modules are not scrubbed The bootloader will load boot modules (e.g. kernel, initramfs...) in a temporary area before they are copied by Xen to each domain memory. To ensure sensitive data is not leaked from the modules, Xen must "scrub" them before handing the page over to the allocator. Unfortunately, it was discovered that modules will not be scrubbed on Arm.

    Published: 30 Jun 2021
    7.1
    High

    CVE-2021-28692

    Last Modified: 21 Nov 2024

    inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such commands. In the current implementation in Xen, asynchronous notification of the completion of such commands is not used. Instead, the issuing CPU spin-waits for the completion of the most recently issued command(s). Some of these waiting loops try to apply a timeout to fail overly-slow commands. The course of action upon a perceived timeout actually being detected is inappropriate: - on Intel hardware guests which did not originally cause the timeout may be marked as crashed, - on AMD hardware higher layer callers would not be notified of the issue, making them continue as if the IOMMU operation succeeded.

    Published: 30 Jun 2021
    6.3
    Medium

    CVE-2021-34385

    Last Modified: 21 Nov 2024

    Trusty TLK contains a vulnerability in the NVIDIA TLK kernel where an integer overflow in the calculation of a length could lead to a heap overflow.

    Published: 30 Jun 2021
    6.3
    Medium

    CVE-2021-34384

    Last Modified: 21 Nov 2024

    Bootloader contains a vulnerability in NVIDIA MB2 where a potential heap overflow could cause memory corruption, which might lead to denial of service or code execution.

    Published: 30 Jun 2021
    6.4
    Medium

    CVE-2021-34383

    Last Modified: 21 Nov 2024

    Bootloader contains a vulnerability in NVIDIA MB2 where a potential heap overflow might lead to denial of service or escalation of privileges.

    Published: 30 Jun 2021
    6.7
    Medium

    CVE-2021-34382

    Last Modified: 21 Nov 2024

    Trusty TLK contains a vulnerability in the NVIDIA TLK kernel’s tz_map_shared_mem function where an integer overflow on the size parameter causes the request buffer and the logging buffer to overflow, allowing writes to arbitrary addresses within the kernel.

    Published: 30 Jun 2021
    7
    High

    CVE-2021-34380

    Last Modified: 21 Nov 2024

    Bootloader contains a vulnerability in NVIDIA MB2 where potential heap overflow might cause corruption of the heap metadata, which might lead to arbitrary code execution, denial of service, and information disclosure during secure boot.

    Published: 30 Jun 2021
    6.7
    Medium

    CVE-2021-34381

    Last Modified: 21 Nov 2024

    Trusty TLK contains a vulnerability in the NVIDIA TLK kernel function where a lack of checks allows the exploitation of an integer overflow on the size parameter of the tz_map_shared_mem function, which might lead to denial of service, information disclosure, or data tampering.

    Published: 30 Jun 2021
    7.7
    High

    CVE-2021-34379

    Last Modified: 21 Nov 2024

    Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 10 is missing. The length of an I/O buffer parameter is not checked, which might lead to memory corruption.

    Published: 30 Jun 2021
    7.7
    High

    CVE-2021-34378

    Last Modified: 21 Nov 2024

    Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 11 is missing. Improper restriction of operations within the bounds of a memory buffer might lead to information disclosure, denial of service, or escalation of privileges.

    Published: 30 Jun 2021
    7.7
    High

    CVE-2021-34377

    Last Modified: 21 Nov 2024

    Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 9 is missing. Improper restriction of operations within the bounds of a memory buffer might lead to escalation of privileges, information disclosure, and denial of service.

    Published: 30 Jun 2021
    7.7
    High

    CVE-2021-34376

    Last Modified: 21 Nov 2024

    Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 5 is missing. Improper restriction of operations within the bounds of a memory buffer might lead to denial of service, escalation of privileges, and information disclosure.

    Published: 30 Jun 2021
    7.7
    High

    CVE-2021-34375

    Last Modified: 21 Nov 2024

    Trusty contains a vulnerability in all trusted applications (TAs) where the stack cookie was not randomized, which might result in stack-based buffer overflow, leading to denial of service, escalation of privileges, and information disclosure.

    Published: 30 Jun 2021
    7.7
    High

    CVE-2021-34374

    Last Modified: 21 Nov 2024

    Trusty contains a vulnerability in command handlers where the length of input buffers is not verified. This vulnerability can cause memory corruption, which may lead to information disclosure, escalation of privileges, and denial of service.

    Published: 30 Jun 2021
    7.9
    High

    CVE-2021-34373

    Last Modified: 21 Nov 2024

    Trusty trusted Linux kernel (TLK) contains a vulnerability in the NVIDIA TLK kernel where a lack of heap hardening could cause heap overflows, which might lead to information disclosure and denial of service.

    Published: 30 Jun 2021
    9.8
    Critical

    CVE-2019-18906

    Last Modified: 21 Nov 2024

    A Improper Authentication vulnerability in cryptctl of SUSE Linux Enterprise Server for SAP 12-SP5, SUSE Manager Server 4.0 allows attackers with access to the hashed password to use it without having to crack it. This issue affects: SUSE Linux Enterprise Server for SAP 12-SP5 cryptctl versions prior to 2.4. SUSE Manager Server 4.0 cryptctl versions prior to 2.4.

    Published: 30 Jun 2021
    9.8
    Critical

    CVE-2021-35474

    Last Modified: 21 Nov 2024

    Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

    Published: 30 Jun 2021
    7.5
    High

    CVE-2021-32567

    Last Modified: 21 Nov 2024

    Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

    Published: 30 Jun 2021
    7.5
    High

    CVE-2021-32566

    Last Modified: 21 Nov 2024

    Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

    Published: 30 Jun 2021
    5.4
    Medium

    CVE-2021-35959

    Last Modified: 21 Nov 2024

    In Plone 5.0 through 5.2.4, Editors are vulnerable to XSS in the folder contents view, if a Contributor has created a folder with a SCRIPT tag in the description field.

    Published: 30 Jun 2021
    9.1
    Critical

    CVE-2021-35958

    Last Modified: 21 Nov 2024

    TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_file is used with extract=True. NOTE: the vendor's position is that tf.keras.utils.get_file is not intended for untrusted archives

    Published: 30 Jun 2021
    9.1
    Critical

    CVE-2021-35942

    Last Modified: 13 Feb 2026

    The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have been used to ensure correct calculations.

    Published: 30 Jun 2021
    4.3
    Medium

    CVE-2021-21670

    Last Modified: 21 Nov 2024

    Jenkins 2.299 and earlier, LTS 2.289.1 and earlier allows users to cancel queue items and abort builds of jobs for which they have Item/Cancel permission even when they do not have Item/Read permission.

    Published: 30 Jun 2021
    6.7
    Medium

    CVE-2021-35939

    Last Modified: 21 Nov 2024

    It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 30 Jun 2021
    7.5
    High

    CVE-2022-27384

    Last Modified: 21 Nov 2024

    An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

    Published: 30 Jun 2021
    7.5
    High

    CVE-2022-32083

    Last Modified: 21 Nov 2024

    MariaDB v10.2 to v10.6.1 was discovered to contain a segmentation fault via the component Item_subselect::init_expr_cache_tracker.

    Published: 30 Jun 2021
    6.4
    Medium

    CVE-2021-35937

    Last Modified: 21 Nov 2024

    A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 30 Jun 2021
    6.7
    Medium

    CVE-2021-35938

    Last Modified: 21 Nov 2024

    A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 30 Jun 2021
    5.3
    Medium

    CVE-2021-3642

    Last Modified: 21 Nov 2024

    A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.

    Published: 30 Jun 2021
    7.5
    High

    CVE-2021-21671

    Last Modified: 21 Nov 2024

    Jenkins 2.299 and earlier, LTS 2.289.1 and earlier does not invalidate the previous session on login.

    Published: 30 Jun 2021
    7.5
    High

    CVE-2021-35941

    Last Modified: 21 Nov 2024

    Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory restore without authentication, as exploited in the wild in June 2021, a different vulnerability than CVE-2018-18472.

    Published: 29 Jun 2021
    4.9
    Medium

    CVE-2021-22341

    Last Modified: 21 Nov 2024

    There is a memory leak vulnerability in Huawei products. A resource management weakness exists in a module. Attackers with high privilege can exploit this vulnerability by performing some operations. This can lead to memory leak. Affected product versions include:IPS Module V500R005C00SPC100,V500R005C00SPC200;NGFW Module V500R005C00SPC100,V500R005C00SPC200;NIP6300 V500R005C00SPC100,V500R005C10SPC200;NIP6600 V500R005C00SPC100,V500R005C00SPC200;Secospace USG6300 V500R005C00SPC100,V500R005C00SPC200;Secospace USG6500 V500R005C00SPC100,V500R005C10SPC200;Secospace USG6600 V500R005C00SPC100,V500R005C00SPC200.

    Published: 29 Jun 2021
    4.9
    Medium

    CVE-2021-22329

    Last Modified: 21 Nov 2024

    There has a license management vulnerability in some Huawei products. An attacker with high privilege needs to perform specific operations to exploit the vulnerability on the affected device. Due to improper license management of the device, as a result, the license file can be applied and affect integrity of the device. Affected product versions include:S12700 V200R007C01,V200R007C01B102,V200R008C00,V200R010C00SPC300,V200R011C00,V200R011C00SPC100,V200R011C10;S1700 V200R010C00SPC300,V200R011C00,V200R011C00SPC100,V200R011C10;S2700 V200R008C00,V200R010C00SPC300,V200R011C00,V200R011C00SPC100,V200R011C10;S5700 V200R008C00,V200R010C00SPC300,V200R011C00,V200R011C00SPC100,V200R011C10,V200R011C10SPC100;S6700 V200R008C00,V200R010C00SPC300,V200R011C00,V200R011C00SPC100,V200R011C10,V200R011C10SPC100;S7700 V200R008C00,V200R010C00SPC300,V200R011C00,V200R011C00SPC100,V200R011C10;S9700 V200R007C01,V200R007C01B102,V200R008C00,V200R010C00SPC300,V200R011C00,V200R011C00SPC100,V200R011C10.

    Published: 29 Jun 2021