CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2020-23323

    Last Modified: 21 Nov 2024

    There is a heap-buffer-overflow at re-parser.c in re_parse_char_escape in JerryScript 2.2.0.

    Published: 10 Jun 2021
    7.5
    High

    CVE-2020-23322

    Last Modified: 21 Nov 2024

    There is an Assertion in 'context_p->token.type == LEXER_RIGHT_BRACE || context_p->token.type == LEXER_ASSIGN || context_p->token.type == LEXER_COMMA' in parser_parse_object_initializer in JerryScript 2.2.0.

    Published: 10 Jun 2021
    9.8
    Critical

    CVE-2020-23321

    Last Modified: 21 Nov 2024

    There is a heap-buffer-overflow at lit-strings.c:431 in lit_read_code_unit_from_utf8 in JerryScript 2.2.0.

    Published: 10 Jun 2021
    7.5
    High

    CVE-2020-23320

    Last Modified: 21 Nov 2024

    There is an Assertion in 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' in parser_parse_function_arguments in JerryScript 2.2.0.

    Published: 10 Jun 2021
    7.5
    High

    CVE-2020-23319

    Last Modified: 21 Nov 2024

    There is an Assertion in '(flags >> CBC_STACK_ADJUST_SHIFT) >= CBC_STACK_ADJUST_BASE || (CBC_STACK_ADJUST_BASE - (flags >> CBC_STACK_ADJUST_SHIFT)) <= context_p->stack_depth' in parser_emit_cbc_backward_branch in JerryScript 2.2.0.

    Published: 10 Jun 2021
    7.5
    High

    CVE-2020-23314

    Last Modified: 21 Nov 2024

    There is an Assertion 'block_found' failed at js-parser-statm.c:2003 parser_parse_try_statement_end in JerryScript 2.2.0.

    Published: 10 Jun 2021
    7.5
    High

    CVE-2020-23313

    Last Modified: 21 Nov 2024

    There is an Assertion 'scope_stack_p > context_p->scope_stack_p' failed at js-scanner-util.c:2510 in scanner_literal_is_created in JerryScript 2.2.0

    Published: 10 Jun 2021
    7.5
    High

    CVE-2020-23312

    Last Modified: 21 Nov 2024

    There is an Assertion 'context.status_flags & PARSER_SCANNING_SUCCESSFUL' failed at js-parser.c:2185 in parser_parse_source in JerryScript 2.2.0.

    Published: 10 Jun 2021
    7.5
    High

    CVE-2020-23311

    Last Modified: 21 Nov 2024

    There is an Assertion 'context_p->token.type == LEXER_RIGHT_BRACE || context_p->token.type == LEXER_ASSIGN || context_p->token.type == LEXER_COMMA' failed at js-parser-expr.c:3230 in parser_parse_object_initializer in JerryScript 2.2.0.

    Published: 10 Jun 2021
    7.5
    High

    CVE-2020-23310

    Last Modified: 21 Nov 2024

    There is an Assertion 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' failed at js-parser-statm.c:733 in parser_parse_function_statement in JerryScript 2.2.0.

    Published: 10 Jun 2021
    7.5
    High

    CVE-2020-23309

    Last Modified: 21 Nov 2024

    There is an Assertion 'context_p->stack_depth == context_p->context_stack_depth' failed at js-parser-statm.c:2756 in parser_parse_statements in JerryScript 2.2.0.

    Published: 10 Jun 2021
    7.5
    High

    CVE-2020-23308

    Last Modified: 21 Nov 2024

    There is an Assertion 'context_p->stack_top_uint8 == LEXER_EXPRESSION_START' at js-parser-expr.c:3565 in parser_parse_expression in JerryScript 2.2.0.

    Published: 10 Jun 2021
    9.8
    Critical

    CVE-2020-23306

    Last Modified: 21 Nov 2024

    There is a stack-overflow at ecma-regexp-object.c:535 in ecma_regexp_match in JerryScript 2.2.0.

    Published: 10 Jun 2021
    9.8
    Critical

    CVE-2020-23303

    Last Modified: 21 Nov 2024

    There is a heap-buffer-overflow at jmem-poolman.c:165 in jmem_pools_collect_empty in JerryScript 2.2.0.

    Published: 10 Jun 2021
    9.8
    Critical

    CVE-2020-23302

    Last Modified: 21 Nov 2024

    There is a heap-use-after-free at ecma-helpers-string.c:772 in ecma_ref_ecma_string in JerryScript 2.2.0

    Published: 10 Jun 2021
    7.3
    High

    CVE-2021-31840

    Last Modified: 21 Nov 2024

    A vulnerability in the preloading mechanism of specific dynamic link libraries in McAfee Agent for Windows prior to 5.7.3 could allow an authenticated, local attacker to perform a DLL preloading attack with unsigned DLLs. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. This would result in the user gaining elevated permissions and being able to execute arbitrary code.

    Published: 10 Jun 2021
    4.8
    Medium

    CVE-2021-31839

    Last Modified: 21 Nov 2024

    Improper privilege management vulnerability in McAfee Agent for Windows prior to 5.7.3 allows a local user to modify event information in the MA event folder. This allows a local user to either add false events or remove events from the event logs prior to them being sent to the ePO server.

    Published: 10 Jun 2021
    4.6
    Medium

    CVE-2021-34557

    Last Modified: 21 Nov 2024

    XScreenSaver 5.45 can be bypassed if the machine has more than ten disconnectable video outputs. A buffer overflow in update_screen_layout() allows an attacker to bypass the standard screen lock authentication mechanism by crashing XScreenSaver. The attacker must physically disconnect many video outputs.

    Published: 10 Jun 2021
    5.5
    Medium

    CVE-2021-27345

    Last Modified: 21 Nov 2024

    A null pointer dereference was discovered in ucompthread in stream.c in Irzip 0.631 which allows attackers to cause a denial of service (DOS) via a crafted compressed file.

    Published: 10 Jun 2021
    5.5
    Medium

    CVE-2020-25467

    Last Modified: 21 Nov 2024

    A null pointer dereference was discovered lzo_decompress_buf in stream.c in Irzip 0.621 which allows an attacker to cause a denial of service (DOS) via a crafted compressed file.

    Published: 10 Jun 2021
    5.5
    Medium

    CVE-2021-27347

    Last Modified: 21 Nov 2024

    Use after free in lzma_decompress_buf function in stream.c in Irzip 0.631 allows attackers to cause Denial of Service (DoS) via a crafted compressed file.

    Published: 10 Jun 2021
    3.1
    Low

    CVE-2021-33031

    Last Modified: 21 Nov 2024

    In LabCup before <v2_next_18022, it is possible to use the save API to perform unauthorized actions for users without access to user management in order to, after successful exploitation, gain access to a victim's account. A user without the user-management privilege can change another user's email address if the attacker knows details of the victim such as the exact roles and group roles, ID, and remote authentication ID settings. These must be sent in a modified save API request. It was fixed in 6.3.0.03.

    Published: 10 Jun 2021
    8.8
    High

    CVE-2020-24667

    Last Modified: 21 Nov 2024

    Trace Financial CRESTBridge <6.3.0.02 contains an authenticated SQL injection vulnerability, which was fixed in 6.3.0.03.

    Published: 10 Jun 2021
    8.8
    High

    CVE-2020-24671

    Last Modified: 21 Nov 2024

    Trace Financial CRESTBridge <6.3.0.02 contains an authenticated SQL injection vulnerability, which was fixed in 6.3.0.03.

    Published: 10 Jun 2021
    5.4
    Medium

    CVE-2020-24663

    Last Modified: 21 Nov 2024

    Trace Financial CRESTBridge <6.3.0.02 contains a stored XSS vulnerability, which was fixed in 6.3.0.03.

    Published: 10 Jun 2021
    5.4
    Medium

    CVE-2020-24668

    Last Modified: 21 Nov 2024

    Trace Financial Crest Bridge <6.3.0.02 contains a stored XSS vulnerability, which was fixed in 6.3.0.03.

    Published: 10 Jun 2021
    7.8
    High

    CVE-2021-23022

    Last Modified: 21 Nov 2024

    On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, the BIG-IP Edge Client Windows Installer Service's temporary folder has weak file and folder permissions. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 10 Jun 2021
    6.8
    Medium

    CVE-2021-34546

    Last Modified: 21 Nov 2024

    An unauthenticated attacker with physical access to a computer with NetSetMan Pro before 5.0 installed, that has the pre-logon profile switch button within the Windows logon screen enabled, is able to drop to an administrative shell and execute arbitrary commands as SYSTEM via the "save log to file" feature. To accomplish this, the attacker can navigate to cmd.exe.

    Published: 10 Jun 2021
    7.5
    High

    CVE-2021-31538

    Last Modified: 21 Nov 2024

    LANCOM R&S Unified Firewall (UF) devices running LCOS FX 10.5 allow Relative Path Traversal.

    Published: 10 Jun 2021
    4.3
    Medium

    CVE-2021-31927

    Last Modified: 21 Nov 2024

    An Insecure Direct Object Reference (IDOR) vulnerability in Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify any existing user, including users assigned to different environments and clients. It was fixed in v2021.1.0.2.

    Published: 10 Jun 2021
    7.5
    High

    CVE-2021-34555

    Last Modified: 21 Nov 2024

    OpenDMARC 1.4.1 and 1.4.1.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a multi-value From header field.

    Published: 10 Jun 2021
    7.8
    High

    CVE-2021-23023

    Last Modified: 21 Nov 2024

    On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, a DLL hijacking issue exists in cachecleaner.dll included in the BIG-IP Edge Client Windows Installer. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 10 Jun 2021
    7.2
    High

    CVE-2021-23024

    Last Modified: 21 Nov 2024

    On version 8.0.x before 8.0.0.1, and all 6.x and 7.x versions, the BIG-IQ Configuration utility has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 10 Jun 2021
    8.8
    High

    CVE-2021-31659

    Last Modified: 21 Nov 2024

    TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is vulnerable to Cross Site Request Forgery (CSRF). All configuration information is placed in the URL, without any additional token authentication information. A malicious link opened by the switch administrator may cause the password of the switch to be modified and the configuration file to be tampered with.

    Published: 10 Jun 2021
    8.8
    High

    CVE-2021-21665

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing Username/password credentials stored in Jenkins.

    Published: 10 Jun 2021
    6.1
    Medium

    CVE-2021-21666

    Last Modified: 21 Nov 2024

    Jenkins Kiuwan Plugin 1.6.0 and earlier does not escape query parameters in an error message for a form validation endpoint, resulting in a reflected cross-site scripting (XSS) vulnerability.

    Published: 10 Jun 2021
    4.3
    Medium

    CVE-2021-21663

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins XebiaLabs XL Deploy Plugin 7.5.8 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing Username/password credentials stored in Jenkins.

    Published: 10 Jun 2021
    6.5
    Medium

    CVE-2021-21664

    Last Modified: 21 Nov 2024

    An incorrect permission check in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers with Generic Create permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing Username/password credentials stored in Jenkins.

    Published: 10 Jun 2021
    4.3
    Medium

    CVE-2021-21662

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins.

    Published: 10 Jun 2021
    4.3
    Medium

    CVE-2021-21661

    Last Modified: 21 Nov 2024

    Jenkins Kubernetes CLI Plugin 1.10.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

    Published: 10 Jun 2021
    8.1
    High

    CVE-2021-31658

    Last Modified: 21 Nov 2024

    TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is affected by an Array index error. The interface that provides the "device description" function only judges the length of the received data, and does not filter special characters. This vulnerability will cause the application to crash, and all device configuration information will be erased.

    Published: 10 Jun 2021
    5.4
    Medium

    CVE-2020-24662

    Last Modified: 21 Nov 2024

    SmartStream Transaction Lifecycle Management (TLM) Reconciliation Premium (RP) <3.1.0 allows XSS. This was fixed in TLM RP 3.1.0.

    Published: 10 Jun 2021
    8.8
    High

    CVE-2021-31928

    Last Modified: 21 Nov 2024

    Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to escalate privileges to superadministrator. It was fixed in v2021.1.0.2.

    Published: 10 Jun 2021
    4.3
    Medium

    CVE-2021-34547

    Last Modified: 21 Nov 2024

    PRTG Network Monitor 20.1.55.1775 allows /editsettings CSRF for user account creation.

    Published: 10 Jun 2021
    4.3
    Medium

    CVE-2021-31929

    Last Modified: 21 Nov 2024

    Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify loyalty campaigns and settings, such as fraud prevention, coupon groups, email templates, or referrals.

    Published: 10 Jun 2021
    7.8
    High

    CVE-2021-3041

    Last Modified: 21 Nov 2024

    A local privilege escalation vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables an authenticated local Windows user to execute programs with SYSTEM privileges. This requires the user to have the privilege to create files in the Windows root directory or to manipulate key registry values. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.11; Cortex XDR agent 6.1 versions earlier than Cortex XDR agent 6.1.8; Cortex XDR agent 7.2 versions earlier than Cortex XDR agent 7.2.3; All versions of Cortex XDR agent 7.2 without content update release 171 or a later version.

    Published: 10 Jun 2021
    6.7
    Medium

    CVE-2021-3040

    Last Modified: 21 Nov 2024

    An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.139. Checkov 1.0 versions are not impacted.

    Published: 10 Jun 2021
    3.8
    Low

    CVE-2021-3039

    Last Modified: 21 Nov 2024

    An information exposure through log file vulnerability exists in the Palo Alto Networks Prisma Cloud Compute Console where a secret used to authorize the role of the authenticated user is logged to a debug log file. Authenticated Operator role and Auditor role users with access to the debug log files can use this secret to gain Administrator role access for their active session in Prisma Cloud Compute. Prisma Cloud Compute SaaS versions were automatically upgraded to the fixed release. This issue impacts all Prisma Cloud Compute versions earlier than Prisma Cloud Compute 21.04.412.

    Published: 10 Jun 2021
    9.8
    Critical

    CVE-2021-25948

    Last Modified: 21 Nov 2024

    Prototype pollution vulnerability in 'expand-hash' versions 0.1.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.

    Published: 10 Jun 2021
    6.8
    Medium

    CVE-2021-25322

    Last Modified: 21 Nov 2024

    A UNIX Symbolic Link (Symlink) Following vulnerability in python-HyperKitty of openSUSE Leap 15.2, Factory allows local attackers to escalate privileges from the user hyperkitty or hyperkitty-admin to root. This issue affects: openSUSE Leap 15.2 python-HyperKitty version 1.3.2-lp152.2.3.1 and prior versions. openSUSE Factory python-HyperKitty versions prior to 1.3.4-5.1.

    Published: 10 Jun 2021