CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2019-25046

    Last Modified: 21 Nov 2024

    The Web Client in Cerberus FTP Server Enterprise before 10.0.19 and 11.x before 11.0.4 allows XSS via an SVG document.

    Published: 10 Jun 2021
    6.8
    Medium

    CVE-2021-31997

    Last Modified: 21 Nov 2024

    A UNIX Symbolic Link (Symlink) Following vulnerability in python-postorius of openSUSE Leap 15.2, Factory allows local attackers to escalate from users postorius or postorius-admin to root. This issue affects: openSUSE Leap 15.2 python-postorius version 1.3.2-lp152.1.2 and prior versions. openSUSE Factory python-postorius version 1.3.4-2.1 and prior versions.

    Published: 10 Jun 2021
    7.2
    High

    CVE-2021-21736

    Last Modified: 21 Nov 2024

    A smart camera product of ZTE is impacted by a permission and access control vulnerability. Due to the defect of user permission management by the cloud-end app, users whose sharing permissions have been revoked can still control the camera, such as restarting the camera, restoring factory settings, etc.. This affects ZXHN HS562 V1.0.0.0B2.0000, V1.0.0.0B3.0000E

    Published: 10 Jun 2021
    6.8
    Medium

    CVE-2021-31998

    Last Modified: 21 Nov 2024

    A Incorrect Default Permissions vulnerability in the packaging of inn of SUSE Linux Enterprise Server 11-SP3; openSUSE Backports SLE-15-SP2, openSUSE Leap 15.2 allows local attackers to escalate their privileges from the news user to root. This issue affects: SUSE Linux Enterprise Server 11-SP3 inn version inn-2.4.2-170.21.3.1 and prior versions. openSUSE Backports SLE-15-SP2 inn versions prior to 2.6.2. openSUSE Leap 15.2 inn versions prior to 2.6.2.

    Published: 10 Jun 2021
    6.5
    Medium

    CVE-2021-21735

    Last Modified: 26 May 2026

    A ZTE product has an information leak vulnerability. Due to improper permission settings, an attacker with ordinary user permissions could exploit this vulnerability to obtain some sensitive user information through the wizard page without authentication. This affects ZXHN H168N all versions up to V3.5.0_EG1T4_TE.

    Published: 10 Jun 2021
    7.2
    High

    CVE-2021-20081

    Last Modified: 21 Nov 2024

    Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticated attacker to execute arbitrary commands with SYSTEM privileges.

    Published: 10 Jun 2021
    7.2
    High

    CVE-2021-34539

    Last Modified: 21 Nov 2024

    An issue was discovered in CubeCoders AMP before 2.1.1.8. A lack of validation of the Java Version setting means that an unintended executable path can be set. The result is that high-privileged users can trigger code execution.

    Published: 10 Jun 2021
    9.1
    Critical

    CVE-2021-34363

    Last Modified: 21 Nov 2024

    The thefuck (aka The Fuck) package before 3.31 for Python allows Path Traversal that leads to arbitrary file deletion via the "undo archive operation" feature.

    Published: 10 Jun 2021
    9.8
    Critical

    CVE-2021-25949

    Last Modified: 21 Nov 2024

    Prototype pollution vulnerability in 'set-getter' version 0.1.0 allows an attacker to cause a denial of service and may lead to remote code execution.

    Published: 10 Jun 2021
    —
    Unknown

    CVE-2021-34603

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 10 Jun 2021
    9.8
    Critical

    CVE-2021-3586

    Last Modified: 21 Nov 2024

    A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify which ports may be accessed, allowing access to all ports on these resources from any pod. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 10 Jun 2021
    —
    Unknown

    CVE-2021-34607

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 10 Jun 2021
    —
    Unknown

    CVE-2021-34608

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 10 Jun 2021
    8.8
    High

    CVE-2021-33393

    Last Modified: 21 Nov 2024

    lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account. It might be owned by an unprivileged account, which could potentially be used to install a Trojan horse backup.pl script that is later executed by root. Similar problems with the ownership/permissions of other files may be present as well.

    Published: 9 Jun 2021
    7.8
    High

    CVE-2021-0104

    Last Modified: 21 Nov 2024

    Uncontrolled search path element in the installer for the Intel(R) Rapid Storage Technology software, before versions 17.9.0.34, 18.0.0.640 and 18.1.0.24, may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 9 Jun 2021
    7.8
    High

    CVE-2021-0106

    Last Modified: 21 Nov 2024

    Incorrect default permissions in the Intel(R) Optane(TM) DC Persistent Memory for Windows software versions before 2.00.00.3842 or 1.00.00.3515 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 9 Jun 2021
    7.8
    High

    CVE-2021-0100

    Last Modified: 21 Nov 2024

    Incorrect default permissions in the installer for the Intel(R) SSD Data Center Tool, versions downloaded before 12/31/2020, may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 9 Jun 2021
    7.8
    High

    CVE-2021-0052

    Last Modified: 21 Nov 2024

    Incorrect default privileges in the Intel(R) Computing Improvement Program before version 2.4.6522 may allow an authenticated user to potentially enable an escalation of privilege via local access.

    Published: 9 Jun 2021
    7.8
    High

    CVE-2021-0074

    Last Modified: 21 Nov 2024

    Improper permissions in the installer for the Intel(R) Computing Improvement Program software before version 2.4.5982 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 9 Jun 2021
    4.9
    Medium

    CVE-2021-0134

    Last Modified: 21 Nov 2024

    Improper input validation in an API for the Intel(R) Security Library before version 3.3 may allow a privileged user to potentially enable denial of service via network access.

    Published: 9 Jun 2021
    6.5
    Medium

    CVE-2021-0131

    Last Modified: 21 Nov 2024

    Use of cryptographically weak pseudo-random number generator (PRNG) in an API for the Intel(R) Security Library before version 3.3 may allow an authenticated user to potentially enable information disclosure via network access.

    Published: 9 Jun 2021
    4.9
    Medium

    CVE-2021-0132

    Last Modified: 21 Nov 2024

    Missing release of resource after effective lifetime in an API for the Intel(R) Security Library before version 3.3 may allow a privileged user to potentially enable denial of service via network access.

    Published: 9 Jun 2021
    8.1
    High

    CVE-2021-0133

    Last Modified: 21 Nov 2024

    Key exchange without entity authentication in the Intel(R) Security Library before version 3.3 may allow an authenticated user to potentially enable escalation of privilege via network access.

    Published: 9 Jun 2021
    7.8
    High

    CVE-2021-0077

    Last Modified: 21 Nov 2024

    Insecure inherited permissions in the installer for the Intel(R) VTune(TM) Profiler before version 2021.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 9 Jun 2021
    6.5
    Medium

    CVE-2021-0089

    Last Modified: 21 Nov 2024

    Observable response discrepancy in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

    Published: 9 Jun 2021
    6.5
    Medium

    CVE-2021-0086

    Last Modified: 21 Nov 2024

    Observable response discrepancy in floating-point operations for some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

    Published: 9 Jun 2021
    6.7
    Medium

    CVE-2021-0054

    Last Modified: 21 Nov 2024

    Improper buffer restrictions in system firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 9 Jun 2021
    6.7
    Medium

    CVE-2021-0067

    Last Modified: 21 Nov 2024

     Improper access control in system firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 9 Jun 2021
    7.3
    High

    CVE-2021-0090

    Last Modified: 21 Nov 2024

    Uncontrolled search path element in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to potentially enable an escalation of privilege via local access.

    Published: 9 Jun 2021
    7.8
    High

    CVE-2021-0073

    Last Modified: 21 Nov 2024

    Insufficient control flow management in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 9 Jun 2021
    7.8
    High

    CVE-2021-0094

    Last Modified: 21 Nov 2024

    Improper link resolution before file access in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to potentially enable an escalation of privilege via local access.

    Published: 9 Jun 2021
    7.8
    High

    CVE-2021-0058

    Last Modified: 21 Nov 2024

    Incorrect default permissions in the Intel(R) NUC M15 Laptop Kit Driver Pack software before updated version 1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 9 Jun 2021
    7.8
    High

    CVE-2021-0057

    Last Modified: 21 Nov 2024

    Uncontrolled search path in the Intel(R) NUC M15 Laptop Kit Driver Pack software before updated version 1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 9 Jun 2021
    7.8
    High

    CVE-2021-0056

    Last Modified: 21 Nov 2024

    Insecure inherited permissions for the Intel(R) NUC M15 Laptop Kit Driver Pack software before updated version 1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 9 Jun 2021
    7.8
    High

    CVE-2021-0102

    Last Modified: 21 Nov 2024

    Insecure inherited permissions in the Intel Unite(R) Client for Windows before version 4.2.25031 may allow an authenticated user to potentially enable an escalation of privilege via local access.

    Published: 9 Jun 2021
    7.3
    High

    CVE-2021-0108

    Last Modified: 21 Nov 2024

    Uncontrolled search path in the Intel Unite(R) Client for Windows before version 4.2.25031 may allow an authenticated user to potentially enable an escalation of privilege via local access.

    Published: 9 Jun 2021
    7.8
    High

    CVE-2021-0098

    Last Modified: 21 Nov 2024

    Improper access control in the Intel Unite(R) Client for Windows before version 4.2.25031 may allow an authenticated user to potentially enable an escalation of privilege via local access.

    Published: 9 Jun 2021
    7.3
    High

    CVE-2021-0112

    Last Modified: 21 Nov 2024

    Unquoted service path in the Intel Unite(R) Client for Windows before version 4.2.25031 may allow an authenticated user to potentially enable an escalation of privilege via local access.

    Published: 9 Jun 2021
    7.8
    High

    CVE-2021-0055

    Last Modified: 21 Nov 2024

    Insecure inherited permissions for some Intel(R) NUC 9 Extreme Laptop Kit LAN Drivers before version 10.42 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 9 Jun 2021
    4.4
    Medium

    CVE-2021-0051

    Last Modified: 21 Nov 2024

    Improper input validation in the Intel(R) SPS versions before SPS_E5_04.04.04.023.0, SPS_E5_04.04.03.228.0 or SPS_SoC-A_05.00.03.098.0 may allow a privileged user to potentially enable denial of service via local access.

    Published: 9 Jun 2021
    4.7
    Medium

    CVE-2021-0001

    Last Modified: 21 Nov 2024

    Observable timing discrepancy in Intel(R) IPP before version 2020 update 1 may allow authorized user to potentially enable information disclosure via local access.

    Published: 9 Jun 2021
    5.5
    Medium

    CVE-2020-24475

    Last Modified: 21 Nov 2024

    Improper initialization in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.48.ce3e3bd2 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 9 Jun 2021
    7.8
    High

    CVE-2020-24473

    Last Modified: 21 Nov 2024

    Out of bounds write in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.48.ce3e3bd2 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 9 Jun 2021
    8
    High

    CVE-2020-24474

    Last Modified: 21 Nov 2024

    Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.48.ce3e3bd2 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

    Published: 9 Jun 2021
    6.5
    Medium

    CVE-2021-0097

    Last Modified: 21 Nov 2024

    Path traversal in the BMC firmware for Intel(R) Server Board M10JNP2SB before version EFI BIOS 7215, BMC 8100.01.08 may allow an unauthenticated user to potentially enable a denial of service via adjacent access.

    Published: 9 Jun 2021
    6.5
    Medium

    CVE-2021-0113

    Last Modified: 21 Nov 2024

    Out of bounds write in the BMC firmware for Intel(R) Server Board M10JNP2SB before version EFI BIOS 7215, BMC 8100.01.08 may allow an unauthenticated user to potentially enable a denial of service via adjacent access.

    Published: 9 Jun 2021
    8.8
    High

    CVE-2021-0070

    Last Modified: 21 Nov 2024

    Improper input validation in the BMC firmware for Intel(R) Server Board M10JNP2SB before version EFI BIOS 7215, BMC 8100.01.08 may allow an unauthenticated user to potentially enable an escalation of privilege via adjacent access.

    Published: 9 Jun 2021
    8.8
    High

    CVE-2021-0101

    Last Modified: 21 Nov 2024

    Buffer overflow in the BMC firmware for Intel(R) Server BoardM10JNP2SB before version EFI BIOS 7215, BMC 8100.01.08 may allow an unauthenticated user to potentially enable an escalation of privilege via adjacent access.

    Published: 9 Jun 2021
    7.3
    High

    CVE-2021-0105

    Last Modified: 21 Nov 2024

    Insecure inherited permissions in some Intel(R) ProSet/Wireless WiFi drivers may allow an authenticated user to potentially enable information disclosure and denial of service via adjacent access.

    Published: 9 Jun 2021
    5.5
    Medium

    CVE-2020-24486

    Last Modified: 21 Nov 2024

    Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.

    Published: 9 Jun 2021