CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2020-12360

    Last Modified: 21 Nov 2024

    Out of bounds read in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 9 Jun 2021
    4.4
    Medium

    CVE-2021-0095

    Last Modified: 21 Nov 2024

    Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access.

    Published: 9 Jun 2021
    4.4
    Medium

    CVE-2020-12358

    Last Modified: 21 Nov 2024

    Out of bounds write in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable denial of service via local access.

    Published: 9 Jun 2021
    6.8
    Medium

    CVE-2020-12359

    Last Modified: 21 Nov 2024

    Insufficient control flow management in the firmware for some Intel(R) Processors may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

    Published: 9 Jun 2021
    6.7
    Medium

    CVE-2020-8700

    Last Modified: 21 Nov 2024

    Improper input validation in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 9 Jun 2021
    6.4
    Medium

    CVE-2020-8670

    Last Modified: 21 Nov 2024

    Race condition in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 9 Jun 2021
    6.7
    Medium

    CVE-2020-12357

    Last Modified: 21 Nov 2024

    Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 9 Jun 2021
    6.8
    Medium

    CVE-2020-24514

    Last Modified: 21 Nov 2024

    Improper authentication in some Intel(R) RealSense(TM) IDs may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

    Published: 9 Jun 2021
    6.8
    Medium

    CVE-2020-24515

    Last Modified: 21 Nov 2024

    Protection mechanism failure in some Intel(R) RealSense(TM) IDs may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

    Published: 9 Jun 2021
    4.4
    Medium

    CVE-2020-24506

    Last Modified: 21 Nov 2024

    Out of bound read in a subsystem in the Intel(R) CSME versions before 12.0.81, 13.0.47, 13.30.17, 14.1.53 and 14.5.32 may allow a privileged user to potentially enable information disclosure via local access.

    Published: 9 Jun 2021
    6.7
    Medium

    CVE-2020-8703

    Last Modified: 21 Nov 2024

    Improper buffer restrictions in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32 and 15.0.22 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 9 Jun 2021
    6.8
    Medium

    CVE-2020-24516

    Last Modified: 21 Nov 2024

    Modification of assumed-immutable data in subsystem in Intel(R) CSME versions before 13.0.47, 13.30.17, 14.1.53, 14.5.32, 15.0.22 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

    Published: 9 Jun 2021
    4.4
    Medium

    CVE-2020-24507

    Last Modified: 21 Nov 2024

    Improper initialization in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32, 13.50.11 and 15.0.22 may allow a privileged user to potentially enable information disclosure via local access.

    Published: 9 Jun 2021
    6.4
    Medium

    CVE-2020-8704

    Last Modified: 21 Nov 2024

    Race condition in a subsystem in the Intel(R) LMS versions before 2039.1.0.0 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 9 Jun 2021
    6.7
    Medium

    CVE-2020-24509

    Last Modified: 21 Nov 2024

    Insufficient control flow management in subsystem in Intel(R) SPS versions before SPS_E3_05.01.04.300.0, SPS_SoC-A_05.00.03.091.0, SPS_E5_04.04.04.023.0, or SPS_E5_04.04.03.263.0 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 9 Jun 2021
    7.3
    High

    CVE-2020-8702

    Last Modified: 21 Nov 2024

    Uncontrolled search path element in the Intel(R) Processor Diagnostic Tool before version 4.1.5.37 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 9 Jun 2021
    6.1
    Medium

    CVE-2021-29049

    Last Modified: 13 May 2025

    Cross-site scripting (XSS) vulnerability in the Portal Workflow module's edit process page in Liferay DXP 7.0 before fix pack 99, 7.1 before fix pack 23, 7.2 before fix pack 12 and 7.3 before fix pack 1, allows remote attackers to inject arbitrary web script or HTML via the currentURL parameter.

    Published: 9 Jun 2021
    5.5
    Medium

    CVE-2020-12289

    Last Modified: 21 Nov 2024

    Out-of-bounds write in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.

    Published: 9 Jun 2021
    5.5
    Medium

    CVE-2020-12288

    Last Modified: 21 Nov 2024

    Protection mechanism failure in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.

    Published: 9 Jun 2021
    5.5
    Medium

    CVE-2020-12290

    Last Modified: 21 Nov 2024

    Improper access control in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.

    Published: 9 Jun 2021
    5.5
    Medium

    CVE-2020-12292

    Last Modified: 21 Nov 2024

    Improper conditions check in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.

    Published: 9 Jun 2021
    5.5
    Medium

    CVE-2020-12291

    Last Modified: 21 Nov 2024

    Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.

    Published: 9 Jun 2021
    5.5
    Medium

    CVE-2020-12296

    Last Modified: 21 Nov 2024

    Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.

    Published: 9 Jun 2021
    5.5
    Medium

    CVE-2020-12295

    Last Modified: 21 Nov 2024

    Improper input validation in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.

    Published: 9 Jun 2021
    5.5
    Medium

    CVE-2020-12294

    Last Modified: 21 Nov 2024

    Insufficient control flow management in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.

    Published: 9 Jun 2021
    5.5
    Medium

    CVE-2020-12293

    Last Modified: 21 Nov 2024

    Improper control of a resource through its lifetime in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.

    Published: 9 Jun 2021
    8.8
    High

    CVE-2021-33894

    Last Modified: 21 Nov 2024

    In Progress MOVEit Transfer before 2019.0.6 (11.0.6), 2019.1.x before 2019.1.5 (11.1.5), 2019.2.x before 2019.2.2 (11.2.2), 2020.x before 2020.0.5 (12.0.5), 2020.1.x before 2020.1.4 (12.1.4), and 2021.x before 2021.0.1 (13.0.1), a SQL injection vulnerability exists in SILUtility.vb in MOVEit.DMZ.WebApp in the MOVEit Transfer web app. This could allow an authenticated attacker to gain unauthorized access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database and/or execute SQL statements that alter or delete database elements.

    Published: 9 Jun 2021
    7.8
    High

    CVE-2020-27383

    Last Modified: 21 Nov 2024

    Battle.net.exe in Battle.Net 1.27.1.12428 suffers from an elevation of privileges vulnerability which can be used by an "Authenticated User" to modify the existing executable file with a binary of his choice. The vulnerability exist due to weak set of permissions being granted to the "Authenticated Users Group" which grants the (F) Flag aka "Full Control"

    Published: 9 Jun 2021
    8.8
    High

    CVE-2021-33358

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities exist in RaspAP 2.3 to 2.6.5 in the "interface", "ssid" and "wpa_passphrase" POST parameters in /hostapd, when the parameter values contain special characters such as ";" or "$()" which enables an authenticated attacker to execute arbitrary OS commands.

    Published: 9 Jun 2021
    9.8
    Critical

    CVE-2021-33357

    Last Modified: 21 Nov 2024

    A vulnerability exists in RaspAP 2.6 to 2.6.5 in the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the "iface" parameter value contains special characters such as ";" which enables an unauthenticated attacker to execute arbitrary OS commands.

    Published: 9 Jun 2021
    8.8
    High

    CVE-2021-33356

    Last Modified: 21 Nov 2024

    Multiple privilege escalation vulnerabilities in RaspAP 1.5 to 2.6.5 could allow an authenticated remote attacker to inject arbitrary commands to /installers/common.sh component that can result in remote command execution with root privileges.

    Published: 9 Jun 2021
    7.5
    High

    CVE-2021-33359

    Last Modified: 21 Nov 2024

    A vulnerability exists in gowitness < 2.3.6 that allows an unauthenticated attacker to perform an arbitrary file read using the file:// scheme in the url parameter to get an image of any file.

    Published: 9 Jun 2021
    9.8
    Critical

    CVE-2021-33833

    Last Modified: 21 Nov 2024

    ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAME, RDATA, or RDLENGTH (for A or AAAA).

    Published: 9 Jun 2021
    8.2
    High

    CVE-2021-32677

    Last Modified: 21 Nov 2024

    FastAPI is a web framework for building APIs with Python 3.6+ based on standard Python type hints. FastAPI versions lower than 0.65.2 that used cookies for authentication in path operations that received JSON payloads sent by browsers were vulnerable to a Cross-Site Request Forgery (CSRF) attack. In versions lower than 0.65.2, FastAPI would try to read the request payload as JSON even if the content-type header sent was not set to application/json or a compatible JSON media type (e.g. application/geo+json). A request with a content type of text/plain containing JSON data would be accepted and the JSON data would be extracted. Requests with content type text/plain are exempt from CORS preflights, for being considered Simple requests. The browser will execute them right away including cookies, and the text content could be a JSON string that would be parsed and accepted by the FastAPI application. This is fixed in FastAPI 0.65.2. The request data is now parsed as JSON only if the content-type header is application/json or another JSON compatible media type like application/geo+json. It's best to upgrade to the latest FastAPI, but if updating is not possible then a middleware or a dependency that checks the content-type header and aborts the request if it is not application/json or another JSON compatible content type can act as a mitigating workaround.

    Published: 9 Jun 2021
    6.6
    Medium

    CVE-2021-32942

    Last Modified: 21 Nov 2024

    The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorized, privileged user creates a diagnostic memory dump of the process and saves it to a non-protected location.

    Published: 9 Jun 2021
    5.3
    Medium

    CVE-2020-15386

    Last Modified: 21 Nov 2024

    Brocade Fabric OS prior to v9.0.1a and 8.2.3a and after v9.0.0 and 8.2.2d may observe high CPU load during security scanning, which could lead to a slower response to CLI commands and other operations.

    Published: 9 Jun 2021
    5.4
    Medium

    CVE-2020-15385

    Last Modified: 21 Nov 2024

    Brocade SANnav before version 2.1.1 allows an authenticated attacker to list directories, and list files without permission. As a result, users without permission can see folders, and hidden files, and can create directories without permission.

    Published: 9 Jun 2021
    5.3
    Medium

    CVE-2020-15384

    Last Modified: 21 Nov 2024

    Brocade SANNav before version 2.1.1 contains an information disclosure vulnerability. Successful exploitation of internal server information in the initial login response header.

    Published: 9 Jun 2021
    7.4
    High

    CVE-2020-15387

    Last Modified: 21 Nov 2024

    The host SSH servers of Brocade Fabric OS before Brocade Fabric OS v7.4.2h, v8.2.1c, v8.2.2, v9.0.0, and Brocade SANnav before v2.1.1 utilize keys of less than 2048 bits, which may be vulnerable to man-in-the-middle attacks and/or insecure SSH communications.

    Published: 9 Jun 2021
    7.5
    High

    CVE-2020-15380

    Last Modified: 21 Nov 2024

    Brocade SANnav before version 2.1.1 logs account credentials at the ‘trace’ logging level.

    Published: 9 Jun 2021
    7.5
    High

    CVE-2020-15379

    Last Modified: 21 Nov 2024

    Brocade SANnav before v.2.1.0a could allow remote attackers cause a denial-of-service condition due to a lack of proper validation, of the length of user-supplied data as name for custom field name.

    Published: 9 Jun 2021
    5.3
    Medium

    CVE-2020-15378

    Last Modified: 21 Nov 2024

    The OVA version of Brocade SANnav before version 2.1.1 installation with IPv6 networking exposes the docker container ports to the network, increasing the potential attack surface.

    Published: 9 Jun 2021
    9.8
    Critical

    CVE-2020-15377

    Last Modified: 21 Nov 2024

    Webtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to a misconfiguration; this is commonly referred to as Server-Side Request Forgery (SSRF).

    Published: 9 Jun 2021
    7.8
    High

    CVE-2020-27384

    Last Modified: 21 Nov 2024

    The Gw2-64.exe in Guild Wars 2 launcher version 106916 suffers from an elevation of privileges vulnerability which can be used by an "Authenticated User" to modify the existing executable file with a binary of his choice. The vulnerability exist due to the improper permissions, with the 'F' flag (Full Control) for 'Everyone' group, making the entire directory 'Guild Wars 2' and its files and sub-dirs world-writable.

    Published: 9 Jun 2021
    6.1
    Medium

    CVE-2021-30133

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in CloverDX Server 5.9.0, CloverDX 5.8.1, CloverDX 5.7.0, and earlier allows remote attackers to inject arbitrary web script or HTML via the sessionToken parameter of multiple methods in Simple HTTP API. This is resolved in 5.9.1 and 5.10.

    Published: 9 Jun 2021
    7.5
    High

    CVE-2020-15383

    Last Modified: 21 Nov 2024

    Running security scans against the SAN switch can cause config and secnotify processes within the firmware before Brocade Fabric OS v9.0.0, v8.2.2d and v8.2.1e to consume all memory leading to denial of service impacts possibly including a switch panic.

    Published: 9 Jun 2021
    7.2
    High

    CVE-2020-15382

    Last Modified: 21 Nov 2024

    Brocade SANnav before version 2.1.1 uses a hard-coded administrator account with the weak password ‘passw0rd’ if a password is not provided for PostgreSQL at install-time.

    Published: 9 Jun 2021
    7.5
    High

    CVE-2020-15381

    Last Modified: 21 Nov 2024

    Brocade SANnav before version 2.1.1 contains an Improper Authentication vulnerability that allows cleartext transmission of authentication credentials of the jmx server.

    Published: 9 Jun 2021
    8.8
    High

    CVE-2021-29995

    Last Modified: 21 Nov 2024

    A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in user (including script execution). The issue is resolved in CloverDX 5.10, CloverDX 5.9.1, CloverDX 5.8.2, and CloverDX 5.7.1.

    Published: 9 Jun 2021
    8.3
    High

    CVE-2021-23854

    Last Modified: 21 Nov 2024

    An error in the handling of a page parameter in Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. This issue only affects versions 7.7x and 7.6x. All other versions are not affected.

    Published: 9 Jun 2021