CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-23847

    Last Modified: 21 Nov 2024

    A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract sensitive information or change settings of the camera by sending crafted requests to the device. Only devices of the CPP6, CPP7 and CPP7.3 family with firmware 7.70, 7.72, and 7.80 prior to B128 are affected by this vulnerability. Versions 7.62 or lower and INTEOX cameras are not affected.

    Published: 9 Jun 2021
    8.3
    High

    CVE-2021-23853

    Last Modified: 21 Nov 2024

    In Bosch IP cameras, improper validation of the HTTP header allows an attacker to inject arbitrary HTTP headers through crafted URLs.

    Published: 9 Jun 2021
    8.3
    High

    CVE-2021-23848

    Last Modified: 21 Nov 2024

    An error in the URL handler Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the camera address can send a crafted link to a user, which will execute javascript code in the context of the user.

    Published: 9 Jun 2021
    4.9
    Medium

    CVE-2021-23852

    Last Modified: 21 Nov 2024

    An authenticated attacker with administrator rights Bosch IP cameras can call an URL with an invalid parameter that causes the camera to become unresponsive for a few seconds and cause a Denial of Service (DoS).

    Published: 9 Jun 2021
    8.8
    High

    CVE-2021-3196

    Last Modified: 21 Nov 2024

    An issue was discovered in Hitachi ID Bravura Security Fabric 11.0.0 through 11.1.3, 12.0.0 through 12.0.2, and 12.1.0. When using federated identity management (authenticating via SAML through a third-party identity provider), an attacker can inject additional data into a signed SAML response being transmitted to the service provider (ID Bravura Security Fabric). The application successfully validates the signed values but uses the unsigned malicious values. An attacker with lower-privilege access to the application can inject the username of a high-privilege user to impersonate that user.

    Published: 9 Jun 2021
    7.8
    High

    CVE-2021-33669

    Last Modified: 21 Nov 2024

    Under certain conditions, SAP Mobile SDK Certificate Provider allows a local unprivileged attacker to exploit an insecure temporary file storage. For a successful exploitation user interaction from another user is required and could lead to complete impact of confidentiality integrity and availability.

    Published: 9 Jun 2021
    5.2
    Medium

    CVE-2021-31832

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input in the ePO administrator extension for McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.200 allows a remote ePO DLP administrator to inject JavaScript code into the alert configuration text field. This JavaScript will be executed when an end user triggers a DLP policy on their machine.

    Published: 9 Jun 2021
    8.8
    High

    CVE-2021-31837

    Last Modified: 21 Nov 2024

    Memory corruption vulnerability in the driver file component in McAfee GetSusp prior to 4.0.0 could allow a program being investigated on the local machine to trigger a buffer overflow in GetSusp, leading to the execution of arbitrary code, potentially triggering a BSOD.

    Published: 9 Jun 2021
    5.4
    Medium

    CVE-2021-33665

    Last Modified: 21 Nov 2024

    SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML), versions - KRNL64NUC - 7.49, KRNL64UC - 7.49,7.53, KERNEL - 7.49,7.53,7.77,7.81,7.84, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

    Published: 9 Jun 2021
    5.3
    Medium

    CVE-2021-33663

    Last Modified: 21 Nov 2024

    SAP NetWeaver AS ABAP, versions - KRNL32NUC - 7.22,7.22EXT, KRNL32UC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73,7.77,7.81,7.82,7.83,7.84, allows an unauthorized attacker to insert cleartext commands due to improper restriction of I/O buffering into encrypted SMTP sessions over the network which can partially impact the integrity of the application.

    Published: 9 Jun 2021
    5.5
    Medium

    CVE-2021-33659

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated GIF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 9 Jun 2021
    5.5
    Medium

    CVE-2021-33661

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 9 Jun 2021
    5.4
    Medium

    CVE-2021-33664

    Last Modified: 21 Nov 2024

    SAP NetWeaver Application Server ABAP (Applications based on Web Dynpro ABAP), versions - SAP_UI - 750,752,753,754,755, SAP_BASIS - 702, 731 does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

    Published: 9 Jun 2021
    6.1
    Medium

    CVE-2021-33666

    Last Modified: 21 Nov 2024

    When SAP Commerce Cloud version 100, hosts a JavaScript storefront, it is vulnerable to MIME sniffing, which, in certain circumstances, could be used to facilitate an XSS attack or malware proliferation.

    Published: 9 Jun 2021
    5.5
    Medium

    CVE-2021-33660

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated FLI file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 9 Jun 2021
    4.4
    Medium

    CVE-2021-33662

    Last Modified: 21 Nov 2024

    Under certain conditions, the installation of SAP Business One, version - 10.0, discloses sensitive information on the file system allowing an attacker to access information which would otherwise be restricted.

    Published: 9 Jun 2021
    5.5
    Medium

    CVE-2021-27642

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 9 Jun 2021
    5.5
    Medium

    CVE-2021-27640

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PSD file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 9 Jun 2021
    5.5
    Medium

    CVE-2021-27643

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 9 Jun 2021
    5.5
    Medium

    CVE-2021-27641

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated TIF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 9 Jun 2021
    5.5
    Medium

    CVE-2021-27638

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated JT file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 9 Jun 2021
    6.5
    Medium

    CVE-2021-27635

    Last Modified: 21 Nov 2024

    SAP NetWeaver AS for JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker authenticated as an administrator to connect over a network and submit a specially crafted XML file in the application because of missing XML Validation, this vulnerability enables attacker to fully compromise confidentiality by allowing them to read any file on the filesystem or fully compromise availability by causing the system to crash. The attack cannot be used to change any data so that there is no compromise as to integrity.

    Published: 9 Jun 2021
    5.5
    Medium

    CVE-2021-27639

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated JT file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 9 Jun 2021
    4.6
    Medium

    CVE-2021-27637

    Last Modified: 21 Nov 2024

    Under certain conditions SAP Enable Now (SAP Workforce Performance Builder - Manager), versions - 1.0, 10 allows an attacker to access information which would otherwise be restricted leading to information disclosure.

    Published: 9 Jun 2021
    4.9
    Medium

    CVE-2021-27621

    Last Modified: 21 Nov 2024

    Information Disclosure vulnerability in UserAdmin application in SAP NetWeaver Application Server for Java, versions - 7.11,7.20,7.30,7.31,7.40 and 7.50 allows attackers to access restricted information by entering malicious server name.

    Published: 9 Jun 2021
    5.4
    Medium

    CVE-2021-27615

    Last Modified: 21 Nov 2024

    SAP Manufacturing Execution versions - 15.1, 1.5.2, 15.3, 15.4, does not contain some HTTP security headers in their HTTP response. The lack of these headers in response can be exploited by the attacker to execute Cross-Site Scripting (XSS) attacks.

    Published: 9 Jun 2021
    6.3
    Medium

    CVE-2021-21473

    Last Modified: 21 Nov 2024

    SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, contains function module SRM_RFC_SUBMIT_REPORT which fails to validate authorization of an authenticated user thus allowing an unauthorized user to execute reports in SAP NetWeaver ABAP Platform.

    Published: 9 Jun 2021
    6.1
    Medium

    CVE-2021-21490

    Last Modified: 21 Nov 2024

    SAP NetWeaver AS for ABAP (Web Survey), versions - 700, 702, 710, 711, 730, 731, 750, 750, 752, 75A, 75F, does not sufficiently encode input and output parameters which results in reflected cross site scripting vulnerability, through which a malicious user can access data relating to the current session and use it to impersonate a user and access all information with the same rights as the target user.

    Published: 9 Jun 2021
    7.5
    High

    CVE-2021-33668

    Last Modified: 21 Nov 2024

    Due to improper input sanitization, specially crafted LDAP queries can be injected by an unauthenticated user. This could partially impact the confidentiality of the application.

    Published: 9 Jun 2021
    6.1
    Medium

    CVE-2021-33829

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.

    Published: 9 Jun 2021
    10
    Critical

    CVE-2021-33841

    Last Modified: 21 Nov 2024

    SGE-PLC1000 device, in its 0.9.2b firmware version, does not handle some requests correctly, allowing a remote attacker to inject code into the operating system with maximum privileges.

    Published: 9 Jun 2021
    8.8
    High

    CVE-2021-33842

    Last Modified: 21 Nov 2024

    Improper Authentication vulnerability in the cookie parameter of Circutor SGE-PLC1000 firmware version 0.9.2b allows an attacker to perform operations as an authenticated user. In order to exploit this vulnerability, the attacker must be within the network where the device affected is located.

    Published: 9 Jun 2021
    6.5
    Medium

    CVE-2021-34369

    Last Modified: 21 Nov 2024

    portlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensitive information via a modified contactSeqNumber value. NOTE: the vendor states "the information that is being queried is authorized for an authenticated user of that application, so we consider this not applicable.

    Published: 9 Jun 2021
    6.1
    Medium

    CVE-2021-34370

    Last Modified: 21 Nov 2024

    Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS. NOTE: the vendor states "there are configurable security flags and we are unable to reproduce them with the available information.

    Published: 9 Jun 2021
    5.5
    Medium

    CVE-2021-26314

    Last Modified: 21 Nov 2024

    Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause the use of incorrect data from FPVI and may result in data leakage.

    Published: 9 Jun 2021
    5.5
    Medium

    CVE-2021-26313

    Last Modified: 21 Nov 2024

    Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution of overwritten instructions, may cause an incorrect speculation and could result in data leakage.

    Published: 9 Jun 2021
    —
    Unknown

    CVE-2021-3533

    Last Modified: 23 Jan 2024

    This vulnerability does not meet the criteria for a security vulnerability

    Published: 9 Jun 2021
    6.1
    Medium

    CVE-2021-34364

    Last Modified: 21 Nov 2024

    The Refined GitHub browser extension before 21.6.8 might allow XSS via a link in a document. NOTE: github.com sends Content-Security-Policy headers to, in general, address XSS and other concerns.

    Published: 9 Jun 2021
    7.5
    High

    CVE-2021-1937

    Last Modified: 21 Nov 2024

    Reachable assertion is possible while processing peer association WLAN message from host and nonstandard incoming packet in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 9 Jun 2021
    8.4
    High

    CVE-2021-1900

    Last Modified: 21 Nov 2024

    Possible use after free in Display due to race condition while creating an external display in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 9 Jun 2021
    7.8
    High

    CVE-2020-11306

    Last Modified: 21 Nov 2024

    Possible integer overflow in RPMB counter due to lack of length check on user provided data in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

    Published: 9 Jun 2021
    7.8
    High

    CVE-2020-11298

    Last Modified: 21 Nov 2024

    While waiting for a response to a callback or listener request, non-secure clients can change permissions to shared memory buffers used by HLOS Invoke Call to secure kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 9 Jun 2021
    7.8
    High

    CVE-2020-11304

    Last Modified: 21 Nov 2024

    Possible out of bound read in DRM due to improper buffer length check. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 9 Jun 2021
    7.8
    High

    CVE-2020-11292

    Last Modified: 21 Nov 2024

    Possible buffer overflow in voice service due to lack of input validation of parameters in QMI Voice API in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 9 Jun 2021
    9.8
    Critical

    CVE-2020-11291

    Last Modified: 21 Nov 2024

    Possible buffer overflow while updating ikev2 parameters for delete payloads received during informational exchange due to lack of check of input validation for certain parameters received from the ePDG server in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile

    Published: 9 Jun 2021
    8.4
    High

    CVE-2020-11267

    Last Modified: 21 Nov 2024

    Stack out-of-bounds write occurs while setting up a cipher device if the provided IV length exceeds the max limit value in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 9 Jun 2021
    9.8
    Critical

    CVE-2020-11176

    Last Modified: 21 Nov 2024

    While processing server certificate from IPSec server, certificate validation for subject alternative name API can cause heap overflow which can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile

    Published: 9 Jun 2021
    6.5
    Medium

    CVE-2020-11266

    Last Modified: 21 Nov 2024

    Image address is dereferenced before validating its range which can cause potential QSEE information leakage in Snapdragon Wired Infrastructure and Networking

    Published: 9 Jun 2021
    5.5
    Medium

    CVE-2020-11265

    Last Modified: 21 Nov 2024

    Information disclosure issue due to lack of validation of pointer arguments passed to TZ BSP in Snapdragon Wired Infrastructure and Networking

    Published: 9 Jun 2021
    7
    High

    CVE-2020-11262

    Last Modified: 21 Nov 2024

    A race between command submission and destroying the context can cause an invalid context being added to the list leads to use after free issue. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 9 Jun 2021