CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2020-29323

    Last Modified: 21 Nov 2024

    The D-link router DIR-885L-MFC 1.15b02, v1.21b05 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.

    Published: 4 Jun 2021
    7.5
    High

    CVE-2020-29322

    Last Modified: 21 Nov 2024

    The D-Link router DIR-880L 1.07 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.

    Published: 4 Jun 2021
    8.8
    High

    CVE-2021-30520

    Last Modified: 21 Nov 2024

    Use after free in Tab Strip in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

    Published: 4 Jun 2021
    8.8
    High

    CVE-2021-30519

    Last Modified: 21 Nov 2024

    Use after free in Payments in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious payments app to potentially exploit heap corruption via a crafted HTML page.

    Published: 4 Jun 2021
    8.8
    High

    CVE-2021-30517

    Last Modified: 21 Nov 2024

    Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 4 Jun 2021
    8.8
    High

    CVE-2021-30518

    Last Modified: 21 Nov 2024

    Heap buffer overflow in Reader Mode in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 4 Jun 2021
    8.8
    High

    CVE-2021-30516

    Last Modified: 21 Nov 2024

    Heap buffer overflow in History in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

    Published: 4 Jun 2021
    8.8
    High

    CVE-2021-30514

    Last Modified: 21 Nov 2024

    Use after free in Autofill in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

    Published: 4 Jun 2021
    8.8
    High

    CVE-2021-30515

    Last Modified: 21 Nov 2024

    Use after free in File API in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 4 Jun 2021
    8.8
    High

    CVE-2021-30513

    Last Modified: 21 Nov 2024

    Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 4 Jun 2021
    8.1
    High

    CVE-2021-30511

    Last Modified: 21 Nov 2024

    Out of bounds read in Tab Groups in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted HTML page.

    Published: 4 Jun 2021
    8.8
    High

    CVE-2021-30512

    Last Modified: 21 Nov 2024

    Use after free in Notifications in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

    Published: 4 Jun 2021
    8.8
    High

    CVE-2021-30510

    Last Modified: 21 Nov 2024

    Use after free in Aura in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 4 Jun 2021
    8.8
    High

    CVE-2021-30508

    Last Modified: 21 Nov 2024

    Heap buffer overflow in Media Feeds in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to enable certain features in Chrome to potentially exploit heap corruption via a crafted HTML page.

    Published: 4 Jun 2021
    8.8
    High

    CVE-2021-30509

    Last Modified: 21 Nov 2024

    Out of bounds write in Tab Strip in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page and a crafted Chrome extension.

    Published: 4 Jun 2021
    8.8
    High

    CVE-2021-30507

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Offline in Google Chrome on Android prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.

    Published: 4 Jun 2021
    8.8
    High

    CVE-2021-30506

    Last Modified: 21 Nov 2024

    Incorrect security UI in Web App Installs in Google Chrome on Android prior to 90.0.4430.212 allowed an attacker who convinced a user to install a web application to inject scripts or HTML into a privileged page via a crafted HTML page.

    Published: 4 Jun 2021
    6.5
    Medium

    CVE-2021-1564

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the implementation of the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) for Cisco Video Surveillance 7000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS) condition on an affected device. These vulnerabilities are due to incorrect processing of certain Cisco Discovery Protocol and LLDP packets at ingress time. An attacker could exploit these vulnerabilities by sending crafted Cisco Discovery Protocol or LLDP packets to an affected device. A successful exploit could allow the attacker to cause the affected device to continuously consume memory, which could cause the device to crash and reload, resulting in a DoS condition. Note: Cisco Discovery Protocol and LLDP are Layer 2 protocols. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).

    Published: 4 Jun 2021
    6.5
    Medium

    CVE-2021-1563

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the implementation of the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) for Cisco Video Surveillance 7000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS) condition on an affected device. These vulnerabilities are due to incorrect processing of certain Cisco Discovery Protocol and LLDP packets at ingress time. An attacker could exploit these vulnerabilities by sending crafted Cisco Discovery Protocol or LLDP packets to an affected device. A successful exploit could allow the attacker to cause the affected device to continuously consume memory, which could cause the device to crash and reload, resulting in a DoS condition. Note: Cisco Discovery Protocol and LLDP are Layer 2 protocols. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).

    Published: 4 Jun 2021
    5.5
    Medium

    CVE-2021-1544

    Last Modified: 21 Nov 2024

    A vulnerability in logging mechanisms of Cisco Webex Meetings client software could allow an authenticated, local attacker to gain access to sensitive information. This vulnerability is due to unsafe logging of application actions. An attacker could exploit this vulnerability by logging onto the local system and accessing files containing the logged details. A successful exploit could allow the attacker to gain access to sensitive information, including meeting data and recorded meeting transcriptions.

    Published: 4 Jun 2021
    8.1
    High

    CVE-2021-1540

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker to bypass authorization and execute a subset of CLI commands on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 4 Jun 2021
    8.1
    High

    CVE-2021-1539

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker to bypass authorization and execute a subset of CLI commands on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 4 Jun 2021
    4.7
    Medium

    CVE-2021-1538

    Last Modified: 21 Nov 2024

    A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to execute arbitrary code. This vulnerability is due to insufficient sanitization of configuration entries. An attacker could exploit this vulnerability by logging in as a super admin and entering crafted input to configuration options on the CSPC configuration dashboard. A successful exploit could allow the attacker to execute remote code as root.

    Published: 4 Jun 2021
    6.2
    Medium

    CVE-2021-1537

    Last Modified: 21 Nov 2024

    A vulnerability in the installer software of Cisco ThousandEyes Recorder could allow an unauthenticated, local attacker to access sensitive information that is contained in the ThousandEyes Recorder installer software. This vulnerability exists because sensitive information is included in the application installer. An attacker could exploit this vulnerability by downloading the installer and extracting its contents. A successful exploit could allow the attacker to access sensitive information that is included in the application installer.

    Published: 4 Jun 2021
    4.8
    Medium

    CVE-2021-1536

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco Webex Meetings Desktop App for Windows, Cisco Webex Meetings Server, Cisco Webex Network Recording Player for Windows, and Cisco Webex Teams for Windows could allow an authenticated, local attacker to perform a DLL injection attack on an affected device. To exploit this vulnerability, the attacker must have valid credentials on the Windows system. This vulnerability is due to incorrect handling of directory paths at run time. An attacker could exploit this vulnerability by inserting a configuration file in a specific path in the system, which can cause a malicious DLL file to be loaded when the application starts. A successful exploit could allow the attacker to execute arbitrary code on the affected system with the privileges of another user account.

    Published: 4 Jun 2021
    7.8
    High

    CVE-2021-1528

    Last Modified: 21 Nov 2024

    A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges on an affected system. This vulnerability exists because the affected software does not properly restrict access to privileged processes. An attacker could exploit this vulnerability by invoking a privileged process in the affected system. A successful exploit could allow the attacker to perform actions with the privileges of the root user.

    Published: 4 Jun 2021
    5.3
    Medium

    CVE-2021-1527

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco Webex Player for Windows and MacOS could allow an attacker to cause the affected software to terminate or to gain access to memory state information that is related to the vulnerable application. The vulnerability is due to insufficient validation of values in Webex recording files that are stored in Webex Recording Format (WRF). An attacker could exploit this vulnerability by sending a malicious WRF file to a user as a link or email attachment and then persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to crash the affected software and view memory state information.

    Published: 4 Jun 2021
    7.8
    High

    CVE-2021-1526

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco Webex Player for Windows and MacOS could allow an attacker to execute arbitrary code on an affected system. This vulnerability is due to insufficient validation of values in Webex recording files that are in Webex Recording Format (WRF). An attacker could exploit this vulnerability by sending a user a malicious WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to execute arbitrary code on the affected system with the privileges of the targeted user.

    Published: 4 Jun 2021
    4.7
    Medium

    CVE-2021-1525

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to redirect users to a malicious file. This vulnerability is due to improper validation of URL paths in the application interface. An attacker could exploit this vulnerability by persuading a user to follow a specially crafted URL that is designed to cause Cisco Webex Meetings to include a remote file in the web UI. A successful exploit could allow the attacker to cause the application to offer a remote file to a user, which could allow the attacker to conduct further phishing or spoofing attacks.

    Published: 4 Jun 2021
    5
    Medium

    CVE-2021-1517

    Last Modified: 21 Nov 2024

    A vulnerability in the multimedia viewer feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to bypass security protections. This vulnerability is due to unsafe handling of shared content within the multimedia viewer feature. An attacker could exploit this vulnerability by sharing a file through the multimedia viewer feature. A successful exploit could allow the attacker to bypass security protections and prevent warning dialogs from appearing before files are offered to other users.

    Published: 4 Jun 2021
    7.8
    High

    CVE-2021-1503

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco Webex Network Recording Player for Windows and MacOS and Cisco Webex Player for Windows and MacOS could allow an attacker to execute arbitrary code on an affected system. This vulnerability is due to insufficient validation of values in Webex recording files that are in either Advanced Recording Format (ARF) or Webex Recording Format (WRF). An attacker could exploit this vulnerability by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to execute arbitrary code on the affected system with the privileges of the targeted user.

    Published: 4 Jun 2021
    7.8
    High

    CVE-2021-1502

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco Webex Network Recording Player for Windows and MacOS and Cisco Webex Player for Windows and MacOS could allow an attacker to execute arbitrary code on an affected system. The vulnerability is due to insufficient validation of values within Webex recording files formatted as either Advanced Recording Format (ARF) or Webex Recording Format (WRF). An attacker could exploit the vulnerability by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file. A successful exploit could allow the attacker to execute arbitrary code on the affected system with the privileges of the targeted user.

    Published: 4 Jun 2021
    5.4
    Medium

    CVE-2020-36139

    Last Modified: 21 Nov 2024

    BloofoxCMS 0.5.2.1 allows Reflected Cross-Site Scripting (XSS) vulnerability by inserting a XSS payload within the 'fileurl' parameter.

    Published: 4 Jun 2021
    6.5
    Medium

    CVE-2020-36140

    Last Modified: 21 Nov 2024

    BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of 'mode=settings&page=editor' to change any file content (Locally/Remotely).

    Published: 4 Jun 2021
    8.8
    High

    CVE-2020-36141

    Last Modified: 21 Nov 2024

    BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpeg' within the 'Content-Type' header.

    Published: 4 Jun 2021
    6.5
    Medium

    CVE-2020-36142

    Last Modified: 21 Nov 2024

    BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter.

    Published: 4 Jun 2021
    7.5
    High

    CVE-2021-33054

    Last Modified: 21 Nov 2024

    SOGo 2.x before 2.4.1 and 3.x through 5.x before 5.1.1 does not validate the signatures of any SAML assertions it receives. Any actor with network access to the deployment could impersonate users when SAML is the authentication method. (Only versions after 2.0.5a are affected.)

    Published: 4 Jun 2021
    8.8
    High

    CVE-2021-27657

    Last Modified: 21 Nov 2024

    Successful exploitation of this vulnerability could give an authenticated Metasys user an unintended level of access to the server file system, allowing them to access or modify system files by sending specifically crafted web messages to the Metasys system. This issue affects: Johnson Controls Metasys version 11.0 and prior versions.

    Published: 4 Jun 2021
    8
    High

    CVE-2020-27302

    Last Modified: 21 Nov 2024

    A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "memcpy" function, when an attacker in Wi-Fi range sends a crafted "Encrypted GTK" value as part of the WPA2 4-way-handshake.

    Published: 4 Jun 2021
    8
    High

    CVE-2020-27301

    Last Modified: 21 Nov 2024

    A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "AES_UnWRAP" function, when an attacker in Wi-Fi range sends a crafted "Encrypted GTK" value as part of the WPA2 4-way-handshake.

    Published: 4 Jun 2021
    7.5
    High

    CVE-2021-22516

    Last Modified: 21 Nov 2024

    Insertion of Sensitive Information into Log File vulnerability in Micro Focus Secure API Manager (SAPIM) product, affecting version 2.0.0. The vulnerability could lead to sensitive information being in a log file.

    Published: 4 Jun 2021
    7.5
    High

    CVE-2020-7469

    Last Modified: 21 Nov 2024

    In FreeBSD 12.2-STABLE before r367402, 11.4-STABLE before r368202, 12.2-RELEASE before p1, 12.1-RELEASE before p11 and 11.4-RELEASE before p5 the handler for a routing option caches a pointer into the packet buffer holding the ICMPv6 message. However, when processing subsequent options the packet buffer may be freed, rendering the cached pointer invalid. The network stack may later dereference the pointer, potentially triggering a use-after-free.

    Published: 4 Jun 2021
    6.5
    Medium

    CVE-2021-26994

    Last Modified: 21 Nov 2024

    Clustered Data ONTAP versions prior to 9.7P13 and 9.8P3 are susceptible to a vulnerability which could allow single workloads to cause a Denial of Service (DoS) on a cluster node.

    Published: 4 Jun 2021
    7.5
    High

    CVE-2020-36382

    Last Modified: 21 Nov 2024

    OpenVPN Access Server 2.7.3 to 2.8.7 allows remote attackers to trigger an assert during the user authentication phase via incorrect authentication token data in an early phase of the user authentication resulting in a denial of service.

    Published: 4 Jun 2021
    5.3
    Medium

    CVE-2020-15077

    Last Modified: 21 Nov 2024

    OpenVPN Access Server 2.8.7 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.

    Published: 4 Jun 2021
    5.3
    Medium

    CVE-2019-17567

    Last Modified: 21 Nov 2024

    Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.

    Published: 4 Jun 2021
    7.5
    High

    CVE-2021-26690

    Last Modified: 21 Nov 2024

    Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service

    Published: 4 Jun 2021
    9.8
    Critical

    CVE-2021-30475

    Last Modified: 21 Nov 2024

    aom_dsp/noise_model.c in libaom in AOMedia before 2021-03-24 has a buffer overflow.

    Published: 4 Jun 2021
    5.3
    Medium

    CVE-2021-30641

    Last Modified: 21 Nov 2024

    Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'

    Published: 4 Jun 2021
    7.5
    High

    CVE-2020-13950

    Last Modified: 21 Nov 2024

    Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of Service

    Published: 4 Jun 2021