CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2021-1351

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of the affected service. The vulnerability is due to insufficient validation of user-supplied input by the web-based interface of the affected service. An attacker could exploit this vulnerability by persuading a user of the interface to click a maliciously crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

    Published: 17 Feb 2021
    7.8
    High

    CVE-2021-1366

    Last Modified: 21 Nov 2024

    A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client. This vulnerability is due to insufficient validation of resources that are loaded by the application at run time. An attacker could exploit this vulnerability by sending a crafted IPC message to the AnyConnect process. A successful exploit could allow the attacker to execute arbitrary code on the affected machine with SYSTEM privileges. To exploit this vulnerability, the attacker needs valid credentials on the Windows system.

    Published: 17 Feb 2021
    5.5
    Medium

    CVE-2021-1372

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows could allow an authenticated, local attacker to gain access to sensitive information on an affected system. This vulnerability is due to the unsafe usage of shared memory by the affected software. An attacker with permissions to view system memory could exploit this vulnerability by running an application on the local system that is designed to read shared memory. A successful exploit could allow the attacker to retrieve sensitive information from the shared memory, including usernames, meeting information, or authentication tokens. Note: To exploit this vulnerability, an attacker must have valid credentials on a Microsoft Windows end-user system and must log in after another user has already authenticated with Webex on the same end-user system.

    Published: 17 Feb 2021
    5.3
    Medium

    CVE-2021-1378

    Last Modified: 21 Nov 2024

    A vulnerability in the SSH service of the Cisco StarOS operating system could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulting in a denial of service (DoS) condition. The vulnerability is due to a logic error that may occur under specific traffic conditions. An attacker could exploit this vulnerability by sending a series of crafted packets to an affected device. A successful exploit could allow the attacker to prevent the targeted service from receiving any traffic, which would lead to a DoS condition on the affected device.

    Published: 17 Feb 2021
    6.5
    Medium

    CVE-2021-1412

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information. These vulnerabilities are due to improper enforcement of administrator privilege levels for sensitive data. An attacker with read-only administrator access to the Admin portal could exploit these vulnerabilities by browsing to one of the pages that contains sensitive data. A successful exploit could allow the attacker to collect sensitive information regarding the configuration of the system. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 17 Feb 2021
    6.5
    Medium

    CVE-2021-1416

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information. These vulnerabilities are due to improper enforcement of administrator privilege levels for sensitive data. An attacker with read-only administrator access to the Admin portal could exploit these vulnerabilities by browsing to one of the pages that contains sensitive data. A successful exploit could allow the attacker to collect sensitive information regarding the configuration of the system. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 17 Feb 2021
    7.5
    High

    CVE-2021-27224

    Last Modified: 21 Nov 2024

    The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a user-mode write access violation starting at WPG+0x0000000000012ec6, which might allow remote attackers to execute arbitrary code.

    Published: 17 Feb 2021
    9.8
    Critical

    CVE-2021-27362

    Last Modified: 21 Nov 2024

    The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a Read Access Violation on Control Flow starting at WPG!ReadWPG_W+0x0000000000000133, which might allow remote attackers to execute arbitrary code.

    Published: 17 Feb 2021
    9.8
    Critical

    CVE-2021-26809

    Last Modified: 21 Nov 2024

    PHPGurukul Car Rental Project version 2.0 suffers from a remote shell upload vulnerability in changeimage1.php.

    Published: 17 Feb 2021
    7.2
    High

    CVE-2021-25780

    Last Modified: 18 Nov 2025

    An arbitrary file upload vulnerability has been identified in posts.php in Baby Care System 1.0. The vulnerability could be exploited by an remote attacker to upload content to the server, including PHP files, which could result in command execution and obtaining a shell.

    Published: 17 Feb 2021
    9.8
    Critical

    CVE-2021-25779

    Last Modified: 18 Nov 2025

    Baby Care System v1.0 is vulnerable to SQL injection via the 'id' parameter on the contentsectionpage.php page.

    Published: 17 Feb 2021
    7.5
    High

    CVE-2020-36003

    Last Modified: 21 Nov 2024

    The id parameter in detail.php of Online Book Store v1.0 is vulnerable to union-based blind SQL injection, which leads to the ability to retrieve all databases.

    Published: 17 Feb 2021
    7.5
    High

    CVE-2020-36002

    Last Modified: 21 Nov 2024

    Seat-Reservation-System 1.0 has a SQL injection vulnerability in index.php in the id parameter where attackers can obtain sensitive database information.

    Published: 17 Feb 2021
    9.8
    Critical

    CVE-2020-35339

    Last Modified: 21 Nov 2024

    In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController.class.php and /ThinkPHP/Common/functions.php where attackers can obtain server permissions and control the server.

    Published: 17 Feb 2021
    5.3
    Medium

    CVE-2021-26697

    Last Modified: 13 Feb 2025

    The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allowed unauthenticated users to hit that endpoint. This is low-severity issue as the attacker needs to be aware of certain parameters to pass to that endpoint and even after can just get some metadata about a DAG and a Task. This issue affects Apache Airflow 2.0.0.

    Published: 17 Feb 2021
    6.5
    Medium

    CVE-2021-26559

    Last Modified: 13 Feb 2025

    Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configurations including sensitive information even when `[webserver] expose_config` is set to `False` in `airflow.cfg`. This allowed a privilege escalation attack. This issue affects Apache Airflow 2.0.0.

    Published: 17 Feb 2021
    5.5
    Medium

    CVE-2020-12365

    Last Modified: 21 Nov 2024

    Untrusted pointer dereference in some Intel(R) Graphics Drivers before versions 15.33.51.5146, 15.45.32.5145, 15.36.39.5144 and 15.40.46.5143 may allow an authenticated user to potentially denial of service via local access.

    Published: 17 Feb 2021
    4.4
    Medium

    CVE-2020-0525

    Last Modified: 21 Nov 2024

    Improper access control in firmware for the Intel(R) Ethernet I210 Controller series of network adapters before version 3.30 may allow a privileged user to potentially enable denial of service via local access.

    Published: 17 Feb 2021
    5.5
    Medium

    CVE-2020-0524

    Last Modified: 21 Nov 2024

    Improper default permissions in the firmware for the Intel(R) Ethernet I210 Controller series of network adapters before version 3.30 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 17 Feb 2021
    4.4
    Medium

    CVE-2020-0523

    Last Modified: 21 Nov 2024

    Improper access control in the firmware for the Intel(R) Ethernet I210 Controller series of network adapters before version 3.30 may potentially allow a privileged user to enable a denial of service via local access.

    Published: 17 Feb 2021
    4.4
    Medium

    CVE-2020-0522

    Last Modified: 21 Nov 2024

    Improper initialization in the firmware for the Intel(R) Ethernet I210 Controller series of network adapters before version 3.30 may allow a privileged user to potentially enable denial of service via local access.

    Published: 17 Feb 2021
    6.7
    Medium

    CVE-2020-8765

    Last Modified: 21 Nov 2024

    Incorrect default permissions in the installer for the Intel(R) RealSense(TM) DCM may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 17 Feb 2021
    8.8
    High

    CVE-2020-12339

    Last Modified: 21 Nov 2024

    Insufficient control flow management in the API for the Intel(R) Collaboration Suite for WebRTC before version 4.3.1 may allow an authenticated user to potentially enable escalation of privilege via network access.

    Published: 17 Feb 2021
    5.5
    Medium

    CVE-2020-12376

    Last Modified: 21 Nov 2024

    Use of hard-coded key in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.47 may allow authenticated user to potentially enable information disclosure via local access.

    Published: 17 Feb 2021
    6.7
    Medium

    CVE-2020-12375

    Last Modified: 21 Nov 2024

    Heap overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.47 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Feb 2021
    7.8
    High

    CVE-2020-12380

    Last Modified: 21 Nov 2024

    Out of bounds read in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.47 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Feb 2021
    7.8
    High

    CVE-2020-12377

    Last Modified: 21 Nov 2024

    Insufficient input validation in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.47 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Feb 2021
    7.3
    High

    CVE-2020-24451

    Last Modified: 21 Nov 2024

    Uncontrolled search path in the Intel(R) Optane(TM) DC Persistent Memory installer for Windows* before version 1.00.00.3506 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Feb 2021
    6.7
    Medium

    CVE-2020-12373

    Last Modified: 21 Nov 2024

    Expired pointer dereference in some Intel(R) Graphics Drivers before version 26.20.100.8141 may allow a privileged user to potentially enable a denial of service via local access.

    Published: 17 Feb 2021
    5.5
    Medium

    CVE-2020-12372

    Last Modified: 21 Nov 2024

    Unchecked return value in some Intel(R) Graphics Drivers before version 26.20.100.8141 may allow a privileged user to potentially enable a denial of service via local access.

    Published: 17 Feb 2021
    5.5
    Medium

    CVE-2020-12371

    Last Modified: 21 Nov 2024

    Divide by zero in some Intel(R) Graphics Drivers before version 26.20.100.8141 may allow a privileged user to potentially enable a denial of service via local access.

    Published: 17 Feb 2021
    5.5
    Medium

    CVE-2020-12370

    Last Modified: 21 Nov 2024

    Untrusted pointer dereference in some Intel(R) Graphics Drivers before version 26.20.100.8141 may allow a privileged user to potentially enable a denial of service via local access.

    Published: 17 Feb 2021
    7.8
    High

    CVE-2020-12384

    Last Modified: 21 Nov 2024

    Improper access control in some Intel(R) Graphics Drivers before version 26.20.100.8476 may allow an authenticated user to potentially enable an escalation of privilege via local access.

    Published: 17 Feb 2021
    5.5
    Medium

    CVE-2020-12386

    Last Modified: 21 Nov 2024

    Out-of-bounds write in some Intel(R) Graphics Drivers before version 15.36.39.5143 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 17 Feb 2021
    5.5
    Medium

    CVE-2020-24448

    Last Modified: 21 Nov 2024

    Uncaught exception in some Intel(R) Graphics Drivers before version 15.33.51.5146 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 17 Feb 2021
    7.8
    High

    CVE-2020-12366

    Last Modified: 21 Nov 2024

    Insufficient input validation in some Intel(R) Graphics Drivers before version 27.20.100.8587 may allow a privileged user to potentially enable an escalation of privilege via local access.

    Published: 17 Feb 2021
    7.8
    High

    CVE-2020-12385

    Last Modified: 21 Nov 2024

    Improper input validation in some Intel(R) Graphics Drivers before version 26.20.100.8141 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 17 Feb 2021
    7.8
    High

    CVE-2020-12369

    Last Modified: 21 Nov 2024

    Out of bound write in some Intel(R) Graphics Drivers before version 26.20.100.8336 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 17 Feb 2021
    7.8
    High

    CVE-2020-12368

    Last Modified: 21 Nov 2024

    Integer overflow in some Intel(R) Graphics Drivers before version 26.20.100.8141 may allow a privileged user to potentially enable an escalation of privilege via local access.

    Published: 17 Feb 2021
    7.8
    High

    CVE-2020-12367

    Last Modified: 21 Nov 2024

    Integer overflow in some Intel(R) Graphics Drivers before version 26.20.100.8476 may allow a privileged user to potentially enable an escalation of privilege via local access.

    Published: 17 Feb 2021
    5.5
    Medium

    CVE-2020-0518

    Last Modified: 21 Nov 2024

    Improper access control in the Intel(R) HD Graphics Control Panel before version 15.40.46.5144 and 15.36.39.5143 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 17 Feb 2021
    7.8
    High

    CVE-2020-8678

    Last Modified: 21 Nov 2024

    Improper access control for Intel(R) Graphics Drivers before version 15.45.33.5164 and 27.20.100.8280 may allow an authenticated user to potentially enable an escalation of privilege via local access.

    Published: 17 Feb 2021
    7.8
    High

    CVE-2020-24462

    Last Modified: 21 Nov 2024

    Out of bounds write in the Intel(R) Graphics Driver before version 15.33.53.5161, 15.36.40.5162, 15.40.47.5166, 15.45.33.5164 and 27.20.100.8336 may allow an authenticated user to potentially enable an escalation of privilege via local access.

    Published: 17 Feb 2021
    5.5
    Medium

    CVE-2020-12361

    Last Modified: 21 Nov 2024

    Use after free in some Intel(R) Graphics Drivers before version 15.33.51.5146 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 17 Feb 2021
    7.8
    High

    CVE-2020-0521

    Last Modified: 21 Nov 2024

    Insufficient control flow management in some Intel(R) Graphics Drivers before version 15.45.32.5145 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Feb 2021
    7.8
    High

    CVE-2020-0544

    Last Modified: 21 Nov 2024

    Insufficient control flow management in the kernel mode driver for some Intel(R) Graphics Drivers before version 15.36.39.5145 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Feb 2021
    7.8
    High

    CVE-2020-24450

    Last Modified: 21 Nov 2024

    Improper conditions check in some Intel(R) Graphics Drivers before versions 26.20.100.8141, 15.45.32.5145 and 15.40.46.5144 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 Feb 2021
    5.5
    Medium

    CVE-2020-24452

    Last Modified: 21 Nov 2024

    Improper input validation in the Intel(R) SGX Platform Software for Windows* may allow an authenticated user to potentially enable a denial of service via local access.

    Published: 17 Feb 2021
    7.8
    High

    CVE-2020-24453

    Last Modified: 21 Nov 2024

    Improper input validation in the Intel(R) EPID SDK before version 8, may allow an authenticated user to potentially enable an escalation of privilege via local access.

    Published: 17 Feb 2021
    5.2
    Medium

    CVE-2020-24458

    Last Modified: 21 Nov 2024

    Incomplete cleanup in some Intel(R) PROSet/Wireless WiFi and Killer (TM) drivers before version 22.0 may allow a privileged user to potentially enable information disclosure and denial of service<b>&nbsp;</b>via adjacent access.

    Published: 17 Feb 2021