Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by NVD-CWE-Other
Total 27865 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-24481 1 Intel 1 Quartus 2021-02-23 4.6 MEDIUM 7.8 HIGH
Insecure inherited permissions for the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2020-24448 1 Intel 1 Graphics Drivers 2021-02-23 2.1 LOW 5.5 MEDIUM
Uncaught exception in some Intel(R) Graphics Drivers before version 15.33.51.5146 may allow an authenticated user to potentially enable denial of service via local access.
CVE-2020-12384 1 Intel 1 Graphics Drivers 2021-02-22 4.6 MEDIUM 7.8 HIGH
Improper access control in some Intel(R) Graphics Drivers before version 26.20.100.8476 may allow an authenticated user to potentially enable an escalation of privilege via local access.
CVE-2020-0544 1 Intel 1 Graphics Drivers 2021-02-22 4.6 MEDIUM 7.8 HIGH
Insufficient control flow management in the kernel mode driver for some Intel(R) Graphics Drivers before version 15.36.39.5145 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2020-0521 1 Intel 1 Graphics Drivers 2021-02-22 4.6 MEDIUM 7.8 HIGH
Insufficient control flow management in some Intel(R) Graphics Drivers before version 15.45.32.5145 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2021-0109 1 Intel 2 Compute Stick Stk1a32sc, Compute Stick Stk1a32sc Firmware 2021-02-22 4.6 MEDIUM 7.8 HIGH
Insecure inherited permissions for the Intel(R) SOC driver package for STK1A32SC before version 604 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2020-8678 1 Intel 1 Graphics Drivers 2021-02-22 4.6 MEDIUM 7.8 HIGH
Improper access control for Intel(R) Graphics Drivers before version 15.45.33.5164 and 27.20.100.8280 may allow an authenticated user to potentially enable an escalation of privilege via local access.
CVE-2020-12339 1 Intel 1 Collaboration Suite 2021-02-22 6.5 MEDIUM 8.8 HIGH
Insufficient control flow management in the API for the Intel(R) Collaboration Suite for WebRTC before version 4.3.1 may allow an authenticated user to potentially enable escalation of privilege via network access.
CVE-2021-21472 1 Sap 1 Software Provisioning Manager 2021-02-16 6.5 MEDIUM 8.8 HIGH
SAP Software Provisioning Manager 1.0 (SAP NetWeaver Master Data Management Server 7.1) does not have an option to set password during its installation, this allows an authenticated attacker to perform various security attacks like Directory Traversal, Password Brute force Attack, SMB Relay attack, Security Downgrade.
CVE-2021-25141 2 Arubanetworks, Hpe 30 Aruba 2530ya, Aruba 2530ya Firmware, Aruba 2530yb and 27 more 2021-02-16 4.9 MEDIUM 4.4 MEDIUM
A security vulnerability has been identified in in certain HPE and Aruba L2/L3 switch firmware. A data processing error due to improper handling of an unexpected data type in user supplied information to the switch's management interface has been identified. The data processing error could be exploited to cause a crash or reboot in the switch management interface and/or possibly the switch itself leading to local denial of service (DoS). The user must have administrator privileges to exploit this vulnerability.
CVE-2020-27259 1 Omron 4 Cx-one, Cx-position, Cx-protocol and 1 more 2021-02-10 6.8 MEDIUM 8.8 HIGH
The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which may allow an attacker to remotely execute arbitrary code.
CVE-2020-4996 1 Ibm 1 Security Identity Governance And Intelligence 2021-02-10 2.1 LOW 5.5 MEDIUM
IBM Security Identity Governance and Intelligence 5.2.6 could allow a local user to obtain sensitive information via the capturing of screenshots of authentication credentials. IBM X-Force ID: 192913.
CVE-2020-27904 1 Apple 1 Macos 2021-02-10 9.3 HIGH 7.8 HIGH
A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1. An application may be able to execute arbitrary code with kernel privileges.
CVE-2020-27222 1 Eclipse 1 Californium 2021-02-09 5.0 MEDIUM 7.5 HIGH
In Eclipse Californium version 2.3.0 to 2.6.0, the certificate based (x509 and RPK) DTLS handshakes accidentally fails, because the DTLS server side sticks to a wrong internal state. That wrong internal state is set by a previous certificate based DTLS handshake failure with TLS parameter mismatch. The DTLS server side must be restarted to recover this. This allow clients to force a DoS.
CVE-2020-8807 1 Electriccoin 1 Zcashd 2021-02-08 5.0 MEDIUM 5.3 MEDIUM
In Electric Coin Company Zcashd before 2.1.1-1, the time offset between messages could be leveraged to obtain sensitive information about the relationship between a suspected victim's address and an IP address, aka a timing side channel.
CVE-2020-28449 1 Decal Project 1 Decal 2021-02-08 7.5 HIGH 8.6 HIGH
This affects all versions of package decal. The vulnerability is in the set function.
CVE-2020-28450 1 Decal Project 1 Decal 2021-02-08 7.5 HIGH 8.6 HIGH
This affects all versions of package decal. The vulnerability is in the extend function.
CVE-2020-35481 1 Solarwinds 1 Serv-u 2021-02-05 7.5 HIGH 9.8 CRITICAL
SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection.
CVE-2021-25912 1 Dotty Project 1 Dotty 2021-02-05 7.5 HIGH 9.8 CRITICAL
Prototype pollution vulnerability in 'dotty' versions 0.0.1 through 0.1.0 allows attackers to cause a denial of service and may lead to remote code execution.
CVE-2021-23329 1 Getadigital 1 Nested-object-assign 2021-02-05 5.0 MEDIUM 7.5 HIGH
The package nested-object-assign before 1.0.4 are vulnerable to Prototype Pollution via the default function, as demonstrated by running the PoC below.