Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by NVD-CWE-noinfo
Total 22706 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-1262 2 Cloudfoundry, Pivotal Software 3 Cf-deployment, Cloud Foundry Uaa, Cloud Foundry Uaa-release 2021-08-17 6.5 MEDIUM 7.2 HIGH
Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clients performing offline validation. A zone administrator could configure their zone to issue tokens which impersonate another zone, granting up to admin privileges in the impersonated zone for clients performing offline token validation.
CVE-2021-38565 1 Foxitsoftware 2 Pdf Editor, Pdf Reader 2021-08-16 5.0 MEDIUM 7.5 HIGH
An issue was discovered in Foxit PDF Reader before 11.0.1 and PDF Editor before 11.0.1. It allows writing to arbitrary files via submitForm.
CVE-2020-36472 1 Max7301 Project 1 Max7301 2021-08-16 4.3 MEDIUM 5.9 MEDIUM
An issue was discovered in the max7301 crate before 0.2.0 for Rust. The ImmediateIO and TransactionalIO types implement Sync for all Expander<EI> types that they contain.
CVE-2020-36471 1 Generator Project 1 Generator 2021-08-16 4.3 MEDIUM 5.9 MEDIUM
An issue was discovered in the generator crate before 0.7.0 for Rust. It does not ensure that a function (for yielding values) has Send bounds.
CVE-2020-36470 1 Disrustor Project 1 Disrustor 2021-08-16 4.3 MEDIUM 5.9 MEDIUM
An issue was discovered in the disrustor crate through 2020-12-17 for Rust. RingBuffer doe not properly limit the number of mutable references.
CVE-2020-36469 1 Appendix Project 1 Appendix 2021-08-16 4.3 MEDIUM 5.9 MEDIUM
An issue was discovered in the appendix crate through 2020-11-15 for Rust. For the generic K and V type parameters, Send and Sync are implemented unconditionally.
CVE-2020-36468 1 Cgc Project 1 Cgc 2021-08-16 4.3 MEDIUM 5.9 MEDIUM
An issue was discovered in the cgc crate through 2020-12-10 for Rust. Ptr::write performs non-atomic write operations on an underlying pointer.
CVE-2020-36453 1 Scottqueue Project 1 Scottqueue 2021-08-16 6.8 MEDIUM 8.1 HIGH
An issue was discovered in the scottqueue crate through 2020-11-15 for Rust. There are unconditional implementations of Send and Sync for Queue<T>.
CVE-2021-38194 1 Arcworks 1 Ark-r1cs-std 2021-08-16 7.5 HIGH 9.8 CRITICAL
An issue was discovered in the ark-r1cs-std crate before 0.3.1 for Rust. It does not enforce any constraints in the FieldVar::mul_by_inverse method. Thus, a prover can produce a proof that is unsound but is nonetheless verified.
CVE-2020-36466 1 Cgc Project 1 Cgc 2021-08-16 4.3 MEDIUM 5.9 MEDIUM
An issue was discovered in the cgc crate through 2020-12-10 for Rust. Ptr implements Send and Sync for all types.
CVE-2020-36467 1 Cgc Project 1 Cgc 2021-08-16 4.3 MEDIUM 5.9 MEDIUM
An issue was discovered in the cgc crate through 2020-12-10 for Rust. Ptr::get returns more than one mutable reference to the same object.
CVE-2020-36465 1 Generic-array Project 1 Generic-array 2021-08-16 5.0 MEDIUM 7.5 HIGH
An issue was discovered in the generic-array crate before 0.13.3 for Rust. It violates soundness by using the arr! macro to extend lifetimes.
CVE-2021-1721 1 Microsoft 5 .net, .net Core, Powershell Core and 2 more 2021-08-16 4.3 MEDIUM 6.5 MEDIUM
.NET Core and Visual Studio Denial of Service Vulnerability
CVE-2021-26586 1 Hp 1 Edgeline Infrastructure Management 2021-08-13 5.0 MEDIUM 7.5 HIGH
A potential security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software. The vulnerability could be remotely exploited to disclose sensitive information. HPE has made software updates available to resolve the vulnerability in the HPE Edgeline Infrastructure Manager (EIM).
CVE-2021-22920 1 Citrix 2 Application Delivery Management, Gateway 2021-08-13 4.3 MEDIUM 6.5 MEDIUM
A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to a phishing attack through a SAML authentication hijack to steal a valid user session.
CVE-2021-29978 1 Mozilla 1 Mozilla Vpn 2021-08-13 10.0 HIGH 9.8 CRITICAL
Multiple low security issues were discovered and fixed in a security audit of Mozilla VPN 2.x branch as part of a 3rd party security audit. This vulnerability affects Mozilla VPN < 2.3.
CVE-2017-5947 1 Oneplus 7 Oneplus 2, Oneplus 3, Oneplus 3t and 4 more 2021-08-12 4.6 MEDIUM 6.8 MEDIUM
An issue was discovered in OnePlus One, X, 2, 3, 3T, and 5 devices with OxygenOS 5.0 and earlier. The attacker can reboot the device into the Qualcomm Emergency Download (EDL) mode through ADB or by using Volume-Up when connected to USB, which in turn could allow for downgrading partitions such as the Android Bootloader.
CVE-2017-4942 1 Vmware 1 Airwatch Console 2021-08-12 4.0 MEDIUM 4.9 MEDIUM
VMware AirWatch Console (AWC) contains a Broken Access Control vulnerability. Successful exploitation of this issue could result in end-user device details being disclosed to an unauthorized administrator.
CVE-2018-1256 1 Vmware 1 Spring Cloud Sso Connector 2021-08-12 6.8 MEDIUM 8.1 HIGH
Spring Cloud SSO Connector, version 2.1.2, contains a regression which disables issuer validation in resource servers that are not bound to the SSO service. In PCF deployments with multiple SSO service plans, a remote attacker can authenticate to unbound resource servers which use this version of the SSO Connector with tokens generated from another service plan.
CVE-2021-38573 1 Foxitsoftware 2 Foxit Reader, Phantompdf 2021-08-12 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because a CombineFiles pathname is not validated.