Unknown · CVSS Not scored
A flaw was found in Cloudforms. A role-based privileges escalation flaw where export or import of administrator files is possible. An attacker with a specific group can perform actions restricted only to system administrator. This is the affect of an incomplete fix for CVE-2020-10783. The highest threat from this vulnerability is to data confidentiality and integrity. Versions before cfme 5.11.10.1 are affected
Published Jun 7, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitrary PHP code.
Published Jun 17, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The id paramater in Online Shopping Alphaware 1.0 has been discovered to be vulnerable to an Error-Based blind SQL injection in the /alphaware/details.php path. This allows an attacker to retrieve all databases.
Published Jun 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A null pointer dereference was discovered lzo_decompress_buf in stream.c in Irzip 0.621 which allows an attacker to cause a denial of service (DOS) via a crafted compressed file.
Published Jun 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in function sync_tree in hetero_decision_tree_guest.py in WeBank FATE (Federated AI Technology Enabler) 0.1 through 1.4.2 allows attackers to read sensitive information during the training process of machine learning joint modeling.
Published Jun 16, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Prototype pollution in Stampit supermixer 1.0.3 allows an attacker to modify the prototype of a base object which can vary in severity depending on the implementation.
Published Jun 16, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Libraw before 0.20.1 has a stack buffer overflow via LibRaw::identify_process_dng_fields in identify.cpp.
Published Jun 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The catID parameter in Pharmacy Medical Store and Sale Point v1.0 has been found to be vulnerable to a Time-Based blind SQL injection via the /medical/inventories.php path which allows attackers to retrieve all databases.
Published Jun 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Trace Financial CRESTBridge <6.3.0.02 contains an authenticated SQL injection vulnerability, which was fixed in 6.3.0.03.
Published Jun 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Trace Financial Crest Bridge <6.3.0.02 contains a stored XSS vulnerability, which was fixed in 6.3.0.03.
Published Jun 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Trace Financial CRESTBridge <6.3.0.02 contains an authenticated SQL injection vulnerability, which was fixed in 6.3.0.03.
Published Jun 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SmartStream Transaction Lifecycle Management (TLM) Reconciliation Premium (RP) <3.1.0 allows XSS. This was fixed in TLM RP 3.1.0.
Published Jun 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Trace Financial CRESTBridge <6.3.0.02 contains a stored XSS vulnerability, which was fixed in 6.3.0.03.
Published Jun 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access.
Published Jun 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.48.ce3e3bd2 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.
Published Jun 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Observable timing discrepancy in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Published Jun 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Insufficient control flow management in subsystem in Intel(R) SPS versions before SPS_E3_05.01.04.300.0, SPS_SoC-A_05.00.03.091.0, SPS_E5_04.04.04.023.0, or SPS_E5_04.04.03.263.0 may allow a privileged user to potentially enable escalation of privilege via local access.
Published Jun 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.
Published Jun 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Out of bound read in a subsystem in the Intel(R) CSME versions before 12.0.81, 13.0.47, 13.30.17, 14.1.53 and 14.5.32 may allow a privileged user to potentially enable information disclosure via local access.
Published Jun 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Published Jun 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Improper initialization in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32, 13.50.11 and 15.0.22 may allow a privileged user to potentially enable information disclosure via local access.
Published Jun 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Modification of assumed-immutable data in subsystem in Intel(R) CSME versions before 13.0.47, 13.30.17, 14.1.53, 14.5.32, 15.0.22 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
Published Jun 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Improper authentication in some Intel(R) RealSense(TM) IDs may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
Published Jun 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Out of bounds write in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.48.ce3e3bd2 may allow an authenticated user to potentially enable escalation of privilege via local access.
Published Jun 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Protection mechanism failure in some Intel(R) RealSense(TM) IDs may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
Published Jun 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Domain-bypass transient execution vulnerability in some Intel Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Published Jun 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Improper initialization in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.48.ce3e3bd2 may allow an authenticated user to potentially enable denial of service via local access.
Published Jun 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A cross site scripting (XSS) vulnerability in Catfish CMS 4.9.90 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "announcement_gonggao" parameter.
Published Jun 23, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection vulnerability in NavigateCMS 2.9 via the URL encoded GET input category in navigate.php.
Published Jun 28, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Directory Traversal vulnerability in Webport CMS 1.19.10.17121 via the file parameter to file/download.
Published Jun 28, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) vulneraiblity in LimeSurvey 4.2.5 on textbox via the Notifications & data feature.
Published Jun 28, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
There is a heap-buffer-overflow at re-parser.c in re_parse_char_escape in JerryScript 2.2.0.
Published Jun 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
There is an Assertion 'context_p->stack_depth == context_p->context_stack_depth' failed at js-parser-statm.c:2756 in parser_parse_statements in JerryScript 2.2.0.
Published Jun 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
There is an Assertion in 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' in parser_parse_function_arguments in JerryScript 2.2.0.
Published Jun 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
There is an Assertion in 'context_p->token.type == LEXER_RIGHT_BRACE || context_p->token.type == LEXER_ASSIGN || context_p->token.type == LEXER_COMMA' in parser_parse_object_initializer in JerryScript 2.2.0.
Published Jun 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
There is an Assertion 'context_p->token.type == LEXER_RIGHT_BRACE || context_p->token.type == LEXER_ASSIGN || context_p->token.type == LEXER_COMMA' failed at js-parser-expr.c:3230 in parser_parse_object_initializer in JerryScript 2.2.0.
Published Jun 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
There is an Assertion 'block_found' failed at js-parser-statm.c:2003 parser_parse_try_statement_end in JerryScript 2.2.0.
Published Jun 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
There is a heap-buffer-overflow at jmem-poolman.c:165 in jmem_pools_collect_empty in JerryScript 2.2.0.
Published Jun 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
There is an Assertion 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' failed at js-parser-statm.c:733 in parser_parse_function_statement in JerryScript 2.2.0.
Published Jun 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
There is an Assertion 'context_p->stack_top_uint8 == LEXER_EXPRESSION_START' at js-parser-expr.c:3565 in parser_parse_expression in JerryScript 2.2.0.
Published Jun 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
There is an Assertion 'scope_stack_p > context_p->scope_stack_p' failed at js-scanner-util.c:2510 in scanner_literal_is_created in JerryScript 2.2.0
Published Jun 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
There is a heap-use-after-free at ecma-helpers-string.c:772 in ecma_ref_ecma_string in JerryScript 2.2.0
Published Jun 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
There is a stack-overflow at ecma-regexp-object.c:535 in ecma_regexp_match in JerryScript 2.2.0.
Published Jun 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
There is an Assertion in '(flags >> CBC_STACK_ADJUST_SHIFT) >= CBC_STACK_ADJUST_BASE || (CBC_STACK_ADJUST_BASE - (flags >> CBC_STACK_ADJUST_SHIFT)) <= context_p->stack_depth' in parser_emit_cbc_backward_branch in JerryScript 2.2.0.
Published Jun 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
There is an Assertion 'context.status_flags & PARSER_SCANNING_SUCCESSFUL' failed at js-parser.c:2185 in parser_parse_source in JerryScript 2.2.0.
Published Jun 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
There is a heap-buffer-overflow at lit-strings.c:431 in lit_read_code_unit_from_utf8 in JerryScript 2.2.0.
Published Jun 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting vulnerabilty in LimeSurvey 4.1.11+200316 via the (1) name and (2) description parameters in application/controllers/admin/PermissiontemplatesController.php.
Published Jun 28, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter in include/class.queue.php.
Published Jun 28, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the config_input function in af_acrossover.c.
Published Jun 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection in ECShop 3.0 via the aid parameter to admin/affiliate_ck.php.
Published Jun 16, 2021 · Updated Aug 4, 2024