Unknown · CVSS Not scored
EmTec ZOC through 8.02.4 allows remote servers to cause a denial of service (Windows GUI hang) by telling the ZOC window to change its title repeatedly at high speed, which results in many SetWindowTextA or SetWindowTextW calls. In other words, it does not implement a usleep or similar delay upon processing a title change.
Published Jun 6, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
In TrendNet TW100-S4W1CA 2.3.32, it is possible to inject arbitrary JavaScript into the router's web interface via the "echo" command.
Published Jun 17, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
FOGProject v1.5.9 is affected by a File Upload RCE (Authenticated).
Published Jun 16, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
In PageKit v1.0.18, a user can upload SVG files in the file upload portion of the CMS. These SVG files can contain malicious scripts. This file will be uploaded to the system and it will not be stripped or filtered. The user can create a link on the website pointing to "/storage/exp.svg" that will point to http://localhost/pagekit/storage/exp.svg. When a user comes along to click that link, it will trigger a XSS attack.
Published Jun 16, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An Out-of-Bounds Read was discovered in arch/arm/mach-footbridge/personal-pci.c in the Linux kernel through 5.12.11 because of the lack of a check for a value that shouldn't be negative, e.g., access to element -2 of an array, aka CID-298a58e165e4.
Published Jun 17, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
In Nuvoton NPCT75x TPM 1.2 firmware 7.4.0.0, a local authenticated malicious user with high privileges could potentially gain unauthorized access to TPM non-volatile memory. NOTE: Upgrading to firmware version 7.4.0.1 will mitigate against the vulnerability, but version 7.4.0.1 is not TCG or Common Criteria (CC) certified. Nuvoton recommends that users apply the NPCT75x TPM 1.2 firmware update.
Published Jun 8, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A flaw was found in postgresql in versions before 13.3, before 12.7, before 11.12, before 10.17 and before 9.6.22. While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Published Jun 1, 2021 · Updated Aug 3, 2024
High · CVSS 7.2
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
Medium · CVSS 5.5
Windows TCP/IP Driver Security Feature Bypass Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
Medium · CVSS 5.5
Microsoft Defender Denial of Service Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
Medium · CVSS 5.7
Microsoft SharePoint Server Information Disclosure Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 8.6
Windows Hyper-V Denial of Service Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 7.5
Server for NFS Information Disclosure Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 7.6
Microsoft SharePoint Server Spoofing Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 7.5
Server for NFS Denial of Service Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 7.8
Paint 3D Remote Code Execution Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 7.8
Microsoft Defender Remote Code Execution Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
Medium · CVSS 5.5
Event Tracing for Windows Information Disclosure Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An Insecure Direct Object Reference (IDOR) vulnerability in Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify any existing user, including users assigned to different environments and clients. It was fixed in v2021.1.0.2.
Published Jun 10, 2021 · Updated Aug 3, 2024
Medium · CVSS 6.8
Windows HTML Platforms Security Feature Bypass Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 7.8
Windows Kernel Elevation of Privilege Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 7.8
Windows Filter Manager Elevation of Privilege Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 7.8
Paint 3D Remote Code Execution Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 7.6
Microsoft SharePoint Server Spoofing Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 7.8
Microsoft Excel Remote Code Execution Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 7.8
3D Viewer Remote Code Execution Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify loyalty campaigns and settings, such as fraud prevention, coupon groups, email templates, or referrals.
Published Jun 10, 2021 · Updated Aug 3, 2024
High · CVSS 7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 7.5
Server for NFS Information Disclosure Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 7.8
VP9 Video Extensions Remote Code Execution Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 7.8
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 7.5
Windows Remote Desktop Services Denial of Service Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
Medium · CVSS 5.9
ASP.NET Core Denial of Service Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 7.8
Microsoft Office Graphics Remote Code Execution Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 7.1
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
Medium · CVSS 5.5
Windows Bind Filter Driver Information Disclosure Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 8.1
Microsoft Intune Management Extension Remote Code Execution Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
Critical · CVSS 9.4
Kerberos AppContainer Security Feature Bypass Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 7.8
Windows GPSVC Elevation of Privilege Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 7.8
3D Viewer Remote Code Execution Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to escalate privileges to superadministrator. It was fixed in v2021.1.0.2.
Published Jun 10, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotely exploitable vulnerability where an external client can access unexpected services in the cluster, bypassing authorization checks, when a gateway is configured with AUTO_PASSTHROUGH routing configuration.
Published Jun 2, 2021 · Updated Aug 3, 2024
High · CVSS 7.3
Microsoft VsCode Kubernetes Tools Extension Elevation of Privilege Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 7.8
Paint 3D Remote Code Execution Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 7.8
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 7.5
Windows NTLM Elevation of Privilege Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 7.8
Microsoft Office Graphics Remote Code Execution Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 7.6
Microsoft SharePoint Server Spoofing Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
Medium · CVSS 5
3D Viewer Information Disclosure Vulnerability
Published Jun 8, 2021 · Updated Aug 3, 2024
High · CVSS 7.3
A vulnerability in the preloading mechanism of specific dynamic link libraries in McAfee Agent for Windows prior to 5.7.3 could allow an authenticated, local attacker to perform a DLL preloading attack with unsigned DLLs. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. This would result in the user gaining elevated permissions and being able to execute arbitrary code.
Published Jun 10, 2021 · Updated Aug 3, 2024