Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-3254 1 Asus 2 Dsl-n14u-b1, Dsl-n14u-b1 Firmware 2022-07-12 7.8 HIGH 7.5 HIGH
Asus DSL-N14U-B1 1.1.2.3_805 allows remote attackers to cause a Denial of Service (DoS) via a TCP SYN scan using nmap.
CVE-2021-33823 1 Moxa 2 Mgate Mb3180, Mgate Mb3180 Firmware 2022-07-12 5.0 MEDIUM 7.5 HIGH
An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attacker could send a huge amount of TCP SYN packet to make web service's resource exhausted. Then the web server is denial-of-service.
CVE-2021-37109 1 Huawei 1 Emui 2022-07-12 4.6 MEDIUM 7.8 HIGH
There is a security protection bypass vulnerability with the modem.Successful exploitation of this vulnerability may cause memory protection failure.
CVE-2021-43223 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2022-07-12 4.6 MEDIUM 7.8 HIGH
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
CVE-2021-39752 1 Google 1 Android 2022-07-12 4.6 MEDIUM 7.8 HIGH
In Bubbles, there is a possible way to interfere with Bubbles due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-202756848
CVE-2021-43240 1 Microsoft 4 Windows 10, Windows 11, Windows Server and 1 more 2022-07-12 4.6 MEDIUM 7.8 HIGH
NTFS Set Short Name Elevation of Privilege Vulnerability
CVE-2021-43228 1 Microsoft 5 Windows 10, Windows 11, Windows Server and 2 more 2022-07-12 7.8 HIGH 7.5 HIGH
SymCrypt Denial of Service Vulnerability
CVE-2021-3134 1 Mubu 1 Mubu 2022-07-12 4.6 MEDIUM 7.8 HIGH
Mubu 2.2.1 allows local users to gain privileges to execute commands, aka CNVD-2020-68878.
CVE-2021-40441 1 Microsoft 5 Windows 7, Windows 8.1, Windows Rt 8.1 and 2 more 2022-07-12 4.6 MEDIUM 7.8 HIGH
Windows Media Center Elevation of Privilege Vulnerability
CVE-2021-38539 1 Netgear 24 D8500, D8500 Firmware, R6400 and 21 more 2022-07-12 6.5 MEDIUM 8.8 HIGH
Certain NETGEAR devices are affected by privilege escalation. This affects D8500 before 1.0.3.44, R6400v2 before 1.0.2.66, R6700 before 1.0.2.6, R6700v3 before 1.0.2.66, R6900 before 1.0.2.4, R6900P before 1.3.2.126, R7000 before 1.0.9.42, R7000P before 1.3.2.126, R7100LG before 1.0.0.50, R7300DST before 1.0.0.70, R7900 before 1.0.3.10, R8300 before 1.0.2.130, and R8500 before 1.0.2.130.
CVE-2021-43145 1 Zammad 1 Zammad 2022-07-12 5.5 MEDIUM 8.1 HIGH
With certain LDAP configurations, Zammad 5.0.1 was found to be vulnerable to unauthorized access with existing user accounts.
CVE-2020-9213 1 Huawei 16 Ngfw Module, Ngfw Module Firmware, Nip6300 and 13 more 2022-07-12 5.0 MEDIUM 7.5 HIGH
There is a denial of service vulnerability in some huawei products. In specific scenarios, due to the improper handling of the packets, an attacker may craft many specific packets. Successful exploit may cause some services to be abnormal. Affected products include some versions of NGFW Module, NIP6300, NIP6600, NIP6800, Secospace USG6300, Secospace USG6500, Secospace USG6600 and SG9500.
CVE-2021-28818 2 Microsoft, Tibco 2 Windows, Rendezvous 2022-07-12 4.6 MEDIUM 7.8 HIGH
The Rendezvous Routing Daemon (rvrd), Rendezvous Secure Routing Daemon (rvrsd), Rendezvous Secure Daemon (rvsd), Rendezvous Cache (rvcache), Rendezvous Secure C API, Rendezvous Java API, and Rendezvous .Net API components of TIBCO Software Inc.'s TIBCO Rendezvous and TIBCO Rendezvous Developer Edition contain a vulnerability that theoretically allows a low privileged attacker with local access on the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from the affected component searching for run-time artifacts outside of the installation hierarchy. Affected releases are TIBCO Software Inc.'s TIBCO Rendezvous: versions 8.5.1 and below and TIBCO Rendezvous Developer Edition: versions 8.5.1 and below.
CVE-2021-0959 1 Google 1 Android 2022-07-12 7.2 HIGH 7.8 HIGH
In jit_memory_region.cc, there is a possible bypass of memory restrictions due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-200284993
CVE-2021-45700 1 Nervos 1 Ckb 2022-07-12 7.8 HIGH 7.5 HIGH
An issue was discovered in the ckb crate before 0.40.0 for Rust. Attackers can cause a denial of service (Nervos CKB blockchain node crash) via a dead call that is used as a DepGroup.
CVE-2021-45510 1 Netgear 2 Xr1000, Xr1000 Firmware 2022-07-12 5.8 MEDIUM 8.8 HIGH
NETGEAR XR1000 devices before 1.0.0.58 are affected by authentication bypass.
CVE-2021-43245 1 Microsoft 5 Windows 7, Windows 8.1, Windows Rt 8.1 and 2 more 2022-07-12 4.6 MEDIUM 7.8 HIGH
Windows Digital TV Tuner Elevation of Privilege Vulnerability
CVE-2021-43239 1 Microsoft 4 Windows 10, Windows 11, Windows Server and 1 more 2022-07-12 4.6 MEDIUM 7.8 HIGH
Windows Recovery Environment Agent Elevation of Privilege Vulnerability
CVE-2021-38950 1 Ibm 1 Mq For Hpe Nonstop 2022-07-12 4.4 MEDIUM 7.8 HIGH
IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation attack when SharedBindingsUserId is set to effective. IBM X-ForceID: 211404.
CVE-2020-12902 2 Amd, Microsoft 2 Radeon Software, Windows 10 2022-07-12 4.6 MEDIUM 7.8 HIGH
Arbitrary Decrement Privilege Escalation in AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service.
CVE-2021-22292 1 Huawei 2 Ecns280, Ecns280 Firmware 2022-07-12 7.8 HIGH 7.5 HIGH
There is a denial of service (DoS) vulnerability in eCNS280 versions V100R005C00, V100R005C10. Due to a design defect, remote unauthorized attackers send a large number of specific messages to affected devices, causing system resource exhaustion and web application DoS.
CVE-2020-12964 1 Amd 1 Radeon Software 2022-07-12 4.6 MEDIUM 7.8 HIGH
A potential privilege escalation/denial of service issue exists in the AMD Radeon Kernel Mode driver Escape 0x2000c00 Call handler. An attacker with low privilege could potentially induce a Windows BugCheck or write to leak information.
CVE-2021-22314 1 Huawei 1 Manageone 2022-07-12 4.6 MEDIUM 7.8 HIGH
There is a local privilege escalation vulnerability in some versions of ManageOne. A local authenticated attacker could perform specific operations to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege and compromise the service.
CVE-2020-25736 1 Acronis 1 True Image 2022-07-12 4.6 MEDIUM 7.8 HIGH
Acronis True Image 2019 update 1 through 2021 update 1 on macOS allows local privilege escalation due to an insecure XPC service configuration.
CVE-2020-15495 1 Acronis 1 True Image 2022-07-12 4.6 MEDIUM 7.8 HIGH
Acronis True Image 2019 update 1 through 2020 on macOS allows local privilege escalation due to an insecure XPC service configuration.
CVE-2021-43196 1 Jetbrains 1 Teamcity 2022-07-12 5.0 MEDIUM 7.5 HIGH
In JetBrains TeamCity before 2021.1, information disclosure via the Docker Registry connection dialog is possible.
CVE-2020-6931 1 Hp 1 Print And Scan Doctor 2022-07-12 4.6 MEDIUM 7.8 HIGH
HP Print and Scan Doctor may potentially be vulnerable to local elevation of privilege.
CVE-2021-36922 1 Realtek 1 Rtsupx Usb Utility Driver 2022-07-12 7.2 HIGH 7.8 HIGH
RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve unauthorized access to USB devices (Escalation of Privileges, Denial of Service, Code Execution, and Information Disclosure) via a crafted Device IO Control packet to a device.
CVE-2021-41504 1 Dlink 4 Dcs-5000l, Dcs-5000l Firmware, Dcs-932l and 1 more 2022-07-12 5.2 MEDIUM 8.0 HIGH
** UNSUPPORTED WHEN ASSIGNED ** An Elevated Privileges issue exists in D-Link DCS-5000L v1.05 and DCS-932L v2.17 and older. The use of the digest-authentication for the devices command interface may allow further attack vectors that may compromise the cameras configuration and allow malicious users on the LAN to access the device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2021-22506 1 Microfocus 1 Access Manager 2022-07-12 5.0 MEDIUM 7.5 HIGH
Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage.
CVE-2021-3440 1 Hp 1 Hp Smart 2022-07-12 4.6 MEDIUM 7.8 HIGH
HP Print and Scan Doctor, an application within the HP Smart App for Windows, is potentially vulnerable to local elevation of privilege.
CVE-2020-12900 2 Amd, Microsoft 2 Radeon Software, Windows 10 2022-07-12 4.6 MEDIUM 7.8 HIGH
An arbitrary write vulnerability in the AMD Radeon Graphics Driver for Windows 10 potentially allows unprivileged users to gain Escalation of Privileges and cause Denial of Service.
CVE-2021-37254 1 M-files 1 M-files Web 2022-07-12 5.0 MEDIUM 7.5 HIGH
In M-Files Web product with versions before 20.10.9524.1 and 20.10.9445.0, a remote attacker could use a flaw to obtain unauthenticated access to 3rd party component license key information on server.
CVE-2021-36991 1 Huawei 2 Emui, Magic Ui 2022-07-12 5.0 MEDIUM 7.5 HIGH
There is an Unauthorized file access vulnerability in Huawei Smartphone due to unstandardized path input.Successful exploitation of this vulnerability by creating malicious file paths can cause unauthorized file access.
CVE-2021-22470 1 Huawei 1 Harmonyos 2022-07-12 4.6 MEDIUM 7.8 HIGH
A component of the HarmonyOS has a Privileges Controls vulnerability. Local attackers may exploit this vulnerability to expand the Recording Trusted Domain.
CVE-2021-22034 1 Vmware 1 Vrealize Operations Tenant 2022-07-12 5.0 MEDIUM 7.5 HIGH
Releases prior to VMware vRealize Operations Tenant App 8.6 contain an Information Disclosure Vulnerability.
CVE-2021-42086 1 Zammad 1 Zammad 2022-07-12 6.5 MEDIUM 8.8 HIGH
An issue was discovered in Zammad before 4.1.1. An Agent account can modify account data, and gain admin access, via a crafted request.
CVE-2021-41869 1 Salesagility 1 Suitecrm 2022-07-12 6.5 MEDIUM 8.8 HIGH
SuiteCRM 7.10.x before 7.10.33 and 7.11.x before 7.11.22 is vulnerable to privilege escalation.
CVE-2021-37274 1 Kingdee 1 Kis Cloud 2022-07-12 8.5 HIGH 8.8 HIGH
Kingdee KIS Professional Edition has a privilege escalation vulnerability. Attackers can use the vulnerability to gain computer administrator rights via unspecified loopholes.
CVE-2021-40104 1 Concretecms 1 Concrete Cms 2022-07-12 5.0 MEDIUM 7.5 HIGH
An issue was discovered in Concrete CMS through 8.5.5. There is an SVG sanitizer bypass.
CVE-2021-41011 1 Linecorp 1 Line 2022-07-12 4.3 MEDIUM 7.5 HIGH
LINE client for iOS before 11.15.0 might expose authentication information for a certain service to external entities under certain conditions. This is usually impossible, but in combination with a server-side bug, attackers could get this information.
CVE-2021-30798 1 Apple 3 Iphone Os, Macos, Watchos 2022-07-12 7.8 HIGH 7.5 HIGH
A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6. A malicious application may be able to bypass certain Privacy preferences.
CVE-2021-42773 1 Broadcom 1 Emulex Hba Manager 2022-07-12 5.0 MEDIUM 7.5 HIGH
Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly Local Management mode, could allow a user to retrieve an arbitrary file from a remote host with the GetDumpFile command. In non-secure mode, the user is unauthenticated.
CVE-2021-40385 1 Kaseya 1 Unitrends Backup Software 2022-07-12 9.0 HIGH 8.8 HIGH
An issue was discovered in the server software in Kaseya Unitrends Backup Software before 10.5.5-2. There is a privilege escalation from read-only user to admin.
CVE-2021-37349 1 Nagios 1 Nagios Xi 2022-07-12 4.6 MEDIUM 7.8 HIGH
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because cleaner.php does not sanitise input read from the database.
CVE-2021-22449 1 Huawei 1 Elf-g10hn 2022-07-12 5.0 MEDIUM 7.5 HIGH
There is a logic vulnerability in Elf-G10HN 1.0.0.608. An unauthenticated attacker could perform specific operations to exploit this vulnerability. Due to insufficient security design, successful exploit could allow an attacker to add users to be friends without prompting in the target device.
CVE-2021-38088 2 Acronis, Microsoft 2 Cyber Protect, Windows 2022-07-12 4.6 MEDIUM 7.8 HIGH
Acronis Cyber Protect 15 for Windows prior to build 27009 allowed local privilege escalation via binary hijacking.
CVE-2021-29765 1 Ibm 1 Powervm 2022-07-12 5.0 MEDIUM 7.5 HIGH
IBM PowerVM Hypervisor FW940 and FW950 could allow an attacker to obtain sensitive information if they gain service access to the FSP. IBM X-Force ID: 202476.
CVE-2021-29741 1 Ibm 2 Aix, Vios 2022-07-12 7.2 HIGH 7.8 HIGH
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in Korn Shell (ksh) to gain root privileges. IBM X-Force ID: 201478.
CVE-2021-25646 1 Apache 1 Druid 2022-07-12 9.0 HIGH 8.8 HIGH
Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it is possible for an authenticated user to send a specially-crafted request that forces Druid to run user-provided JavaScript code for that request, regardless of server configuration. This can be leveraged to execute code on the target machine with the privileges of the Druid server process.