Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2021-09-17 CVE-2020-12080 Improper Input Validation vulnerability in Flexera Flexnet Publisher 11.16.6
A Denial of Service vulnerability has been identified in FlexNet Publisher's lmadmin.exe version 11.16.6.
network
low complexity
flexera CWE-20
7.5
2021-09-17 CVE-2021-40825 Insecure Default Initialization of Resource vulnerability in Acuitybrands Nlight Eclypse System Controller Firmware
nLight ECLYPSE (nECY) system Controllers running software prior to 1.17.21245.754 contain a default key vulnerability.
network
low complexity
acuitybrands CWE-1188
8.6
2021-09-17 CVE-2019-9060 Path Traversal vulnerability in Cmsmadesimple CMS Made Simple 2.2.8
An issue was discovered in CMS Made Simple 2.2.8.
network
low complexity
cmsmadesimple CWE-22
7.5
2021-09-17 CVE-2021-38304 Improper Input Validation vulnerability in NI Ni-Pal 20.0.0
Improper input validation in the National Instruments NI-PAL driver in versions 20.0.0 and prior may allow a privileged user to potentially enable escalation of privilege via local access.
local
low complexity
ni CWE-20
7.8
2021-09-17 CVE-2021-41315 OS Command Injection vulnerability in Device42 Remote Collector
The Device42 Remote Collector before 17.05.01 does not sanitize user input in its SNMP Connectivity utility.
network
low complexity
device42 CWE-78
8.8
2021-09-17 CVE-2021-41316 Argument Injection or Modification vulnerability in Device42
The Device42 Main Appliance before 17.05.01 does not sanitize user input in its Nmap Discovery utility.
network
low complexity
device42 CWE-88
8.1
2021-09-17 CVE-2021-31843 Link Following vulnerability in Mcafee Endpoint Security
Improper privileges management vulnerability in McAfee Endpoint Security (ENS) Windows prior to 10.7.0 September 2021 Update allows local users to access files which they would otherwise not have access to via manipulating junction links to redirect McAfee folder operations to an unintended location.
local
low complexity
mcafee CWE-59
7.8
2021-09-17 CVE-2021-31844 Classic Buffer Overflow vulnerability in Mcafee Data Loss Prevention Endpoint
A buffer overflow vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.200 allows a local attacker to execute arbitrary code with elevated privileges through placing carefully constructed Ami Pro (.sam) files onto the local system and triggering a DLP Endpoint scan through accessing a file.
local
low complexity
mcafee CWE-120
7.3
2021-09-17 CVE-2021-31845 Classic Buffer Overflow vulnerability in Mcafee Data Loss Prevention Discover
A buffer overflow vulnerability in McAfee Data Loss Prevention (DLP) Discover prior to 11.6.100 allows an attacker in the same network as the DLP Discover to execute arbitrary code through placing carefully constructed Ami Pro (.sam) files onto a machine and having DLP Discover scan it, leading to remote code execution with elevated privileges.
local
low complexity
mcafee CWE-120
7.3
2021-09-17 CVE-2021-1947 Use After Free vulnerability in Qualcomm products
Use-after-free vulnerability in kernel graphics driver because of storing an invalid pointer in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
local
low complexity
qualcomm CWE-416
7.8