Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2021-09-02 CVE-2021-35996 Out-of-bounds Write vulnerability in Adobe After Effects
Adobe After Effects version 18.2.1 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file.
local
low complexity
adobe CWE-787
7.8
2021-09-02 CVE-2021-21086 Out-of-bounds Write vulnerability in Adobe products
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an Out-of-bounds Write vulnerability in the CoolType library.
local
low complexity
adobe CWE-787
7.8
2021-09-02 CVE-2021-39187 Improper Handling of Exceptional Conditions vulnerability in Parseplatform Parse-Server
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js.
network
low complexity
parseplatform CWE-755
7.5
2021-09-02 CVE-2021-33928 Out-of-bounds Write vulnerability in Opensuse Libsolv
Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
network
low complexity
opensuse CWE-787
7.5
2021-09-02 CVE-2021-33929 Out-of-bounds Write vulnerability in Opensuse Libsolv
Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
network
low complexity
opensuse CWE-787
7.5
2021-09-02 CVE-2021-33930 Out-of-bounds Write vulnerability in Opensuse Libsolv
Buffer overflow vulnerability in function pool_installable_whatprovides in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
network
low complexity
opensuse CWE-787
7.5
2021-09-02 CVE-2021-33938 Out-of-bounds Write vulnerability in Opensuse Libsolv
Buffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
network
low complexity
opensuse CWE-787
7.5
2021-09-02 CVE-2021-31796 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Cyberark Credential Provider
An inadequate encryption vulnerability discovered in CyberArk Credential Provider before 12.1 may lead to Information Disclosure.
network
low complexity
cyberark CWE-327
7.5
2021-09-01 CVE-2021-39115 Code Injection vulnerability in Atlassian Jira Service Desk
Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to execute arbitrary Java code or run arbitrary system commands via a Server_Side Template Injection vulnerability in the Email Template feature.
network
low complexity
atlassian CWE-94
7.2
2021-09-01 CVE-2021-40385 Unspecified vulnerability in Kaseya Unitrends Backup Software
An issue was discovered in the server software in Kaseya Unitrends Backup Software before 10.5.5-2.
network
low complexity
kaseya
8.8