Vulnerabilities (CVE)
1,704 pages, showing 801–900, ordered by identifier.
- CVE-2021-27101 — Accellion FTA SQL Injection Vulnerability Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html.
- CVE-2021-27102 — Accellion FTA OS Command Injection Vulnerability Accellion FTA contains an OS command injection vulnerability exploited via a local web service call.
- CVE-2021-27103 — Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to...
- CVE-2021-27104 — Accellion FTA OS Command Injection Vulnerability Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints.
- CVE-2021-27137 — DD-WRT Stack-Based Buffer Overflow Vulnerability DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow...
- CVE-2021-27561 — Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability Yealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for...
- CVE-2021-27562 — Arm Trusted Firmware Out-of-Bounds Write Vulnerability Arm Trusted Firmware contains an out-of-bounds write vulnerability allowing the non-secure (NS) world to trigger a...
- CVE-2021-27852 — Checkbox Survey Deserialization of Untrusted Data Vulnerability Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated...
- CVE-2021-27860 — FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote,...
- CVE-2021-27876 — Veritas Backup Exec Agent File Access Vulnerability Veritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an attacker to specially craft...
- CVE-2021-27877 — Veritas Backup Exec Agent Improper Authentication Vulnerability Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker...
- CVE-2021-27878 — Veritas Backup Exec Agent Command Execution Vulnerability Veritas Backup Exec (BE) Agent contains a command execution vulnerability that could allow an attacker to use a data...
- CVE-2021-28310 — Microsoft Win32k Privilege Escalation Vulnerability Microsoft Windows Win32k contains an unspecified vulnerability that allows for privilege escalation.
- CVE-2021-28550 — Adobe Acrobat and Reader Use-After-Free Vulnerability Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to...
- CVE-2021-28663 — Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability Arm Mali Graphics Processing Unit (GPU) kernel driver contains a use-after-free vulnerability that may allow a...
- CVE-2021-28664 — Arm Mali Graphics Processing Unit (GPU) Unspecified Vulnerability Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a...
- CVE-2021-28799 — QNAP NAS Improper Authorization Vulnerability QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in...
- CVE-2021-29256 — Arm Mali GPU Kernel Driver Use-After-Free Vulnerability Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root...
- CVE-2021-30116 — Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an...
- CVE-2021-30533 — Google Chromium PopupBlocker Security Bypass Vulnerability Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability that allows a remote attacker...
- CVE-2021-30551 — Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially...
- CVE-2021-30554 — Google Chromium WebGL Use-After-Free Vulnerability Google Chromium WebGL contains a use-after-free vulnerability that allows a remote attacker to potentially exploit...
- CVE-2021-30563 — Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially...
- CVE-2021-30632 — Google Chromium V8 Out-of-Bounds Write Vulnerability Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially...
- CVE-2021-30633 — Google Chromium Indexed DB API Use-After-Free Vulnerability Google Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker, who has...
- CVE-2021-30657 — Apple macOS Unspecified Vulnerability Apple macOS contains an unspecified logic issue in System Preferences that may allow a malicious application to...
- CVE-2021-30661 — Apple Multiple Products WebKit Storage Use-After-Free Vulnerability Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit Storage contain a use-after-free vulnerability that leads...
- CVE-2021-30663 — Apple Multiple Products WebKit Integer Overflow Vulnerability Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain an integer overflow vulnerability that leads to code...
- CVE-2021-30665 — Apple Multiple Products WebKit Memory Corruption Vulnerability Apple iOS, iPadOS, macOS, watchOS, and tvOS WebKit contain a memory corruption vulnerability that leads to code...
- CVE-2021-30666 — Apple iOS WebKit Buffer Overflow Vulnerability Apple iOS WebKit contains a buffer-overflow vulnerability that leads to code execution when processing maliciously...
- CVE-2021-30713 — Apple macOS Unspecified Vulnerability Apple macOS Transparency, Consent, and Control (TCC) contains an unspecified permissions issue which may allow a...
- CVE-2021-30761 — Apple iOS WebKit Memory Corruption Vulnerability Apple iOS WebKit contains a memory corruption vulnerability that leads to code execution when processing maliciously...
- CVE-2021-30762 — Apple iOS WebKit Use-After-Free Vulnerability Apple iOS WebKit contains a use-after-free vulnerability that leads to code execution when processing maliciously...
- CVE-2021-30807 — Apple Multiple Products Memory Corruption Vulnerability Apple iOS, iPadOS, macOS, and watchOS IOMobileFrameBuffer contain a memory corruption vulnerability which may allow...
- CVE-2021-30858 — Apple iOS, iPadOS, macOS Use-After-Free Vulnerability Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when...
- CVE-2021-30860 — Apple Multiple Products Integer Overflow Vulnerability Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code...
- CVE-2021-30869 — Apple iOS, iPadOS, and macOS Type Confusion Vulnerability Apple iOS, iPadOS, and macOS contain a type confusion vulnerability in the XNU which may allow a malicious...
- CVE-2021-30883 — Apple Multiple Products Memory Corruption Vulnerability Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for remote code execution.
- CVE-2021-30900 — Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability Apple GPU drivers, included in iOS, iPadOS, and macOS, contain an out-of-bounds write vulnerability that may allow a...
- CVE-2021-30952 — Apple Multiple Products Integer Overflow or Wraparound Vulnerability Apple tvOS, macOS, Safari, iPadOS and watchOS contain an integer overflow or wraparound vulnerability due to the...
- CVE-2021-30983 — Apple iOS and iPadOS Buffer Overflow Vulnerability Apple iOS and iPadOS contain a buffer overflow vulnerability that could allow an application to execute code with...
- CVE-2021-31010 — Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability In affected versions of Apple iOS, macOS, and watchOS, a sandboxed process may be able to circumvent sandbox restrictions.
- CVE-2021-31166 — Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.
- CVE-2021-31196 — Microsoft Exchange Server Information Disclosure Vulnerability Microsoft Exchange Server contains an information disclosure vulnerability that allows for remote code execution.
- CVE-2021-31199 — Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation.
- CVE-2021-31201 — Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation.
- CVE-2021-31207 — Microsoft Exchange Server Security Feature Bypass Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.
- CVE-2021-3129 — Laravel Ignition File Upload Vulnerability Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute...
- CVE-2021-3156 — Sudo Heap-Based Buffer Overflow Vulnerability Sudo contains an off-by-one error that can result in a heap-based buffer overflow, which allows for privilege escalation.
- CVE-2021-31755 — Tenda AC11 Router Stack Buffer Overflow Vulnerability Tenda AC11 devices contain a stack buffer overflow vulnerability in /goform/setmac which allows attackers to execute...
- CVE-2021-31955 — Microsoft Windows Kernel Information Disclosure Vulnerability Microsoft Windows Kernel contains an unspecified vulnerability that allows for information disclosure. Successful...
- CVE-2021-31956 — Microsoft Windows NTFS Privilege Escalation Vulnerability Microsoft Windows New Technology File System (NTFS) contains an unspecified vulnerability that allows attackers to...
- CVE-2021-31979 — Microsoft Windows Kernel Privilege Escalation Vulnerability Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
- CVE-2021-32030 — ASUS Routers Improper Authentication Vulnerability ASUS Lyra Mini and ASUS GT-AC2900 devices contain an improper authentication vulnerability that allows an attacker...
- CVE-2021-32648 — October CMS Improper Authentication In affected versions of the october/system package an attacker can request an account password reset and then gain...
- CVE-2021-33044 — Dahua IP Camera Authentication Bypass Vulnerability Dahua IP cameras and related products contain an authentication bypass vulnerability when the NetKeyboard type...
- CVE-2021-33045 — Dahua IP Camera Authentication Bypass Vulnerability Dahua IP cameras and related products contain an authentication bypass vulnerability when the loopback device is...
- CVE-2021-33739 — Microsoft Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability Microsoft Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege...
- CVE-2021-33742 — Microsoft Windows MSHTML Platform Remote Code Execution Vulnerability Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for remote code execution.
- CVE-2021-33766 — Microsoft Exchange Server Information Disclosure Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated...
- CVE-2021-33771 — Microsoft Windows Kernel Privilege Escalation Vulnerability Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
- CVE-2021-34448 — Microsoft Windows Scripting Engine Memory Corruption Vulnerability Microsoft Windows Scripting Engine contains an unspecified vulnerability that allows for memory corruption.
- CVE-2021-34473 — Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.
- CVE-2021-34484 — Microsoft Windows User Profile Service Privilege Escalation Vulnerability Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
- CVE-2021-34486 — Microsoft Windows Event Tracing Privilege Escalation Vulnerability Microsoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation.
- CVE-2021-34523 — Microsoft Exchange Server Privilege Escalation Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
- CVE-2021-34527 — Microsoft Windows Print Spooler Remote Code Execution Vulnerability Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service...
- CVE-2021-3493 — Linux Kernel Privilege Escalation Vulnerability The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities...
- CVE-2021-35211 — SolarWinds Serv-U Remote Code Execution Vulnerability SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution.
- CVE-2021-35247 — SolarWinds Serv-U Improper Input Validation Vulnerability SolarWinds Serv-U versions 15.2.5 and earlier contain an improper input validation vulnerability that allows...
- CVE-2021-35394 — Realtek Jungle SDK Remote Code Execution Vulnerability RealTek Jungle SDK contains multiple memory corruption vulnerabilities which can allow an attacker to perform remote...
- CVE-2021-35395 — Realtek AP-Router SDK Buffer Overflow Vulnerability Realtek AP-Router SDK HTTP web server boa contains a buffer overflow vulnerability due to unsafe copies of some...
- CVE-2021-35464 — ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of...
- CVE-2021-35587 — Oracle Fusion Middleware Unspecified Vulnerability Oracle Fusion Middleware Access Manager allows an unauthenticated attacker with network access via HTTP to takeover...
- CVE-2021-3560 — Red Hat Polkit Incorrect Authorization Vulnerability Red Hat Polkit contains an incorrect authorization vulnerability through the bypassing of credential checks for...
- CVE-2021-36260 — Hikvision Improper Input Validation A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation.
- CVE-2021-36380 — Sunhillo SureLine OS Command Injection Vulnerablity Sunhillo SureLine contains an OS command injection vulnerability that allows an attacker to cause a...
- CVE-2021-36741 — Trend Micro Multiple Products Improper Input Validation Vulnerability Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation...
- CVE-2021-36742 — Trend Micro Multiple Products Improper Input Validation Vulnerability Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation...
- CVE-2021-36934 — Microsoft Windows SAM Local Privilege Escalation Vulnerability If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would...
- CVE-2021-36942 — Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated...
- CVE-2021-36948 — Microsoft Windows Update Medic Service Privilege Escalation Vulnerability Microsoft Windows Update Medic Service contains an unspecified vulnerability that allows for privilege escalation.
- CVE-2021-36955 — Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for...
- CVE-2021-37415 — Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API...
- CVE-2021-37973 — Google Chromium Portals Use-After-Free Vulnerability Google Chromium Portals contains a use-after-free vulnerability that allows a remote attacker, who has compromised...
- CVE-2021-37975 — Google Chromium V8 Use-After-Free Vulnerability Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially...
- CVE-2021-37976 — Google Chromium Information Disclosure Vulnerability Google Chromium contains an information disclosure vulnerability within the core memory component that allows a...
- CVE-2021-38000 — Google Chromium Intents Improper Input Validation Vulnerability Google Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to...
- CVE-2021-38003 — Google Chromium V8 Memory Corruption Vulnerability Google Chromium V8 Engine has a bug in JSON.stringify, where the internal TheHole value can leak to script code,...
- CVE-2021-38163 — SAP NetWeaver Unrestricted File Upload Vulnerability SAP NetWeaver contains a vulnerability that allows unrestricted file upload.
- CVE-2021-38406 — Delta Electronics DOPSoft 2 Improper Input Validation Vulnerability Delta Electronics DOPSoft 2 lacks proper validation of user-supplied data when parsing specific project files...
- CVE-2021-38645 — Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified...
- CVE-2021-38646 — Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.
- CVE-2021-38647 — Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified...
- CVE-2021-38648 — Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified...
- CVE-2021-38649 — Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified...
- CVE-2021-39144 — XStream Remote Code Execution Vulnerability XStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input...
- CVE-2021-39226 — Grafana Authentication Bypass Vulnerability Grafana contains an authentication bypass vulnerability that allows authenticated and unauthenticated users to view...
- CVE-2021-39793 — Google Pixel Out-of-Bounds Write Vulnerability Google Pixel contains a possible out-of-bounds write due to a logic error in the code that could lead to local...
- CVE-2021-39935 — GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow...
Browse by topic
Every page in the corpus, grouped. Search finds one page; this shows what else is here.