CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2021-46164

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Desktop Central before 10.0.662 allows remote code execution by an authenticated user who has complete access to the Reports module.

    Published: 9 Jan 2022
    7.8
    High

    CVE-2021-46165

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Desktop Central before 10.0.662, during startup, launches an executable file from the batch files, but this file's path might not be properly defined.

    Published: 9 Jan 2022
    6.5
    Medium

    CVE-2021-46166

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the database by visiting the Reports page.

    Published: 9 Jan 2022
    5.3
    Medium

    CVE-2022-22932

    Last Modified: 21 Nov 2024

    Apache Karaf obr:* commands and run goal on the karaf-maven-plugin have partial path traversal which allows to break out of expected folder. The risk is low as obr:* commands are not very used and the entry is set by user. This has been fixed in revision: https://gitbox.apache.org/repos/asf?p=karaf.git;h=36a2bc4 https://gitbox.apache.org/repos/asf?p=karaf.git;h=52b70cf Mitigation: Apache Karaf users should upgrade to 4.2.15 or 4.3.6 or later as soon as possible, or use correct path. JIRA Tickets: https://issues.apache.org/jira/browse/KARAF-7326

    Published: 9 Jan 2022
    6.5
    Medium

    CVE-2022-22836

    Last Modified: 21 Nov 2024

    CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request.

    Published: 8 Jan 2022
    7.1
    High

    CVE-2021-45442

    Last Modified: 21 Nov 2024

    A link following denial-of-service vulnerability in Trend Micro Worry-Free Business Security (on prem only) could allow a local attacker to overwrite arbitrary files in the context of SYSTEM. This is similar to, but not the same as CVE-2021-44024. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 8 Jan 2022
    7.8
    High

    CVE-2021-45441

    Last Modified: 21 Nov 2024

    A origin validation error vulnerability in Trend Micro Apex One (on-prem and SaaS) could allow a local attacker drop and manipulate a specially crafted file to issue commands over a certain pipe and elevate to a higher level of privileges. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 8 Jan 2022
    7.8
    High

    CVE-2021-45440

    Last Modified: 21 Nov 2024

    A unnecessary privilege vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security 10.0 SP1 (on-prem versions only) could allow a local attacker to abuse an impersonation privilege and elevate to a higher level of privileges. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 8 Jan 2022
    7.8
    High

    CVE-2021-45231

    Last Modified: 21 Nov 2024

    A link following privilege escalation vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to create a specially crafted file with arbitrary content which could grant local privilege escalation on the affected system. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 8 Jan 2022
    7.1
    High

    CVE-2021-44024

    Last Modified: 21 Nov 2024

    A link following denial-of-service vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to overwrite arbitrary files in the context of SYSTEM. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 8 Jan 2022
    9.8
    Critical

    CVE-2022-22822

    Last Modified: 5 May 2025

    addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

    Published: 8 Jan 2022
    9.8
    Critical

    CVE-2022-22823

    Last Modified: 5 May 2025

    build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

    Published: 8 Jan 2022
    9.8
    Critical

    CVE-2022-22824

    Last Modified: 5 May 2025

    defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

    Published: 8 Jan 2022
    8.8
    High

    CVE-2022-22825

    Last Modified: 5 May 2025

    lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

    Published: 8 Jan 2022
    8.8
    High

    CVE-2022-22826

    Last Modified: 5 May 2025

    nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

    Published: 8 Jan 2022
    8.8
    High

    CVE-2022-22827

    Last Modified: 5 May 2025

    storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

    Published: 8 Jan 2022
    2
    Low

    CVE-2022-22821

    Last Modified: 21 Nov 2024

    NVIDIA NeMo before 1.6.0 contains a vulnerability in ASR WebApp, in which ../ Path Traversal may lead to deletion of any directory when admin privileges are available.

    Published: 8 Jan 2022
    7.5
    High

    CVE-2021-46174

    Last Modified: 21 Nov 2024

    Heap-based Buffer Overflow in function bfd_getl32 in Binutils objdump 3.37.

    Published: 8 Jan 2022
    —
    Unknown

    CVE-2021-46060

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 7 Jan 2022
    7.8
    High

    CVE-2021-30360

    Last Modified: 21 Nov 2024

    Users have access to the directory where the installation repair occurs. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted EXE in the repair folder which runs with the Check Point Remote Access Client privileges.

    Published: 7 Jan 2022
    4.3
    Medium

    CVE-2021-22060

    Last Modified: 21 Nov 2024

    In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.

    Published: 7 Jan 2022
    2.6
    Low

    CVE-2021-23173

    Last Modified: 16 Apr 2025

    The affected product is vulnerable to an improper access control, which may allow an authenticated user to gain unauthorized access to sensitive data.

    Published: 7 Jan 2022
    5.5
    Medium

    CVE-2022-21823

    Last Modified: 21 Nov 2024

    A insecure storage of sensitive information vulnerability exists in Ivanti Workspace Control <2021.2 (10.7.30.0) that could allow an attacker with locally authenticated low privileges to obtain key information due to an unspecified attack vector.

    Published: 7 Jan 2022
    4.3
    Medium

    CVE-2021-35247

    Last Modified: 27 Oct 2025

    Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.

    Published: 7 Jan 2022
    9.8
    Critical

    CVE-2021-39996

    Last Modified: 21 Nov 2024

    There is a Heap-based buffer overflow vulnerability with the NFC module in smartphones. Successful exploitation of this vulnerability may cause memory overflow.

    Published: 7 Jan 2022
    9.8
    Critical

    CVE-2021-39993

    Last Modified: 21 Nov 2024

    There is an Integer overflow vulnerability with ACPU in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access.

    Published: 7 Jan 2022
    7.5
    High

    CVE-2021-39998

    Last Modified: 21 Nov 2024

    There is Vulnerability of APIs being concurrently called for multiple times in HwConnectivityExService a in smartphones. Successful exploitation of this vulnerability may cause the system to crash and restart.

    Published: 7 Jan 2022
    7.5
    High

    CVE-2021-40032

    Last Modified: 24 Feb 2026

    The bone voice ID TA has a vulnerability in information management,Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 7 Jan 2022
    7.5
    High

    CVE-2021-40028

    Last Modified: 21 Nov 2024

    The eID module has an out-of-bounds memory write vulnerability,Successful exploitation of this vulnerability may affect data integrity.

    Published: 7 Jan 2022
    7.5
    High

    CVE-2021-40027

    Last Modified: 24 Feb 2026

    The bone voice ID TA has a vulnerability in calculating the buffer length,Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 7 Jan 2022
    7.5
    High

    CVE-2021-40022

    Last Modified: 21 Nov 2024

    The weaver module has a vulnerability in parameter type verification,Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 7 Jan 2022
    7.5
    High

    CVE-2021-40025

    Last Modified: 21 Nov 2024

    The eID module has a vulnerability that causes the memory to be used without being initialized,Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 7 Jan 2022
    7.5
    High

    CVE-2021-40021

    Last Modified: 21 Nov 2024

    The eID module has an out-of-bounds memory write vulnerability,Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 7 Jan 2022
    7.5
    High

    CVE-2021-40018

    Last Modified: 21 Nov 2024

    The eID module has a null pointer reference vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 7 Jan 2022
    7.5
    High

    CVE-2021-40014

    Last Modified: 24 Feb 2026

    The bone voice ID trusted application (TA) has a heap overflow vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 7 Jan 2022
    9.8
    Critical

    CVE-2021-40010

    Last Modified: 21 Nov 2024

    The bone voice ID TA has a heap overflow vulnerability.Successful exploitation of this vulnerability may result in malicious code execution.

    Published: 7 Jan 2022
    7.5
    High

    CVE-2021-40039

    Last Modified: 21 Nov 2024

    There is a Null pointer dereference vulnerability in the camera module in smartphones. Successful exploitation of this vulnerability may affect service integrity.

    Published: 7 Jan 2022
    7.5
    High

    CVE-2021-40038

    Last Modified: 21 Nov 2024

    There is a Double free vulnerability in the AOD module in smartphones. Successful exploitation of this vulnerability may affect service integrity.

    Published: 7 Jan 2022
    5.5
    Medium

    CVE-2021-40037

    Last Modified: 21 Nov 2024

    There is a Vulnerability of accessing resources using an incompatible type (type confusion) in the MPTCP subsystem in smartphones. Successful exploitation of this vulnerability may cause the system to crash and restart.

    Published: 7 Jan 2022
    7.5
    High

    CVE-2021-40035

    Last Modified: 21 Nov 2024

    There is a Buffer overflow vulnerability due to a boundary error with the Samba server in the file management module in smartphones. Successful exploitation of this vulnerability may affect function stability.

    Published: 7 Jan 2022
    7.5
    High

    CVE-2021-40031

    Last Modified: 21 Nov 2024

    There is a Null pointer dereference vulnerability in the camera module in smartphones. Successful exploitation of this vulnerability may affect service integrity.

    Published: 7 Jan 2022
    7.5
    High

    CVE-2021-40029

    Last Modified: 21 Nov 2024

    There is a Buffer overflow vulnerability due to a boundary error with the Samba server in the file management module in smartphones. Successful exploitation of this vulnerability may affect function stability.

    Published: 7 Jan 2022
    7.5
    High

    CVE-2021-40026

    Last Modified: 21 Nov 2024

    There is a Heap-based buffer overflow vulnerability in the AOD module in smartphones. Successful exploitation of this vulnerability may affect service integrity.

    Published: 7 Jan 2022
    5.3
    Medium

    CVE-2021-40009

    Last Modified: 21 Nov 2024

    There is an Out-of-bounds write vulnerability in the AOD module in smartphones. Successful exploitation of this vulnerability may affect service integrity.

    Published: 7 Jan 2022
    —
    Unknown

    CVE-2021-46059

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 7 Jan 2022
    7.5
    High

    CVE-2021-40020

    Last Modified: 21 Nov 2024

    There is an Out-of-bounds array read vulnerability in the security storage module in smartphones. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 7 Jan 2022
    7.5
    High

    CVE-2021-40011

    Last Modified: 21 Nov 2024

    There is an uncontrolled resource consumption vulnerability in the display module. Successful exploitation of this vulnerability may affect integrity.

    Published: 7 Jan 2022
    4.6
    Medium

    CVE-2021-40006

    Last Modified: 24 Feb 2026

    Vulnerability of design defects in the security algorithm component. Successful exploitation of this vulnerability may affect confidentiality.

    Published: 7 Jan 2022
    7.5
    High

    CVE-2021-40005

    Last Modified: 21 Nov 2024

    The distributed data service component has a vulnerability in data access control. Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 7 Jan 2022
    7.5
    High

    CVE-2021-40004

    Last Modified: 21 Nov 2024

    The cellular module has a vulnerability in permission management. Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 7 Jan 2022