CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-0889

    Last Modified: 21 Nov 2024

    In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-8.1 Android-9Android ID: A-180745296

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-0932

    Last Modified: 21 Nov 2024

    In showNotification of NavigationModeController.java, there is a possible confused deputy due to an unsafe PendingIntent. This could lead to local escalation of privilege that allows actions performed as the System UI with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-173025705

    Published: 15 Dec 2021
    5.5
    Medium

    CVE-2021-0653

    Last Modified: 21 Nov 2024

    In enqueueNotification of NetworkPolicyManagerService.java, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-9Android ID: A-177931370

    Published: 15 Dec 2021
    8
    High

    CVE-2021-0933

    Last Modified: 21 Nov 2024

    In onCreate of CompanionDeviceActivity.java or DeviceChooserActivity.java, there is a possible way for HTML tags to interfere with a consent dialog due to improper input validation. This could lead to remote escalation of privilege, confusing the user into accepting pairing of a malicious Bluetooth device, with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-172251622

    Published: 15 Dec 2021
    7.3
    High

    CVE-2021-0434

    Last Modified: 21 Nov 2024

    In onReceive of BluetoothPermissionRequest.java, there is a possible phishing attack allowing a malicious Bluetooth device to acquire permissions based on insufficient information presented to the user in the consent dialog. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-9Android ID: A-167403112

    Published: 15 Dec 2021
    8.1
    High

    CVE-2021-43935

    Last Modified: 21 Nov 2024

    The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the application to accept manual entry of any active directory (AD) account provisioned in the application without supplying a password, resulting in access to the application as the supplied AD account, with all associated privileges.

    Published: 15 Dec 2021
    9.8
    Critical

    CVE-2021-42216

    Last Modified: 21 Nov 2024

    A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php.

    Published: 15 Dec 2021
    9.8
    Critical

    CVE-2021-4119

    Last Modified: 21 Nov 2024

    bookstack is vulnerable to Improper Access Control

    Published: 15 Dec 2021
    5.9
    Medium

    CVE-2021-29847

    Last Modified: 21 Nov 2024

    BMC firmware (IBM Power System S821LC Server (8001-12C) OP825.50) configuration changed to allow an authenticated user to open an insecure communication channel which could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 205267.

    Published: 15 Dec 2021
    5.5
    Medium

    CVE-2021-4135

    Last Modified: 21 Nov 2024

    A memory leak vulnerability was found in the Linux kernel's eBPF for the Simulated networking device driver in the way user uses BPF for the device such that function nsim_map_alloc_elem being called. A local user could use this flaw to get unauthorized access to some data.

    Published: 15 Dec 2021
    8.8
    High

    CVE-2021-27859

    Last Modified: 21 Nov 2024

    A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows an authenticated, remote attacker with read-only privileges to create an account with administrative privileges. Older versions of FatPipe software may also be vulnerable. This does not appear to be a CSRF vulnerability. The FatPipe advisory identifier for this vulnerability is FPSA005.

    Published: 15 Dec 2021
    5.3
    Medium

    CVE-2021-27858

    Last Modified: 21 Nov 2024

    A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote attacker to access at least the URL "/fpui/jsp/index.jsp" leading to unknown impact, presumably some violation of confidentiality. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is FPSA004.

    Published: 15 Dec 2021
    7.5
    High

    CVE-2021-27857

    Last Modified: 21 Nov 2024

    A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote, unauthenticated attacker to download a configuration archive. The attacker needs to know or correctly guess the hostname of the target system since the hostname is used as part of the configuration archive file name. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is FPSA003.

    Published: 15 Dec 2021
    9.8
    Critical

    CVE-2021-27856

    Last Modified: 21 Nov 2024

    FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 includes an account named "cmuser" that has administrative privileges and no password. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is FPSA002.

    Published: 15 Dec 2021
    8.8
    High

    CVE-2021-27855

    Last Modified: 21 Nov 2024

    FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote, authenticated attacker with read-only privileges to grant themselves administrative privileges. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is FPSA001.

    Published: 15 Dec 2021
    9.8
    Critical

    CVE-2021-44655

    Last Modified: 21 Nov 2024

    Online Pre-owned/Used Car Showroom Management System 1.0 contains a SQL injection authentication bypass vulnerability. Admin panel authentication can be bypassed due to SQL injection vulnerability in the login form allowing attacker to get admin access on the application.

    Published: 15 Dec 2021
    9.8
    Critical

    CVE-2021-44653

    Last Modified: 21 Nov 2024

    Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel authentication can be bypassed due to SQL injection vulnerability in the login form allowing attacker to gain access as admin to the application.

    Published: 15 Dec 2021
    6.1
    Medium

    CVE-2021-43675

    Last Modified: 21 Nov 2024

    Lychee-v3 3.2.16 is affected by a Cross Site Scripting (XSS) vulnerability in php/Access/Guest.php. The function exit will terminate the script and print the message to the user. The message will contain albumID which is controlled by the user.

    Published: 15 Dec 2021
    4.3
    Medium

    CVE-2021-4117

    Last Modified: 21 Nov 2024

    yetiforcecrm is vulnerable to Business Logic Errors

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-43518

    Last Modified: 21 Nov 2024

    Teeworlds up to and including 0.7.5 is vulnerable to Buffer Overflow. A map parser does not validate m_Channels value coming from a map file, leading to a buffer overflow. A malicious server may offer a specially crafted map that will overwrite client's stack causing denial of service or code execution.

    Published: 15 Dec 2021
    8.8
    High

    CVE-2021-44657

    Last Modified: 21 Nov 2024

    In StackStorm versions prior to 3.6.0, the jinja interpreter was not run in sandbox mode and thus allows execution of unsafe system commands. Jinja does not enable sandboxed mode by default due to backwards compatibility. Stackstorm now sets sandboxed mode for jinja by default.

    Published: 15 Dec 2021
    9.8
    Critical

    CVE-2021-43907

    Last Modified: 21 Nov 2024

    Visual Studio Code WSL Extension Remote Code Execution Vulnerability

    Published: 15 Dec 2021
    4.3
    Medium

    CVE-2021-43908

    Last Modified: 21 Nov 2024

    Visual Studio Code Spoofing Vulnerability

    Published: 15 Dec 2021
    9.6
    Critical

    CVE-2021-43905

    Last Modified: 11 Jun 2025

    Microsoft Office app Remote Code Execution Vulnerability

    Published: 15 Dec 2021
    9.8
    Critical

    CVE-2021-43899

    Last Modified: 21 Nov 2024

    Microsoft 4K Wireless Display Adapter Remote Code Execution Vulnerability

    Published: 15 Dec 2021
    5.5
    Medium

    CVE-2021-43896

    Last Modified: 21 Nov 2024

    Microsoft PowerShell Spoofing Vulnerability

    Published: 15 Dec 2021
    7.4
    High

    CVE-2021-43892

    Last Modified: 21 Nov 2024

    Microsoft BizTalk ESB Toolkit Spoofing Vulnerability

    Published: 15 Dec 2021
    7.5
    High

    CVE-2021-43893

    Last Modified: 21 Nov 2024

    Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-43891

    Last Modified: 21 Nov 2024

    Visual Studio Code Remote Code Execution Vulnerability

    Published: 15 Dec 2021
    7.1
    High

    CVE-2021-43890

    Last Modified: 5 Aug 2026

    We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emotet/Trickbot/Bazaloader. An attacker could craft a malicious attachment to be used in phishing campaigns. The attacker would then have to convince the user to open the specially crafted attachment. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Please see the Security Updates table for the link to the updated app. Alternatively you can download and install the Installer using the links provided in the FAQ section. Please see the Mitigations and Workaround sections for important information about steps you can take to protect your system from this vulnerability. December 27 2023 Update: In recent months, Microsoft Threat Intelligence has seen an increase in activity from threat actors leveraging social engineering and phishing techniques to target Windows OS users and utilizing the ms-appinstaller URI scheme. To address this increase in activity, we have updated the App Installer to disable the ms-appinstaller protocol by default and recommend other potential mitigations.

    Published: 15 Dec 2021
    7.2
    High

    CVE-2021-43889

    Last Modified: 21 Nov 2024

    Microsoft Defender for IoT Remote Code Execution Vulnerability

    Published: 15 Dec 2021
    7.5
    High

    CVE-2021-43888

    Last Modified: 21 Nov 2024

    Microsoft Defender for IoT Information Disclosure Vulnerability

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-43883

    Last Modified: 21 Nov 2024

    Windows Installer Elevation of Privilege Vulnerability

    Published: 15 Dec 2021
    5.5
    Medium

    CVE-2021-43880

    Last Modified: 21 Nov 2024

    Windows Mobile Device Management Elevation of Privilege Vulnerability

    Published: 15 Dec 2021
    9
    Critical

    CVE-2021-43882

    Last Modified: 21 Nov 2024

    Microsoft Defender for IoT Remote Code Execution Vulnerability

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-43875

    Last Modified: 19 May 2026

    Microsoft Office Graphics Remote Code Execution Vulnerability

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-43256

    Last Modified: 19 May 2026

    Microsoft Excel Remote Code Execution Vulnerability

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-43248

    Last Modified: 21 Nov 2024

    Windows Digital Media Receiver Elevation of Privilege Vulnerability

    Published: 15 Dec 2021
    5.5
    Medium

    CVE-2021-43255

    Last Modified: 19 May 2026

    Microsoft Office Trust Center Spoofing Vulnerability

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-43247

    Last Modified: 21 Nov 2024

    Windows TCP/IP Driver Elevation of Privilege Vulnerability

    Published: 15 Dec 2021
    5.6
    Medium

    CVE-2021-43246

    Last Modified: 21 Nov 2024

    Windows Hyper-V Denial of Service Vulnerability

    Published: 15 Dec 2021
    6.5
    Medium

    CVE-2021-43244

    Last Modified: 21 Nov 2024

    Windows Kernel Information Disclosure Vulnerability

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-43245

    Last Modified: 21 Nov 2024

    Windows Digital TV Tuner Elevation of Privilege Vulnerability

    Published: 15 Dec 2021
    5.5
    Medium

    CVE-2021-43243

    Last Modified: 28 May 2026

    VP9 Video Extensions Information Disclosure Vulnerability

    Published: 15 Dec 2021
    7.6
    High

    CVE-2021-43242

    Last Modified: 21 Nov 2024

    Microsoft SharePoint Server Spoofing Vulnerability

    Published: 15 Dec 2021
    7.1
    High

    CVE-2021-43239

    Last Modified: 21 Nov 2024

    Windows Recovery Environment Agent Elevation of Privilege Vulnerability

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-43240

    Last Modified: 21 Nov 2024

    NTFS Set Short Name Elevation of Privilege Vulnerability

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-43238

    Last Modified: 21 Nov 2024

    Windows Remote Access Elevation of Privilege Vulnerability

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-43237

    Last Modified: 21 Nov 2024

    Windows Setup Elevation of Privilege Vulnerability

    Published: 15 Dec 2021
    5.5
    Medium

    CVE-2021-43235

    Last Modified: 21 Nov 2024

    Storage Spaces Controller Information Disclosure Vulnerability

    Published: 15 Dec 2021