CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2021-30254

    Last Modified: 21 Nov 2024

    Possible buffer overflow due to improper input validation in factory calibration and test DIAG command in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 12 Nov 2021
    7.5
    High

    CVE-2021-1982

    Last Modified: 21 Nov 2024

    Possible denial of service scenario due to improper input validation of received NAS OTA message in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 12 Nov 2021
    7.5
    High

    CVE-2021-1981

    Last Modified: 21 Nov 2024

    Possible buffer over read due to improper IE size check of Bearer capability IE in MT setup request from network in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 12 Nov 2021
    7.8
    High

    CVE-2021-1979

    Last Modified: 21 Nov 2024

    Possible buffer overflow due to improper validation of FTM command payload in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 12 Nov 2021
    9.8
    Critical

    CVE-2021-1975

    Last Modified: 21 Nov 2024

    Possible heap overflow due to improper length check of domain while parsing the DNS response in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 12 Nov 2021
    7.8
    High

    CVE-2021-1973

    Last Modified: 21 Nov 2024

    A FTM Diag command can allow an arbitrary write into modem OS space in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 12 Nov 2021
    9
    Critical

    CVE-2021-1924

    Last Modified: 21 Nov 2024

    Information disclosure through timing and power side-channels during mod exponentiation for RSA-CRT in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 12 Nov 2021
    7.8
    High

    CVE-2021-1921

    Last Modified: 21 Nov 2024

    Possible memory corruption due to Improper handling of hypervisor unmap operations for concurrent memory operations in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 12 Nov 2021
    8.4
    High

    CVE-2021-1912

    Last Modified: 21 Nov 2024

    Possible integer overflow can occur due to improper length check while calculating count and grace period in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 12 Nov 2021
    5.3
    Medium

    CVE-2021-1903

    Last Modified: 21 Nov 2024

    Possible denial of service scenario can occur due to lack of length check on Channel Switch Announcement IE in beacon or probe response frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 12 Nov 2021
    —
    Unknown

    CVE-2022-21207

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 12 Nov 2021
    3.7
    Low

    CVE-2021-37910

    Last Modified: 21 Nov 2024

    ASUS routers Wi-Fi protected access protocol (WPA2 and WPA3-SAE) has improper control of Interaction frequency vulnerability, an unauthenticated attacker can remotely disconnect other users' connections by sending specially crafted SAE authentication frames.

    Published: 12 Nov 2021
    9.1
    Critical

    CVE-2021-42775

    Last Modified: 21 Nov 2024

    Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly Local Management mode, have a vulnerability in the remote firmware download feature that could allow a user to place or replace an arbitrary file on the remote host. In non-secure mode, the user is unauthenticated.

    Published: 12 Nov 2021
    7.5
    High

    CVE-2021-42773

    Last Modified: 21 Nov 2024

    Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly Local Management mode, could allow a user to retrieve an arbitrary file from a remote host with the GetDumpFile command. In non-secure mode, the user is unauthenticated.

    Published: 12 Nov 2021
    9.8
    Critical

    CVE-2021-42774

    Last Modified: 21 Nov 2024

    Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly Local Management mode, have a buffer overflow vulnerability in the remote firmware download feature that could allow remote unauthenticated users to perform various attacks. In non-secure mode, the user is unauthenticated.

    Published: 12 Nov 2021
    4.3
    Medium

    CVE-2021-41229

    Last Modified: 4 Nov 2025

    BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will always be hung in the singly linked list of cstates and will not be freed. This will cause a memory leak over time. The data can be a very large object, which can be caused by an attacker continuously sending sdp packets and this may cause the service of the target device to crash.

    Published: 12 Nov 2021
    8.8
    High

    CVE-2022-0204

    Last Modified: 15 Apr 2026

    A heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially crafted files causing an application to halt or crash, leading to a denial of service.

    Published: 12 Nov 2021
    7.9
    High

    CVE-2021-34417

    Last Modified: 21 Nov 2024

    The network proxy page on the web portal for the Zoom On-Premise Meeting Connector Controller before version 4.6.365.20210703, Zoom On-Premise Meeting Connector MMR before version 4.6.365.20210703, Zoom On-Premise Recording Connector before version 3.8.45.20210703, Zoom On-Premise Virtual Room Connector before version 4.4.6868.20210703, and Zoom On-Premise Virtual Room Connector Load Balancer before version 2.5.5496.20210703 fails to validate input sent in requests to set the network proxy password. This could lead to remote command injection by a web portal administrator.

    Published: 11 Nov 2021
    4
    Medium

    CVE-2021-34418

    Last Modified: 21 Nov 2024

    The login routine of the web console in the Zoom On-Premise Meeting Connector before version 4.6.239.20200613, Zoom On-Premise Meeting Connector MMR before version 4.6.239.20200613, Zoom On-Premise Recording Connector before version 3.8.42.20200905, Zoom On-Premise Virtual Room Connector before version 4.4.6344.20200612, and Zoom On-Premise Virtual Room Connector Load Balancer before version 2.5.5492.20200616 fails to validate that a NULL byte was sent while authenticating. This could lead to a crash of the login service.

    Published: 11 Nov 2021
    3.7
    Low

    CVE-2021-34419

    Last Modified: 21 Nov 2024

    In the Zoom Client for Meetings for Ubuntu Linux before version 5.1.0, there is an HTML injection flaw when sending a remote control request to a user in the process of in-meeting screen sharing. This could allow meeting participants to be targeted for social engineering attacks.

    Published: 11 Nov 2021
    4.7
    Medium

    CVE-2021-34420

    Last Modified: 21 Nov 2024

    The Zoom Client for Meetings for Windows installer before version 5.5.4 does not properly verify the signature of files with .msi, .ps1, and .bat extensions. This could lead to a malicious actor installing malicious software on a customer’s computer.

    Published: 11 Nov 2021
    3.7
    Low

    CVE-2021-34421

    Last Modified: 21 Nov 2024

    The Keybase Client for Android before version 5.8.0 and the Keybase Client for iOS before version 5.8.0 fails to properly remove exploded messages initiated by a user if the receiving user places the chat session in the background while the sending user explodes the messages. This could lead to disclosure of sensitive information which was meant to be deleted from the customer's device.

    Published: 11 Nov 2021
    7.2
    High

    CVE-2021-34422

    Last Modified: 21 Nov 2024

    The Keybase Client for Windows before version 5.7.0 contains a path traversal vulnerability when checking the name of a file uploaded to a team folder. A malicious user could upload a file to a shared folder with a specially crafted file name which could allow a user to execute an application which was not intended on their host machine. If a malicious user leveraged this issue with the public folder sharing feature of the Keybase client, this could lead to remote code execution.

    Published: 11 Nov 2021
    4.2
    Medium

    CVE-2021-3912

    Last Modified: 21 Nov 2024

    OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to create a repository that makes OctoRPKI run out of memory (and thus crash).

    Published: 11 Nov 2021
    4.2
    Medium

    CVE-2021-3911

    Last Modified: 21 Nov 2024

    If the ROA that a repository returns contains too many bits for the IP address then OctoRPKI will crash.

    Published: 11 Nov 2021
    4.4
    Medium

    CVE-2021-3910

    Last Modified: 15 Apr 2026

    OctoRPKI crashes when encountering a repository that returns an invalid ROA (just an encoded NUL (\0) character).

    Published: 11 Nov 2021
    4.4
    Medium

    CVE-2021-3909

    Last Modified: 21 Nov 2024

    OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically, the repository that OctoRPKI sends HTTP requests to will keep the connection open for a day before a response is returned, but does keep drip feeding new bytes to keep the connection alive.

    Published: 11 Nov 2021
    5.9
    Medium

    CVE-2021-3908

    Last Modified: 21 Nov 2024

    OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal never end.

    Published: 11 Nov 2021
    7.4
    High

    CVE-2021-3907

    Last Modified: 21 Nov 2024

    OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the base cache folder. This could allow for remote code execution on the host machine OctoRPKI is running on.

    Published: 11 Nov 2021
    9.8
    Critical

    CVE-2021-43350

    Last Modified: 21 Nov 2024

    An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any API version to inject unsanitized content into the LDAP filter.

    Published: 11 Nov 2021
    7.5
    High

    CVE-2021-26558

    Last Modified: 21 Nov 2024

    Deserialization of Untrusted Data vulnerability of Apache ShardingSphere-UI allows an attacker to inject outer link resources. This issue affects Apache ShardingSphere-UI Apache ShardingSphere-UI version 4.1.1 and later versions; Apache ShardingSphere-UI versions prior to 5.0.0.

    Published: 11 Nov 2021
    8.8
    High

    CVE-2021-25980

    Last Modified: 30 Apr 2025

    In Talkyard, versions v0.04.01 through v0.6.74-WIP-63220cb, v0.2020.22-WIP-b2e97fe0e through v0.2021.02-WIP-879ef3fe1 and tyse-v0.2021.02-879ef3fe1-regular through tyse-v0.2021.28-af66b6905-regular, are vulnerable to Host Header Injection. By luring a victim application-user to click on a link, an unauthenticated attacker can use the “forgot password” functionality to reset the victim’s password and successfully take over their account.

    Published: 11 Nov 2021
    8.8
    High

    CVE-2021-43397

    Last Modified: 21 Nov 2024

    LiquidFiles before 3.6.3 allows remote attackers to elevate their privileges from Admin (or User Admin) to Sysadmin.

    Published: 11 Nov 2021
    9.8
    Critical

    CVE-2021-42002

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADManager Plus before 7115 is vulnerable to a filter bypass that leads to file-upload remote code execution.

    Published: 11 Nov 2021
    9.8
    Critical

    CVE-2021-41833

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution.

    Published: 11 Nov 2021
    9.8
    Critical

    CVE-2021-41081

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a configuration search.

    Published: 11 Nov 2021
    9.8
    Critical

    CVE-2021-41080

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a hardware details search.

    Published: 11 Nov 2021
    9.8
    Critical

    CVE-2021-43573

    Last Modified: 21 Nov 2024

    A buffer overflow was discovered on Realtek RTL8195AM devices before 2.0.10. It exists in the client code when processing a malformed IE length of HT capability information in the Beacon and Association response frame.

    Published: 11 Nov 2021
    7.5
    High

    CVE-2015-5236

    Last Modified: 21 Nov 2024

    It was discovered that the IcedTea-Web used codebase attribute of the <applet> tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified codebase does not have to match the applet's actual origin, this allowed malicious site to bypass SOP via spoofed codebase value.

    Published: 11 Nov 2021
    8.1
    High

    CVE-2021-23214

    Last Modified: 21 Nov 2024

    When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.

    Published: 11 Nov 2021
    7.5
    High

    CVE-2002-20001

    Last Modified: 22 Aug 2025

    The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.

    Published: 11 Nov 2021
    9.8
    Critical

    CVE-2021-42847

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files.

    Published: 11 Nov 2021
    5.9
    Medium

    CVE-2021-23222

    Last Modified: 21 Nov 2024

    A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption.

    Published: 11 Nov 2021
    7.5
    High

    CVE-2021-40873

    Last Modified: 21 Nov 2024

    An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66, and uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) by sending crafted messages to a client or server. The server process may crash unexpectedly because of a double free, and must be restarted.

    Published: 10 Nov 2021
    7.5
    High

    CVE-2021-40872

    Last Modified: 21 Nov 2024

    An issue was discovered in Softing Industrial Automation uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) or login as an anonymous user (bypassing security checks) by sending crafted messages to a OPC/UA server. The server process may crash unexpectedly because of an invalid type cast, and must be restarted.

    Published: 10 Nov 2021
    7.5
    High

    CVE-2021-40871

    Last Modified: 21 Nov 2024

    An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66. Remote attackers to cause a denial of service (DoS) by sending crafted messages to a OPC/UA client. The client process may crash unexpectedly because of a wrong type cast, and must be restarted.

    Published: 10 Nov 2021
    6.1
    Medium

    CVE-2021-33618

    Last Modified: 21 Nov 2024

    Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove attribute of a BODY element to the user-management feature.

    Published: 10 Nov 2021
    9.8
    Critical

    CVE-2021-33816

    Last Modified: 21 Nov 2024

    The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, and shell_exec are blocked but backticks are not blocked.

    Published: 10 Nov 2021
    5.5
    Medium

    CVE-2020-23906

    Last Modified: 21 Nov 2024

    FFmpeg N-98388-g76a3ee996b allows attackers to cause a denial of service (DoS) via a crafted audio file due to insufficient verification of data authenticity.

    Published: 10 Nov 2021
    5.5
    Medium

    CVE-2020-23902

    Last Modified: 21 Nov 2024

    A buffer overflow in WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tga file. Related to Data from Faulting Address may be used as a return value starting at Editor!TMethodImplementationIntercept+0x528a3.

    Published: 10 Nov 2021