CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2021-40502

    Last Modified: 21 Nov 2024

    SAP Commerce - versions 2105.3, 2011.13, 2005.18, 1905.34, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. Authenticated attackers will be able to access and edit data from b2b units they do not belong to.

    Published: 10 Nov 2021
    8.1
    High

    CVE-2021-40501

    Last Modified: 21 Nov 2024

    SAP ABAP Platform Kernel - versions 7.77, 7.81, 7.85, 7.86, does not perform necessary authorization checks for an authenticated business user, resulting in escalation of privileges. That means this business user is able to read and modify data beyond the vulnerable system. However, the attacker can neither significantly reduce the performance of the system nor stop the system.

    Published: 10 Nov 2021
    7.5
    High

    CVE-2021-43564

    Last Modified: 21 Nov 2024

    An issue was discovered in the jobfair (aka Job Fair) extension before 1.0.13 and 2.x before 2.0.2 for TYPO3. The extension fails to protect or obfuscate filenames of uploaded files. This allows unauthenticated users to download files with sensitive data by simply guessing the filename of uploaded files (e.g., uploads/tx_jobfair/cv.pdf).

    Published: 10 Nov 2021
    8.8
    High

    CVE-2021-43563

    Last Modified: 21 Nov 2024

    An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The Access Control in the bundled media browser is broken, which allows an unauthenticated attacker to perform requests to the pixx.io API for the configured API user. This allows an attacker to download various media files from the DAM system.

    Published: 10 Nov 2021
    8.8
    High

    CVE-2021-43562

    Last Modified: 21 Nov 2024

    An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The extension fails to restrict the image download to the configured pixx.io DAM URL, resulting in SSRF. As a result, an attacker can download various content from a remote location and save it to a user-controlled filename, which may result in Remote Code Execution. A TYPO3 backend user account is required to exploit this.

    Published: 10 Nov 2021
    5.4
    Medium

    CVE-2021-43561

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in the google_for_jobs (aka Google for Jobs) extension before 1.5.1 and 2.x before 2.1.1 for TYPO3. The extension fails to properly encode user input for output in HTML context. A TYPO3 backend user account is required to exploit the vulnerability.

    Published: 10 Nov 2021
    6.5
    Medium

    CVE-2021-38887

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information from application response requests that could be used in further attacks against the system. IBM X-Force ID: 209401.

    Published: 10 Nov 2021
    9.6
    Critical

    CVE-2021-43523

    Last Modified: 5 May 2025

    In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution, XSS, applications crashes, etc.). In other words, a validation step, which is expected in any stub resolver, does not occur.

    Published: 10 Nov 2021
    7.2
    High

    CVE-2021-39474

    Last Modified: 21 Nov 2024

    Vulnerability in the product Docsis 3.0 UBC1319BA00 Router supported affected version 1319010201r009. The vulnerability allows an attacker with privileges and network access through the ping.cmd component to execute commands on the device.

    Published: 10 Nov 2021
    7.5
    High

    CVE-2021-34598

    Last Modified: 21 Nov 2024

    In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 the remote logging functionality is impaired by the lack of memory release for data structures from syslog-ng when remote logging is active

    Published: 10 Nov 2021
    4.8
    Medium

    CVE-2021-34582

    Last Modified: 21 Nov 2024

    In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 a user with high privileges can inject HTML code (XSS) through web-based management or the REST API with a manipulated certificate file.

    Published: 10 Nov 2021
    5.4
    Medium

    CVE-2021-25975

    Last Modified: 30 Apr 2025

    In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file.

    Published: 10 Nov 2021
    5.4
    Medium

    CVE-2021-25974

    Last Modified: 30 Apr 2025

    In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a “publisher” role is able to inject and execute arbitrary JavaScript code while creating a page/article.

    Published: 10 Nov 2021
    9.8
    Critical

    CVE-2021-43136

    Last Modified: 21 Nov 2024

    An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform.

    Published: 10 Nov 2021
    7.8
    High

    CVE-2021-31853

    Last Modified: 21 Nov 2024

    DLL Search Order Hijacking Vulnerability in McAfee Drive Encryption (MDE) prior to 7.3.0 HF2 (7.3.0.183) allows local users to execute arbitrary code and escalate privileges via execution from a compromised folder.

    Published: 10 Nov 2021
    6.5
    Medium

    CVE-2021-22870

    Last Modified: 21 Nov 2024

    A path traversal vulnerability was identified in GitHub Pages builds on GitHub Enterprise Server that could allow an attacker to read system files. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.3 and was fixed in versions 3.0.19, 3.1.11, and 3.2.3. This vulnerability was reported via the GitHub Bug Bounty program.

    Published: 10 Nov 2021
    7.8
    High

    CVE-2021-43209

    Last Modified: 19 Aug 2026

    3D Viewer Remote Code Execution Vulnerability

    Published: 10 Nov 2021
    7.8
    High

    CVE-2021-43208

    Last Modified: 19 Aug 2026

    3D Viewer Remote Code Execution Vulnerability

    Published: 10 Nov 2021
    3.3
    Low

    CVE-2021-42323

    Last Modified: 19 Aug 2026

    Azure RTOS Information Disclosure Vulnerability

    Published: 10 Nov 2021
    7.8
    High

    CVE-2021-42322

    Last Modified: 19 Aug 2026

    Visual Studio Code Elevation of Privilege Vulnerability

    Published: 10 Nov 2021
    8.8
    High

    CVE-2021-42321

    Last Modified: 19 Aug 2026

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Published: 10 Nov 2021
    4.7
    Medium

    CVE-2021-42319

    Last Modified: 19 Aug 2026

    Visual Studio Elevation of Privilege Vulnerability

    Published: 10 Nov 2021
    8.8
    High

    CVE-2021-42316

    Last Modified: 19 Aug 2026

    Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability

    Published: 10 Nov 2021
    6.5
    Medium

    CVE-2021-42305

    Last Modified: 19 Aug 2026

    Microsoft Exchange Server Spoofing Vulnerability

    Published: 10 Nov 2021
    6.6
    Medium

    CVE-2021-42304

    Last Modified: 19 Aug 2026

    Azure RTOS Elevation of Privilege Vulnerability

    Published: 10 Nov 2021
    6.6
    Medium

    CVE-2021-42303

    Last Modified: 19 Aug 2026

    Azure RTOS Elevation of Privilege Vulnerability

    Published: 10 Nov 2021
    6.6
    Medium

    CVE-2021-42302

    Last Modified: 19 Aug 2026

    Azure RTOS Elevation of Privilege Vulnerability

    Published: 10 Nov 2021
    3.3
    Low

    CVE-2021-42301

    Last Modified: 19 Aug 2026

    Azure RTOS Information Disclosure Vulnerability

    Published: 10 Nov 2021
    6
    Medium

    CVE-2021-42300

    Last Modified: 19 Aug 2026

    Azure Sphere Tampering Vulnerability

    Published: 10 Nov 2021
    7.8
    High

    CVE-2021-42298

    Last Modified: 19 Aug 2026

    Microsoft Defender Remote Code Execution Vulnerability

    Published: 10 Nov 2021
    7.8
    High

    CVE-2021-42296

    Last Modified: 19 Aug 2026

    Microsoft Word Remote Code Execution Vulnerability

    Published: 10 Nov 2021
    7.8
    High

    CVE-2021-42292

    Last Modified: 19 Aug 2026

    Microsoft Excel Security Feature Bypass Vulnerability

    Published: 10 Nov 2021
    7.5
    High

    CVE-2021-42291

    Last Modified: 19 Aug 2026

    Active Directory Domain Services Elevation of Privilege Vulnerability

    Published: 10 Nov 2021
    5.7
    Medium

    CVE-2021-42288

    Last Modified: 19 Aug 2026

    Windows Hello Security Feature Bypass Vulnerability

    Published: 10 Nov 2021
    7.5
    High

    CVE-2021-42287

    Last Modified: 19 Aug 2026

    Active Directory Domain Services Elevation of Privilege Vulnerability

    Published: 10 Nov 2021
    7.8
    High

    CVE-2021-42286

    Last Modified: 19 Aug 2026

    Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability

    Published: 10 Nov 2021
    7.8
    High

    CVE-2021-42285

    Last Modified: 19 Aug 2026

    Windows Kernel Elevation of Privilege Vulnerability

    Published: 10 Nov 2021
    6.8
    Medium

    CVE-2021-42284

    Last Modified: 19 Aug 2026

    Windows Hyper-V Denial of Service Vulnerability

    Published: 10 Nov 2021
    8.8
    High

    CVE-2021-42283

    Last Modified: 19 Aug 2026

    NTFS Elevation of Privilege Vulnerability

    Published: 10 Nov 2021
    7.5
    High

    CVE-2021-42282

    Last Modified: 19 Aug 2026

    Active Directory Domain Services Elevation of Privilege Vulnerability

    Published: 10 Nov 2021
    5.5
    Medium

    CVE-2021-42280

    Last Modified: 19 Aug 2026

    Windows Feedback Hub Elevation of Privilege Vulnerability

    Published: 10 Nov 2021
    4.2
    Medium

    CVE-2021-42279

    Last Modified: 19 Aug 2026

    Chakra Scripting Engine Memory Corruption Vulnerability

    Published: 10 Nov 2021
    7.5
    High

    CVE-2021-42278

    Last Modified: 19 Aug 2026

    Active Directory Domain Services Elevation of Privilege Vulnerability

    Published: 10 Nov 2021
    5.5
    Medium

    CVE-2021-42277

    Last Modified: 19 Aug 2026

    Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability

    Published: 10 Nov 2021
    7.8
    High

    CVE-2021-42276

    Last Modified: 19 Aug 2026

    Microsoft Windows Media Foundation Remote Code Execution Vulnerability

    Published: 10 Nov 2021
    8.8
    High

    CVE-2021-42275

    Last Modified: 19 Aug 2026

    Microsoft COM for Windows Remote Code Execution Vulnerability

    Published: 10 Nov 2021
    6.8
    Medium

    CVE-2021-42274

    Last Modified: 19 Aug 2026

    Windows Hyper-V Discrete Device Assignment (DDA) Denial of Service Vulnerability

    Published: 10 Nov 2021
    5.5
    Medium

    CVE-2021-41379

    Last Modified: 19 Aug 2026

    Windows Installer Elevation of Privilege Vulnerability

    Published: 10 Nov 2021
    7.8
    High

    CVE-2021-41378

    Last Modified: 19 Aug 2026

    Windows NTFS Remote Code Execution Vulnerability

    Published: 10 Nov 2021
    7.8
    High

    CVE-2021-41377

    Last Modified: 19 Aug 2026

    Windows Fast FAT File System Driver Elevation of Privilege Vulnerability

    Published: 10 Nov 2021