CVE-2021-40502
Last Modified: 21 Nov 2024SAP Commerce - versions 2105.3, 2011.13, 2005.18, 1905.34, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. Authenticated attackers will be able to access and edit data from b2b units they do not belong to.
CVE-2021-40501
Last Modified: 21 Nov 2024SAP ABAP Platform Kernel - versions 7.77, 7.81, 7.85, 7.86, does not perform necessary authorization checks for an authenticated business user, resulting in escalation of privileges. That means this business user is able to read and modify data beyond the vulnerable system. However, the attacker can neither significantly reduce the performance of the system nor stop the system.
CVE-2021-43564
Last Modified: 21 Nov 2024An issue was discovered in the jobfair (aka Job Fair) extension before 1.0.13 and 2.x before 2.0.2 for TYPO3. The extension fails to protect or obfuscate filenames of uploaded files. This allows unauthenticated users to download files with sensitive data by simply guessing the filename of uploaded files (e.g., uploads/tx_jobfair/cv.pdf).
CVE-2021-43563
Last Modified: 21 Nov 2024An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The Access Control in the bundled media browser is broken, which allows an unauthenticated attacker to perform requests to the pixx.io API for the configured API user. This allows an attacker to download various media files from the DAM system.
CVE-2021-43562
Last Modified: 21 Nov 2024An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The extension fails to restrict the image download to the configured pixx.io DAM URL, resulting in SSRF. As a result, an attacker can download various content from a remote location and save it to a user-controlled filename, which may result in Remote Code Execution. A TYPO3 backend user account is required to exploit this.
CVE-2021-43561
Last Modified: 21 Nov 2024An XSS issue was discovered in the google_for_jobs (aka Google for Jobs) extension before 1.5.1 and 2.x before 2.1.1 for TYPO3. The extension fails to properly encode user input for output in HTML context. A TYPO3 backend user account is required to exploit the vulnerability.
CVE-2021-38887
Last Modified: 21 Nov 2024IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information from application response requests that could be used in further attacks against the system. IBM X-Force ID: 209401.
CVE-2021-43523
Last Modified: 5 May 2025In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution, XSS, applications crashes, etc.). In other words, a validation step, which is expected in any stub resolver, does not occur.
CVE-2021-39474
Last Modified: 21 Nov 2024Vulnerability in the product Docsis 3.0 UBC1319BA00 Router supported affected version 1319010201r009. The vulnerability allows an attacker with privileges and network access through the ping.cmd component to execute commands on the device.
CVE-2021-34598
Last Modified: 21 Nov 2024In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 the remote logging functionality is impaired by the lack of memory release for data structures from syslog-ng when remote logging is active
CVE-2021-34582
Last Modified: 21 Nov 2024In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 a user with high privileges can inject HTML code (XSS) through web-based management or the REST API with a manipulated certificate file.
CVE-2021-25975
Last Modified: 30 Apr 2025In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file.
CVE-2021-25974
Last Modified: 30 Apr 2025In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a “publisher” role is able to inject and execute arbitrary JavaScript code while creating a page/article.
CVE-2021-43136
Last Modified: 21 Nov 2024An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform.
CVE-2021-31853
Last Modified: 21 Nov 2024DLL Search Order Hijacking Vulnerability in McAfee Drive Encryption (MDE) prior to 7.3.0 HF2 (7.3.0.183) allows local users to execute arbitrary code and escalate privileges via execution from a compromised folder.
CVE-2021-22870
Last Modified: 21 Nov 2024A path traversal vulnerability was identified in GitHub Pages builds on GitHub Enterprise Server that could allow an attacker to read system files. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.3 and was fixed in versions 3.0.19, 3.1.11, and 3.2.3. This vulnerability was reported via the GitHub Bug Bounty program.
CVE-2021-43209
Last Modified: 19 Aug 20263D Viewer Remote Code Execution Vulnerability
CVE-2021-43208
Last Modified: 19 Aug 20263D Viewer Remote Code Execution Vulnerability
CVE-2021-42323
Last Modified: 19 Aug 2026Azure RTOS Information Disclosure Vulnerability
CVE-2021-42322
Last Modified: 19 Aug 2026Visual Studio Code Elevation of Privilege Vulnerability
CVE-2021-42321
Last Modified: 19 Aug 2026Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-42319
Last Modified: 19 Aug 2026Visual Studio Elevation of Privilege Vulnerability
CVE-2021-42316
Last Modified: 19 Aug 2026Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
CVE-2021-42305
Last Modified: 19 Aug 2026Microsoft Exchange Server Spoofing Vulnerability
CVE-2021-42304
Last Modified: 19 Aug 2026Azure RTOS Elevation of Privilege Vulnerability
CVE-2021-42303
Last Modified: 19 Aug 2026Azure RTOS Elevation of Privilege Vulnerability
CVE-2021-42302
Last Modified: 19 Aug 2026Azure RTOS Elevation of Privilege Vulnerability
CVE-2021-42301
Last Modified: 19 Aug 2026Azure RTOS Information Disclosure Vulnerability
CVE-2021-42300
Last Modified: 19 Aug 2026Azure Sphere Tampering Vulnerability
CVE-2021-42298
Last Modified: 19 Aug 2026Microsoft Defender Remote Code Execution Vulnerability
CVE-2021-42296
Last Modified: 19 Aug 2026Microsoft Word Remote Code Execution Vulnerability
CVE-2021-42292
Last Modified: 19 Aug 2026Microsoft Excel Security Feature Bypass Vulnerability
CVE-2021-42291
Last Modified: 19 Aug 2026Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2021-42288
Last Modified: 19 Aug 2026Windows Hello Security Feature Bypass Vulnerability
CVE-2021-42287
Last Modified: 19 Aug 2026Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2021-42286
Last Modified: 19 Aug 2026Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability
CVE-2021-42285
Last Modified: 19 Aug 2026Windows Kernel Elevation of Privilege Vulnerability
CVE-2021-42284
Last Modified: 19 Aug 2026Windows Hyper-V Denial of Service Vulnerability
CVE-2021-42283
Last Modified: 19 Aug 2026NTFS Elevation of Privilege Vulnerability
CVE-2021-42282
Last Modified: 19 Aug 2026Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2021-42280
Last Modified: 19 Aug 2026Windows Feedback Hub Elevation of Privilege Vulnerability
CVE-2021-42279
Last Modified: 19 Aug 2026Chakra Scripting Engine Memory Corruption Vulnerability
CVE-2021-42278
Last Modified: 19 Aug 2026Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2021-42277
Last Modified: 19 Aug 2026Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
CVE-2021-42276
Last Modified: 19 Aug 2026Microsoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2021-42275
Last Modified: 19 Aug 2026Microsoft COM for Windows Remote Code Execution Vulnerability
CVE-2021-42274
Last Modified: 19 Aug 2026Windows Hyper-V Discrete Device Assignment (DDA) Denial of Service Vulnerability
CVE-2021-41379
Last Modified: 19 Aug 2026Windows Installer Elevation of Privilege Vulnerability
CVE-2021-41378
Last Modified: 19 Aug 2026Windows NTFS Remote Code Execution Vulnerability
CVE-2021-41377
Last Modified: 19 Aug 2026Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
