CVE Feed

    Dashboard / CVE

    2.3
    Low

    CVE-2021-41376

    Last Modified: 19 Aug 2026

    Azure Sphere Information Disclosure Vulnerability

    Published: 10 Nov 2021
    4.4
    Medium

    CVE-2021-41375

    Last Modified: 19 Aug 2026

    Azure Sphere Information Disclosure Vulnerability

    Published: 10 Nov 2021
    6.7
    Medium

    CVE-2021-41374

    Last Modified: 19 Aug 2026

    Azure Sphere Information Disclosure Vulnerability

    Published: 10 Nov 2021
    5.5
    Medium

    CVE-2021-41373

    Last Modified: 19 Aug 2026

    FSLogix Information Disclosure Vulnerability

    Published: 10 Nov 2021
    7.6
    High

    CVE-2021-41372

    Last Modified: 19 Aug 2026

    A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directly by the victim. Combining these 2 vulnerabilities together, an attacker is able to upload malicious Power BI templates files to the server using the victim's session and run scripts in the security context of the user and perform privilege escalation in case the victim has admin privileges when the victim access one of the HTML files present in the malicious Power BI template uploaded. The security update addresses the vulnerability by helping to ensure that Power BI Report Server properly sanitize file uploads.

    Published: 10 Nov 2021
    4.4
    Medium

    CVE-2021-41371

    Last Modified: 19 Aug 2026

    Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

    Published: 10 Nov 2021
    7.8
    High

    CVE-2021-41370

    Last Modified: 19 Aug 2026

    NTFS Elevation of Privilege Vulnerability

    Published: 10 Nov 2021
    6.1
    Medium

    CVE-2021-41368

    Last Modified: 19 Aug 2026

    Microsoft Access Remote Code Execution Vulnerability

    Published: 10 Nov 2021
    7.8
    High

    CVE-2021-41367

    Last Modified: 19 Aug 2026

    NTFS Elevation of Privilege Vulnerability

    Published: 10 Nov 2021
    7.8
    High

    CVE-2021-41366

    Last Modified: 19 Aug 2026

    Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability

    Published: 10 Nov 2021
    7.5
    High

    CVE-2021-41356

    Last Modified: 19 Aug 2026

    Windows Denial of Service Vulnerability

    Published: 10 Nov 2021
    4.3
    Medium

    CVE-2021-41351

    Last Modified: 19 Aug 2026

    Microsoft Edge (Chrome based) Spoofing on IE Mode

    Published: 10 Nov 2021
    6.5
    Medium

    CVE-2021-41349

    Last Modified: 19 Aug 2026

    Microsoft Exchange Server Spoofing Vulnerability

    Published: 10 Nov 2021
    7.8
    High

    CVE-2021-40442

    Last Modified: 19 Aug 2026

    Microsoft Excel Remote Code Execution Vulnerability

    Published: 10 Nov 2021
    8.8
    High

    CVE-2021-38666

    Last Modified: 19 Aug 2026

    Remote Desktop Client Remote Code Execution Vulnerability

    Published: 10 Nov 2021
    7.4
    High

    CVE-2021-38665

    Last Modified: 19 Aug 2026

    Remote Desktop Protocol Client Information Disclosure Vulnerability

    Published: 10 Nov 2021
    4.4
    Medium

    CVE-2021-38631

    Last Modified: 19 Aug 2026

    Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

    Published: 10 Nov 2021
    7.8
    High

    CVE-2021-36957

    Last Modified: 19 Aug 2026

    Windows Desktop Bridge Elevation of Privilege Vulnerability

    Published: 10 Nov 2021
    3.3
    Low

    CVE-2021-26444

    Last Modified: 19 Aug 2026

    Azure RTOS Information Disclosure Vulnerability

    Published: 10 Nov 2021
    9
    Critical

    CVE-2021-26443

    Last Modified: 19 Aug 2026

    Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability

    Published: 10 Nov 2021
    2.7
    Low

    CVE-2021-37939

    Last Modified: 21 Nov 2024

    It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from public view. Using this vulnerability, a malicious user with the ability to create connectors, could utilize these connectors to view limited HTTP response data on hosts accessible to the cluster.

    Published: 10 Nov 2021
    5.5
    Medium

    CVE-2021-3947

    Last Modified: 21 Nov 2024

    A stack-buffer-overflow was found in QEMU in the NVME component. The flaw lies in nvme_changed_nslist() where a malicious guest controlling certain input can read out of bounds memory. A malicious user could use this flaw leading to disclosure of sensitive information.

    Published: 10 Nov 2021
    6.3
    Medium

    CVE-2021-3948

    Last Modified: 21 Nov 2024

    An incorrect default permissions vulnerability was found in the mig-controller. Due to an incorrect cluster namespaces handling an attacker may be able to migrate a malicious workload to the target cluster, impacting confidentiality, integrity, and availability of the services located on that cluster.

    Published: 10 Nov 2021
    8.8
    High

    CVE-2021-37157

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. $HOME/OGP/Cfg/Config.pm has the root password in cleartext.

    Published: 9 Nov 2021
    8.8
    High

    CVE-2021-37158

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. An authenticated attacker could inject OS commands by starting a Counter-Strike server and using the map field to enter a Bash command.

    Published: 9 Nov 2021
    5.5
    Medium

    CVE-2021-43575

    Last Modified: 21 Nov 2024

    KNX ETS6 through 6.0.0 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project information, a similar issue to CVE-2021-36799. NOTE: The vendor disputes this because it is not the responsibility of the ETS to securely store cryptographic key material when it is not being exported

    Published: 9 Nov 2021
    6.1
    Medium

    CVE-2021-35488

    Last Modified: 21 Nov 2024

    Thruk 2.40-2 allows /thruk/#cgi-bin/status.cgi?style=combined&title={TITLE] Reflected XSS via the host or title parameter. An attacker could inject arbitrary JavaScript into status.cgi. The payload would be triggered every time an authenticated user browses the page containing it.

    Published: 9 Nov 2021
    6.1
    Medium

    CVE-2021-35489

    Last Modified: 21 Nov 2024

    Thruk 2.40-2 allows /thruk/#cgi-bin/extinfo.cgi?type=2&host={HOSTNAME]&service={SERVICENAME]&backend={BACKEND] Reflected XSS via the host or service parameter. An attacker could inject arbitrary JavaScript into extinfo.cgi. The malicious payload would be triggered every time an authenticated user browses the page containing it.

    Published: 9 Nov 2021
    9.8
    Critical

    CVE-2021-43568

    Last Modified: 21 Nov 2024

    The verify function in the Stark Bank Elixir ECDSA library (ecdsa-elixir) 1.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.

    Published: 9 Nov 2021
    9.8
    Critical

    CVE-2021-43570

    Last Modified: 21 Nov 2024

    The verify function in the Stark Bank Java ECDSA library (ecdsa-java) 1.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.

    Published: 9 Nov 2021
    9.8
    Critical

    CVE-2021-43571

    Last Modified: 21 Nov 2024

    The verify function in the Stark Bank Node.js ECDSA library (ecdsa-node) 1.1.2 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.

    Published: 9 Nov 2021
    9.8
    Critical

    CVE-2021-43572

    Last Modified: 21 Nov 2024

    The verify function in the Stark Bank Python ECDSA library (aka starkbank-escada or ecdsa-python) before 2.0.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.

    Published: 9 Nov 2021
    9.8
    Critical

    CVE-2021-43569

    Last Modified: 21 Nov 2024

    The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.

    Published: 9 Nov 2021
    7.1
    High

    CVE-2021-20119

    Last Modified: 21 Nov 2024

    The password change utility for the Arris SurfBoard SB8200 can have safety measures bypassed that allow any logged-in user to change the administrator password.

    Published: 9 Nov 2021
    8.8
    High

    CVE-2020-28419

    Last Modified: 21 Nov 2024

    During installation with certain driver software or application packages an arbitrary code execution could occur.

    Published: 9 Nov 2021
    7.5
    High

    CVE-2021-43174

    Last Modified: 21 Nov 2024

    NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in these versions of Routinator. RRDP uses XML which allows arbitrary amounts of white space in the encoded data. The gzip scheme compresses such white space extremely well, leading to very small compressed files that become huge when being decompressed for further processing, big enough that Routinator runs out of memory when parsing input data waiting for the next XML element.

    Published: 9 Nov 2021
    7.5
    High

    CVE-2021-43173

    Last Modified: 21 Nov 2024

    In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feeding bytes to keep the connection alive. This can be used to effectively stall validation. While Routinator has a configurable time-out value for RRDP connections, this time-out was only applied to individual read or write operations rather than the complete request. Thus, if an RRDP repository sends a little bit of data before that time-out expired, it can continuously extend the time it takes for the request to finish. Since validation will only continue once the update of an RRDP repository has concluded, this delay will cause validation to stall, leading to Routinator continuing to serve the old data set or, if in the initial validation run directly after starting, never serve any data at all.

    Published: 9 Nov 2021
    7.5
    High

    CVE-2021-43172

    Last Modified: 21 Nov 2024

    NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuously generating a new child CA that only consists of another CA using a different RRDP repository, a malicious CA can create a chain of CAs of de-facto infinite length. Routinator prior to version 0.10.2 did not contain a limit on the length of such a chain and will therefore continue to process this chain forever. As a result, the validation run will never finish, leading to Routinator continuing to serve the old data set or, if in the initial validation run directly after starting, never serve any data at all.

    Published: 9 Nov 2021
    7.5
    High

    CVE-2021-43180

    Last Modified: 21 Nov 2024

    In JetBrains Hub before 2021.1.13690, information disclosure via avatar metadata is possible.

    Published: 9 Nov 2021
    7.5
    High

    CVE-2021-43182

    Last Modified: 21 Nov 2024

    In JetBrains Hub before 2021.1.13415, a DoS via user information is possible.

    Published: 9 Nov 2021
    6.1
    Medium

    CVE-2021-43181

    Last Modified: 21 Nov 2024

    In JetBrains Hub before 2021.1.13690, stored XSS is possible.

    Published: 9 Nov 2021
    7.8
    High

    CVE-2019-18912

    Last Modified: 21 Nov 2024

    A potential security vulnerability has been identified for certain HP printers and MFPs with Troy solutions. For affected printers with FutureSmart Firmware bundle version 4.9 or 4.9.0.1 the potential vulnerability may cause instability in the solution.

    Published: 9 Nov 2021
    9.8
    Critical

    CVE-2021-43183

    Last Modified: 21 Nov 2024

    In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed.

    Published: 9 Nov 2021
    7.5
    High

    CVE-2021-43203

    Last Modified: 21 Nov 2024

    In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly.

    Published: 9 Nov 2021
    5.3
    Medium

    CVE-2021-43194

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2021.1.2, user enumeration was possible.

    Published: 9 Nov 2021
    9.8
    Critical

    CVE-2021-43193

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible.

    Published: 9 Nov 2021
    7.5
    High

    CVE-2021-43196

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2021.1, information disclosure via the Docker Registry connection dialog is possible.

    Published: 9 Nov 2021
    5.3
    Medium

    CVE-2021-43195

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2021.1.2, some HTTP security headers were missing.

    Published: 9 Nov 2021
    6.1
    Medium

    CVE-2021-43197

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2021.1.2, email notifications could include unescaped HTML for XSS.

    Published: 9 Nov 2021
    5.3
    Medium

    CVE-2021-43199

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2021.1.2, permission checks in the Create Patch functionality are insufficient.

    Published: 9 Nov 2021