CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2020-9897

    Last Modified: 21 Nov 2024

    An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.2 and iPadOS 14.2, macOS Big Sur 11.0.1. Processing a maliciously crafted PDF may lead to arbitrary code execution.

    Published: 28 Oct 2021
    6.6
    Medium

    CVE-2021-3745

    Last Modified: 21 Nov 2024

    flatcore-cms is vulnerable to Unrestricted Upload of File with Dangerous Type

    Published: 28 Oct 2021
    7.5
    High

    CVE-2020-7875

    Last Modified: 21 Nov 2024

    DEXT5 Upload 5.0.0.117 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged for code execution.

    Published: 28 Oct 2021
    6.5
    Medium

    CVE-2021-22097

    Last Modified: 21 Nov 2024

    In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a message with content type application/x-java-serialized-object. It is possible to construct a malicious java.util.Dictionary object that can cause 100% CPU usage in the application if the toString() method is called.

    Published: 28 Oct 2021
    5.3
    Medium

    CVE-2021-22047

    Last Modified: 21 Nov 2024

    In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally exposed under URIs that can potentially be exposed for unauthorized access depending on the Spring Security configuration.

    Published: 28 Oct 2021
    7.5
    High

    CVE-2021-22044

    Last Modified: 21 Nov 2024

    In Spring Cloud OpenFeign 3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older unsupported versions, applications using type-level `@RequestMapping`annotations over Feign client interfaces, can be involuntarily exposing endpoints corresponding to `@RequestMapping`-annotated interface methods.

    Published: 28 Oct 2021
    6.1
    Medium

    CVE-2021-41728

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability exists in Sourcecodester News247 CMS 1.0 via the search function in articles.

    Published: 28 Oct 2021
    6.1
    Medium

    CVE-2020-22312

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability was discovered in the OJ/admin-tool /cal_scores.php function of HZNUOJ v1.0.

    Published: 28 Oct 2021
    7.1
    High

    CVE-2021-3823

    Last Modified: 21 Nov 2024

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects: Bitdefender GravityZone versions prior to 3.3.8.249.

    Published: 28 Oct 2021
    7.8
    High

    CVE-2021-3576

    Last Modified: 21 Nov 2024

    Execution with Unnecessary Privileges vulnerability in Bitdefender Endpoint Security Tools, Total Security allows a local attacker to elevate to 'NT AUTHORITY\System. Impersonation enables the server thread to perform actions on behalf of the client but within the limits of the client's security context. This issue affects: Bitdefender Endpoint Security Tools versions prior to 7.2.1.65. Bitdefender Total Security versions prior to 25.0.26.

    Published: 28 Oct 2021
    7.8
    High

    CVE-2021-3579

    Last Modified: 21 Nov 2024

    Incorrect Default Permissions vulnerability in the bdservicehost.exe and Vulnerability.Scan.exe components as used in Bitdefender Endpoint Security Tools for Windows, Total Security allows a local attacker to elevate privileges to NT AUTHORITY\SYSTEM This issue affects: Bitdefender Endpoint Security Tools for Windows versions prior to 7.2.1.65. Bitdefender Total Security versions prior to 7.2.1.65.

    Published: 28 Oct 2021
    —
    Unknown

    CVE-2018-14640

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2021
    —
    Unknown

    CVE-2018-1105

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 28 Oct 2021
    7.5
    High

    CVE-2021-37254

    Last Modified: 21 Nov 2024

    In M-Files Web product with versions before 20.10.9524.1 and 20.10.9445.0, a remote attacker could use a flaw to obtain unauthenticated access to 3rd party component license key information on server.

    Published: 28 Oct 2021
    6.7
    Medium

    CVE-2021-22278

    Last Modified: 21 Nov 2024

    A certificate validation vulnerability in PCM600 Update Manager allows attacker to get unwanted software packages to be installed on computer which has PCM600 installed.

    Published: 28 Oct 2021
    5.5
    Medium

    CVE-2021-22471

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may exploit this vulnerability to cause nearby process crash.

    Published: 28 Oct 2021
    3.3
    Low

    CVE-2021-22464

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Out-of-bounds Read vulnerability. Local attackers may exploit this vulnerability to cause system Soft Restart.

    Published: 28 Oct 2021
    5.5
    Medium

    CVE-2021-22461

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Allocation of Resources Without Limits or Throttling vulnerability. Local attackers may exploit this vulnerability to cause nearby process crash.

    Published: 28 Oct 2021
    3.3
    Low

    CVE-2021-22453

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to cause nearby process crash.

    Published: 28 Oct 2021
    5.5
    Medium

    CVE-2021-22467

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to read at any address.

    Published: 28 Oct 2021
    7.8
    High

    CVE-2021-22458

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability. Local attackers may exploit this vulnerability to cause arbitrary code execution.

    Published: 28 Oct 2021
    5.5
    Medium

    CVE-2021-22454

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause core dump.

    Published: 28 Oct 2021
    7.1
    High

    CVE-2021-22469

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Out-of-bounds Read vulnerability. Local attackers may exploit this vulnerability to cause kernel out-of-bounds read.

    Published: 28 Oct 2021
    3.3
    Low

    CVE-2021-22468

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability. Local attackers may exploit this vulnerability to cause kernel address leakage.

    Published: 28 Oct 2021
    5.5
    Medium

    CVE-2021-22466

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Use After Free vulnerability. Local attackers may exploit this vulnerability to cause kernel crash.

    Published: 28 Oct 2021
    5.5
    Medium

    CVE-2021-22463

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Use After Free vulnerability . Local attackers may exploit this vulnerability to cause Kernel Information disclosure.

    Published: 28 Oct 2021
    5.5
    Medium

    CVE-2021-22462

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may exploit this vulnerability to cause kernel crash.

    Published: 28 Oct 2021
    5.5
    Medium

    CVE-2021-22455

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause the memory which is not released.

    Published: 28 Oct 2021
    5.5
    Medium

    CVE-2021-22452

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to read at any address.

    Published: 28 Oct 2021
    5.5
    Medium

    CVE-2021-22465

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Heap-based Buffer Overflow vulnerability. Local attackers may exploit this vulnerability to cause Kernel System unavailable.

    Published: 28 Oct 2021
    5.5
    Medium

    CVE-2021-22456

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel System unavailable.

    Published: 28 Oct 2021
    5.5
    Medium

    CVE-2021-22450

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Incomplete Cleanup vulnerability. Local attackers may exploit this vulnerability to cause memory exhaustion.

    Published: 28 Oct 2021
    7.8
    High

    CVE-2021-22470

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Privileges Controls vulnerability. Local attackers may exploit this vulnerability to expand the Recording Trusted Domain.

    Published: 28 Oct 2021
    5.5
    Medium

    CVE-2021-22460

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Insufficient Verification of Data Authenticity vulnerability. Local attackers may exploit this vulnerability to bypass the control mechanism.

    Published: 28 Oct 2021
    5.5
    Medium

    CVE-2021-22459

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may exploit this vulnerability to cause System functions which are unavailable.

    Published: 28 Oct 2021
    3.3
    Low

    CVE-2021-22457

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to cause out-of-bounds write.

    Published: 28 Oct 2021
    7.8
    High

    CVE-2021-22451

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting.

    Published: 28 Oct 2021
    9.8
    Critical

    CVE-2021-37002

    Last Modified: 21 Nov 2024

    There is a Memory out-of-bounds access vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause malicious code to be executed.

    Published: 28 Oct 2021
    7.5
    High

    CVE-2021-37001

    Last Modified: 21 Nov 2024

    There is a Register tampering vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may allow the register value to be modified.

    Published: 28 Oct 2021
    7.8
    High

    CVE-2021-36999

    Last Modified: 21 Nov 2024

    There is a Buffer overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability by sending malicious images and inducing users to open the images may cause remote code execution.

    Published: 28 Oct 2021
    5.3
    Medium

    CVE-2021-36998

    Last Modified: 21 Nov 2024

    There is an Improper verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may allow attempts to read an array that is out of bounds.

    Published: 28 Oct 2021
    5.3
    Medium

    CVE-2021-36997

    Last Modified: 21 Nov 2024

    There is a Low memory error in Huawei Smartphone due to the unlimited size of images to be parsed.Successful exploitation of this vulnerability may cause the Gallery or Files app to exit unexpectedly.

    Published: 28 Oct 2021
    5.3
    Medium

    CVE-2021-36996

    Last Modified: 21 Nov 2024

    There is an Improper verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause transmission of certain virtual information.

    Published: 28 Oct 2021
    7.5
    High

    CVE-2021-36995

    Last Modified: 21 Nov 2024

    There is an Unauthorized file access vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability by modifying soft links may tamper with the files restored from backups.

    Published: 28 Oct 2021
    3.7
    Low

    CVE-2021-36994

    Last Modified: 21 Nov 2024

    There is a issue that trustlist strings being repeatedly inserted into the linked list in Huawei Smartphone due to race conditions. Successful exploitation of this vulnerability can cause exceptions when managing the system trustlist.

    Published: 28 Oct 2021
    7.5
    High

    CVE-2021-36993

    Last Modified: 21 Nov 2024

    There is a Memory leaks vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.

    Published: 28 Oct 2021
    7.5
    High

    CVE-2021-36992

    Last Modified: 21 Nov 2024

    There is a Public key verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 28 Oct 2021
    7.5
    High

    CVE-2021-36991

    Last Modified: 21 Nov 2024

    There is an Unauthorized file access vulnerability in Huawei Smartphone due to unstandardized path input.Successful exploitation of this vulnerability by creating malicious file paths can cause unauthorized file access.

    Published: 28 Oct 2021
    9.8
    Critical

    CVE-2021-36990

    Last Modified: 21 Nov 2024

    There is a vulnerability of tampering with the kernel in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions.

    Published: 28 Oct 2021
    9.8
    Critical

    CVE-2021-36989

    Last Modified: 21 Nov 2024

    There is a Kernel crash vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions.

    Published: 28 Oct 2021