CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-36988

    Last Modified: 21 Nov 2024

    There is a Parameter verification issue in Huawei Smartphone.Successful exploitation of this vulnerability can affect service integrity.

    Published: 28 Oct 2021
    5.9
    Medium

    CVE-2021-36987

    Last Modified: 21 Nov 2024

    There is a issue that nodes in the linked list being freed for multiple times in Huawei Smartphone due to race conditions. Successful exploitation of this vulnerability can cause the system to restart.

    Published: 28 Oct 2021
    9.8
    Critical

    CVE-2021-36986

    Last Modified: 21 Nov 2024

    There is a vulnerability of tampering with the kernel in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions.

    Published: 28 Oct 2021
    7.5
    High

    CVE-2021-36985

    Last Modified: 21 Nov 2024

    There is a Code injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may exhaust system resources and cause the system to restart.

    Published: 28 Oct 2021
    7.5
    High

    CVE-2021-22491

    Last Modified: 21 Nov 2024

    There is an Input verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.

    Published: 28 Oct 2021
    5.3
    Medium

    CVE-2021-22490

    Last Modified: 21 Nov 2024

    There is a Permission verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect the device performance.

    Published: 28 Oct 2021
    7.5
    High

    CVE-2021-22488

    Last Modified: 21 Nov 2024

    There is an Unauthorized file access vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability by modifying soft links may tamper with the files restored from backups.

    Published: 28 Oct 2021
    7.5
    High

    CVE-2021-22487

    Last Modified: 21 Nov 2024

    There is an Out-of-bounds read vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service availability.

    Published: 28 Oct 2021
    7.5
    High

    CVE-2021-22486

    Last Modified: 21 Nov 2024

    There is a issue of Unstandardized field names in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 28 Oct 2021
    7.5
    High

    CVE-2021-22485

    Last Modified: 21 Nov 2024

    There is a SSID vulnerability with Wi-Fi network connections in Huawei devices.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 28 Oct 2021
    7.5
    High

    CVE-2021-22483

    Last Modified: 21 Nov 2024

    There is a issue of IP address spoofing in Huawei Smartphone. Successful exploitation of this vulnerability may cause DoS.

    Published: 28 Oct 2021
    5.3
    Medium

    CVE-2021-22475

    Last Modified: 21 Nov 2024

    There is an Improper permission management vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 28 Oct 2021
    9.8
    Critical

    CVE-2021-22474

    Last Modified: 21 Nov 2024

    There is an Out-of-bounds memory access in Huawei Smartphone.Successful exploitation of this vulnerability may cause process exceptions.

    Published: 28 Oct 2021
    7.5
    High

    CVE-2021-22473

    Last Modified: 21 Nov 2024

    There is an Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 28 Oct 2021
    7.5
    High

    CVE-2021-22472

    Last Modified: 21 Nov 2024

    There is an Improper verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 28 Oct 2021
    5.3
    Medium

    CVE-2021-22407

    Last Modified: 21 Nov 2024

    There is a Configuration defects in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 28 Oct 2021
    7.5
    High

    CVE-2021-22406

    Last Modified: 21 Nov 2024

    There is an Uncaught Exception vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the app to exit unexpectedly.

    Published: 28 Oct 2021
    7.5
    High

    CVE-2021-22405

    Last Modified: 21 Nov 2024

    There is a Configuration defects in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.

    Published: 28 Oct 2021
    5.3
    Medium

    CVE-2021-22404

    Last Modified: 21 Nov 2024

    There is a Directory traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 28 Oct 2021
    9.8
    Critical

    CVE-2021-22403

    Last Modified: 21 Nov 2024

    There is a vulnerability of hijacking unverified providers in Huawei Smartphone.Successful exploitation of this vulnerability may allow attackers to hijack the device and forge UIs to induce users to execute malicious commands.

    Published: 28 Oct 2021
    7.5
    High

    CVE-2021-22402

    Last Modified: 21 Nov 2024

    There is a DoS vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause DoS attacks.

    Published: 28 Oct 2021
    7.5
    High

    CVE-2021-22401

    Last Modified: 21 Nov 2024

    There is a Remote DoS vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability can affect service integrity.

    Published: 28 Oct 2021
    5.3
    Medium

    CVE-2021-22482

    Last Modified: 21 Nov 2024

    There is an Uninitialized variable vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause transmission of invalid data.

    Published: 28 Oct 2021
    7.5
    High

    CVE-2021-22481

    Last Modified: 21 Nov 2024

    There is a Verification errors vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 28 Oct 2021
    9.1
    Critical

    CVE-2021-22436

    Last Modified: 21 Nov 2024

    There is a Logic Bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service integrity and availability.

    Published: 28 Oct 2021
    8.8
    High

    CVE-2021-37915

    Last Modified: 21 Nov 2024

    An issue was discovered on the Grandstream HT801 Analog Telephone Adaptor before 1.0.29.8. From the limited configuration shell, it is possible to set the malicious gdb_debug_server variable. As a result, after a reboot, the device downloads and executes malicious scripts from an attacker-defined host.

    Published: 28 Oct 2021
    8.8
    High

    CVE-2021-37748

    Last Modified: 21 Nov 2024

    Multiple buffer overflows in the limited configuration shell (/sbin/gs_config) on Grandstream HT801 devices before 1.0.29 allow remote authenticated users to execute arbitrary code as root via a crafted manage_if setting, thus bypassing the intended restrictions of this shell and taking full control of the device. There are default weak credentials that can be used to authenticate.

    Published: 28 Oct 2021
    10
    Critical

    CVE-2019-19810

    Last Modified: 21 Nov 2024

    Zoom Call Recording 6.3.1 from Eleveo is vulnerable to Java Deserialization attacks targeting the inbuilt RMI service. A remote unauthenticated attacker can exploit this vulnerability by sending crafted RMI requests to execute arbitrary code on the target host.

    Published: 28 Oct 2021
    4.3
    Medium

    CVE-2021-22096

    Last Modified: 21 Nov 2024

    In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.

    Published: 28 Oct 2021
    6.5
    Medium

    CVE-2020-10005

    Last Modified: 21 Nov 2024

    A resource exhaustion issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1. An attacker in a privileged network position may be able to perform denial of service.

    Published: 28 Oct 2021
    6.5
    Medium

    CVE-2021-3906

    Last Modified: 21 Nov 2024

    bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type

    Published: 27 Oct 2021
    5.4
    Medium

    CVE-2021-3904

    Last Modified: 21 Nov 2024

    grav is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 27 Oct 2021
    8.8
    High

    CVE-2021-3901

    Last Modified: 21 Nov 2024

    firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

    Published: 27 Oct 2021
    4.7
    Medium

    CVE-2021-1117

    Last Modified: 21 Nov 2024

    Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an attacker through specific configuration and with local unprivileged system access may cause improper input validation, which may lead to denial of service.

    Published: 27 Oct 2021
    5.5
    Medium

    CVE-2021-1116

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where a NULL pointer dereference in the kernel, created within user mode code, may lead to a denial of service in the form of a system crash.

    Published: 27 Oct 2021
    6.5
    Medium

    CVE-2021-1115

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for private IOCTLs, where an attacker with local unprivileged system access may cause a NULL pointer dereference, which may lead to denial of service in a component beyond the vulnerable component.

    Published: 27 Oct 2021
    7.5
    High

    CVE-2021-41191

    Last Modified: 21 Nov 2024

    Roblox-Purchasing-Hub is an open source Roblox product purchasing hub. A security risk in versions 1.0.1 and prior allowed people who have someone's API URL to get product files without an API key. This issue is fixed in version 1.0.2. As a workaround, add `@require_apikey` in `BOT/lib/cogs/website.py` under the route for `/v1/products`.

    Published: 27 Oct 2021
    9.8
    Critical

    CVE-2020-21250

    Last Modified: 21 Nov 2024

    CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php.

    Published: 27 Oct 2021
    8.6
    High

    CVE-2021-40118

    Last Modified: 11 Aug 2026

    A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS requests. An attacker could exploit this vulnerability by sending a malicious HTTPS request to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

    Published: 27 Oct 2021
    8.6
    High

    CVE-2021-40117

    Last Modified: 11 Aug 2026

    A vulnerability in SSL/TLS message handler for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because incoming SSL/TLS packets are not properly processed. An attacker could exploit this vulnerability by sending a crafted SSL/TLS packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

    Published: 27 Oct 2021
    8.6
    High

    CVE-2021-40116

    Last Modified: 11 Aug 2026

    Multiple Cisco products are affected by a vulnerability in Snort rules that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.The vulnerability is due to improper handling of the Block with Reset or Interactive Block with Reset actions if a rule is configured without proper constraints. An attacker could exploit this vulnerability by sending a crafted IP packet to the affected device. A successful exploit could allow the attacker to cause through traffic to be dropped. Note: Only products with Snort3 configured and either a rule with Block with Reset or Interactive Block with Reset actions configured are vulnerable. Products configured with Snort2 are not vulnerable.

    Published: 27 Oct 2021
    6.8
    Medium

    CVE-2021-40114

    Last Modified: 11 Aug 2026

    Multiple Cisco products are affected by a vulnerability in the way the Snort detection engine processes ICMP traffic that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper memory resource management while the Snort detection engine is processing ICMP packets. An attacker could exploit this vulnerability by sending a series of ICMP packets through an affected device. A successful exploit could allow the attacker to exhaust resources on the affected device, causing the device to reload.

    Published: 27 Oct 2021
    5.3
    Medium

    CVE-2021-34794

    Last Modified: 11 Aug 2026

    A vulnerability in the Simple Network Management Protocol version 3 (SNMPv3) access control functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to query SNMP data. This vulnerability is due to ineffective access control. An attacker could exploit this vulnerability by sending an SNMPv3 query to an affected device from a host that is not permitted by the SNMPv3 access control list. A successful exploit could allow the attacker to send an SNMP query to an affected device and retrieve information from the device. The attacker would need valid credentials to perform the SNMP query.

    Published: 27 Oct 2021
    8.6
    High

    CVE-2021-34793

    Last Modified: 11 Aug 2026

    A vulnerability in the TCP Normalizer of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software operating in transparent mode could allow an unauthenticated, remote attacker to poison MAC address tables, resulting in a denial of service (DoS) vulnerability. This vulnerability is due to incorrect handling of certain TCP segments when the affected device is operating in transparent mode. An attacker could exploit this vulnerability by sending a crafted TCP segment through an affected device. A successful exploit could allow the attacker to poison the MAC address tables in adjacent devices, resulting in network disruption.

    Published: 27 Oct 2021
    8.6
    High

    CVE-2021-34792

    Last Modified: 11 Aug 2026

    A vulnerability in the memory management of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management when connection rates are high. An attacker could exploit this vulnerability by opening a significant number of connections on an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

    Published: 27 Oct 2021
    4.7
    Medium

    CVE-2021-34791

    Last Modified: 11 Aug 2026

    Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the ALG and open unauthorized connections with a host located behind the ALG. For more information about these vulnerabilities, see the Details section of this advisory. Note: These vulnerabilities have been publicly discussed as NAT Slipstreaming.

    Published: 27 Oct 2021
    4.7
    Medium

    CVE-2021-34790

    Last Modified: 11 Aug 2026

    Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the ALG and open unauthorized connections with a host located behind the ALG. For more information about these vulnerabilities, see the Details section of this advisory. Note: These vulnerabilities have been publicly discussed as NAT Slipstreaming.

    Published: 27 Oct 2021
    5.3
    Medium

    CVE-2021-34787

    Last Modified: 11 Aug 2026

    A vulnerability in the identity-based firewall (IDFW) rule processing feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass security protections. This vulnerability is due to improper handling of network requests by affected devices configured to use object group search. An attacker could exploit this vulnerability by sending a specially crafted network request to an affected device. A successful exploit could allow the attacker to bypass access control list (ACL) rules on the device, bypass security protections, and send network traffic to unauthorized hosts.

    Published: 27 Oct 2021
    8.6
    High

    CVE-2021-34783

    Last Modified: 11 Aug 2026

    A vulnerability in the software-based SSL/TLS message handler of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient validation of SSL/TLS messages when the device performs software-based SSL/TLS decryption. An attacker could exploit this vulnerability by sending a crafted SSL/TLS message to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Note: Datagram TLS (DTLS) messages cannot be used to exploit this vulnerability.

    Published: 27 Oct 2021
    8.6
    High

    CVE-2021-34781

    Last Modified: 11 Aug 2026

    A vulnerability in the processing of SSH connections for multi-instance deployments of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to a lack of proper error handling when an SSH session fails to be established. An attacker could exploit this vulnerability by sending a high rate of crafted SSH connections to the instance. A successful exploit could allow the attacker to cause resource exhaustion, which causes a DoS condition on the affected device. The device must be manually reloaded to recover.

    Published: 27 Oct 2021