CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2021-40449

    Last Modified: 30 Oct 2025

    Win32k Elevation of Privilege Vulnerability

    Published: 13 Oct 2021
    7.8
    High

    CVE-2021-40443

    Last Modified: 21 Nov 2024

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

    Published: 13 Oct 2021
    8
    High

    CVE-2021-38672

    Last Modified: 21 Nov 2024

    Windows Hyper-V Remote Code Execution Vulnerability

    Published: 13 Oct 2021
    5.5
    Medium

    CVE-2021-38663

    Last Modified: 21 Nov 2024

    Windows exFAT File System Information Disclosure Vulnerability

    Published: 13 Oct 2021
    5.5
    Medium

    CVE-2021-38662

    Last Modified: 21 Nov 2024

    Windows Fast FAT File System Driver Information Disclosure Vulnerability

    Published: 13 Oct 2021
    8.8
    High

    CVE-2021-36970

    Last Modified: 21 Nov 2024

    Windows Print Spooler Spoofing Vulnerability

    Published: 13 Oct 2021
    7.5
    High

    CVE-2021-36953

    Last Modified: 21 Nov 2024

    Windows TCP/IP Denial of Service Vulnerability

    Published: 13 Oct 2021
    7.5
    High

    CVE-2021-34453

    Last Modified: 21 Nov 2024

    Microsoft Exchange Server Denial of Service Vulnerability

    Published: 13 Oct 2021
    7
    High

    CVE-2021-26442

    Last Modified: 21 Nov 2024

    Windows HTTP.sys Elevation of Privilege Vulnerability

    Published: 13 Oct 2021
    7.8
    High

    CVE-2021-26441

    Last Modified: 21 Nov 2024

    Storage Spaces Controller Elevation of Privilege Vulnerability

    Published: 13 Oct 2021
    9
    Critical

    CVE-2021-26427

    Last Modified: 21 Nov 2024

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Published: 13 Oct 2021
    6.7
    Medium

    CVE-2021-42327

    Last Modified: 21 Nov 2024

    dp_link_settings_write in drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_debugfs.c in the Linux kernel through 5.14.14 allows a heap-based buffer overflow by an attacker who can write a string to the AMD GPU display drivers debug filesystem. There are no checks on size within parse_write_buffer_into_params when it uses the size of copy_from_user to copy a userspace buffer into a 40-byte heap buffer.

    Published: 13 Oct 2021
    6.1
    Medium

    CVE-2021-20031

    Last Modified: 21 Nov 2024

    A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domains.

    Published: 12 Oct 2021
    7.1
    High

    CVE-2021-3330

    Last Modified: 21 Nov 2024

    RCE/DOS: Linked-list corruption leading to large out-of-bounds write while sorting for forged fragment list in Zephyr. Zephyr versions >= >=2.4.0 contain Out-of-bounds Write (CWE-787). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-fj4r-373f-9456

    Published: 12 Oct 2021
    8.3
    High

    CVE-2021-3323

    Last Modified: 21 Nov 2024

    Integer Underflow in 6LoWPAN IPHC Header Uncompression in Zephyr. Zephyr versions >= >=2.4.0 contain Integer Underflow (Wrap or Wraparound) (CWE-191). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-89j6-qpxf-pfpc

    Published: 12 Oct 2021
    6.5
    Medium

    CVE-2021-3322

    Last Modified: 21 Nov 2024

    Unexpected Pointer Aliasing in IEEE 802154 Fragment Reassembly in Zephyr. Zephyr versions >= >=2.4.0 contain NULL Pointer Dereference (CWE-476). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-p86r-gc4r-4mq3

    Published: 12 Oct 2021
    7.5
    High

    CVE-2021-3321

    Last Modified: 21 Nov 2024

    Integer Underflow in Zephyr in IEEE 802154 Fragment Reassembly Header Removal. Zephyr versions >= >=2.4.0 contain Integer Overflow to Buffer Overflow (CWE-680). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-w44j-66g7-xw99

    Published: 12 Oct 2021
    5.5
    Medium

    CVE-2020-22673

    Last Modified: 21 Nov 2024

    Memory leak in the senc_Parse function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a crafted input.

    Published: 12 Oct 2021
    5.5
    Medium

    CVE-2020-22674

    Last Modified: 21 Nov 2024

    An issue was discovered in gpac 0.8.0. An invalid memory dereference exists in the function FixTrackID located in isom_intern.c, which allows attackers to cause a denial of service (DoS) via a crafted input.

    Published: 12 Oct 2021
    5.5
    Medium

    CVE-2020-22675

    Last Modified: 21 Nov 2024

    An issue was discovered in gpac 0.8.0. The GetGhostNum function in stbl_read.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted input.

    Published: 12 Oct 2021
    5.5
    Medium

    CVE-2020-22677

    Last Modified: 21 Nov 2024

    An issue was discovered in gpac 0.8.0. The dump_data_hex function in box_dump.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted input.

    Published: 12 Oct 2021
    5.5
    Medium

    CVE-2020-22679

    Last Modified: 21 Nov 2024

    Memory leak in the sgpd_parse_entry function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a crafted input.

    Published: 12 Oct 2021
    5.5
    Medium

    CVE-2020-22678

    Last Modified: 21 Nov 2024

    An issue was discovered in gpac 0.8.0. The gf_media_nalu_remove_emulation_bytes function in av_parsers.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted input.

    Published: 12 Oct 2021
    6.8
    Medium

    CVE-2021-39184

    Last Modified: 21 Nov 2024

    Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to 11.5.0, 12.1.0, and 13.3.0 allows a sandboxed renderer to request a "thumbnail" image of an arbitrary file on the user's system. The thumbnail can potentially include significant parts of the original file, including textual data in many cases. Versions 15.0.0-alpha.10, 14.0.0, 13.3.0, 12.1.0, and 11.5.0 all contain a fix for the vulnerability. Two workarounds aside from upgrading are available. One may make the vulnerability significantly more difficult for an attacker to exploit by enabling `contextIsolation` in one's app. One may also disable the functionality of the `createThumbnailFromPath` API if one does not need it.

    Published: 12 Oct 2021
    9.8
    Critical

    CVE-2021-42325

    Last Modified: 21 Nov 2024

    Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.

    Published: 12 Oct 2021
    6.5
    Medium

    CVE-2021-38915

    Last Modified: 21 Nov 2024

    IBM Data Risk Manager 2.0.6 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 209947.

    Published: 12 Oct 2021
    7.5
    High

    CVE-2021-38862

    Last Modified: 21 Nov 2024

    IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 207980.

    Published: 12 Oct 2021
    7
    High

    CVE-2021-29645

    Last Modified: 21 Nov 2024

    Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 calls the SendMessageTimeoutW API with arbitrary arguments via a local pipe, leading to a local privilege escalation vulnerability. An attacker who exploits this issue could execute arbitrary code on the local system.

    Published: 12 Oct 2021
    8.1
    High

    CVE-2021-29644

    Last Modified: 21 Nov 2024

    Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 contains a remote code execution vulnerability because of an Integer Overflow. An attacker with network access to port 31016 may exploit this issue to execute code with unrestricted privileges on the underlying OS.

    Published: 12 Oct 2021
    5.3
    Medium

    CVE-2021-42326

    Last Modified: 21 Nov 2024

    Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.

    Published: 12 Oct 2021
    4.7
    Medium

    CVE-2021-27003

    Last Modified: 21 Nov 2024

    Clustered Data ONTAP versions prior to 9.5P18, 9.6P15, 9.7P14, 9.8P5 and 9.9.1 are missing an X-Frame-Options header which could allow a clickjacking attack.

    Published: 12 Oct 2021
    9.8
    Critical

    CVE-2021-40618

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability exists in openSIS Classic 8.0 via the 1) ADDR_CONT_USRN, 2) ADDR_CONT_PSWD, 3) SECN_CONT_USRN or 4) SECN_CONT_PSWD parameters in HoldAddressFields.php.

    Published: 12 Oct 2021
    7.5
    High

    CVE-2021-35496

    Last Modified: 21 Nov 2024

    The XMLA Connections component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO JasperReports Server for Microsoft Azure contains a difficult to exploit vulnerability that allows a low privileged attacker with network access to interfere with XML processing in the affected component. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions 7.2.1 and below, TIBCO JasperReports Server: versions 7.5.0 and 7.5.1, TIBCO JasperReports Server: version 7.8.0, TIBCO JasperReports Server: version 7.9.0, TIBCO JasperReports Server - Community Edition: versions 7.8.0 and below, TIBCO JasperReports Server - Developer Edition: versions 7.9.0 and below, TIBCO JasperReports Server for AWS Marketplace: versions 7.9.0 and below, TIBCO JasperReports Server for ActiveMatrix BPM: versions 7.9.0 and below, and TIBCO JasperReports Server for Microsoft Azure: version 7.8.0.

    Published: 12 Oct 2021
    9
    Critical

    CVE-2021-35495

    Last Modified: 21 Nov 2024

    The Scheduler Connection component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO JasperReports Server for Microsoft Azure contains an easily exploitable vulnerability that allows an authenticated attacker with network access to obtain FTP server passwords for other users of the affected system. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions 7.2.1 and below, TIBCO JasperReports Server: versions 7.5.0 and 7.5.1, TIBCO JasperReports Server: version 7.8.0, TIBCO JasperReports Server: version 7.9.0, TIBCO JasperReports Server - Community Edition: versions 7.8.0 and below, TIBCO JasperReports Server - Developer Edition: versions 7.9.0 and below, TIBCO JasperReports Server for AWS Marketplace: versions 7.9.0 and below, TIBCO JasperReports Server for ActiveMatrix BPM: versions 7.9.0 and below, and TIBCO JasperReports Server for Microsoft Azure: version 7.8.0.

    Published: 12 Oct 2021
    5.7
    Medium

    CVE-2021-35494

    Last Modified: 21 Nov 2024

    The Rest API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO JasperReports Server for Microsoft Azure contain a race condition that allows a low privileged authenticated attacker via the REST API to obtain read access to temporary objects created by other users on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions 7.2.1 and below, TIBCO JasperReports Server: versions 7.5.0 and 7.5.1, TIBCO JasperReports Server: version 7.8.0, TIBCO JasperReports Server: version 7.9.0, TIBCO JasperReports Server - Community Edition: versions 7.8.0 and below, TIBCO JasperReports Server - Developer Edition: versions 7.9.0 and below, TIBCO JasperReports Server for AWS Marketplace: versions 7.9.0 and below, TIBCO JasperReports Server for ActiveMatrix BPM: versions 7.9.0 and below, and TIBCO JasperReports Server for Microsoft Azure: version 7.8.0.

    Published: 12 Oct 2021
    5.4
    Medium

    CVE-2021-40292

    Last Modified: 21 Nov 2024

    A Stored Cross Site Sripting (XSS) vulnerability exists in DzzOffice 2.02.1 via the settingnew parameter.

    Published: 12 Oct 2021
    5.7
    Medium

    CVE-2021-41355

    Last Modified: 21 Nov 2024

    .NET Core and Visual Studio Information Disclosure Vulnerability

    Published: 12 Oct 2021
    —
    Unknown

    CVE-2021-41070

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: non

    Published: 12 Oct 2021
    —
    Unknown

    CVE-2021-41797

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: non

    Published: 12 Oct 2021
    —
    Unknown

    CVE-2021-41796

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: non

    Published: 12 Oct 2021
    —
    Unknown

    CVE-2021-41071

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 12 Oct 2021
    4.8
    Medium

    CVE-2021-35214

    Last Modified: 21 Nov 2024

    The vulnerability in SolarWinds Pingdom can be described as a failure to invalidate user session upon password or email address change. When running multiple active sessions in separate browser windows, it was observed a password or email address change could be changed without terminating the user session. This issue has been resolved on September 13, 2021.

    Published: 12 Oct 2021
    6.5
    Medium

    CVE-2021-37734

    Last Modified: 21 Nov 2024

    A remote unauthorized read access to files vulnerability was discovered in Aruba Instant version(s): 6.4.x.x: 6.4.4.8-4.2.4.18 and below; Aruba Instant 6.5.x.x: 6.5.4.19 and below; Aruba Instant 8.5.x.x: 8.5.0.12 and below; Aruba Instant 8.6.x.x: 8.6.0.11 and below; Aruba Instant 8.7.x.x: 8.7.1.3 and below; Aruba Instant 8.8.x.x: 8.8.0.0 and below. Aruba has released patches for Aruba Instant (IAP) that address this security vulnerability.

    Published: 12 Oct 2021
    5.3
    Medium

    CVE-2021-37735

    Last Modified: 21 Nov 2024

    A remote denial of service vulnerability was discovered in Aruba Instant version(s): Aruba Instant 6.5.x.x: 6.5.4.18 and below; Aruba Instant 8.5.x.x: 8.5.0.10 and below; Aruba Instant 8.6.x.x: 8.6.0.4 and below. Aruba has released patches for Aruba Instant (IAP) that address this security vulnerability.

    Published: 12 Oct 2021
    7.2
    High

    CVE-2021-37732

    Last Modified: 21 Nov 2024

    A remote arbitrary command execution vulnerability was discovered in HPE Aruba Instant (IAP) version(s): Aruba Instant 6.4.x.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x.x: 6.5.4.18 and below; Aruba Instant 8.5.x.x: 8.5.0.11 and below; Aruba Instant 8.6.x.x: 8.6.0.6 and below; Aruba Instant 8.7.x.x: 8.7.1.0 and below. Aruba has released patches for Aruba Instant (IAP) that address this security vulnerability.

    Published: 12 Oct 2021
    7.2
    High

    CVE-2021-37727

    Last Modified: 21 Nov 2024

    A remote arbitrary command execution vulnerability was discovered in HPE Aruba Instant (IAP) version(s): 6.4.x.x: 6.4.4.8-4.2.4.18 and below; Aruba Instant 6.5.x.x: 6.5.4.20 and below; Aruba Instant 8.5.x.x: 8.5.0.12 and below; Aruba Instant 8.6.x.x: 8.6.0.11 and below; Aruba Instant 8.7.x.x: 8.7.1.3 and below. Aruba has released patches for Aruba Instant (IAP) that address this security vulnerability.

    Published: 12 Oct 2021
    7.2
    High

    CVE-2021-37730

    Last Modified: 21 Nov 2024

    A remote arbitrary command execution vulnerability was discovered in HPE Aruba Instant (IAP) version(s): Aruba Instant 6.4.x.x: 6.4.4.8-4.2.4.18 and below; Aruba Instant 6.5.x.x: 6.5.4.20 and below; Aruba Instant 8.5.x.x: 8.5.0.12 and below; Aruba Instant 8.6.x.x: 8.6.0.11 and below; Aruba Instant 8.7.x.x: 8.7.1.3 and below. Aruba has released patches for Aruba Instant (IAP) that address this security vulnerability.

    Published: 12 Oct 2021
    9.8
    Critical

    CVE-2021-37726

    Last Modified: 21 Nov 2024

    A remote buffer overflow vulnerability was discovered in HPE Aruba Instant (IAP) version(s): Aruba Instant 8.7.x.x: 8.7.0.0 through 8.7.1.2. Aruba has released patches for Aruba Instant (IAP) that address this security vulnerability.

    Published: 12 Oct 2021
    7.5
    High

    CVE-2021-40500

    Last Modified: 21 Nov 2024

    SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an unauthenticated attacker to exploit missing XML validations at endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation can enable the attacker to retrieve arbitrary files from the server.

    Published: 12 Oct 2021
    5.5
    Medium

    CVE-2021-40498

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SAP SuccessFactors Mobile Application for Android - versions older than 2108, which allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service, which can lead to denial of service. The vulnerability is related to Android implementation methods that are widely used across Android mobile applications, and such methods are embedded into the SAP SuccessFactors mobile application. These Android methods begin executing once the user accesses their profile on the mobile application. While executing, it can also pick up the activities from other Android applications that are running in the background of the users device and are using the same types of methods in the application. Such vulnerability can also lead to phishing attacks that can be used for staging other types of attacks.

    Published: 12 Oct 2021