CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2021-40845

    Last Modified: 21 Nov 2024

    The web part of Zenitel AlphaCom XE Audio Server through 11.2.3.10, called AlphaWeb XE, does not restrict file upload in the Custom Scripts section at php/index.php. Neither the content nor extension of the uploaded files is checked, allowing execution of PHP code under the /cmd directory.

    Published: 15 Sept 2021
    7.7
    High

    CVE-2021-30137

    Last Modified: 21 Nov 2024

    Assyst 10 SP7.5 has authenticated XXE leading to SSRF via XML unmarshalling. The application allows users to send JSON or XML data to the server. It was possible to inject malicious XML data through several access points.

    Published: 15 Sept 2021
    7.5
    High

    CVE-2021-3794

    Last Modified: 24 Sept 2025

    vuelidate is vulnerable to Inefficient Regular Expression Complexity

    Published: 15 Sept 2021
    8.4
    High

    CVE-2020-3960

    Last Modified: 21 Nov 2024

    VMware ESXi (6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds read vulnerability in NVMe functionality. A malicious actor with local non-administrative access to a virtual machine with a virtual NVMe controller present may be able to read privileged information contained in physical memory.

    Published: 15 Sept 2021
    5.4
    Medium

    CVE-2021-3785

    Last Modified: 21 Nov 2024

    yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 15 Sept 2021
    8.6
    High

    CVE-2021-27662

    Last Modified: 21 Nov 2024

    The KT-1 door controller is susceptible to replay or man-in-the-middle attacks where an attacker can record and replay TCP packets. This issue affects Johnson Controls KT-1 all versions up to and including 3.01

    Published: 15 Sept 2021
    6.1
    Medium

    CVE-2021-3783

    Last Modified: 21 Nov 2024

    yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 15 Sept 2021
    8.8
    High

    CVE-2021-22148

    Last Modified: 21 Nov 2024

    Elastic Enterprise Search App Search versions before 7.14.0 was vulnerable to an issue where API keys were not bound to the same engines as their creator. This could lead to a less privileged user gaining access to unauthorized engines.

    Published: 15 Sept 2021
    8.8
    High

    CVE-2021-22149

    Last Modified: 21 Nov 2024

    Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alternate route. Using this vulnerability, an authenticated attacker could utilize API keys belonging to higher privileged users.

    Published: 15 Sept 2021
    7.5
    High

    CVE-2020-35340

    Last Modified: 21 Nov 2024

    A local file inclusion vulnerability in ExpertPDF 9.5.0 through 14.1.0 allows attackers to read the file contents from files that the running ExpertPDF process has access to read.

    Published: 15 Sept 2021
    6.3
    Medium

    CVE-2021-40448

    Last Modified: 10 Aug 2026

    Microsoft Accessibility Insights for Android Information Disclosure Vulnerability

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-40447

    Last Modified: 10 Aug 2026

    Windows Print Spooler Elevation of Privilege Vulnerability

    Published: 15 Sept 2021
    8.8
    High

    CVE-2021-40444

    Last Modified: 10 Aug 2026

    Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents. An attacker could craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine. The attacker would then have to convince the user to open the malicious document. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Microsoft Defender Antivirus and Microsoft Defender for Endpoint both provide detection and protections for the known vulnerability. Customers should keep antimalware products up to date. Customers who utilize automatic updates do not need to take additional action. Enterprise customers who manage updates should select the detection build 1.349.22.0 or newer and deploy it across their environments. Microsoft Defender for Endpoint alerts will be displayed as: “Suspicious Cpl File Execution”. Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs. Please see the Mitigations and Workaround sections for important information about steps you can take to protect your system from this vulnerability. UPDATE September 14, 2021: Microsoft has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. Please see the FAQ for important information about which updates are applicable to your system.

    Published: 15 Sept 2021
    5.4
    Medium

    CVE-2021-40440

    Last Modified: 10 Aug 2026

    Microsoft Dynamics Business Central Cross-site Scripting Vulnerability

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-38671

    Last Modified: 10 Aug 2026

    Windows Print Spooler Elevation of Privilege Vulnerability

    Published: 15 Sept 2021
    6.4
    Medium

    CVE-2021-38669

    Last Modified: 10 Aug 2026

    Microsoft Edge (Chromium-based) Tampering Vulnerability

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-38667

    Last Modified: 10 Aug 2026

    Windows Print Spooler Elevation of Privilege Vulnerability

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-38661

    Last Modified: 10 Aug 2026

    HEVC Video Extensions Remote Code Execution Vulnerability

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-38660

    Last Modified: 10 Aug 2026

    Microsoft Office Graphics Remote Code Execution Vulnerability

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-38659

    Last Modified: 10 Aug 2026

    Microsoft Office Graphics Remote Code Execution Vulnerability

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-38658

    Last Modified: 10 Aug 2026

    Microsoft Office Graphics Remote Code Execution Vulnerability

    Published: 15 Sept 2021
    6.1
    Medium

    CVE-2021-38657

    Last Modified: 10 Aug 2026

    Microsoft Office Graphics Component Information Disclosure Vulnerability

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-38656

    Last Modified: 10 Aug 2026

    Microsoft Word Remote Code Execution Vulnerability

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-38655

    Last Modified: 10 Aug 2026

    Microsoft Excel Remote Code Execution Vulnerability

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-38654

    Last Modified: 10 Aug 2026

    Microsoft Office Visio Remote Code Execution Vulnerability

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-38653

    Last Modified: 10 Aug 2026

    Microsoft Office Visio Remote Code Execution Vulnerability

    Published: 15 Sept 2021
    7.6
    High

    CVE-2021-38652

    Last Modified: 10 Aug 2026

    Microsoft SharePoint Server Spoofing Vulnerability

    Published: 15 Sept 2021
    7.6
    High

    CVE-2021-38650

    Last Modified: 10 Aug 2026

    Microsoft Office Spoofing Vulnerability

    Published: 15 Sept 2021
    7.6
    High

    CVE-2021-38651

    Last Modified: 10 Aug 2026

    Microsoft SharePoint Server Spoofing Vulnerability

    Published: 15 Sept 2021
    7
    High

    CVE-2021-38649

    Last Modified: 10 Aug 2026

    Open Management Infrastructure Elevation of Privilege Vulnerability

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-38648

    Last Modified: 10 Aug 2026

    Open Management Infrastructure Elevation of Privilege Vulnerability

    Published: 15 Sept 2021
    9.8
    Critical

    CVE-2021-38647

    Last Modified: 10 Aug 2026

    Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-38646

    Last Modified: 10 Aug 2026

    Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-38645

    Last Modified: 10 Aug 2026

    Open Management Infrastructure Elevation of Privilege Vulnerability

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-38644

    Last Modified: 10 Aug 2026

    Microsoft MPEG-2 Video Extension Remote Code Execution Vulnerability

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-38639

    Last Modified: 10 Aug 2026

    Win32k Elevation of Privilege Vulnerability

    Published: 15 Sept 2021
    5.5
    Medium

    CVE-2021-38637

    Last Modified: 10 Aug 2026

    Windows Storage Information Disclosure Vulnerability

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-38638

    Last Modified: 10 Aug 2026

    Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

    Published: 15 Sept 2021
    5.5
    Medium

    CVE-2021-38636

    Last Modified: 10 Aug 2026

    Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability

    Published: 15 Sept 2021
    5.5
    Medium

    CVE-2021-38635

    Last Modified: 10 Aug 2026

    Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability

    Published: 15 Sept 2021
    7.1
    High

    CVE-2021-38634

    Last Modified: 10 Aug 2026

    Microsoft Windows Update Client Elevation of Privilege Vulnerability

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-38633

    Last Modified: 10 Aug 2026

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

    Published: 15 Sept 2021
    5.7
    Medium

    CVE-2021-38632

    Last Modified: 10 Aug 2026

    Windows BitLocker Security Feature Bypass Vulnerability

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-38630

    Last Modified: 10 Aug 2026

    Windows Event Tracing Elevation of Privilege Vulnerability

    Published: 15 Sept 2021
    6.5
    Medium

    CVE-2021-38629

    Last Modified: 10 Aug 2026

    Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-38628

    Last Modified: 10 Aug 2026

    Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-38626

    Last Modified: 10 Aug 2026

    Windows Kernel Elevation of Privilege Vulnerability

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-38625

    Last Modified: 10 Aug 2026

    Windows Kernel Elevation of Privilege Vulnerability

    Published: 15 Sept 2021
    6.5
    Medium

    CVE-2021-38624

    Last Modified: 10 Aug 2026

    Windows Key Storage Provider Security Feature Bypass Vulnerability

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-36975

    Last Modified: 10 Aug 2026

    Win32k Elevation of Privilege Vulnerability

    Published: 15 Sept 2021