CVE-2021-40845
Last Modified: 21 Nov 2024The web part of Zenitel AlphaCom XE Audio Server through 11.2.3.10, called AlphaWeb XE, does not restrict file upload in the Custom Scripts section at php/index.php. Neither the content nor extension of the uploaded files is checked, allowing execution of PHP code under the /cmd directory.
CVE-2021-30137
Last Modified: 21 Nov 2024Assyst 10 SP7.5 has authenticated XXE leading to SSRF via XML unmarshalling. The application allows users to send JSON or XML data to the server. It was possible to inject malicious XML data through several access points.
CVE-2021-3794
Last Modified: 24 Sept 2025vuelidate is vulnerable to Inefficient Regular Expression Complexity
CVE-2020-3960
Last Modified: 21 Nov 2024VMware ESXi (6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds read vulnerability in NVMe functionality. A malicious actor with local non-administrative access to a virtual machine with a virtual NVMe controller present may be able to read privileged information contained in physical memory.
CVE-2021-3785
Last Modified: 21 Nov 2024yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-27662
Last Modified: 21 Nov 2024The KT-1 door controller is susceptible to replay or man-in-the-middle attacks where an attacker can record and replay TCP packets. This issue affects Johnson Controls KT-1 all versions up to and including 3.01
CVE-2021-3783
Last Modified: 21 Nov 2024yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-22148
Last Modified: 21 Nov 2024Elastic Enterprise Search App Search versions before 7.14.0 was vulnerable to an issue where API keys were not bound to the same engines as their creator. This could lead to a less privileged user gaining access to unauthorized engines.
CVE-2021-22149
Last Modified: 21 Nov 2024Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alternate route. Using this vulnerability, an authenticated attacker could utilize API keys belonging to higher privileged users.
CVE-2020-35340
Last Modified: 21 Nov 2024A local file inclusion vulnerability in ExpertPDF 9.5.0 through 14.1.0 allows attackers to read the file contents from files that the running ExpertPDF process has access to read.
CVE-2021-40448
Last Modified: 10 Aug 2026Microsoft Accessibility Insights for Android Information Disclosure Vulnerability
CVE-2021-40447
Last Modified: 10 Aug 2026Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2021-40444
Last Modified: 10 Aug 2026Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents. An attacker could craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine. The attacker would then have to convince the user to open the malicious document. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Microsoft Defender Antivirus and Microsoft Defender for Endpoint both provide detection and protections for the known vulnerability. Customers should keep antimalware products up to date. Customers who utilize automatic updates do not need to take additional action. Enterprise customers who manage updates should select the detection build 1.349.22.0 or newer and deploy it across their environments. Microsoft Defender for Endpoint alerts will be displayed as: “Suspicious Cpl File Execution”. Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs. Please see the Mitigations and Workaround sections for important information about steps you can take to protect your system from this vulnerability. UPDATE September 14, 2021: Microsoft has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. Please see the FAQ for important information about which updates are applicable to your system.
CVE-2021-40440
Last Modified: 10 Aug 2026Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
CVE-2021-38671
Last Modified: 10 Aug 2026Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2021-38669
Last Modified: 10 Aug 2026Microsoft Edge (Chromium-based) Tampering Vulnerability
CVE-2021-38667
Last Modified: 10 Aug 2026Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2021-38661
Last Modified: 10 Aug 2026HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2021-38660
Last Modified: 10 Aug 2026Microsoft Office Graphics Remote Code Execution Vulnerability
CVE-2021-38659
Last Modified: 10 Aug 2026Microsoft Office Graphics Remote Code Execution Vulnerability
CVE-2021-38658
Last Modified: 10 Aug 2026Microsoft Office Graphics Remote Code Execution Vulnerability
CVE-2021-38657
Last Modified: 10 Aug 2026Microsoft Office Graphics Component Information Disclosure Vulnerability
CVE-2021-38656
Last Modified: 10 Aug 2026Microsoft Word Remote Code Execution Vulnerability
CVE-2021-38655
Last Modified: 10 Aug 2026Microsoft Excel Remote Code Execution Vulnerability
CVE-2021-38654
Last Modified: 10 Aug 2026Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2021-38653
Last Modified: 10 Aug 2026Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2021-38652
Last Modified: 10 Aug 2026Microsoft SharePoint Server Spoofing Vulnerability
CVE-2021-38650
Last Modified: 10 Aug 2026Microsoft Office Spoofing Vulnerability
CVE-2021-38651
Last Modified: 10 Aug 2026Microsoft SharePoint Server Spoofing Vulnerability
CVE-2021-38649
Last Modified: 10 Aug 2026Open Management Infrastructure Elevation of Privilege Vulnerability
CVE-2021-38648
Last Modified: 10 Aug 2026Open Management Infrastructure Elevation of Privilege Vulnerability
CVE-2021-38647
Last Modified: 10 Aug 2026Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
CVE-2021-38646
Last Modified: 10 Aug 2026Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
CVE-2021-38645
Last Modified: 10 Aug 2026Open Management Infrastructure Elevation of Privilege Vulnerability
CVE-2021-38644
Last Modified: 10 Aug 2026Microsoft MPEG-2 Video Extension Remote Code Execution Vulnerability
CVE-2021-38639
Last Modified: 10 Aug 2026Win32k Elevation of Privilege Vulnerability
CVE-2021-38637
Last Modified: 10 Aug 2026Windows Storage Information Disclosure Vulnerability
CVE-2021-38638
Last Modified: 10 Aug 2026Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2021-38636
Last Modified: 10 Aug 2026Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability
CVE-2021-38635
Last Modified: 10 Aug 2026Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability
CVE-2021-38634
Last Modified: 10 Aug 2026Microsoft Windows Update Client Elevation of Privilege Vulnerability
CVE-2021-38633
Last Modified: 10 Aug 2026Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2021-38632
Last Modified: 10 Aug 2026Windows BitLocker Security Feature Bypass Vulnerability
CVE-2021-38630
Last Modified: 10 Aug 2026Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2021-38629
Last Modified: 10 Aug 2026Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability
CVE-2021-38628
Last Modified: 10 Aug 2026Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2021-38626
Last Modified: 10 Aug 2026Windows Kernel Elevation of Privilege Vulnerability
CVE-2021-38625
Last Modified: 10 Aug 2026Windows Kernel Elevation of Privilege Vulnerability
CVE-2021-38624
Last Modified: 10 Aug 2026Windows Key Storage Provider Security Feature Bypass Vulnerability
CVE-2021-36975
Last Modified: 10 Aug 2026Win32k Elevation of Privilege Vulnerability
