CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-40346

    Last Modified: 21 Nov 2024

    An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.

    Published: 8 Sept 2021
    —
    Unknown

    CVE-2021-28732

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-28372. Reason: This candidate is a duplicate of CVE-2021-28372. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2021-28372 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 8 Sept 2021
    8.3
    High

    CVE-2021-28571

    Last Modified: 23 Apr 2025

    Adobe After Effects version 18.1 (and earlier) is affected by a potential Command injection vulnerability when chained with a development and debugging tool for JavaScript scripts. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Sept 2021
    4.3
    Medium

    CVE-2021-28569

    Last Modified: 21 Nov 2024

    Adobe Media Encoder version 15.1 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Sept 2021
    5.8
    Medium

    CVE-2021-28568

    Last Modified: 21 Nov 2024

    Adobe Genuine Services version 7.1 (and earlier) is affected by an Insecure file permission vulnerability during installation process. A local authenticated attacker could leverage this vulnerability to achieve privilege escalation in the context of the current user.

    Published: 8 Sept 2021
    6.5
    Medium

    CVE-2021-28567

    Last Modified: 21 Nov 2024

    Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Improper Authorization vulnerability in the customers module. Successful exploitation could allow a low-privileged user to modify customer data. Access to the admin console is required for successful exploitation.

    Published: 8 Sept 2021
    3.7
    Low

    CVE-2021-28566

    Last Modified: 21 Nov 2024

    Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Information Disclosure vulnerability when uploading a modified png file to a product image. Successful exploitation could lead to the disclosure of document root path by an unauthenticated attacker. Access to the admin console is required for successful exploitation.

    Published: 8 Sept 2021
    8.8
    High

    CVE-2021-21105

    Last Modified: 21 Nov 2024

    Adobe Illustrator version 25.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve remote code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Sept 2021
    8.8
    High

    CVE-2021-21104

    Last Modified: 21 Nov 2024

    Adobe Illustrator version 25.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to remote code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Sept 2021
    4.3
    Medium

    CVE-2021-21103

    Last Modified: 21 Nov 2024

    Adobe Illustrator version 25.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Sept 2021
    8.8
    High

    CVE-2021-21897

    Last Modified: 21 Nov 2024

    A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 8 Sept 2021
    6.3
    Medium

    CVE-2021-35526

    Last Modified: 21 Nov 2024

    Backup file without encryption vulnerability is found in Hitachi ABB Power Grids System Data Manager – SDM600 allows attacker to gain access to sensitive information. This issue affects: Hitachi ABB Power Grids System Data Manager – SDM600 1.2 versions prior to FP2 HF6 (Build Nr. 1.2.14002.257).

    Published: 8 Sept 2021
    9.8
    Critical

    CVE-2020-24672

    Last Modified: 21 Nov 2024

    A vulnerability in Base Software for SoftControl allows an attacker to insert and run arbitrary code in a computer running the affected product. This issue affects: .

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-1762

    Last Modified: 21 Nov 2024

    An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.4 and iPadOS 14.4, macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution.

    Published: 8 Sept 2021
    7.5
    High

    CVE-2021-1784

    Last Modified: 21 Nov 2024

    A permissions issue existed in DiskArbitration. This was addressed with additional ownership checks. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. A malicious application may be able to modify protected parts of the file system.

    Published: 8 Sept 2021
    7.5
    High

    CVE-2021-1809

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A malicious application may be able to read restricted memory.

    Published: 8 Sept 2021
    4.4
    Medium

    CVE-2021-1824

    Last Modified: 21 Nov 2024

    This issue was addressed with improved entitlements. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application with root privileges may be able to access private information.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-1740

    Last Modified: 21 Nov 2024

    A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A local user may be able to modify protected parts of the file system.

    Published: 8 Sept 2021
    7.1
    High

    CVE-2021-1828

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. An application may be able to cause unexpected system termination or write kernel memory.

    Published: 8 Sept 2021
    6.5
    Medium

    CVE-2021-1811

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.11.3 for Windows, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iCloud for Windows 12.3, macOS Big Sur 11.3, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing a maliciously crafted font may result in the disclosure of process memory.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-1807

    Last Modified: 21 Nov 2024

    A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4. A local user may be able to write arbitrary files.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-1812

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved validation. This issue is fixed in iOS 14.5 and iPadOS 14.5. A malicious application may be able to execute arbitrary code with system privileges.

    Published: 8 Sept 2021
    4.3
    Medium

    CVE-2020-27940

    Last Modified: 21 Nov 2024

    This issue was addressed with improved file handling. This issue is fixed in Apple TV app for Fire OS 6.1.0.6A142:7.1.0. An attacker with file system access may modify scripts used by the app.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-1822

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved restrictions. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A local user may be able to modify protected parts of the file system.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2020-27942

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. Processing a maliciously crafted font file may lead to arbitrary code execution.

    Published: 8 Sept 2021
    9.8
    Critical

    CVE-2021-1770

    Last Modified: 21 Nov 2024

    A buffer overflow may result in arbitrary code execution. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A logic issue was addressed with improved state management.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-1810

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-1816

    Last Modified: 21 Nov 2024

    A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A malicious application may be able to execute arbitrary code with kernel privileges.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-1813

    Last Modified: 21 Nov 2024

    A validation issue was addressed with improved logic. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A malicious application may be able to gain root privileges.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-1814

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.3, watchOS 7.4. Processing a maliciously crafted image may lead to arbitrary code execution.

    Published: 8 Sept 2021
    7.5
    High

    CVE-2021-1808

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An application may be able to read restricted memory.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-1739

    Last Modified: 21 Nov 2024

    A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A local user may be able to modify protected parts of the file system.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-1815

    Last Modified: 21 Nov 2024

    A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A local user may be able to modify protected parts of the file system.

    Published: 8 Sept 2021
    6.5
    Medium

    CVE-2021-30659

    Last Modified: 21 Nov 2024

    A validation issue was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, macOS Big Sur 11.3. A malicious application may be able to leak sensitive user information.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-30657

    Last Modified: 23 Oct 2025

    A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited..

    Published: 8 Sept 2021
    8.8
    High

    CVE-2021-1867

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.5 and iPadOS 14.5, macOS Big Sur 11.3. A malicious application may be able to execute arbitrary code with kernel privileges.

    Published: 8 Sept 2021
    8.8
    High

    CVE-2021-1876

    Last Modified: 21 Nov 2024

    A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-1875

    Last Modified: 21 Nov 2024

    A double free issue was addressed with improved memory management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. Processing a maliciously crafted file may lead to heap corruption.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-1868

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A local attacker may be able to elevate their privileges.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-1883

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in Security Update 2021-004 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, Security Update 2021-003 Catalina, tvOS 14.5, macOS Big Sur 11.3. Processing maliciously crafted server messages may lead to heap corruption.

    Published: 8 Sept 2021
    5.9
    Medium

    CVE-2021-1884

    Last Modified: 21 Nov 2024

    A race condition was addressed with improved locking. This issue is fixed in Security Update 2021-004 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, Security Update 2021-003 Catalina, tvOS 14.5, macOS Big Sur 11.3. A remote attacker may be able to cause a denial of service.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-1877

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.5 and iPadOS 14.5. A local user may be able to read kernel memory.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-1885

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing a maliciously crafted image may lead to arbitrary code execution.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-30656

    Last Modified: 21 Nov 2024

    An access issue was addressed with improved memory management. This issue is fixed in iOS 14.5 and iPadOS 14.5. A malicious application may be able to determine kernel memory layout.

    Published: 8 Sept 2021
    9.8
    Critical

    CVE-2021-1864

    Last Modified: 21 Nov 2024

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. An attacker with JavaScript execution may be able to execute arbitrary code.

    Published: 8 Sept 2021
    7.8
    High

    CVE-2021-30653

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing a maliciously crafted image may lead to arbitrary code execution.

    Published: 8 Sept 2021
    5.5
    Medium

    CVE-2021-30658

    Last Modified: 21 Nov 2024

    This issue was addressed with improved handling of file metadata. This issue is fixed in macOS Big Sur 11.3. A malicious application may bypass Gatekeeper checks.

    Published: 8 Sept 2021
    7
    High

    CVE-2021-30652

    Last Modified: 21 Nov 2024

    A race condition was addressed with additional validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A malicious application may be able to gain root privileges.

    Published: 8 Sept 2021
    7.5
    High

    CVE-2021-30660

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A malicious application may be able to disclose kernel memory.

    Published: 8 Sept 2021
    9.8
    Critical

    CVE-2021-1882

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved validation. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An application may be able to gain elevated privileges.

    Published: 8 Sept 2021