CVE-2021-3452
Last Modified: 21 Nov 2024A potential vulnerability in the system shutdown SMI callback function in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
CVE-2021-34481
Last Modified: 10 Aug 2026A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. UPDATE August 10, 2021: Microsoft has completed the investigation and has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. This security update changes the Point and Print default behavior; please see KB5005652.
CVE-2021-34467
Last Modified: 10 Aug 2026Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2021-34466
Last Modified: 10 Aug 2026Windows Hello Security Feature Bypass Vulnerability
CVE-2021-34464
Last Modified: 10 Aug 2026Microsoft Defender Remote Code Execution Vulnerability
CVE-2021-34462
Last Modified: 10 Aug 2026Windows AppX Deployment Extensions Elevation of Privilege Vulnerability
CVE-2021-34461
Last Modified: 10 Aug 2026Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability
CVE-2021-34460
Last Modified: 10 Aug 2026Windows Storage Spaces Controller Elevation of Privilege Vulnerability
CVE-2021-34459
Last Modified: 10 Aug 2026Windows AppContainer Elevation Of Privilege Vulnerability
CVE-2021-34458
Last Modified: 10 Aug 2026Windows Kernel Remote Code Execution Vulnerability
CVE-2021-34457
Last Modified: 10 Aug 2026Windows Remote Access Connection Manager Information Disclosure Vulnerability
CVE-2021-34456
Last Modified: 10 Aug 2026Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
CVE-2021-34454
Last Modified: 10 Aug 2026Windows Remote Access Connection Manager Information Disclosure Vulnerability
CVE-2021-34455
Last Modified: 10 Aug 2026Windows File History Service Elevation of Privilege Vulnerability
CVE-2021-34452
Last Modified: 10 Aug 2026Microsoft Word Remote Code Execution Vulnerability
CVE-2021-34451
Last Modified: 10 Aug 2026Microsoft Office Online Server Spoofing Vulnerability
CVE-2021-34450
Last Modified: 10 Aug 2026Windows Hyper-V Remote Code Execution Vulnerability
CVE-2021-34449
Last Modified: 10 Aug 2026Win32k Elevation of Privilege Vulnerability
CVE-2021-34448
Last Modified: 10 Aug 2026Scripting Engine Memory Corruption Vulnerability
CVE-2021-34447
Last Modified: 10 Aug 2026Windows MSHTML Platform Remote Code Execution Vulnerability
CVE-2021-34446
Last Modified: 10 Aug 2026Windows HTML Platforms Security Feature Bypass Vulnerability
CVE-2021-34445
Last Modified: 10 Aug 2026Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
CVE-2021-34444
Last Modified: 10 Aug 2026Windows DNS Server Denial of Service Vulnerability
CVE-2021-34442
Last Modified: 10 Aug 2026Windows DNS Server Remote Code Execution Vulnerability
CVE-2021-34441
Last Modified: 10 Aug 2026Microsoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2021-34440
Last Modified: 10 Aug 2026GDI+ Information Disclosure Vulnerability
CVE-2021-34439
Last Modified: 10 Aug 2026Microsoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2021-34438
Last Modified: 10 Aug 2026Windows Font Driver Host Remote Code Execution Vulnerability
CVE-2021-32769
Last Modified: 21 Nov 2024Micronaut is a JVM-based, full stack Java framework designed for building JVM applications. A path traversal vulnerability exists in versions prior to 2.5.9. With a basic configuration, it is possible to access any file from a filesystem, using "/../../" in the URL. This occurs because Micronaut does not restrict file access to configured paths. The vulnerability is patched in version 2.5.9. As a workaround, do not use `**` in mapping, use only `*`, which exposes only flat structure of a directory not allowing traversal. If using Linux, another workaround is to run micronaut in chroot.
CVE-2020-4980
Last Modified: 21 Nov 2024IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as well as data at rest. IBM X-Force ID: 192539.
CVE-2020-4821
Last Modified: 21 Nov 2024IBM InfoSphere Data Replication 11.4 and IBM InfoSphere Change Data Capture for z/OS 10.2.1, under certain configurations, could allow a user to bypass authentication mechanisms using an empty password string. IBM X-Force ID: 189834
CVE-2020-4675
Last Modified: 21 Nov 2024IBM InfoSphere Master Data Management Server 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 186324.
CVE-2021-35962
Last Modified: 21 Nov 2024Specific page parameters in Dr. ID Door Access Control and Personnel Attendance Management system does not filter special characters. Remote attackers can apply Path Traversal means to download credential files from the system without permission.
CVE-2021-35961
Last Modified: 21 Nov 2024Dr. ID Door Access Control and Personnel Attendance Management system uses the hard-code admin default credentials that allows remote attackers to access the system through the default password and obtain the highest permission.
CVE-2021-28053
Last Modified: 21 Nov 2024An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. A SQL injection vulnerability in "Configuration > Users > Contacts / Users" allows remote authenticated users to execute arbitrary SQL commands via the Additional Information parameters.
CVE-2021-28054
Last Modified: 21 Nov 2024An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. A Stored Cross-Site Scripting (XSS) issue in "Configuration > Hosts" allows remote authenticated users to inject arbitrary web script or HTML via the Alias parameter.
CVE-2021-3649
Last Modified: 21 Nov 2024chatwoot is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-1422
Last Modified: 11 Aug 2026A vulnerability in the software cryptography module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker or an unauthenticated attacker in a man-in-the-middle position to cause an unexpected reload of the device that results in a denial of service (DoS) condition. The vulnerability is due to a logic error in how the software cryptography module handles specific types of decryption errors. An attacker could exploit this vulnerability by sending malicious packets over an established IPsec connection. A successful exploit could cause the device to crash, forcing it to reload. Important: Successful exploitation of this vulnerability would not cause a compromise of any encrypted data. Note: This vulnerability affects only Cisco ASA Software Release 9.16.1 and Cisco FTD Software Release 7.0.0.
CVE-2021-28114
Last Modified: 21 Nov 2024Froala WYSIWYG Editor 3.2.6-1 is affected by XSS due to a namespace confusion during parsing.
CVE-2021-21803
Last Modified: 21 Nov 2024This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.
CVE-2021-21802
Last Modified: 21 Nov 2024This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.
CVE-2021-21801
Last Modified: 21 Nov 2024This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.
CVE-2021-21804
Last Modified: 21 Nov 2024A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HTTP request can lead to arbitrary PHP code execution. An attacker can send a crafted HTTP request to trigger this vulnerability.
CVE-2021-21800
Last Modified: 21 Nov 2024Cross-site scripting vulnerabilities exist in the ssh_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can lead to arbitrary JavaScript code execution in the context of the targeted user’s browser. An attacker can provide a crafted URL to trigger this vulnerability.
CVE-2021-21799
Last Modified: 21 Nov 2024Cross-site scripting vulnerabilities exist in the telnet_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can lead to arbitrary JavaScript code execution in the context of the targeted user’s browser. An attacker can provide a crafted URL to trigger this vulnerability.
CVE-2021-21816
Last Modified: 21 Nov 2024An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to the disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability.
CVE-2021-21817
Last Modified: 21 Nov 2024An information disclosure vulnerability exists in the Zebra IP Routing Manager functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to the disclosure of sensitive information. An attacker can send a sequence of requests to trigger this vulnerability.
CVE-2021-21818
Last Modified: 21 Nov 2024A hard-coded password vulnerability exists in the Zebra IP Routing Manager functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to a denial of service. An attacker can send a sequence of requests to trigger this vulnerability.
CVE-2021-21819
Last Modified: 21 Nov 2024A code execution vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.
CVE-2021-21820
Last Modified: 21 Nov 2024A hard-coded password vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to code execution. An attacker can send a sequence of requests to trigger this vulnerability.
