CVE Feed

    Dashboard / CVE

    6.7
    Medium

    CVE-2021-3452

    Last Modified: 21 Nov 2024

    A potential vulnerability in the system shutdown SMI callback function in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.

    Published: 16 Jul 2021
    8.8
    High

    CVE-2021-34481

    Last Modified: 10 Aug 2026

    A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. UPDATE August 10, 2021: Microsoft has completed the investigation and has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. This security update changes the Point and Print default behavior; please see KB5005652.

    Published: 16 Jul 2021
    7.1
    High

    CVE-2021-34467

    Last Modified: 10 Aug 2026

    Microsoft SharePoint Server Remote Code Execution Vulnerability

    Published: 16 Jul 2021
    5.7
    Medium

    CVE-2021-34466

    Last Modified: 10 Aug 2026

    Windows Hello Security Feature Bypass Vulnerability

    Published: 16 Jul 2021
    7.8
    High

    CVE-2021-34464

    Last Modified: 10 Aug 2026

    Microsoft Defender Remote Code Execution Vulnerability

    Published: 16 Jul 2021
    7
    High

    CVE-2021-34462

    Last Modified: 10 Aug 2026

    Windows AppX Deployment Extensions Elevation of Privilege Vulnerability

    Published: 16 Jul 2021
    7.8
    High

    CVE-2021-34461

    Last Modified: 10 Aug 2026

    Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability

    Published: 16 Jul 2021
    7.8
    High

    CVE-2021-34460

    Last Modified: 10 Aug 2026

    Windows Storage Spaces Controller Elevation of Privilege Vulnerability

    Published: 16 Jul 2021
    7.8
    High

    CVE-2021-34459

    Last Modified: 10 Aug 2026

    Windows AppContainer Elevation Of Privilege Vulnerability

    Published: 16 Jul 2021
    9.9
    Critical

    CVE-2021-34458

    Last Modified: 10 Aug 2026

    Windows Kernel Remote Code Execution Vulnerability

    Published: 16 Jul 2021
    5.5
    Medium

    CVE-2021-34457

    Last Modified: 10 Aug 2026

    Windows Remote Access Connection Manager Information Disclosure Vulnerability

    Published: 16 Jul 2021
    7.8
    High

    CVE-2021-34456

    Last Modified: 10 Aug 2026

    Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

    Published: 16 Jul 2021
    5.5
    Medium

    CVE-2021-34454

    Last Modified: 10 Aug 2026

    Windows Remote Access Connection Manager Information Disclosure Vulnerability

    Published: 16 Jul 2021
    7.8
    High

    CVE-2021-34455

    Last Modified: 10 Aug 2026

    Windows File History Service Elevation of Privilege Vulnerability

    Published: 16 Jul 2021
    7.8
    High

    CVE-2021-34452

    Last Modified: 10 Aug 2026

    Microsoft Word Remote Code Execution Vulnerability

    Published: 16 Jul 2021
    5.3
    Medium

    CVE-2021-34451

    Last Modified: 10 Aug 2026

    Microsoft Office Online Server Spoofing Vulnerability

    Published: 16 Jul 2021
    8.5
    High

    CVE-2021-34450

    Last Modified: 10 Aug 2026

    Windows Hyper-V Remote Code Execution Vulnerability

    Published: 16 Jul 2021
    7
    High

    CVE-2021-34449

    Last Modified: 10 Aug 2026

    Win32k Elevation of Privilege Vulnerability

    Published: 16 Jul 2021
    6.8
    Medium

    CVE-2021-34448

    Last Modified: 10 Aug 2026

    Scripting Engine Memory Corruption Vulnerability

    Published: 16 Jul 2021
    6.8
    Medium

    CVE-2021-34447

    Last Modified: 10 Aug 2026

    Windows MSHTML Platform Remote Code Execution Vulnerability

    Published: 16 Jul 2021
    8
    High

    CVE-2021-34446

    Last Modified: 10 Aug 2026

    Windows HTML Platforms Security Feature Bypass Vulnerability

    Published: 16 Jul 2021
    7.8
    High

    CVE-2021-34445

    Last Modified: 10 Aug 2026

    Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

    Published: 16 Jul 2021
    6.5
    Medium

    CVE-2021-34444

    Last Modified: 10 Aug 2026

    Windows DNS Server Denial of Service Vulnerability

    Published: 16 Jul 2021
    8.8
    High

    CVE-2021-34442

    Last Modified: 10 Aug 2026

    Windows DNS Server Remote Code Execution Vulnerability

    Published: 16 Jul 2021
    7.8
    High

    CVE-2021-34441

    Last Modified: 10 Aug 2026

    Microsoft Windows Media Foundation Remote Code Execution Vulnerability

    Published: 16 Jul 2021
    5.5
    Medium

    CVE-2021-34440

    Last Modified: 10 Aug 2026

    GDI+ Information Disclosure Vulnerability

    Published: 16 Jul 2021
    7.8
    High

    CVE-2021-34439

    Last Modified: 10 Aug 2026

    Microsoft Windows Media Foundation Remote Code Execution Vulnerability

    Published: 16 Jul 2021
    7.8
    High

    CVE-2021-34438

    Last Modified: 10 Aug 2026

    Windows Font Driver Host Remote Code Execution Vulnerability

    Published: 16 Jul 2021
    7.5
    High

    CVE-2021-32769

    Last Modified: 21 Nov 2024

    Micronaut is a JVM-based, full stack Java framework designed for building JVM applications. A path traversal vulnerability exists in versions prior to 2.5.9. With a basic configuration, it is possible to access any file from a filesystem, using "/../../" in the URL. This occurs because Micronaut does not restrict file access to configured paths. The vulnerability is patched in version 2.5.9. As a workaround, do not use `**` in mapping, use only `*`, which exposes only flat structure of a directory not allowing traversal. If using Linux, another workaround is to run micronaut in chroot.

    Published: 16 Jul 2021
    6.5
    Medium

    CVE-2020-4980

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as well as data at rest. IBM X-Force ID: 192539.

    Published: 16 Jul 2021
    9.8
    Critical

    CVE-2020-4821

    Last Modified: 21 Nov 2024

    IBM InfoSphere Data Replication 11.4 and IBM InfoSphere Change Data Capture for z/OS 10.2.1, under certain configurations, could allow a user to bypass authentication mechanisms using an empty password string. IBM X-Force ID: 189834

    Published: 16 Jul 2021
    6.5
    Medium

    CVE-2020-4675

    Last Modified: 21 Nov 2024

    IBM InfoSphere Master Data Management Server 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 186324.

    Published: 16 Jul 2021
    7.5
    High

    CVE-2021-35962

    Last Modified: 21 Nov 2024

    Specific page parameters in Dr. ID Door Access Control and Personnel Attendance Management system does not filter special characters. Remote attackers can apply Path Traversal means to download credential files from the system without permission.

    Published: 16 Jul 2021
    9.8
    Critical

    CVE-2021-35961

    Last Modified: 21 Nov 2024

    Dr. ID Door Access Control and Personnel Attendance Management system uses the hard-code admin default credentials that allows remote attackers to access the system through the default password and obtain the highest permission.

    Published: 16 Jul 2021
    8.8
    High

    CVE-2021-28053

    Last Modified: 21 Nov 2024

    An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. A SQL injection vulnerability in "Configuration > Users > Contacts / Users" allows remote authenticated users to execute arbitrary SQL commands via the Additional Information parameters.

    Published: 16 Jul 2021
    5.4
    Medium

    CVE-2021-28054

    Last Modified: 21 Nov 2024

    An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. A Stored Cross-Site Scripting (XSS) issue in "Configuration > Hosts" allows remote authenticated users to inject arbitrary web script or HTML via the Alias parameter.

    Published: 16 Jul 2021
    7.5
    High

    CVE-2021-3649

    Last Modified: 21 Nov 2024

    chatwoot is vulnerable to Inefficient Regular Expression Complexity

    Published: 16 Jul 2021
    7.7
    High

    CVE-2021-1422

    Last Modified: 11 Aug 2026

    A vulnerability in the software cryptography module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker or an unauthenticated attacker in a man-in-the-middle position to cause an unexpected reload of the device that results in a denial of service (DoS) condition. The vulnerability is due to a logic error in how the software cryptography module handles specific types of decryption errors. An attacker could exploit this vulnerability by sending malicious packets over an established IPsec connection. A successful exploit could cause the device to crash, forcing it to reload. Important: Successful exploitation of this vulnerability would not cause a compromise of any encrypted data. Note: This vulnerability affects only Cisco ASA Software Release 9.16.1 and Cisco FTD Software Release 7.0.0.

    Published: 16 Jul 2021
    5.4
    Medium

    CVE-2021-28114

    Last Modified: 21 Nov 2024

    Froala WYSIWYG Editor 3.2.6-1 is affected by XSS due to a namespace confusion during parsing.

    Published: 16 Jul 2021
    6.1
    Medium

    CVE-2021-21803

    Last Modified: 21 Nov 2024

    This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

    Published: 16 Jul 2021
    6.1
    Medium

    CVE-2021-21802

    Last Modified: 21 Nov 2024

    This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

    Published: 16 Jul 2021
    6.1
    Medium

    CVE-2021-21801

    Last Modified: 21 Nov 2024

    This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

    Published: 16 Jul 2021
    9.8
    Critical

    CVE-2021-21804

    Last Modified: 21 Nov 2024

    A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HTTP request can lead to arbitrary PHP code execution. An attacker can send a crafted HTTP request to trigger this vulnerability.

    Published: 16 Jul 2021
    6.1
    Medium

    CVE-2021-21800

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerabilities exist in the ssh_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can lead to arbitrary JavaScript code execution in the context of the targeted user’s browser. An attacker can provide a crafted URL to trigger this vulnerability.

    Published: 16 Jul 2021
    6.1
    Medium

    CVE-2021-21799

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerabilities exist in the telnet_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can lead to arbitrary JavaScript code execution in the context of the targeted user’s browser. An attacker can provide a crafted URL to trigger this vulnerability.

    Published: 16 Jul 2021
    4.3
    Medium

    CVE-2021-21816

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to the disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 16 Jul 2021
    7.5
    High

    CVE-2021-21817

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the Zebra IP Routing Manager functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to the disclosure of sensitive information. An attacker can send a sequence of requests to trigger this vulnerability.

    Published: 16 Jul 2021
    7.5
    High

    CVE-2021-21818

    Last Modified: 21 Nov 2024

    A hard-coded password vulnerability exists in the Zebra IP Routing Manager functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to a denial of service. An attacker can send a sequence of requests to trigger this vulnerability.

    Published: 16 Jul 2021
    7.2
    High

    CVE-2021-21819

    Last Modified: 21 Nov 2024

    A code execution vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

    Published: 16 Jul 2021
    9.8
    Critical

    CVE-2021-21820

    Last Modified: 21 Nov 2024

    A hard-coded password vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to code execution. An attacker can send a sequence of requests to trigger this vulnerability.

    Published: 16 Jul 2021