CVE-2021-31179
Last Modified: 21 Nov 2024Microsoft Office Remote Code Execution Vulnerability
CVE-2021-31177
Last Modified: 21 Nov 2024Microsoft Office Remote Code Execution Vulnerability
CVE-2021-31175
Last Modified: 21 Nov 2024Microsoft Office Remote Code Execution Vulnerability
CVE-2021-31176
Last Modified: 21 Nov 2024Microsoft Office Remote Code Execution Vulnerability
CVE-2021-31174
Last Modified: 21 Nov 2024Microsoft Excel Information Disclosure Vulnerability
CVE-2021-31172
Last Modified: 28 Feb 2025Microsoft SharePoint Server Spoofing Vulnerability
CVE-2021-31173
Last Modified: 28 Feb 2025Microsoft SharePoint Server Information Disclosure Vulnerability
CVE-2021-31171
Last Modified: 21 Nov 2024Microsoft SharePoint Information Disclosure Vulnerability
CVE-2021-31169
Last Modified: 21 Nov 2024Windows Container Manager Service Elevation of Privilege Vulnerability
CVE-2021-31170
Last Modified: 21 Nov 2024Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2021-31168
Last Modified: 21 Nov 2024Windows Container Manager Service Elevation of Privilege Vulnerability
CVE-2021-31167
Last Modified: 21 Nov 2024Windows Container Manager Service Elevation of Privilege Vulnerability
CVE-2021-31166
Last Modified: 30 Oct 2025HTTP Protocol Stack Remote Code Execution Vulnerability
CVE-2021-31165
Last Modified: 21 Nov 2024Windows Container Manager Service Elevation of Privilege Vulnerability
CVE-2021-28479
Last Modified: 21 Nov 2024Windows CSC Service Information Disclosure Vulnerability
CVE-2021-28478
Last Modified: 28 Feb 2025Microsoft SharePoint Server Spoofing Vulnerability
CVE-2021-28476
Last Modified: 21 Nov 2024Windows Hyper-V Remote Code Execution Vulnerability
CVE-2021-28474
Last Modified: 21 Nov 2024Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2021-28465
Last Modified: 28 May 2026Web Media Extensions Remote Code Execution Vulnerability
CVE-2021-28461
Last Modified: 21 Nov 2024Dynamics Finance and Operations Cross-site Scripting Vulnerability
CVE-2021-28455
Last Modified: 21 Nov 2024Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability
CVE-2021-27068
Last Modified: 21 Nov 2024Visual Studio Remote Code Execution Vulnerability
CVE-2021-26422
Last Modified: 21 Nov 2024Skype for Business and Lync Remote Code Execution Vulnerability
CVE-2021-26421
Last Modified: 21 Nov 2024Skype for Business and Lync Spoofing Vulnerability
CVE-2021-26419
Last Modified: 21 Nov 2024Scripting Engine Memory Corruption Vulnerability
CVE-2021-26418
Last Modified: 28 Feb 2025Microsoft SharePoint Server Spoofing Vulnerability
CVE-2021-31921
Last Modified: 21 Nov 2024Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotely exploitable vulnerability where an external client can access unexpected services in the cluster, bypassing authorization checks, when a gateway is configured with AUTO_PASSTHROUGH routing configuration.
CVE-2021-3495
Last Modified: 21 Nov 2024An incorrect access control flaw was found in the kiali-operator in versions before 1.33.0 and before 1.24.7. This flaw allows an attacker with a basic level of access to the cluster (to deploy a kiali operand) to use this vulnerability and deploy a given image to anywhere in the cluster, potentially gaining access to privileged service account tokens. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
CVE-2021-31920
Last Modified: 21 Nov 2024Istio before 1.8.6 and 1.9.x before 1.9.5 has a remotely exploitable vulnerability where an HTTP request path with multiple slashes or escaped slash characters (%2F or %5C) could potentially bypass an Istio authorization policy when path based authorization rules are used.
CVE-2021-29492
Last Modified: 21 Nov 2024Envoy is a cloud-native edge/middle/service proxy. Envoy does not decode escaped slash sequences `%2F` and `%5C` in HTTP URL paths in versions 1.18.2 and before. A remote attacker may craft a path with escaped slashes, e.g. `/something%2F..%2Fadmin`, to bypass access control, e.g. a block on `/admin`. A backend server could then decode slash sequences and normalize path and provide an attacker access beyond the scope provided for by the access control policy. ### Impact Escalation of Privileges when using RBAC or JWT filters with enforcement based on URL path. Users with back end servers that interpret `%2F` and `/` and `%5C` and `\` interchangeably are impacted. ### Attack Vector URL paths containing escaped slash characters delivered by untrusted client. Patches in versions 1.18.3, 1.17.3, 1.16.4, 1.15.5 contain new path normalization option to decode escaped slash characters. As a workaround, if back end servers treat `%2F` and `/` and `%5C` and `\` interchangeably and a URL path based access control is configured, one may reconfigure the back end server to not treat `%2F` and `/` and `%5C` and `\` interchangeably.
CVE-2020-18964
Last Modified: 21 Nov 2024Cross Site Request Forgery (CSRF) Vulnerability in ForestBlog latest version via the website Management background, which could let a remote malicious gain privileges.
CVE-2021-31204
Last Modified: 21 Nov 2024.NET and Visual Studio Elevation of Privilege Vulnerability
CVE-2021-32573
Last Modified: 21 Nov 2024The express-cart package through 1.1.10 for Node.js allows Reflected XSS (for an admin) via a user input field for product options. NOTE: the vendor states that this "would rely on an admin hacking his/her own website.
CVE-2021-29508
Last Modified: 21 Nov 2024Due to how Wire handles type information in its serialization format, malicious payloads can be passed to a deserializer. e.g. using a surrogate on the sender end, an attacker can pass information about a different type for the receiving end. And by doing so allowing the serializer to create any type on the deserializing end. This is the same issue that exists for .NET BinaryFormatter https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300?view=vs-2019. This also applies to the fork of Wire.
CVE-2020-4536
Last Modified: 21 Nov 2024IBM OpenPages GRC Platform 8.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 182907.
CVE-2020-4535
Last Modified: 21 Nov 2024IBM OpenPages GRC Platform 8.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182906.
CVE-2021-29471
Last Modified: 21 Nov 2024Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.33.2 "Push rules" can specify conditions under which they will match, including `event_match`, which matches event content against a pattern including wildcards. Certain patterns can cause very poor performance in the matching engine, leading to a denial-of-service when processing moderate length events. The issue is patched in version 1.33.2. A potential workaround might be to prevent users from making custom push rules, by blocking such requests at a reverse-proxy.
CVE-2020-20265
Last Modified: 21 Nov 2024Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /ram/pckg/wireless/nova/bin/wireless process. An authenticated remote attacker can cause a Denial of Service due via a crafted packet.
CVE-2020-20267
Last Modified: 21 Nov 2024Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/resolver process. An authenticated remote attacker can cause a Denial of Service due to invalid memory access.
CVE-2021-27613
Last Modified: 21 Nov 2024Under certain conditions, SAP Business One Chef cookbook, version - 9.2, 9.3, 10.0, used to install SAP Business One, allows an attacker to exploit an insecure temporary folder for incoming & outgoing payroll data and to access information which would otherwise be restricted, which could lead to Information Disclosure and highly impact system confidentiality, integrity and availability.
CVE-2021-27616
Last Modified: 21 Nov 2024Under certain conditions, SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One for SAP HANA, allows an attacker to exploit an insecure temporary backup path and to access information which would otherwise be restricted, resulting in Information Disclosure vulnerability highly impacting the confidentiality, integrity and availability of the application.
CVE-2021-27619
Last Modified: 21 Nov 2024SAP Commerce (Backoffice Search), versions - 1808, 1811, 1905, 2005, 2011, allows a low privileged user to search for attributes which are not supposed to be displayed to them. Although the search results are masked, the user can iteratively enter one character at a time to search and determine the masked attribute value thereby leading to information disclosure.
CVE-2021-27611
Last Modified: 21 Nov 2024SAP NetWeaver AS ABAP, versions - 700, 701, 702, 730, 731, allow a high privileged attacker to inject malicious code by executing an ABAP report when the attacker has access to the local SAP system. The attacker could then get access to data, overwrite them, or execute a denial of service.
CVE-2021-27612
Last Modified: 21 Nov 2024In specific situations SAP GUI for Windows until and including 7.60 PL9, 7.70 PL0, forwards a user to specific malicious website which could contain malware or might lead to phishing attacks to steal credentials of the victim.
CVE-2021-27617
Last Modified: 21 Nov 2024The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate an XML document uploaded from local source. An attacker can craft a malicious XML which when uploaded and parsed by the application, could lead to Denial-of-service conditions due to consumption of a large amount of system memory, thus highly impacting system availability.
CVE-2021-27618
Last Modified: 21 Nov 2024The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not check the file type extension of the file uploaded from local source. An attacker could craft a malicious file and upload it to the application, which could lead to denial of service and impact the availability of the application.
CVE-2021-27614
Last Modified: 21 Nov 2024SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One on SAP HANA, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application thereby highly impacting the integrity and availability of the application.
CVE-2021-21655
Last Modified: 21 Nov 2024A cross-site request forgery (CSRF) vulnerability in Jenkins P4 Plugin 1.11.4 and earlier allows attackers to connect to an attacker-specified Perforce server using attacker-specified username and password.
CVE-2021-21656
Last Modified: 21 Nov 2024Jenkins Xcode integration Plugin 2.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2021-21654
Last Modified: 21 Nov 2024Jenkins P4 Plugin 1.11.4 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified Perforce server using attacker-specified username and password.
