CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2021-31179

    Last Modified: 21 Nov 2024

    Microsoft Office Remote Code Execution Vulnerability

    Published: 11 May 2021
    7.8
    High

    CVE-2021-31177

    Last Modified: 21 Nov 2024

    Microsoft Office Remote Code Execution Vulnerability

    Published: 11 May 2021
    7.8
    High

    CVE-2021-31175

    Last Modified: 21 Nov 2024

    Microsoft Office Remote Code Execution Vulnerability

    Published: 11 May 2021
    7.8
    High

    CVE-2021-31176

    Last Modified: 21 Nov 2024

    Microsoft Office Remote Code Execution Vulnerability

    Published: 11 May 2021
    5.5
    Medium

    CVE-2021-31174

    Last Modified: 21 Nov 2024

    Microsoft Excel Information Disclosure Vulnerability

    Published: 11 May 2021
    7.1
    High

    CVE-2021-31172

    Last Modified: 28 Feb 2025

    Microsoft SharePoint Server Spoofing Vulnerability

    Published: 11 May 2021
    5.3
    Medium

    CVE-2021-31173

    Last Modified: 28 Feb 2025

    Microsoft SharePoint Server Information Disclosure Vulnerability

    Published: 11 May 2021
    4.1
    Medium

    CVE-2021-31171

    Last Modified: 21 Nov 2024

    Microsoft SharePoint Information Disclosure Vulnerability

    Published: 11 May 2021
    7.8
    High

    CVE-2021-31169

    Last Modified: 21 Nov 2024

    Windows Container Manager Service Elevation of Privilege Vulnerability

    Published: 11 May 2021
    7.8
    High

    CVE-2021-31170

    Last Modified: 21 Nov 2024

    Windows Graphics Component Elevation of Privilege Vulnerability

    Published: 11 May 2021
    7.8
    High

    CVE-2021-31168

    Last Modified: 21 Nov 2024

    Windows Container Manager Service Elevation of Privilege Vulnerability

    Published: 11 May 2021
    7.8
    High

    CVE-2021-31167

    Last Modified: 21 Nov 2024

    Windows Container Manager Service Elevation of Privilege Vulnerability

    Published: 11 May 2021
    9.8
    Critical

    CVE-2021-31166

    Last Modified: 30 Oct 2025

    HTTP Protocol Stack Remote Code Execution Vulnerability

    Published: 11 May 2021
    7.8
    High

    CVE-2021-31165

    Last Modified: 21 Nov 2024

    Windows Container Manager Service Elevation of Privilege Vulnerability

    Published: 11 May 2021
    5.5
    Medium

    CVE-2021-28479

    Last Modified: 21 Nov 2024

    Windows CSC Service Information Disclosure Vulnerability

    Published: 11 May 2021
    7.6
    High

    CVE-2021-28478

    Last Modified: 28 Feb 2025

    Microsoft SharePoint Server Spoofing Vulnerability

    Published: 11 May 2021
    9.9
    Critical

    CVE-2021-28476

    Last Modified: 21 Nov 2024

    Windows Hyper-V Remote Code Execution Vulnerability

    Published: 11 May 2021
    8.8
    High

    CVE-2021-28474

    Last Modified: 21 Nov 2024

    Microsoft SharePoint Server Remote Code Execution Vulnerability

    Published: 11 May 2021
    7.8
    High

    CVE-2021-28465

    Last Modified: 28 May 2026

    Web Media Extensions Remote Code Execution Vulnerability

    Published: 11 May 2021
    6.1
    Medium

    CVE-2021-28461

    Last Modified: 21 Nov 2024

    Dynamics Finance and Operations Cross-site Scripting Vulnerability

    Published: 11 May 2021
    8.8
    High

    CVE-2021-28455

    Last Modified: 21 Nov 2024

    Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability

    Published: 11 May 2021
    8.8
    High

    CVE-2021-27068

    Last Modified: 21 Nov 2024

    Visual Studio Remote Code Execution Vulnerability

    Published: 11 May 2021
    7.2
    High

    CVE-2021-26422

    Last Modified: 21 Nov 2024

    Skype for Business and Lync Remote Code Execution Vulnerability

    Published: 11 May 2021
    6.5
    Medium

    CVE-2021-26421

    Last Modified: 21 Nov 2024

    Skype for Business and Lync Spoofing Vulnerability

    Published: 11 May 2021
    7.5
    High

    CVE-2021-26419

    Last Modified: 21 Nov 2024

    Scripting Engine Memory Corruption Vulnerability

    Published: 11 May 2021
    4.6
    Medium

    CVE-2021-26418

    Last Modified: 28 Feb 2025

    Microsoft SharePoint Server Spoofing Vulnerability

    Published: 11 May 2021
    9.8
    Critical

    CVE-2021-31921

    Last Modified: 21 Nov 2024

    Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotely exploitable vulnerability where an external client can access unexpected services in the cluster, bypassing authorization checks, when a gateway is configured with AUTO_PASSTHROUGH routing configuration.

    Published: 11 May 2021
    8.8
    High

    CVE-2021-3495

    Last Modified: 21 Nov 2024

    An incorrect access control flaw was found in the kiali-operator in versions before 1.33.0 and before 1.24.7. This flaw allows an attacker with a basic level of access to the cluster (to deploy a kiali operand) to use this vulnerability and deploy a given image to anywhere in the cluster, potentially gaining access to privileged service account tokens. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 11 May 2021
    6.5
    Medium

    CVE-2021-31920

    Last Modified: 21 Nov 2024

    Istio before 1.8.6 and 1.9.x before 1.9.5 has a remotely exploitable vulnerability where an HTTP request path with multiple slashes or escaped slash characters (%2F or %5C) could potentially bypass an Istio authorization policy when path based authorization rules are used.

    Published: 11 May 2021
    8.1
    High

    CVE-2021-29492

    Last Modified: 21 Nov 2024

    Envoy is a cloud-native edge/middle/service proxy. Envoy does not decode escaped slash sequences `%2F` and `%5C` in HTTP URL paths in versions 1.18.2 and before. A remote attacker may craft a path with escaped slashes, e.g. `/something%2F..%2Fadmin`, to bypass access control, e.g. a block on `/admin`. A backend server could then decode slash sequences and normalize path and provide an attacker access beyond the scope provided for by the access control policy. ### Impact Escalation of Privileges when using RBAC or JWT filters with enforcement based on URL path. Users with back end servers that interpret `%2F` and `/` and `%5C` and `\` interchangeably are impacted. ### Attack Vector URL paths containing escaped slash characters delivered by untrusted client. Patches in versions 1.18.3, 1.17.3, 1.16.4, 1.15.5 contain new path normalization option to decode escaped slash characters. As a workaround, if back end servers treat `%2F` and `/` and `%5C` and `\` interchangeably and a URL path based access control is configured, one may reconfigure the back end server to not treat `%2F` and `/` and `%5C` and `\` interchangeably.

    Published: 11 May 2021
    8.8
    High

    CVE-2020-18964

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) Vulnerability in ForestBlog latest version via the website Management background, which could let a remote malicious gain privileges.

    Published: 11 May 2021
    7.3
    High

    CVE-2021-31204

    Last Modified: 21 Nov 2024

    .NET and Visual Studio Elevation of Privilege Vulnerability

    Published: 11 May 2021
    4.8
    Medium

    CVE-2021-32573

    Last Modified: 21 Nov 2024

    The express-cart package through 1.1.10 for Node.js allows Reflected XSS (for an admin) via a user input field for product options. NOTE: the vendor states that this "would rely on an admin hacking his/her own website.

    Published: 11 May 2021
    9.1
    Critical

    CVE-2021-29508

    Last Modified: 21 Nov 2024

    Due to how Wire handles type information in its serialization format, malicious payloads can be passed to a deserializer. e.g. using a surrogate on the sender end, an attacker can pass information about a different type for the receiving end. And by doing so allowing the serializer to create any type on the deserializing end. This is the same issue that exists for .NET BinaryFormatter https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300?view=vs-2019. This also applies to the fork of Wire.

    Published: 11 May 2021
    4.3
    Medium

    CVE-2020-4536

    Last Modified: 21 Nov 2024

    IBM OpenPages GRC Platform 8.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 182907.

    Published: 11 May 2021
    5.4
    Medium

    CVE-2020-4535

    Last Modified: 21 Nov 2024

    IBM OpenPages GRC Platform 8.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182906.

    Published: 11 May 2021
    3.7
    Low

    CVE-2021-29471

    Last Modified: 21 Nov 2024

    Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.33.2 "Push rules" can specify conditions under which they will match, including `event_match`, which matches event content against a pattern including wildcards. Certain patterns can cause very poor performance in the matching engine, leading to a denial-of-service when processing moderate length events. The issue is patched in version 1.33.2. A potential workaround might be to prevent users from making custom push rules, by blocking such requests at a reverse-proxy.

    Published: 11 May 2021
    6.5
    Medium

    CVE-2020-20265

    Last Modified: 21 Nov 2024

    Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /ram/pckg/wireless/nova/bin/wireless process. An authenticated remote attacker can cause a Denial of Service due via a crafted packet.

    Published: 11 May 2021
    6.5
    Medium

    CVE-2020-20267

    Last Modified: 21 Nov 2024

    Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/resolver process. An authenticated remote attacker can cause a Denial of Service due to invalid memory access.

    Published: 11 May 2021
    7.8
    High

    CVE-2021-27613

    Last Modified: 21 Nov 2024

    Under certain conditions, SAP Business One Chef cookbook, version - 9.2, 9.3, 10.0, used to install SAP Business One, allows an attacker to exploit an insecure temporary folder for incoming & outgoing payroll data and to access information which would otherwise be restricted, which could lead to Information Disclosure and highly impact system confidentiality, integrity and availability.

    Published: 11 May 2021
    7.8
    High

    CVE-2021-27616

    Last Modified: 21 Nov 2024

    Under certain conditions, SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One for SAP HANA, allows an attacker to exploit an insecure temporary backup path and to access information which would otherwise be restricted, resulting in Information Disclosure vulnerability highly impacting the confidentiality, integrity and availability of the application.

    Published: 11 May 2021
    6.5
    Medium

    CVE-2021-27619

    Last Modified: 21 Nov 2024

    SAP Commerce (Backoffice Search), versions - 1808, 1811, 1905, 2005, 2011, allows a low privileged user to search for attributes which are not supposed to be displayed to them. Although the search results are masked, the user can iteratively enter one character at a time to search and determine the masked attribute value thereby leading to information disclosure.

    Published: 11 May 2021
    6.7
    Medium

    CVE-2021-27611

    Last Modified: 21 Nov 2024

    SAP NetWeaver AS ABAP, versions - 700, 701, 702, 730, 731, allow a high privileged attacker to inject malicious code by executing an ABAP report when the attacker has access to the local SAP system. The attacker could then get access to data, overwrite them, or execute a denial of service.

    Published: 11 May 2021
    6.1
    Medium

    CVE-2021-27612

    Last Modified: 21 Nov 2024

    In specific situations SAP GUI for Windows until and including 7.60 PL9, 7.70 PL0, forwards a user to specific malicious website which could contain malware or might lead to phishing attacks to steal credentials of the victim.

    Published: 11 May 2021
    4.9
    Medium

    CVE-2021-27617

    Last Modified: 21 Nov 2024

    The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate an XML document uploaded from local source. An attacker can craft a malicious XML which when uploaded and parsed by the application, could lead to Denial-of-service conditions due to consumption of a large amount of system memory, thus highly impacting system availability.

    Published: 11 May 2021
    4.9
    Medium

    CVE-2021-27618

    Last Modified: 21 Nov 2024

    The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not check the file type extension of the file uploaded from local source. An attacker could craft a malicious file and upload it to the application, which could lead to denial of service and impact the availability of the application.

    Published: 11 May 2021
    7.1
    High

    CVE-2021-27614

    Last Modified: 21 Nov 2024

    SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One on SAP HANA, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application thereby highly impacting the integrity and availability of the application.

    Published: 11 May 2021
    7.1
    High

    CVE-2021-21655

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins P4 Plugin 1.11.4 and earlier allows attackers to connect to an attacker-specified Perforce server using attacker-specified username and password.

    Published: 11 May 2021
    7.1
    High

    CVE-2021-21656

    Last Modified: 21 Nov 2024

    Jenkins Xcode integration Plugin 2.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

    Published: 11 May 2021
    4.3
    Medium

    CVE-2021-21654

    Last Modified: 21 Nov 2024

    Jenkins P4 Plugin 1.11.4 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified Perforce server using attacker-specified username and password.

    Published: 11 May 2021