CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2021-27095

    Last Modified: 21 Nov 2024

    Windows Media Video Decoder Remote Code Execution Vulnerability

    Published: 13 Apr 2021
    4.4
    Medium

    CVE-2021-27094

    Last Modified: 21 Nov 2024

    Windows Early Launch Antimalware Driver Security Feature Bypass Vulnerability

    Published: 13 Apr 2021
    5.5
    Medium

    CVE-2021-27093

    Last Modified: 21 Nov 2024

    Windows Kernel Information Disclosure Vulnerability

    Published: 13 Apr 2021
    6.8
    Medium

    CVE-2021-27092

    Last Modified: 21 Nov 2024

    Azure AD Web Sign-in Security Feature Bypass Vulnerability

    Published: 13 Apr 2021
    7.8
    High

    CVE-2021-27091

    Last Modified: 21 Nov 2024

    RPC Endpoint Mapper Service Elevation of Privilege Vulnerability

    Published: 13 Apr 2021
    7.8
    High

    CVE-2021-27090

    Last Modified: 21 Nov 2024

    Windows Secure Kernel Mode Elevation of Privilege Vulnerability

    Published: 13 Apr 2021
    7.8
    High

    CVE-2021-27089

    Last Modified: 21 Nov 2024

    Microsoft Internet Messaging API Remote Code Execution Vulnerability

    Published: 13 Apr 2021
    7.8
    High

    CVE-2021-27088

    Last Modified: 21 Nov 2024

    Windows Event Tracing Elevation of Privilege Vulnerability

    Published: 13 Apr 2021
    7.8
    High

    CVE-2021-27086

    Last Modified: 21 Nov 2024

    Windows Services and Controller App Elevation of Privilege Vulnerability

    Published: 13 Apr 2021
    5.7
    Medium

    CVE-2021-27079

    Last Modified: 21 Nov 2024

    Windows Media Photo Codec Information Disclosure Vulnerability

    Published: 13 Apr 2021
    7
    High

    CVE-2021-27072

    Last Modified: 21 Nov 2024

    Win32k Elevation of Privilege Vulnerability

    Published: 13 Apr 2021
    6.5
    Medium

    CVE-2021-27067

    Last Modified: 21 Nov 2024

    Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability

    Published: 13 Apr 2021
    7.8
    High

    CVE-2021-27064

    Last Modified: 15 Aug 2025

    Visual Studio Installer Elevation of Privilege Vulnerability

    Published: 13 Apr 2021
    5.5
    Medium

    CVE-2021-26417

    Last Modified: 21 Nov 2024

    Windows Overlay Filter Information Disclosure Vulnerability

    Published: 13 Apr 2021
    7.7
    High

    CVE-2021-26416

    Last Modified: 21 Nov 2024

    Windows Hyper-V Denial of Service Vulnerability

    Published: 13 Apr 2021
    7.8
    High

    CVE-2021-26415

    Last Modified: 21 Nov 2024

    Windows Installer Elevation of Privilege Vulnerability

    Published: 13 Apr 2021
    6.2
    Medium

    CVE-2021-26413

    Last Modified: 21 Nov 2024

    Windows Installer Spoofing Vulnerability

    Published: 13 Apr 2021
    6.5
    Medium

    CVE-2021-27609

    Last Modified: 21 Nov 2024

    SAP Focused RUN versions 200, 300, does not perform necessary authorization checks for an authenticated user, which allows a user to call the oData service and manipulate the activation for the SAP EarlyWatch Alert service data collection and sending to SAP without the intended authorization.

    Published: 13 Apr 2021
    6.5
    Medium

    CVE-2021-21485

    Last Modified: 21 Nov 2024

    An unauthorized attacker may be able to entice an administrator to invoke telnet commands of an SAP NetWeaver Application Server for Java that allow the attacker to gain NTLM hashes of a privileged user.

    Published: 13 Apr 2021
    4.3
    Medium

    CVE-2021-27605

    Last Modified: 21 Nov 2024

    SAP's HCM Travel Management Fiori Apps V2, version - 608, does not perform proper authorization check, allowing an authenticated but unauthorized attacker to read personnel numbers of employees, resulting in escalation of privileges. However, the attacker can only read some information like last name, first name of the employees, so there is some loss of confidential information, Integrity and Availability are not impacted.

    Published: 13 Apr 2021
    5.4
    Medium

    CVE-2021-27601

    Last Modified: 21 Nov 2024

    SAP NetWeaver AS Java (Applications based on HTMLB for Java) allows a basic-level authorized attacker to store a malicious file on the server. When a victim tries to open this file, it results in a Cross-Site Scripting (XSS) vulnerability and the attacker can read and modify data. However, the attacker does not have control over kind or degree.

    Published: 13 Apr 2021
    5.4
    Medium

    CVE-2021-27600

    Last Modified: 21 Nov 2024

    SAP Manufacturing Execution (System Rules), versions - 15.1, 15.2, 15.3, 15.4, allows an authorized attacker to embed malicious code into HTTP parameter and send it to the server because SAP Manufacturing Execution (System Rules) tab does not sufficiently encode some parameters, resulting in Stored Cross-Site Scripting (XSS) vulnerability. The malicious code can be used for different purposes. e.g., information can be read, modified, and sent to the attacker. However, availability of the server cannot be impacted.

    Published: 13 Apr 2021
    9.9
    Critical

    CVE-2021-27602

    Last Modified: 21 Nov 2024

    SAP Commerce, versions - 1808, 1811, 1905, 2005, 2011, Backoffice application allows certain authorized users to create source rules which are translated to drools rule when published to certain modules within the application. An attacker with this authorization can inject malicious code in the source rules and perform remote code execution enabling them to compromise the confidentiality, integrity and availability of the application.

    Published: 13 Apr 2021
    6.5
    Medium

    CVE-2021-27603

    Last Modified: 21 Nov 2024

    An RFC enabled function module SPI_WAIT_MILLIS in SAP NetWeaver AS ABAP, versions - 731, 740, 750, allows to keep a work process busy for any length of time. An attacker could call this function module multiple times to block all work processes thereby causing Denial of Service and affecting the Availability of the SAP system.

    Published: 13 Apr 2021
    4.3
    Medium

    CVE-2021-21492

    Last Modified: 21 Nov 2024

    SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate logon group in URLs, resulting in a content spoofing vulnerability when directory listing is enabled.

    Published: 13 Apr 2021
    4.6
    Medium

    CVE-2021-29438

    Last Modified: 21 Nov 2024

    The Nextcloud dialogs library (npm package @nextcloud/dialogs) before 3.1.2 insufficiently escaped text input passed to a toast. If your application displays toasts with user-supplied input, this could lead to a XSS vulnerability. The vulnerability has been patched in version 3.1.2 If you need to display HTML in the toast, explicitly pass the `options.isHTML` config flag.

    Published: 13 Apr 2021
    8.3
    High

    CVE-2021-21482

    Last Modified: 21 Nov 2024

    SAP NetWeaver Master Data Management, versions - 710, 710.750, allows a malicious unauthorized user with access to the MDM Server subnet to find the password using a brute force method. If successful, the attacker could obtain access to highly sensitive data and MDM administrative privileges leading to information disclosure vulnerability thereby affecting the confidentiality and integrity of the application. This happens when security guidelines and recommendations concerning administrative accounts of an SAP NetWeaver Master Data Management installation have not been thoroughly reviewed.

    Published: 13 Apr 2021
    4.9
    Medium

    CVE-2021-21483

    Last Modified: 21 Nov 2024

    Under certain conditions SAP Solution Manager, version - 720, allows a high privileged attacker to get access to sensitive information which has a direct serious impact beyond the exploitable component thereby affecting the confidentiality in the application.

    Published: 13 Apr 2021
    5.3
    Medium

    CVE-2021-27598

    Last Modified: 21 Nov 2024

    SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like product version, traffic, timestamp etc. because of missing authorization check in the servlet.

    Published: 13 Apr 2021
    7.2
    High

    CVE-2021-22720

    Last Modified: 21 Nov 2024

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when restoring a project.

    Published: 13 Apr 2021
    8.8
    High

    CVE-2021-22719

    Last Modified: 21 Nov 2024

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when a file is uploaded.

    Published: 13 Apr 2021
    7.8
    High

    CVE-2021-22718

    Last Modified: 21 Nov 2024

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when restoring project files.

    Published: 13 Apr 2021
    8.8
    High

    CVE-2021-22717

    Last Modified: 21 Nov 2024

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when processing config files.

    Published: 13 Apr 2021
    7.8
    High

    CVE-2021-22716

    Last Modified: 21 Nov 2024

    A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could allow remote code execution when an unprivileged user modifies a file. Affected Product: C-Bus Toolkit (V1.15.9 and prior)

    Published: 13 Apr 2021
    6.6
    Medium

    CVE-2021-0468

    Last Modified: 21 Nov 2024

    In LK, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-180427272

    Published: 13 Apr 2021
    5.5
    Medium

    CVE-2021-0444

    Last Modified: 21 Nov 2024

    In onActivityResult of QuickContactActivity.java, there is an unnecessary return of an intent. This could lead to local information disclosure of contact data with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-178825358

    Published: 13 Apr 2021
    9.8
    Critical

    CVE-2021-0430

    Last Modified: 21 Nov 2024

    In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution via a malicious NFC packet with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-178725766

    Published: 13 Apr 2021
    5.5
    Medium

    CVE-2021-0400

    Last Modified: 21 Nov 2024

    In injectBestLocation and handleUpdateLocation of GnssLocationProvider.java, there is a possible incorrect reporting of location data to emergency services due to improper input validation. This could lead to incorrect reporting of location data to emergency services with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11Android ID: A-177561690

    Published: 13 Apr 2021
    5.5
    Medium

    CVE-2021-0436

    Last Modified: 21 Nov 2024

    In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds read due to integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-176496160

    Published: 13 Apr 2021
    8
    High

    CVE-2021-29437

    Last Modified: 21 Nov 2024

    ScratchOAuth2 is an Oauth implementation for Scratch. Any ScratchOAuth2-related data normally accessible and modifiable by a user can be read and modified by a third party. 1. Scratch user visits 3rd party site. 2. 3rd party site asks user for Scratch username. 3. 3rd party site pretends to be user and gets login code from ScratchOAuth2. 4. 3rd party site gives code to user and instructs them to post it on their profile. 5. User posts code on their profile, not knowing it is a ScratchOAuth2 login code. 6. 3rd party site completes login with ScratchOAuth2. 7. 3rd party site has full access to anything the user could do if they directly logged in. See referenced GitHub security advisory for patch notes and workarounds.

    Published: 13 Apr 2021
    5.5
    Medium

    CVE-2021-0471

    Last Modified: 21 Nov 2024

    In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-176444786

    Published: 13 Apr 2021
    7.8
    High

    CVE-2021-0437

    Last Modified: 21 Nov 2024

    In setPlayPolicy of DrmPlugin.cpp, there is a possible double free. This could lead to local escalation of privilege in a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-176168330

    Published: 13 Apr 2021
    7.8
    High

    CVE-2021-0429

    Last Modified: 21 Nov 2024

    In pollOnce of ALooper.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-175074139

    Published: 13 Apr 2021
    7.8
    High

    CVE-2021-0442

    Last Modified: 21 Nov 2024

    In updateInfo of android_hardware_input_InputApplicationHandle.cpp, there is a possible control of code flow due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174768985

    Published: 13 Apr 2021
    7.8
    High

    CVE-2021-0427

    Last Modified: 21 Nov 2024

    In parseExclusiveStateAnnotation of LogEvent.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174488848

    Published: 13 Apr 2021
    7.8
    High

    CVE-2021-0426

    Last Modified: 21 Nov 2024

    In parsePrimaryFieldFirstUidAnnotation of LogEvent.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174485572

    Published: 13 Apr 2021
    7.8
    High

    CVE-2021-0439

    Last Modified: 21 Nov 2024

    In setPowerModeWithHandle of com_android_server_power_PowerManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174243830

    Published: 13 Apr 2021
    7.5
    High

    CVE-2021-0435

    Last Modified: 21 Nov 2024

    In avrc_proc_vendor_command of avrc_api.cc, there is a possible leak of heap data due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-174150451

    Published: 13 Apr 2021
    7.5
    High

    CVE-2021-0431

    Last Modified: 21 Nov 2024

    In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a paired device with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-174149901

    Published: 13 Apr 2021
    7
    High

    CVE-2021-0432

    Last Modified: 21 Nov 2024

    In ClearPullerCacheIfNecessary and ForceClearPullerCache of StatsPullerManager.cpp, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-173552790

    Published: 13 Apr 2021