CVE-2019-18943
Last Modified: 21 Nov 2024Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to XML External Entity Processing (XXE) on certain operations.
CVE-2019-18942
Last Modified: 21 Nov 2024Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to stored XSS. The application reflects previously stored user input without encoding.
CVE-2019-18944
Last Modified: 21 Nov 2024Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to reflected XSS.
CVE-2019-18945
Last Modified: 21 Nov 2024Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to privilege escalation vulnerability.
CVE-2019-18947
Last Modified: 21 Nov 2024Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to information disclosure.
CVE-2019-18946
Last Modified: 21 Nov 2024Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to session fixation.
CVE-2021-21724
Last Modified: 21 Nov 2024A ZTE product has a memory leak vulnerability. Due to the product's improper handling of memory release in certain scenarios, a local attacker with device permissions repeatedly attenuated the optical signal to cause memory leak and abnormal service. This affects: ZXR10 8900E, all versions up to V3.03.20R2B30P1.
CVE-2021-23977
Last Modified: 21 Nov 2024Firefox for Android suffered from a time-of-check-time-of-use vulnerability that allowed a malicious application to read sensitive data from application directories. Note: This issue is only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 86.
CVE-2021-23963
Last Modified: 21 Nov 2024When sharing geolocation during an active WebRTC share, Firefox could have reset the webRTC sharing state in the user interface, leading to loss of control over the currently granted permission. This vulnerability affects Firefox < 85.
CVE-2021-23955
Last Modified: 21 Nov 2024The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to clickjacking attacks. This vulnerability affects Firefox < 85.
CVE-2021-23956
Last Modified: 21 Nov 2024An ambiguous file picker design could have confused users who intended to select and upload a single file into uploading a whole directory. This was addressed by adding a new prompt. This vulnerability affects Firefox < 85.
CVE-2021-23957
Last Modified: 21 Nov 2024Navigations through the Android-specific `intent` URL scheme could have been misused to escape iframe sandbox. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.
CVE-2021-23958
Last Modified: 21 Nov 2024The browser could have been confused into transferring a screen sharing state into another tab, which would leak unintended information. This vulnerability affects Firefox < 85.
CVE-2021-23959
Last Modified: 21 Nov 2024An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.
CVE-2021-23961
Last Modified: 21 Nov 2024Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 85.
CVE-2021-23962
Last Modified: 21 Nov 2024Incorrect use of the '<RowCountChanged>' method could have led to a user-after-poison and a potentially exploitable crash. This vulnerability affects Firefox < 85.
CVE-2021-23970
Last Modified: 21 Nov 2024Context-specific code was included in a shared jump table; resulting in assertions being triggered in multithreaded wasm code. This vulnerability affects Firefox < 86.
CVE-2021-23971
Last Modified: 21 Nov 2024When processing a redirect with a conflicting Referrer-Policy, Firefox would have adopted the redirect's Referrer-Policy. This would have potentially resulted in more information than intended by the original origin being provided to the destination of the redirect. This vulnerability affects Firefox < 86.
CVE-2021-23972
Last Modified: 21 Nov 2024One phishing tactic on the web is to provide a link with HTTP Auth. For example 'https://[email protected]'. To mitigate this type of attack, Firefox will display a warning dialog; however, this warning dialog would not have been displayed if evil.com used a redirect that was cached by the browser. This vulnerability affects Firefox < 86.
CVE-2021-23974
Last Modified: 21 Nov 2024The DOMParser API did not properly process '<noscript>' elements for escaping. This could be used as an mXSS vector to bypass an HTML Sanitizer. This vulnerability affects Firefox < 86.
CVE-2021-23975
Last Modified: 21 Nov 2024The developer page about:memory has a Measure function for exploring what object types the browser has allocated and their sizes. When this function was invoked we incorrectly called the sizeof function, instead of using the API method that checks for invalid pointers. This vulnerability affects Firefox < 86.
CVE-2021-23976
Last Modified: 21 Nov 2024When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to cross-origin attacks on targeted websites. Note: This issue is a different issue from CVE-2020-26954 and only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 86.
CVE-2021-21328
Last Modified: 21 Nov 2024Vapor is a web framework for Swift. In Vapor before version 4.40.1, there is a DoS attack against anyone who Bootstraps a metrics backend for their Vapor app. The following is the attack vector: 1. send unlimited requests against a vapor instance with different paths. this will create unlimited counters and timers, which will eventually drain the system. 2. downstream services might suffer from this attack as well by being spammed with error paths. This has been patched in 4.40.1. The `DefaultResponder` will rewrite any undefined route paths for to `vapor_route_undefined` to avoid unlimited counters.
CVE-2020-27223
Last Modified: 20 Aug 2025In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.
CVE-2021-30178
Last Modified: 21 Nov 2024An issue was discovered in the Linux kernel through 5.11.11. synic_get in arch/x86/kvm/hyperv.c has a NULL pointer dereference for certain accesses to the SynIC Hyper-V context, aka CID-919f4ebc5987.
CVE-2021-26700
Last Modified: 16 Jul 2025Visual Studio Code npm-script Extension Remote Code Execution Vulnerability
CVE-2021-25195
Last Modified: 21 Nov 2024Windows PKU2U Elevation of Privilege Vulnerability
CVE-2021-24114
Last Modified: 21 Nov 2024Microsoft Teams iOS Information Disclosure Vulnerability
CVE-2021-24113
Last Modified: 21 Nov 2024Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2021-24109
Last Modified: 21 Nov 2024Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
CVE-2021-24106
Last Modified: 21 Nov 2024Windows DirectX Information Disclosure Vulnerability
CVE-2021-24105
Last Modified: 24 Feb 2026<p>Depending on configuration of various package managers it is possible for an attacker to insert a malicious package into a package manager's repository which can be retrieved and used during development, build, and release processes. This insertion could lead to remote code execution. We believe this vulnerability affects multiple package managers across multiple languages, including but not limited to: Python/pip, .NET/NuGet, Java/Maven, JavaScript/npm.</p> <p><strong>Attack scenarios</strong></p> <p>An attacker could take advantage of this ecosystem-wide issue to cause harm in a variety of ways. The original attack scenarios were discovered by Alex Birsan and are detailed in their whitepaper, <a href="https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610">Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies</a>.</p> <ul> <li><p>With basic knowledge of the target ecosystems, an attacker could create an empty shell for a package and insert malicious code in the install scripts, give it a high version, and publish it to the public repository. Vulnerable victim machines will download the higher version of the package between the public and private repositories and attempt to install it. Due to code incompatibility it will probably error out upon import or upon compilation, making it easier to detect; however the attacker would have gained code execution by that point.</p> </li> <li><p>An advanced attacker with some inside knowledge of the target could take a copy of a working package, insert the malicious code (in the package itself or in the install), and then publish it to a public repository. The package will likely install and import correctly, granting the attacker an initial foothold and persistence.</p> </li> </ul> <p>These two methods could affect target organizations at any of these various levels:</p> <ul> <li>Developer machines</li> <li>An entire team if the configuration to import the malicious package is uploaded to a code repository</li> <li>Continuous integration pipelines if they pull the malicious packages during the build, test, and/or deploy stages</li> <li>Customers, download servers, production services if the malicious code has not been detected</li> </ul> <p>This remote code execution vulnerability can only be addressed by reconfiguring installation tools and workflows, and not by correcting anything in the package repositories themselves. See the <strong>FAQ</strong> section of this CVE for configuration guidance.</p>
CVE-2021-24103
Last Modified: 21 Nov 2024Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2021-24101
Last Modified: 21 Nov 2024Microsoft Dataverse Information Disclosure Vulnerability
CVE-2021-24102
Last Modified: 21 Nov 2024Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2021-24100
Last Modified: 21 Nov 2024Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2021-24098
Last Modified: 21 Nov 2024Windows Console Driver Denial of Service Vulnerability
CVE-2021-24099
Last Modified: 21 Nov 2024Skype for Business and Lync Denial of Service Vulnerability
CVE-2021-24094
Last Modified: 21 Nov 2024Windows TCP/IP Remote Code Execution Vulnerability
CVE-2021-24096
Last Modified: 21 Nov 2024Windows Kernel Elevation of Privilege Vulnerability
CVE-2021-24093
Last Modified: 21 Nov 2024Windows Graphics Component Remote Code Execution Vulnerability
CVE-2021-24092
Last Modified: 21 Nov 2024Microsoft Defender Elevation of Privilege Vulnerability
CVE-2021-24088
Last Modified: 21 Nov 2024Windows Local Spooler Remote Code Execution Vulnerability
CVE-2021-24091
Last Modified: 21 Nov 2024Windows Camera Codec Pack Remote Code Execution Vulnerability
CVE-2021-24086
Last Modified: 21 Nov 2024Windows TCP/IP Denial of Service Vulnerability
CVE-2021-24087
Last Modified: 21 Nov 2024Azure IoT CLI extension Elevation of Privilege Vulnerability
CVE-2021-24085
Last Modified: 21 Nov 2024Microsoft Exchange Server Spoofing Vulnerability
CVE-2021-24083
Last Modified: 21 Nov 2024Windows Address Book Remote Code Execution Vulnerability
CVE-2021-24084
Last Modified: 21 Nov 2024Windows Mobile Device Management Information Disclosure Vulnerability
CVE-2021-24082
Last Modified: 21 Nov 2024Microsoft.PowerShell.Utility Module WDAC Security Feature Bypass Vulnerability
