CVE-2021-24080
Last Modified: 21 Nov 2024Windows Trust Verification API Denial of Service Vulnerability
CVE-2021-24081
Last Modified: 21 Nov 2024Microsoft Windows Codecs Library Remote Code Execution Vulnerability
CVE-2021-24079
Last Modified: 21 Nov 2024Windows Backup Engine Information Disclosure Vulnerability
CVE-2021-24077
Last Modified: 21 Nov 2024Windows Fax Service Remote Code Execution Vulnerability
CVE-2021-24078
Last Modified: 21 Nov 2024Windows DNS Server Remote Code Execution Vulnerability
CVE-2021-24076
Last Modified: 21 Nov 2024Microsoft Windows VMSwitch Information Disclosure Vulnerability
CVE-2021-24074
Last Modified: 21 Nov 2024Windows TCP/IP Remote Code Execution Vulnerability
CVE-2021-24075
Last Modified: 21 Nov 2024Microsoft Windows VMSwitch Denial of Service Vulnerability
CVE-2021-24072
Last Modified: 21 Nov 2024Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2021-24073
Last Modified: 21 Nov 2024Skype for Business and Lync Spoofing Vulnerability
CVE-2021-24071
Last Modified: 21 Nov 2024Microsoft SharePoint Information Disclosure Vulnerability
CVE-2021-24070
Last Modified: 21 Nov 2024Microsoft Excel Remote Code Execution Vulnerability
CVE-2021-24069
Last Modified: 21 Nov 2024Microsoft Excel Remote Code Execution Vulnerability
CVE-2021-24068
Last Modified: 21 Nov 2024Microsoft Excel Remote Code Execution Vulnerability
CVE-2021-24067
Last Modified: 21 Nov 2024Microsoft Excel Remote Code Execution Vulnerability
CVE-2021-24066
Last Modified: 21 Nov 2024Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2021-1733
Last Modified: 21 Nov 2024Sysinternals PsExec Elevation of Privilege Vulnerability
CVE-2021-1734
Last Modified: 21 Nov 2024Windows Remote Procedure Call Information Disclosure Vulnerability
CVE-2021-1732
Last Modified: 30 Oct 2025Windows Win32k Elevation of Privilege Vulnerability
CVE-2021-1730
Last Modified: 24 Feb 2026<p>A spoofing vulnerability exists in Microsoft Exchange Server which could result in an attack that would allow a malicious actor to impersonate the user.</p> <p>This update addresses this vulnerability.</p> <p>To prevent these types of attacks, Microsoft recommends customers to download inline images from different DNSdomains than the rest of OWA. Please see further instructions in the FAQ to put in place this mitigations.</p>
CVE-2021-1731
Last Modified: 21 Nov 2024PFX Encryption Security Feature Bypass Vulnerability
CVE-2021-1728
Last Modified: 21 Nov 2024System Center Operations Manager Elevation of Privilege Vulnerability
CVE-2021-1726
Last Modified: 21 Nov 2024Microsoft SharePoint Server Spoofing Vulnerability
CVE-2021-1727
Last Modified: 21 Nov 2024Windows Installer Elevation of Privilege Vulnerability
CVE-2021-1724
Last Modified: 21 Nov 2024Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
CVE-2021-1722
Last Modified: 21 Nov 2024Windows Fax Service Remote Code Execution Vulnerability
CVE-2021-1698
Last Modified: 21 Nov 2024Windows Win32k Elevation of Privilege Vulnerability
CVE-2020-17162
Last Modified: 21 Nov 2024Microsoft Windows Security Feature Bypass Vulnerability
CVE-2021-1639
Last Modified: 21 Nov 2024Visual Studio Code Remote Code Execution Vulnerability
CVE-2018-3633
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none
CVE-2021-3406
Last Modified: 21 Nov 2024A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the Endorsement Key certificate to agent attestations.
CVE-2021-20327
Last Modified: 17 Sept 2026A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM attack could result in interception of traffic between the Node.js driver and the KMS service rendering client-side field level encryption (CSFLE) ineffective. This issue was discovered during internal testing and affects mongodb-client-encryption module version 1.2.0, which was available from 2021-Jan-29 and deprecated in the NPM Registry on 2021-Feb-04. This vulnerability does not impact driver traffic payloads with CSFLE-supported key services from applications residing inside the AWS, GCP, and Azure nework fabrics due to compensating controls in these environments. This issue does not impact driver workloads that don’t use Field Level Encryption. This issue affect MongoDB Node.js Driver mongodb-client-encryption module version 1.2.0
CVE-2020-27543
Last Modified: 21 Nov 2024The restify-paginate package 0.0.5 for Node.js allows remote attackers to cause a Denial-of-Service by omitting the HTTP Host header. A Restify-based web service would crash with an uncaught exception.
CVE-2020-23534
Last Modified: 21 Nov 2024A server-side request forgery (SSRF) vulnerability in Upgrade.php of gopeak masterlab 2.1.5, via the 'source' parameter.
CVE-2021-27330
Last Modified: 21 Nov 2024Triconsole Datepicker Calendar <3.77 is affected by cross-site scripting (XSS) in calendar_form.php. Attackers can read authentication cookies that are still active, which can be used to perform further attacks such as reading browser history, directory listings, and file contents.
CVE-2021-3124
Last Modified: 21 Nov 2024Stored cross-site scripting (XSS) in form field in robust.systems product Custom Global Variables v 1.0.5 allows a remote attacker to inject arbitrary code via the vars[0][name] field.
CVE-2021-3273
Last Modified: 21 Nov 2024Nagios XI below 5.7 is affected by code injection in the /nagiosxi/admin/graphtemplates.php component. To exploit this vulnerability, someone must have an admin user account in Nagios XI's web system.
CVE-2021-21066
Last Modified: 21 Nov 2024Adobe Bridge version 11.0 (and earlier) is affected by an out-of-bounds write vulnerability when parsing TTF files that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2021-21065
Last Modified: 21 Nov 2024Adobe Bridge version 11.0 (and earlier) is affected by an out-of-bounds write vulnerability when parsing TTF files that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2021-21064
Last Modified: 21 Nov 2024Magento UPWARD-php version 1.1.4 (and earlier) is affected by a Path traversal vulnerability in Magento UPWARD Connector version 1.1.2 (and earlier) due to the upload feature. An attacker could potentially exploit this vulnerability to upload a malicious YAML file that can contain instructions which allows reading arbitrary files from the remote server. Access to the admin console is required for successful exploitation.
CVE-2020-8032
Last Modified: 21 Nov 2024A Insecure Temporary File vulnerability in the packaging of cyrus-sasl of openSUSE Factory allows local attackers to escalate to root. This issue affects: openSUSE Factory cyrus-sasl version 2.1.27-4.2 and prior versions.
CVE-2020-36254
Last Modified: 3 Dec 2025scp.c in Dropbear before 2020.79 mishandles the filename of . or an empty filename, a related issue to CVE-2018-20685.
CVE-2021-27671
Last Modified: 21 Nov 2024An issue was discovered in the comrak crate before 0.9.1 for Rust. XSS can occur because the protection mechanism for data: and javascript: URIs is case-sensitive, allowing (for example) Data: to be used in an attack.
CVE-2021-27670
Last Modified: 21 Nov 2024Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.
CVE-2021-26701
Last Modified: 28 May 2026.NET Core Remote Code Execution Vulnerability
CVE-2021-20313
Last Modified: 21 Nov 2024A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in TransformSignature is possible. The highest threat from this vulnerability is to data confidentiality.
CVE-2021-3144
Last Modified: 21 Nov 2024In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)
CVE-2020-28243
Last Modified: 21 Nov 2024An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.
CVE-2020-35662
Last Modified: 21 Nov 2024In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not always validated.
CVE-2021-20310
Last Modified: 21 Nov 2024A flaw was found in ImageMagick in versions before 7.0.11, where a division by zero ConvertXYZToJzazbz() of MagickCore/colorspace.c may trigger undefined behavior via a crafted image file that is submitted by an attacker and processed by an application using ImageMagick. The highest threat from this vulnerability is to system availability.
