CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2021-24080

    Last Modified: 21 Nov 2024

    Windows Trust Verification API Denial of Service Vulnerability

    Published: 25 Feb 2021
    7.8
    High

    CVE-2021-24081

    Last Modified: 21 Nov 2024

    Microsoft Windows Codecs Library Remote Code Execution Vulnerability

    Published: 25 Feb 2021
    5.5
    Medium

    CVE-2021-24079

    Last Modified: 21 Nov 2024

    Windows Backup Engine Information Disclosure Vulnerability

    Published: 25 Feb 2021
    9.8
    Critical

    CVE-2021-24077

    Last Modified: 21 Nov 2024

    Windows Fax Service Remote Code Execution Vulnerability

    Published: 25 Feb 2021
    9.8
    Critical

    CVE-2021-24078

    Last Modified: 21 Nov 2024

    Windows DNS Server Remote Code Execution Vulnerability

    Published: 25 Feb 2021
    5.5
    Medium

    CVE-2021-24076

    Last Modified: 21 Nov 2024

    Microsoft Windows VMSwitch Information Disclosure Vulnerability

    Published: 25 Feb 2021
    9.8
    Critical

    CVE-2021-24074

    Last Modified: 21 Nov 2024

    Windows TCP/IP Remote Code Execution Vulnerability

    Published: 25 Feb 2021
    6.8
    Medium

    CVE-2021-24075

    Last Modified: 21 Nov 2024

    Microsoft Windows VMSwitch Denial of Service Vulnerability

    Published: 25 Feb 2021
    8.8
    High

    CVE-2021-24072

    Last Modified: 21 Nov 2024

    Microsoft SharePoint Server Remote Code Execution Vulnerability

    Published: 25 Feb 2021
    6.5
    Medium

    CVE-2021-24073

    Last Modified: 21 Nov 2024

    Skype for Business and Lync Spoofing Vulnerability

    Published: 25 Feb 2021
    5.3
    Medium

    CVE-2021-24071

    Last Modified: 21 Nov 2024

    Microsoft SharePoint Information Disclosure Vulnerability

    Published: 25 Feb 2021
    7.8
    High

    CVE-2021-24070

    Last Modified: 21 Nov 2024

    Microsoft Excel Remote Code Execution Vulnerability

    Published: 25 Feb 2021
    7.8
    High

    CVE-2021-24069

    Last Modified: 21 Nov 2024

    Microsoft Excel Remote Code Execution Vulnerability

    Published: 25 Feb 2021
    7.8
    High

    CVE-2021-24068

    Last Modified: 21 Nov 2024

    Microsoft Excel Remote Code Execution Vulnerability

    Published: 25 Feb 2021
    7.8
    High

    CVE-2021-24067

    Last Modified: 21 Nov 2024

    Microsoft Excel Remote Code Execution Vulnerability

    Published: 25 Feb 2021
    8.8
    High

    CVE-2021-24066

    Last Modified: 21 Nov 2024

    Microsoft SharePoint Remote Code Execution Vulnerability

    Published: 25 Feb 2021
    7.8
    High

    CVE-2021-1733

    Last Modified: 21 Nov 2024

    Sysinternals PsExec Elevation of Privilege Vulnerability

    Published: 25 Feb 2021
    7.5
    High

    CVE-2021-1734

    Last Modified: 21 Nov 2024

    Windows Remote Procedure Call Information Disclosure Vulnerability

    Published: 25 Feb 2021
    7.8
    High

    CVE-2021-1732

    Last Modified: 30 Oct 2025

    Windows Win32k Elevation of Privilege Vulnerability

    Published: 25 Feb 2021
    5.4
    Medium

    CVE-2021-1730

    Last Modified: 24 Feb 2026

    <p>A spoofing vulnerability exists in Microsoft Exchange Server which could result in an attack that would allow a malicious actor to impersonate the user.</p> <p>This update addresses this vulnerability.</p> <p>To prevent these types of attacks, Microsoft recommends customers to download inline images from different DNSdomains than the rest of OWA. Please see further instructions in the FAQ to put in place this mitigations.</p>

    Published: 25 Feb 2021
    5.5
    Medium

    CVE-2021-1731

    Last Modified: 21 Nov 2024

    PFX Encryption Security Feature Bypass Vulnerability

    Published: 25 Feb 2021
    8.8
    High

    CVE-2021-1728

    Last Modified: 21 Nov 2024

    System Center Operations Manager Elevation of Privilege Vulnerability

    Published: 25 Feb 2021
    8
    High

    CVE-2021-1726

    Last Modified: 21 Nov 2024

    Microsoft SharePoint Server Spoofing Vulnerability

    Published: 25 Feb 2021
    7.8
    High

    CVE-2021-1727

    Last Modified: 21 Nov 2024

    Windows Installer Elevation of Privilege Vulnerability

    Published: 25 Feb 2021
    6.1
    Medium

    CVE-2021-1724

    Last Modified: 21 Nov 2024

    Microsoft Dynamics Business Central Cross-site Scripting Vulnerability

    Published: 25 Feb 2021
    8.1
    High

    CVE-2021-1722

    Last Modified: 21 Nov 2024

    Windows Fax Service Remote Code Execution Vulnerability

    Published: 25 Feb 2021
    7.8
    High

    CVE-2021-1698

    Last Modified: 21 Nov 2024

    Windows Win32k Elevation of Privilege Vulnerability

    Published: 25 Feb 2021
    8.8
    High

    CVE-2020-17162

    Last Modified: 21 Nov 2024

    Microsoft Windows Security Feature Bypass Vulnerability

    Published: 25 Feb 2021
    7
    High

    CVE-2021-1639

    Last Modified: 21 Nov 2024

    Visual Studio Code Remote Code Execution Vulnerability

    Published: 25 Feb 2021
    —
    Unknown

    CVE-2018-3633

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 25 Feb 2021
    9.8
    Critical

    CVE-2021-3406

    Last Modified: 21 Nov 2024

    A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the Endorsement Key certificate to agent attestations.

    Published: 25 Feb 2021
    6.4
    Medium

    CVE-2021-20327

    Last Modified: 17 Sept 2026

    A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM attack could result in interception of traffic between the Node.js driver and the KMS service rendering client-side field level encryption (CSFLE) ineffective. This issue was discovered during internal testing and affects mongodb-client-encryption module version 1.2.0, which was available from 2021-Jan-29 and deprecated in the NPM Registry on 2021-Feb-04. This vulnerability does not impact driver traffic payloads with CSFLE-supported key services from applications residing inside the AWS, GCP, and Azure nework fabrics due to compensating controls in these environments. This issue does not impact driver workloads that don’t use Field Level Encryption. This issue affect MongoDB Node.js Driver mongodb-client-encryption module version 1.2.0

    Published: 25 Feb 2021
    7.5
    High

    CVE-2020-27543

    Last Modified: 21 Nov 2024

    The restify-paginate package 0.0.5 for Node.js allows remote attackers to cause a Denial-of-Service by omitting the HTTP Host header. A Restify-based web service would crash with an uncaught exception.

    Published: 25 Feb 2021
    9.8
    Critical

    CVE-2020-23534

    Last Modified: 21 Nov 2024

    A server-side request forgery (SSRF) vulnerability in Upgrade.php of gopeak masterlab 2.1.5, via the 'source' parameter.

    Published: 25 Feb 2021
    6.1
    Medium

    CVE-2021-27330

    Last Modified: 21 Nov 2024

    Triconsole Datepicker Calendar <3.77 is affected by cross-site scripting (XSS) in calendar_form.php. Attackers can read authentication cookies that are still active, which can be used to perform further attacks such as reading browser history, directory listings, and file contents.

    Published: 25 Feb 2021
    5.4
    Medium

    CVE-2021-3124

    Last Modified: 21 Nov 2024

    Stored cross-site scripting (XSS) in form field in robust.systems product Custom Global Variables v 1.0.5 allows a remote attacker to inject arbitrary code via the vars[0][name] field.

    Published: 25 Feb 2021
    7.2
    High

    CVE-2021-3273

    Last Modified: 21 Nov 2024

    Nagios XI below 5.7 is affected by code injection in the /nagiosxi/admin/graphtemplates.php component. To exploit this vulnerability, someone must have an admin user account in Nagios XI's web system.

    Published: 25 Feb 2021
    7.8
    High

    CVE-2021-21066

    Last Modified: 21 Nov 2024

    Adobe Bridge version 11.0 (and earlier) is affected by an out-of-bounds write vulnerability when parsing TTF files that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 25 Feb 2021
    7.8
    High

    CVE-2021-21065

    Last Modified: 21 Nov 2024

    Adobe Bridge version 11.0 (and earlier) is affected by an out-of-bounds write vulnerability when parsing TTF files that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 25 Feb 2021
    4.9
    Medium

    CVE-2021-21064

    Last Modified: 21 Nov 2024

    Magento UPWARD-php version 1.1.4 (and earlier) is affected by a Path traversal vulnerability in Magento UPWARD Connector version 1.1.2 (and earlier) due to the upload feature. An attacker could potentially exploit this vulnerability to upload a malicious YAML file that can contain instructions which allows reading arbitrary files from the remote server. Access to the admin console is required for successful exploitation.

    Published: 25 Feb 2021
    6.7
    Medium

    CVE-2020-8032

    Last Modified: 21 Nov 2024

    A Insecure Temporary File vulnerability in the packaging of cyrus-sasl of openSUSE Factory allows local attackers to escalate to root. This issue affects: openSUSE Factory cyrus-sasl version 2.1.27-4.2 and prior versions.

    Published: 25 Feb 2021
    8.1
    High

    CVE-2020-36254

    Last Modified: 3 Dec 2025

    scp.c in Dropbear before 2020.79 mishandles the filename of . or an empty filename, a related issue to CVE-2018-20685.

    Published: 25 Feb 2021
    6.1
    Medium

    CVE-2021-27671

    Last Modified: 21 Nov 2024

    An issue was discovered in the comrak crate before 0.9.1 for Rust. XSS can occur because the protection mechanism for data: and javascript: URIs is case-sensitive, allowing (for example) Data: to be used in an attack.

    Published: 25 Feb 2021
    9.8
    Critical

    CVE-2021-27670

    Last Modified: 21 Nov 2024

    Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.

    Published: 25 Feb 2021
    8.1
    High

    CVE-2021-26701

    Last Modified: 28 May 2026

    .NET Core Remote Code Execution Vulnerability

    Published: 25 Feb 2021
    7.5
    High

    CVE-2021-20313

    Last Modified: 21 Nov 2024

    A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in TransformSignature is possible. The highest threat from this vulnerability is to data confidentiality.

    Published: 25 Feb 2021
    9.1
    Critical

    CVE-2021-3144

    Last Modified: 21 Nov 2024

    In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)

    Published: 25 Feb 2021
    7.8
    High

    CVE-2020-28243

    Last Modified: 21 Nov 2024

    An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.

    Published: 25 Feb 2021
    7.4
    High

    CVE-2020-35662

    Last Modified: 21 Nov 2024

    In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not always validated.

    Published: 25 Feb 2021
    7.5
    High

    CVE-2021-20310

    Last Modified: 21 Nov 2024

    A flaw was found in ImageMagick in versions before 7.0.11, where a division by zero ConvertXYZToJzazbz() of MagickCore/colorspace.c may trigger undefined behavior via a crafted image file that is submitted by an attacker and processed by an application using ImageMagick. The highest threat from this vulnerability is to system availability.

    Published: 25 Feb 2021