CVE-2021-1657
Last Modified: 21 Nov 2024Windows Fax Compose Form Remote Code Execution Vulnerability
CVE-2021-1655
Last Modified: 21 Nov 2024Windows CSC Service Elevation of Privilege Vulnerability
CVE-2021-1656
Last Modified: 21 Nov 2024TPM Device Driver Information Disclosure Vulnerability
CVE-2021-1654
Last Modified: 21 Nov 2024Windows CSC Service Elevation of Privilege Vulnerability
CVE-2021-1652
Last Modified: 21 Nov 2024Windows CSC Service Elevation of Privilege Vulnerability
CVE-2021-1653
Last Modified: 21 Nov 2024Windows CSC Service Elevation of Privilege Vulnerability
CVE-2021-1651
Last Modified: 21 Nov 2024Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
CVE-2021-1649
Last Modified: 21 Nov 2024Active Template Library Elevation of Privilege Vulnerability
CVE-2021-1650
Last Modified: 21 Nov 2024Windows Runtime C++ Template Library Elevation of Privilege Vulnerability
CVE-2021-1647
Last Modified: 30 Oct 2025Microsoft Defender Remote Code Execution Vulnerability
CVE-2021-1648
Last Modified: 21 Nov 2024Microsoft splwow64 Elevation of Privilege Vulnerability
CVE-2021-1646
Last Modified: 21 Nov 2024Windows WLAN Service Elevation of Privilege Vulnerability
CVE-2021-1644
Last Modified: 21 Nov 2024HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2021-1645
Last Modified: 21 Nov 2024Windows Docker Information Disclosure Vulnerability
CVE-2021-1643
Last Modified: 21 Nov 2024HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2021-1641
Last Modified: 21 Nov 2024Microsoft SharePoint Server Spoofing Vulnerability
CVE-2021-1642
Last Modified: 21 Nov 2024Windows AppX Deployment Extensions Elevation of Privilege Vulnerability
CVE-2021-1638
Last Modified: 21 Nov 2024Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG. To address the vulnerability, Microsoft has released a software update that will fail attempts to pair if the remote device exchanges a public key with the same X coordinate as the locally exchanged public key
CVE-2021-1637
Last Modified: 21 Nov 2024Windows DNS Query Information Disclosure Vulnerability
CVE-2021-1636
Last Modified: 21 Nov 2024Microsoft SQL Elevation of Privilege Vulnerability
CVE-2020-36190
Last Modified: 21 Nov 2024RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms.
CVE-2020-4079
Last Modified: 21 Nov 2024Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 2.8.0, when the ajax endpoint for the "excel export" portal functionality is called directly it allows getting data without scope filtering. This allows a user to access data they which they should not have access to. This is fixed in versions 2.7.2 and 3.0.0.
CVE-2021-3134
Last Modified: 21 Nov 2024Mubu 2.2.1 allows local users to gain privileges to execute commands, aka CNVD-2020-68878.
CVE-2021-3133
Last Modified: 21 Nov 2024The Elementor Contact Form DB plugin before 1.6 for WordPress allows CSRF via backend admin pages.
CVE-2020-13116
Last Modified: 21 Nov 2024OpenText Carbonite Server Backup Portal before 8.8.7 allows XSS by an authenticated user via policy creation.
CVE-2020-27148
Last Modified: 21 Nov 2024The TIBCO EBX Add-on for Oracle Hyperion EPM, TIBCO EBX Data Exchange Add-on, and TIBCO EBX Insight Add-on components of TIBCO Software Inc.'s TIBCO EBX Add-ons contain a vulnerability that theoretically allows a low privileged attacker with network access to execute an XML External Entity (XXE) attack. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 4.4.2 and below.
CVE-2021-1723
Last Modified: 21 Nov 2024ASP.NET Core and Visual Studio Denial of Service Vulnerability
CVE-2020-4838
Last Modified: 21 Nov 2024IBM API Connect 5.0.0.0 through 5.0.8.10 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190036.
CVE-2020-4674
Last Modified: 21 Nov 2024IBM Workload Automation 9.5 stores the server path in URLs that could aid in further attacks against the system. IBM X-Force ID: 186287.
CVE-2020-4673
Last Modified: 21 Nov 2024IBM Workload Automation 9.5 stores sensitive information in HTML comments that could aid in further attacks against the system. IBM X-Force ID: 186286.
CVE-2021-21469
Last Modified: 21 Nov 2024When security guidelines for SAP NetWeaver Master Data Management running on windows have not been thoroughly reviewed, it might be possible for an external operator to try and set custom paths in the MDS server configuration. When no adequate protection has been enforced on any level (e.g., MDS Server password not set, network and OS configuration not properly secured, etc.), a malicious user might define UNC paths which could then be exploited to put the system at risk using a so-called SMB relay attack and obtain highly sensitive data, which leads to Information Disclosure.
CVE-2021-21466
Last Modified: 21 Nov 2024SAP Business Warehouse, versions 700, 701, 702, 711, 730, 731, 740, 750, 782 and SAP BW/4HANA, versions 100, 200, allow a low privileged attacker to inject code using a remote enabled function module over the network. Via the function module an attacker can create a malicious ABAP report which could be used to get access to sensitive data, to inject malicious UPDATE statements that could have also impact on the operating system, to disrupt the functionality of the SAP system which can thereby lead to a Denial of Service.
CVE-2021-21445
Last Modified: 21 Nov 2024SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated data in the HTTP response Content Type header, due to improper input validation, and sent to a Web user. A successful exploitation of this vulnerability may lead to advanced attacks, including cross-site scripting and page hijacking.
CVE-2021-21463
Last Modified: 21 Nov 2024SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
CVE-2021-21467
Last Modified: 21 Nov 2024SAP Banking Services (Generic Market Data) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. An unauthorized User is allowed to display restricted Business Partner Generic Market Data (GMD), due to improper authorization check.
CVE-2021-21470
Last Modified: 21 Nov 2024SAP EPM Add-in for Microsoft Office, version - 1010 and SAP EPM Add-in for SAP Analysis Office, version - 2.8, allows an authenticated attacker with user privileges to parse malicious XML files which could result in XXE-based attacks in applications that accept attacker-controlled XML configuration files. This occurs as logging service does not disable XML external entities when parsing configuration files and a successful exploit would result in limited impact on integrity and availability of the application.
CVE-2021-21465
Last Modified: 21 Nov 2024The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute without properly sanitizing the untrusted data leading to SQL injection vulnerability which can fully compromise the affected SAP system.
CVE-2021-21468
Last Modified: 21 Nov 2024The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allows the user to practically read out any database table.
CVE-2021-21462
Last Modified: 21 Nov 2024SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
CVE-2021-21447
Last Modified: 21 Nov 2024SAP BusinessObjects Business Intelligence platform, versions 410, 420, allows an authenticated attacker to inject malicious JavaScript payload into the custom value input field of an Input Control, which can be executed by User who views the relevant application content, which leads to Stored Cross-Site Scripting.
CVE-2021-21457
Last Modified: 21 Nov 2024SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
CVE-2021-21456
Last Modified: 21 Nov 2024SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated DIB file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
CVE-2021-21448
Last Modified: 21 Nov 2024SAP GUI for Windows, version - 7.60, allows an attacker to spoof logon credentials for Application Server ABAP backend systems in the client PCs memory. Under certain conditions the attacker can access information which would otherwise be restricted. The exploit can only be executed locally on the client PC and not via Network and the attacker needs at least user authorization of the Operating System user of the victim.
CVE-2021-21461
Last Modified: 21 Nov 2024SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated BMP file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
CVE-2021-21446
Last Modified: 21 Nov 2024SAP NetWeaver AS ABAP, versions 740, 750, 751, 752, 753, 754, 755, allows an unauthenticated attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service, this has a high impact on the availability of the service.
CVE-2021-21449
Last Modified: 21 Nov 2024SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
CVE-2021-21458
Last Modified: 21 Nov 2024SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
CVE-2021-21450
Last Modified: 21 Nov 2024SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PSD file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
CVE-2021-21453
Last Modified: 21 Nov 2024SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated RLE file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
CVE-2021-21454
Last Modified: 21 Nov 2024SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated RLE file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
