CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2021-1657

    Last Modified: 21 Nov 2024

    Windows Fax Compose Form Remote Code Execution Vulnerability

    Published: 12 Jan 2021
    7.8
    High

    CVE-2021-1655

    Last Modified: 21 Nov 2024

    Windows CSC Service Elevation of Privilege Vulnerability

    Published: 12 Jan 2021
    5.5
    Medium

    CVE-2021-1656

    Last Modified: 21 Nov 2024

    TPM Device Driver Information Disclosure Vulnerability

    Published: 12 Jan 2021
    7.8
    High

    CVE-2021-1654

    Last Modified: 21 Nov 2024

    Windows CSC Service Elevation of Privilege Vulnerability

    Published: 12 Jan 2021
    7.8
    High

    CVE-2021-1652

    Last Modified: 21 Nov 2024

    Windows CSC Service Elevation of Privilege Vulnerability

    Published: 12 Jan 2021
    7.8
    High

    CVE-2021-1653

    Last Modified: 21 Nov 2024

    Windows CSC Service Elevation of Privilege Vulnerability

    Published: 12 Jan 2021
    7.8
    High

    CVE-2021-1651

    Last Modified: 21 Nov 2024

    Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability

    Published: 12 Jan 2021
    7.8
    High

    CVE-2021-1649

    Last Modified: 21 Nov 2024

    Active Template Library Elevation of Privilege Vulnerability

    Published: 12 Jan 2021
    7.8
    High

    CVE-2021-1650

    Last Modified: 21 Nov 2024

    Windows Runtime C++ Template Library Elevation of Privilege Vulnerability

    Published: 12 Jan 2021
    7.8
    High

    CVE-2021-1647

    Last Modified: 30 Oct 2025

    Microsoft Defender Remote Code Execution Vulnerability

    Published: 12 Jan 2021
    7.8
    High

    CVE-2021-1648

    Last Modified: 21 Nov 2024

    Microsoft splwow64 Elevation of Privilege Vulnerability

    Published: 12 Jan 2021
    6.6
    Medium

    CVE-2021-1646

    Last Modified: 21 Nov 2024

    Windows WLAN Service Elevation of Privilege Vulnerability

    Published: 12 Jan 2021
    7.8
    High

    CVE-2021-1644

    Last Modified: 21 Nov 2024

    HEVC Video Extensions Remote Code Execution Vulnerability

    Published: 12 Jan 2021
    5
    Medium

    CVE-2021-1645

    Last Modified: 21 Nov 2024

    Windows Docker Information Disclosure Vulnerability

    Published: 12 Jan 2021
    7.8
    High

    CVE-2021-1643

    Last Modified: 21 Nov 2024

    HEVC Video Extensions Remote Code Execution Vulnerability

    Published: 12 Jan 2021
    4.6
    Medium

    CVE-2021-1641

    Last Modified: 21 Nov 2024

    Microsoft SharePoint Server Spoofing Vulnerability

    Published: 12 Jan 2021
    7.8
    High

    CVE-2021-1642

    Last Modified: 21 Nov 2024

    Windows AppX Deployment Extensions Elevation of Privilege Vulnerability

    Published: 12 Jan 2021
    7.7
    High

    CVE-2021-1638

    Last Modified: 21 Nov 2024

    Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG. To address the vulnerability, Microsoft has released a software update that will fail attempts to pair if the remote device exchanges a public key with the same X coordinate as the locally exchanged public key

    Published: 12 Jan 2021
    5.5
    Medium

    CVE-2021-1637

    Last Modified: 21 Nov 2024

    Windows DNS Query Information Disclosure Vulnerability

    Published: 12 Jan 2021
    8.8
    High

    CVE-2021-1636

    Last Modified: 21 Nov 2024

    Microsoft SQL Elevation of Privilege Vulnerability

    Published: 12 Jan 2021
    6.1
    Medium

    CVE-2020-36190

    Last Modified: 21 Nov 2024

    RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms.

    Published: 12 Jan 2021
    7.7
    High

    CVE-2020-4079

    Last Modified: 21 Nov 2024

    Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 2.8.0, when the ajax endpoint for the "excel export" portal functionality is called directly it allows getting data without scope filtering. This allows a user to access data they which they should not have access to. This is fixed in versions 2.7.2 and 3.0.0.

    Published: 12 Jan 2021
    7.8
    High

    CVE-2021-3134

    Last Modified: 21 Nov 2024

    Mubu 2.2.1 allows local users to gain privileges to execute commands, aka CNVD-2020-68878.

    Published: 12 Jan 2021
    6.5
    Medium

    CVE-2021-3133

    Last Modified: 21 Nov 2024

    The Elementor Contact Form DB plugin before 1.6 for WordPress allows CSRF via backend admin pages.

    Published: 12 Jan 2021
    5.4
    Medium

    CVE-2020-13116

    Last Modified: 21 Nov 2024

    OpenText Carbonite Server Backup Portal before 8.8.7 allows XSS by an authenticated user via policy creation.

    Published: 12 Jan 2021
    7.1
    High

    CVE-2020-27148

    Last Modified: 21 Nov 2024

    The TIBCO EBX Add-on for Oracle Hyperion EPM, TIBCO EBX Data Exchange Add-on, and TIBCO EBX Insight Add-on components of TIBCO Software Inc.'s TIBCO EBX Add-ons contain a vulnerability that theoretically allows a low privileged attacker with network access to execute an XML External Entity (XXE) attack. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 4.4.2 and below.

    Published: 12 Jan 2021
    7.5
    High

    CVE-2021-1723

    Last Modified: 21 Nov 2024

    ASP.NET Core and Visual Studio Denial of Service Vulnerability

    Published: 12 Jan 2021
    5.4
    Medium

    CVE-2020-4838

    Last Modified: 21 Nov 2024

    IBM API Connect 5.0.0.0 through 5.0.8.10 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190036.

    Published: 12 Jan 2021
    4.3
    Medium

    CVE-2020-4674

    Last Modified: 21 Nov 2024

    IBM Workload Automation 9.5 stores the server path in URLs that could aid in further attacks against the system. IBM X-Force ID: 186287.

    Published: 12 Jan 2021
    4.3
    Medium

    CVE-2020-4673

    Last Modified: 21 Nov 2024

    IBM Workload Automation 9.5 stores sensitive information in HTML comments that could aid in further attacks against the system. IBM X-Force ID: 186286.

    Published: 12 Jan 2021
    7.5
    High

    CVE-2021-21469

    Last Modified: 21 Nov 2024

    When security guidelines for SAP NetWeaver Master Data Management running on windows have not been thoroughly reviewed, it might be possible for an external operator to try and set custom paths in the MDS server configuration. When no adequate protection has been enforced on any level (e.g., MDS Server password not set, network and OS configuration not properly secured, etc.), a malicious user might define UNC paths which could then be exploited to put the system at risk using a so-called SMB relay attack and obtain highly sensitive data, which leads to Information Disclosure.

    Published: 12 Jan 2021
    8.8
    High

    CVE-2021-21466

    Last Modified: 21 Nov 2024

    SAP Business Warehouse, versions 700, 701, 702, 711, 730, 731, 740, 750, 782 and SAP BW/4HANA, versions 100, 200, allow a low privileged attacker to inject code using a remote enabled function module over the network. Via the function module an attacker can create a malicious ABAP report which could be used to get access to sensitive data, to inject malicious UPDATE statements that could have also impact on the operating system, to disrupt the functionality of the SAP system which can thereby lead to a Denial of Service.

    Published: 12 Jan 2021
    5.4
    Medium

    CVE-2021-21445

    Last Modified: 21 Nov 2024

    SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated data in the HTTP response Content Type header, due to improper input validation, and sent to a Web user. A successful exploitation of this vulnerability may lead to advanced attacks, including cross-site scripting and page hijacking.

    Published: 12 Jan 2021
    8.8
    High

    CVE-2021-21463

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 12 Jan 2021
    4.3
    Medium

    CVE-2021-21467

    Last Modified: 21 Nov 2024

    SAP Banking Services (Generic Market Data) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. An unauthorized User is allowed to display restricted Business Partner Generic Market Data (GMD), due to improper authorization check.

    Published: 12 Jan 2021
    4.4
    Medium

    CVE-2021-21470

    Last Modified: 21 Nov 2024

    SAP EPM Add-in for Microsoft Office, version - 1010 and SAP EPM Add-in for SAP Analysis Office, version - 2.8, allows an authenticated attacker with user privileges to parse malicious XML files which could result in XXE-based attacks in applications that accept attacker-controlled XML configuration files. This occurs as logging service does not disable XML external entities when parsing configuration files and a successful exploit would result in limited impact on integrity and availability of the application.

    Published: 12 Jan 2021
    9.9
    Critical

    CVE-2021-21465

    Last Modified: 21 Nov 2024

    The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute without properly sanitizing the untrusted data leading to SQL injection vulnerability which can fully compromise the affected SAP system.

    Published: 12 Jan 2021
    6.5
    Medium

    CVE-2021-21468

    Last Modified: 21 Nov 2024

    The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allows the user to practically read out any database table.

    Published: 12 Jan 2021
    8.8
    High

    CVE-2021-21462

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 12 Jan 2021
    5.4
    Medium

    CVE-2021-21447

    Last Modified: 21 Nov 2024

    SAP BusinessObjects Business Intelligence platform, versions 410, 420, allows an authenticated attacker to inject malicious JavaScript payload into the custom value input field of an Input Control, which can be executed by User who views the relevant application content, which leads to Stored Cross-Site Scripting.

    Published: 12 Jan 2021
    8.8
    High

    CVE-2021-21457

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 12 Jan 2021
    8.8
    High

    CVE-2021-21456

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated DIB file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 12 Jan 2021
    6.5
    Medium

    CVE-2021-21448

    Last Modified: 21 Nov 2024

    SAP GUI for Windows, version - 7.60, allows an attacker to spoof logon credentials for Application Server ABAP backend systems in the client PCs memory. Under certain conditions the attacker can access information which would otherwise be restricted. The exploit can only be executed locally on the client PC and not via Network and the attacker needs at least user authorization of the Operating System user of the victim.

    Published: 12 Jan 2021
    8.8
    High

    CVE-2021-21461

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated BMP file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 12 Jan 2021
    7.5
    High

    CVE-2021-21446

    Last Modified: 21 Nov 2024

    SAP NetWeaver AS ABAP, versions 740, 750, 751, 752, 753, 754, 755, allows an unauthenticated attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service, this has a high impact on the availability of the service.

    Published: 12 Jan 2021
    8.8
    High

    CVE-2021-21449

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 12 Jan 2021
    8.8
    High

    CVE-2021-21458

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 12 Jan 2021
    8.8
    High

    CVE-2021-21450

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PSD file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 12 Jan 2021
    8.8
    High

    CVE-2021-21453

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated RLE file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 12 Jan 2021
    8.8
    High

    CVE-2021-21454

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated RLE file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 12 Jan 2021