Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows Server 2004 HIGH 7.5
CVE-2021-42287 KEVEPSS 74%

Active Directory Domain Services Elevation of Privilege Vulnerability

Fix: 10.0.14393.4770 / 10.0.17763.2300+
Fix from $1,950 2021-11-10
Windows Server 2004 HIGH 7.5
CVE-2021-42278 KEVEPSS 70%

Active Directory Domain Services Elevation of Privilege Vulnerability

Fix: 10.0.14393.4770 / 10.0.17763.2300+
Fix from $1,950 2021-11-10
Windows 10 1507 MEDIUM 5.5
CVE-2021-41379 KEVEPSS 20%

Windows Installer Elevation of Privilege Vulnerability

Fix: 10.0.10240.19119 / 10.0.14393.4770+
Fix from $1,600 2021-11-10
Experience Platform CRITICAL 9.8
CVE-2021-42237 KEVEPSS 98%

Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remot…

Mitigation only
Fix from $2,300 2021-11-05
Billquick Web Suite CRITICAL 9.8
CVE-2021-42258 KEVEPSS 74%

BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in…

Fix: 22.0.9.1+
Fix from $2,300 2021-10-22
Ipados HIGH 7.8
CVE-2021-30807 KEVEPSS 29%

A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS 14.7.1, wat…

Fix: 7.6.1 / 11.5.1+
Fix from $1,950 2021-10-19
Device Management CRITICAL 9.8
CVE-2021-27561 KEVEPSS 83%

Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.

Fix: after 3.6.0.20
Fix from $2,300 2021-10-15
Vigorconnect HIGH 7.5
CVE-2021-20124 KEVEPSS 71%

A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauth…

Mitigation only
Fix from $1,950 2021-10-13
Vigorconnect HIGH 7.5
CVE-2021-20123 KEVEPSS 75%

A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. …

Mitigation only
Fix from $1,950 2021-10-13
Windows 10 2004 HIGH 7.8
CVE-2021-41357 KEV

Win32k Elevation of Privilege Vulnerability

Fix: 10.0.19041.1288 / 10.0.19042.1288+
Fix from $1,950 2021-10-13
Windows 10 1809 HIGH 7.8
CVE-2021-40450 KEV

Win32k Elevation of Privilege Vulnerability

Fix: 10.0.17763.2237 / 10.0.18363.1854+
Fix from $1,950 2021-10-13
Windows 10 1507 HIGH 7.8
CVE-2021-40449 KEVEPSS 74%

Win32k Elevation of Privilege Vulnerability

Fix: 10.0.10240.19086 / 10.0.14393.4704+
Fix from $1,950 2021-10-13
Chrome MEDIUM 6.5
CVE-2021-37976 KEVEPSS 20%

Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information f…

Fix: 94.0.4606.71+
Fix from $1,600 2021-10-08
Chrome HIGH 8.8
CVE-2021-37975 KEVEPSS 35%

Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 94.0.4606.71+
Fix from $1,950 2021-10-08
Chrome CRITICAL 9.6
CVE-2021-37973 KEVEPSS 12%

Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially pe…

Fix: 94.0.4606.61+
Fix from $2,300 2021-10-08
Chrome CRITICAL 9.6
CVE-2021-30633 KEVEPSS 33%

Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potenti…

Fix: 93.0.4577.82+
Fix from $2,300 2021-10-08
Chrome HIGH 8.8
CVE-2021-30632 KEVEPSS 65%

Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 93.0.4577.82+
Fix from $1,950 2021-10-08
HTTP Server CRITICAL 9.8
CVE-2021-42013 KEVEPSS 100%

It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs…

Fix: 9.2.6.0 / 18.1.0.1.0+
Fix from $2,300 2021-10-07
Android MEDIUM 5.5
CVE-2021-25489 KEV

Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug …

Mitigation only
Fix from $1,600 2021-10-06
Android HIGH 7.8
CVE-2021-25487 KEV

Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in a…

Mitigation only
Fix from $1,950 2021-10-06
Grafana HIGH 7.3
CVE-2021-39226 KEVEPSS 100%

Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot wit…

Fix: 7.5.11 / 8.1.6+
Fix from $1,950 2021-10-05
HTTP Server CRITICAL 9.8
CVE-2021-41773 KEVEPSS 100%

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to fi…

Patch available
Fix from $2,300 2021-10-05
Sma 200 Firmware MEDIUM 6.5
CVE-2021-20035 KEV

Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as…

Fix: 9.0.0.11-31sv / 10.2.0.8-37sv+
Fix from $1,600 2021-09-27
Dir 605l Firmware HIGH 7.5
CVE-2021-40655 KEVEPSS 87%

An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a po…

Mitigation only
Fix from $1,950 2021-09-24
Sharefile Storagezones Controller CRITICAL 9.8
CVE-2021-22941 KEVEPSS 54%

Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the …

Fix: 5.11.20+
Fix from $2,300 2021-09-23
Vcenter Server MEDIUM 5.3
CVE-2021-22017 KEVEPSS 49%

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network acce…

Patch available
Fix from $1,600 2021-09-23
Cloud Foundation CRITICAL 9.8
CVE-2021-22005 KEVEPSS 100%

The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCe…

Fix: 5.0+
Fix from $2,300 2021-09-23
Ds 2cd2026g2 Iu\/sl Firmware CRITICAL 9.8
CVE-2021-36260 KEVEPSS 100%

A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vul…

Mitigation only
Fix from $2,300 2021-09-22
Dopsoft HIGH 7.8
CVE-2021-38406 KEVEPSS 78%

Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could …

Fix: after 2.00.07
Fix from $1,950 2021-09-17
Enterprise Linux CRITICAL 9.0
CVE-2021-40438 KEVEPSS 100%

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP …

Patch available
Fix from $2,300 2021-09-16