Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Chrome HIGH 8.8
CVE-2021-30551 KEVEPSS 65%

Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 91.0.4472.101+
Fix from $1,950 2021-06-15
GitLab CRITICAL 9.8
CVE-2021-22175 KEVEPSS 53%

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting…

Fix: 13.6.7 / 13.7.7+
Fix from $2,300 2021-06-11
Android MEDIUM 6.4
CVE-2021-25395 KEV

A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is co…

Mitigation only
Fix from $1,600 2021-06-11
Android MEDIUM 6.4
CVE-2021-25394 KEV

A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privileg…

Mitigation only
Fix from $1,600 2021-06-11
Scadabr MEDIUM 5.4
CVE-2021-26829 KEVEPSS 48%

OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.

Fix: after 1.12.4
Fix from $1,600 2021-06-11
Scadabr HIGH 8.8
CVE-2021-26828 KEVEPSS 39%

OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via …

Fix: after 1.12.4
Fix from $1,950 2021-06-11
Apq8009 Firmware HIGH 7.8
CVE-2020-11261 KEV

Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdrago…

Patch available
Fix from $1,950 2021-06-09
Windows 10 1507 HIGH 7.5
CVE-2021-33742 KEVEPSS 59%

Windows MSHTML Platform Remote Code Execution Vulnerability

Fix: 10.0.10240.18967 / 10.0.14393.4467+
Fix from $1,950 2021-06-08
Windows 10 1909 HIGH 8.4
CVE-2021-33739 KEVEPSS 7%

Microsoft DWM Core Library Elevation of Privilege Vulnerability

Fix: 10.0.18363.1621 / 10.0.19041.1052+
Fix from $1,950 2021-06-08
Windows 10 1507 HIGH 7.8
CVE-2021-31956 KEVEPSS 20%

Windows NTFS Elevation of Privilege Vulnerability

Fix: 10.0.10240.18967 / 10.0.14393.4467+
Fix from $1,950 2021-06-08
Windows 10 1809 MEDIUM 5.5
CVE-2021-31955 KEVEPSS 81%

Windows Kernel Information Disclosure Vulnerability

Fix: 10.0.17763.1999 / 10.0.18363.1621+
Fix from $1,600 2021-06-08
Windows 10 1507 MEDIUM 5.2
CVE-2021-31201 KEV

Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

Fix: 10.0.10240.18967 / 10.0.14393.4467+
Fix from $1,600 2021-06-08
Windows 10 1507 MEDIUM 5.2
CVE-2021-31199 KEV

Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

Fix: 10.0.10240.18967 / 10.0.14393.4467+
Fix from $1,600 2021-06-08
Windows 10 1507 HIGH 7.8
CVE-2021-1675 KEVEPSS 85%

Windows Print Spooler Remote Code Execution Vulnerability

Fix: 10.0.10240.18967 / 10.0.14393.4467+
Fix from $1,950 2021-06-08
Chrome MEDIUM 6.5
CVE-2021-30533 KEVEPSS 17%

Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions vi…

Fix: 91.0.4472.77+
Fix from $1,600 2021-06-07
Survey CRITICAL 9.8
CVE-2021-27852 KEVEPSS 32%

Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary …

Fix: 7.0+
Fix from $2,300 2021-05-27
Connect Secure HIGH 7.2
CVE-2021-22900 KEVEPSS 14%

A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to pe…

Fix: after 9.1
Fix from $1,950 2021-05-27
Connect Secure HIGH 8.8
CVE-2021-22899 KEVEPSS 23%

A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execut…

Mitigation only
Fix from $1,950 2021-05-27
Connect Secure HIGH 8.8
CVE-2021-22894 KEVEPSS 41%

A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as th…

Mitigation only
Fix from $1,950 2021-05-27
Vcenter Server CRITICAL 9.8
CVE-2021-21985 KEVEPSS 100%

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in whi…

Fix: 3.10.2.1 / 4.2.1+
Fix from $2,300 2021-05-26
Trusted Firmware M MEDIUM 5.5
CVE-2021-27562 KEV

In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when c…

Fix: after 1.2.0
Fix from $1,600 2021-05-25
Bifrost Gpu Kernel Driver HIGH 8.8
CVE-2021-29256 KEV

. The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege e…

Mitigation only
Fix from $1,950 2021-05-24
Hybrid Backup Sync CRITICAL 9.8
CVE-2021-28799 KEVEPSS 78%

An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability all…

Fix: 3.0.210411 / 3.0.210412+
Fix from $2,300 2021-05-13
Exchange Server MEDIUM 6.6
CVE-2021-31207 KEVEPSS 100%

Microsoft Exchange Server Security Feature Bypass Vulnerability

Patch available
Fix from $1,600 2021-05-11
Windows 10 2004 CRITICAL 9.8
CVE-2021-31166 KEVEPSS 100%

HTTP Protocol Stack Remote Code Execution Vulnerability

Fix: 10.0.19041.982 / 10.0.19042.982+
Fix from $2,300 2021-05-11
Bifrost Gpu Kernel Driver HIGH 8.8
CVE-2021-28664 KEVEPSS 5%

The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/w…

Mitigation only
Fix from $1,950 2021-05-10
Bifrost Gpu Kernel Driver HIGH 8.8
CVE-2021-28663 KEVEPSS 12%

The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-a…

Mitigation only
Fix from $1,950 2021-05-10
Ac11 Firmware CRITICAL 9.8
CVE-2021-31755 KEVEPSS 86%

An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows a…

Fix: after 02.03.01.104_cn
Fix from $2,300 2021-05-07
Apq8009 Firmware MEDIUM 5.5
CVE-2021-1906 KEV

Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdr…

Patch available
Fix from $1,600 2021-05-07
Apq8009 Firmware HIGH 7.8
CVE-2021-1905 KEV

Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snap…

Patch available
Fix from $1,950 2021-05-07