Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Lyra Mini Firmware CRITICAL 9.8
CVE-2021-32030 KEVEPSS 99%

The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass …

Fix: 3.0.0.4.384.46630 / 3.0.0.4.386.42643+
Fix from $2,300 2021-05-06
Hyperflex Hx Data Platform CRITICAL 9.8
CVE-2021-1498 KEVEPSS 100%

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform comma…

Fix: 4.0 / 4.5+
Fix from $2,300 2021-05-06
Hyperflex Hx Data Platform CRITICAL 9.8
CVE-2021-1497 KEVEPSS 100%

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform comma…

Fix: 4.0 / 4.5+
Fix from $2,300 2021-05-06
Dbutil HIGH 7.8
CVE-2021-21551 KEVEPSS 53%

Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or in…

Fix: after 2.3
Fix from $1,950 2021-05-04
Wsr 2533dhpl2 Bk Firmware CRITICAL 9.8
CVE-2021-20090 KEVEPSS 100%

A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 coul…

Fix: after 1.24
Fix from $2,300 2021-04-29
Chrome HIGH 8.8
CVE-2021-21224 KEVEPSS 56%

Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML p…

Fix: 90.0.4430.85+
Fix from $1,950 2021-04-26
Chrome HIGH 8.8
CVE-2021-21220 KEVEPSS 69%

Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corrup…

Fix: 89.0.4389.128+
Fix from $1,950 2021-04-26
Chrome HIGH 8.8
CVE-2021-21206 KEVEPSS 9%

Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 89.0.4389.128+
Fix from $1,950 2021-04-26
GitLab CRITICAL 10.0
CVE-2021-22205 KEVEPSS 100%

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were pass…

Fix: 13.8.8 / 13.9.6+
Fix from $2,300 2021-04-23
Debian Linux HIGH 7.8
CVE-2021-22204 KEVEPSS 100%

Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malici…

Fix: 12.24+
Fix from $1,950 2021-04-23
Connect Secure CRITICAL 10.0
CVE-2021-22893 KEVEPSS 47%

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pul…

Mitigation only
Fix from $2,300 2021-04-23
Ubuntu Linux HIGH 7.8
CVE-2021-3493 KEVEPSS 49%

The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files …

Fix: 18.04 / 20.04+
Fix from $1,950 2021-04-17
Qts CRITICAL 9.8
CVE-2020-2509 KEVEPSS 33%

A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitra…

Fix: 4.2.6 / 4.3.6+
Fix from $2,300 2021-04-17
Windows 10 1803 HIGH 7.8
CVE-2021-28310 KEVEPSS 8%

Win32k Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-04-13
Email Security HIGH 7.2
CVE-2021-20022 KEVEPSS 17%

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remot…

Fix: 10.0.9.6103 / 10.0.9.6105+
Fix from $1,950 2021-04-09
Email Security CRITICAL 9.8
CVE-2021-20021 KEVEPSS 83%

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP req…

Fix: 10.0.9.6103 / 10.0.9.6105+
Fix from $2,300 2021-04-09
Ipados MEDIUM 6.1
CVE-2021-1879 KEVEPSS 7%

This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS 7.3.3. …

Fix: 7.3.3 / 12.5.2+
Fix from $1,600 2021-04-02
Debian Linux CRITICAL 9.8
CVE-2021-1871 KEVEPSS 7%

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update…

Fix: 10.15.7 / 11.2+
Fix from $2,300 2021-04-02
Fedora CRITICAL 9.8
CVE-2021-1870 KEVEPSS 8%

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update…

Fix: 2.30.6 / 10.15.7+
Fix from $2,300 2021-04-02
Fedora HIGH 8.8
CVE-2021-1789 KEVEPSS 13%

A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Secu…

Fix: 2.30.6 / 7.3+
Fix from $1,950 2021-04-02
Ipados HIGH 7.0
CVE-2021-1782 KEV

A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2…

Fix: 7.3 / 10.14.6+
Fix from $1,950 2021-04-02
Big Ip Access Policy Manager CRITICAL 9.8
CVE-2021-22991 KEVEPSS 61%

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclo…

Fix: 12.1.5.3 / 13.1.3.6+
Fix from $2,300 2021-03-31
Cloud Foundation HIGH 7.5
CVE-2021-21975 KEVEPSS 78%

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the v…

Mitigation only
Fix from $1,950 2021-03-31
Big Ip Access Policy Manager CRITICAL 9.8
CVE-2021-22986 KEVEPSS 100%

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-I…

Fix: 12.1.5.3 / 13.1.3.6+
Fix from $2,300 2021-03-31
Android MEDIUM 6.7
CVE-2021-25372 KEV

An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.

Mitigation only
Fix from $1,600 2021-03-26
Android MEDIUM 6.7
CVE-2021-25371 KEV

A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.

Mitigation only
Fix from $1,600 2021-03-26
Android MEDIUM 5.5
CVE-2021-25369 KEV

An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.

Mitigation only
Fix from $1,600 2021-03-26
Access Manager HIGH 7.5
CVE-2021-22506 KEVEPSS 26%

Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. Th…

Fix: 5.0+
Fix from $1,950 2021-03-26
Chrome HIGH 8.8
CVE-2021-21193 KEVEPSS 10%

Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa…

Fix: 89.0.4389.90+
Fix from $1,950 2021-03-16
Internet Explorer HIGH 8.8
CVE-2021-27085 KEV

Internet Explorer Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-03-11