Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2021-42287 KEVEPSS 74% Active Directory Domain Services Elevation of Privilege Vulnerability Windows Server 2004 10.0.14393.4770 / 10.0.17763.2300+ Fix from $1,9502021-11-10 HIGH 7.5 CVE-2021-42278 KEVEPSS 70% Active Directory Domain Services Elevation of Privilege Vulnerability Windows Server 2004 10.0.14393.4770 / 10.0.17763.2300+ Fix from $1,9502021-11-10 MEDIUM 5.5 CVE-2021-41379 KEVEPSS 20% Windows Installer Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.19119 / 10.0.14393.4770+ Fix from $1,6002021-11-10 CRITICAL 9.8 CVE-2021-42237 KEVEPSS 98% Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remot… Experience Platform Mitigation only Fix from $2,3002021-11-05 CRITICAL 9.8 CVE-2021-42258 KEVEPSS 74% BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in… Billquick Web Suite 22.0.9.1+ Fix from $2,3002021-10-22 HIGH 7.8 CVE-2021-30807 KEVEPSS 29% A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS 14.7.1, wat… Ipados 7.6.1 / 11.5.1+ Fix from $1,9502021-10-19 CRITICAL 9.8 CVE-2021-27561 KEVEPSS 83% Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication. Device Management after 3.6.0.20 Fix from $2,3002021-10-15 HIGH 7.5 CVE-2021-20124 KEVEPSS 71% A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauth… Vigorconnect Mitigation only Fix from $1,9502021-10-13 HIGH 7.5 CVE-2021-20123 KEVEPSS 75% A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. … Vigorconnect Mitigation only Fix from $1,9502021-10-13 HIGH 7.8 CVE-2021-41357 KEV Win32k Elevation of Privilege Vulnerability Windows 10 2004 10.0.19041.1288 / 10.0.19042.1288+ Fix from $1,9502021-10-13 HIGH 7.8 CVE-2021-40450 KEV Win32k Elevation of Privilege Vulnerability Windows 10 1809 10.0.17763.2237 / 10.0.18363.1854+ Fix from $1,9502021-10-13 HIGH 7.8 CVE-2021-40449 KEVEPSS 74% Win32k Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.19086 / 10.0.14393.4704+ Fix from $1,9502021-10-13 MEDIUM 6.5 CVE-2021-37976 KEVEPSS 20% Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information f… Chrome 94.0.4606.71+ Fix from $1,6002021-10-08 HIGH 8.8 CVE-2021-37975 KEVEPSS 35% Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Chrome 94.0.4606.71+ Fix from $1,9502021-10-08 CRITICAL 9.6 CVE-2021-37973 KEVEPSS 12% Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially pe… Chrome 94.0.4606.61+ Fix from $2,3002021-10-08 CRITICAL 9.6 CVE-2021-30633 KEVEPSS 33% Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potenti… Chrome 93.0.4577.82+ Fix from $2,3002021-10-08 HIGH 8.8 CVE-2021-30632 KEVEPSS 65% Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML … Chrome 93.0.4577.82+ Fix from $1,9502021-10-08 CRITICAL 9.8 CVE-2021-42013 KEVEPSS 100% It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs… HTTP Server 9.2.6.0 / 18.1.0.1.0+ Fix from $2,3002021-10-07 MEDIUM 5.5 CVE-2021-25489 KEV Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug … Android Mitigation only Fix from $1,6002021-10-06 HIGH 7.8 CVE-2021-25487 KEV Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in a… Android Mitigation only Fix from $1,9502021-10-06 HIGH 7.3 CVE-2021-39226 KEVEPSS 100% Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot wit… Grafana 7.5.11 / 8.1.6+ Fix from $1,9502021-10-05 CRITICAL 9.8 CVE-2021-41773 KEVEPSS 100% A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to fi… HTTP Server Patch available Fix from $2,3002021-10-05 MEDIUM 6.5 CVE-2021-20035 KEV Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as… Sma 200 Firmware 9.0.0.11-31sv / 10.2.0.8-37sv+ Fix from $1,6002021-09-27 HIGH 7.5 CVE-2021-40655 KEVEPSS 87% An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a po… Dir 605l Firmware Mitigation only Fix from $1,9502021-09-24 CRITICAL 9.8 CVE-2021-22941 KEVEPSS 54% Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the … Sharefile Storagezones Controller 5.11.20+ Fix from $2,3002021-09-23 MEDIUM 5.3 CVE-2021-22017 KEVEPSS 49% Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network acce… Vcenter Server Patch available Fix from $1,6002021-09-23 CRITICAL 9.8 CVE-2021-22005 KEVEPSS 100% The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCe… Cloud Foundation 5.0+ Fix from $2,3002021-09-23 CRITICAL 9.8 CVE-2021-36260 KEVEPSS 100% A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vul… Ds 2cd2026g2 Iu\/sl Firmware Mitigation only Fix from $2,3002021-09-22 HIGH 7.8 CVE-2021-38406 KEVEPSS 78% Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could … Dopsoft after 2.00.07 Fix from $1,9502021-09-17 CRITICAL 9.0 CVE-2021-40438 KEVEPSS 100% A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP … Enterprise Linux Patch available Fix from $2,3002021-09-16