Common Vulnerabilities and Exposures (CVE) is a critical tool for maintaining software security, providing a standardized way to track and manage vulnerabilities across systems. Organizations should regularly monitor CVE databases, assess the impact of vulnerabilities, and apply patches promptly to reduce the risk of exploitation.
CVE (Common Vulnerabilities and Exposures) is a public database that provides a standardized method for identifying, tracking, and referencing publicly disclosed security vulnerabilities in software and hardware.
Each vulnerability receives a unique identifier called a CVE ID (e.g., CVE-2023-12345), making it easier to reference specific vulnerabilities across different tools and databases.
Total Search Results: 158437
CVE ID | Description | Severity | Published Date | Affected Vendor | Action |
---|---|---|---|---|---|
CVE-2021-25692 | Sensitive smart card data is logged in default INFO logs by Teradici's PCoIP Connection Manager and Security Gateway prior to version 21.01.3. | Unknown | N/A | n/a | |
CVE-2021-25693 | An attacker may cause a Denial of Service (DoS) in multiple versions of Teradici PCoIP Agent via a null pointer dereference. | Unknown | N/A | n/a | |
CVE-2021-25694 | Teradici PCoIP Graphics Agent for Windows prior to 21.03 does not validate NVENC.dll. An attacker could replace the .dll and redirect pixels elsewhere. | Unknown | N/A | n/a | |
CVE-2021-25695 | The USB vHub in the Teradici PCOIP Software Agent prior to version 21.07.0 would accept commands from any program, which may allow an attacker to elevate privileges by changing the flow of program execution within the vHub driver. | Unknown | N/A | n/a | |
CVE-2021-25698 | The OpenSSL component of the Teradici PCoIP Standard Agent prior to version 21.07.0 was compiled without the no-autoload-config option, which allowed an attacker to elevate to the privileges of the running process via placing a specially crafted dll in a build configuration directory. | Unknown | N/A | n/a | |
CVE-2021-25699 | The OpenSSL component of the Teradici PCoIP Software Client prior to version 21.07.0 was compiled without the no-autoload-config option, which allowed an attacker to elevate to the privileges of the running process via placing a specially crafted dll in a build configuration directory. | Unknown | N/A | n/a | |
CVE-2021-25701 | The fUSBHub driver in the PCoIP Software Client prior to version 21.07.0 had an error in object management during the handling of a variety of IOCTLs, which allowed an attacker to cause a denial of service. | Unknown | N/A | n/a | |
CVE-2021-25735 | A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some previous fields. | Unknown | N/A | Kubernetes | |
CVE-2021-25736 | Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (“spec.ports[*].port”) as a LoadBalancer Service when the LoadBalancer controller does not set the “status.loadBalancer.ingress[].ip” field. Clusters where the LoadBalancer controller sets the “status.loadBalancer.ingress[].ip” field are unaffected. | Unknown | N/A | Kubernetes | |
CVE-2021-25737 | A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or link-local range, but the same validation was not performed on EndpointSlice IPs. | Unknown | N/A | Kubernetes | |
CVE-2021-25738 | Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution. | Unknown | N/A | Kubernetes | |
CVE-2021-25740 | A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack. | Unknown | N/A | Kubernetes | |
CVE-2021-25741 | A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem. | Unknown | N/A | Kubernetes | |
CVE-2021-25742 | A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster. | Unknown | N/A | Kubernetes | |
CVE-2021-25743 | kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events. | Unknown | N/A | Kubernetes | |
CVE-2021-25745 | A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path field of an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster. | Unknown | N/A | Kubernetes | |
CVE-2021-25746 | A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster. | Unknown | N/A | Kubernetes | |
CVE-2021-25748 | A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the `spec.rules[].http.paths[].path` field of an Ingress object (in the `networking.k8s.io` or `extensions` API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster. | Unknown | N/A | Kubernetes | |
CVE-2021-25749 | Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true. | Unknown | N/A | Kubernetes | |
CVE-2021-25755 | In JetBrains Code With Me before 2020.3, an attacker on the local network, knowing a session ID, could get access to the encrypted traffic. | Unknown | N/A | n/a | |
CVE-2021-25756 | In JetBrains IntelliJ IDEA before 2020.2, HTTP links were used for several remote repositories instead of HTTPS. | Unknown | N/A | n/a | |
CVE-2021-25757 | In JetBrains Hub before 2020.1.12629, an open redirect was possible. | Unknown | N/A | n/a | |
CVE-2021-25758 | In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution. | Unknown | N/A | n/a | |
CVE-2021-25759 | In JetBrains Hub before 2020.1.12629, an authenticated user can delete 2FA settings of any other user. | Unknown | N/A | n/a | |
CVE-2021-25760 | In JetBrains Hub before 2020.1.12669, information disclosure via the public API was possible. | Unknown | N/A | n/a | |
CVE-2021-25761 | In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible. | Unknown | N/A | n/a | |
CVE-2021-25762 | In JetBrains Ktor before 1.4.3, HTTP Request Smuggling was possible. | Unknown | N/A | n/a | |
CVE-2021-25763 | In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default. | Unknown | N/A | n/a | |
CVE-2021-25764 | In JetBrains PhpStorm before 2020.3, source code could be added to debug logs. | Unknown | N/A | n/a | |
CVE-2021-25765 | In JetBrains YouTrack before 2020.4.4701, CSRF via attachment upload was possible. | Unknown | N/A | n/a | |
CVE-2021-25766 | In JetBrains YouTrack before 2020.4.4701, improper resource access checks were made. | Unknown | N/A | n/a | |
CVE-2021-25767 | In JetBrains YouTrack before 2020.6.1767, an issue's existence could be disclosed via YouTrack command execution. | Unknown | N/A | n/a | |
CVE-2021-25768 | In JetBrains YouTrack before 2020.4.4701, permissions for attachments actions were checked improperly. | Unknown | N/A | n/a | |
CVE-2021-25769 | In JetBrains YouTrack before 2020.4.6808, the YouTrack administrator wasn't able to access attachments. | Unknown | N/A | n/a | |
CVE-2021-25770 | In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code execution. | Unknown | N/A | n/a | |
CVE-2021-25771 | In JetBrains YouTrack before 2020.6.1099, project information could be potentially disclosed. | Unknown | N/A | n/a | |
CVE-2021-25772 | In JetBrains TeamCity before 2020.2.2, TeamCity server DoS was possible via server integration. | Unknown | N/A | n/a | |
CVE-2021-25773 | JetBrains TeamCity before 2020.2 was vulnerable to reflected XSS on several pages. | Unknown | N/A | n/a | |
CVE-2021-25774 | In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user. | Unknown | N/A | n/a | |
CVE-2021-25775 | In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users. | Unknown | N/A | n/a | |
CVE-2021-25776 | In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters. | Unknown | N/A | n/a | |
CVE-2021-25777 | In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly. | Unknown | N/A | n/a | |
CVE-2021-25778 | In JetBrains TeamCity before 2020.2.1, permissions during user deletion were checked improperly. | Unknown | N/A | n/a | |
CVE-2021-25779 | Baby Care System v1.0 is vulnerable to SQL injection via the 'id' parameter on the contentsectionpage.php page. | Unknown | N/A | n/a | |
CVE-2021-25780 | An arbitrary file upload vulnerability has been identified in posts.php in Baby Care System 1.0. The vulnerability could be exploited by an remote attacker to upload content to the server, including PHP files, which could result in command execution and obtaining a shell. | Unknown | N/A | n/a | |
CVE-2021-25783 | Taocms v2.5Beta5 was discovered to contain a blind SQL injection vulnerability via the function Article Search. | Unknown | N/A | n/a | |
CVE-2021-25784 | Taocms v2.5Beta5 was discovered to contain a blind SQL injection vulnerability via the function Edit Article. | Unknown | N/A | n/a | |
CVE-2021-25785 | Taocms v2.5Beta5 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Management column. | Unknown | N/A | n/a | |
CVE-2021-25786 | An issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file to Pl_ASCII85Decoder::write parameter in libqpdf. | Unknown | N/A | n/a | |
CVE-2021-25790 | Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in all text fields except for Phone Number and Alternate Phone Number. | Unknown | N/A | n/a | |
CVE-2021-25791 | Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in the First Name, Last Name, and Address text fields. | Unknown | N/A | n/a | |
CVE-2021-25801 | A buffer overflow vulnerability in the __Parse_indx component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file. | Unknown | N/A | n/a | |
CVE-2021-25802 | A buffer overflow vulnerability in the AVI_ExtractSubtitle component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file. | Unknown | N/A | n/a | |
CVE-2021-25803 | A buffer overflow vulnerability in the vlc_input_attachment_New component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file. | Unknown | N/A | n/a | |
CVE-2021-25804 | A NULL-pointer dereference in "Open" in avi.c of VideoLAN VLC Media Player 3.0.11 can a denial of service (DOS) in the application. | Unknown | N/A | n/a | |
CVE-2021-25808 | A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a crafted ZIP file. | Unknown | N/A | n/a | |
CVE-2021-25809 | UCMS 1.5.0 was discovered to contain a physical path leakage via an error message returned by the adminchannelscache() function in top.php. | Unknown | N/A | n/a | |
CVE-2021-25810 | Cross site Scripting (XSS) vulnerability in MERCUSYS Mercury X18G 1.0.5 devices, via crafted values to the 'src_dport_start', 'src_dport_end', and 'dest_port' parameters. | Unknown | N/A | n/a | |
CVE-2021-25811 | MERCUSYS Mercury X18G 1.0.5 devices allow Denial of service via a crafted value to the POST listen_http_lan parameter. Upon subsequent device restarts after this vulnerability is exploted the device will not be able to access the webserver unless the listen_http_lan parameter to uhttpd.json is manually fixed. | Unknown | N/A | n/a | |
CVE-2021-25812 | Command injection vulnerability in China Mobile An Lianbao WF-1 1.01 via the 'ip' parameter with a POST request to /api/ZRQos/set_online_client. | Unknown | N/A | n/a | |
CVE-2021-25827 | Emby Server < 4.7.12.0 is vulnerable to a login bypass attack by setting the X-Forwarded-For header to a local IP-address. | Unknown | N/A | n/a | |
CVE-2021-25828 | Emby Server versions < 4.6.0.50 is vulnerable to Cross Site Scripting (XSS) vulnerability via a crafted GET request to /web. | Unknown | N/A | n/a | |
CVE-2021-25829 | An improper binary stream data handling issue was found in the [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. Using this bug, an attacker is able to produce a denial of service attack that can eventually shut down the target server. | Unknown | N/A | n/a | |
CVE-2021-25830 | A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13. An attacker must request the conversion of the crafted file from DOCT into DOCX format. Using the chain of two other bugs related to improper string handling, an attacker can achieve remote code execution on DocumentServer. | Unknown | N/A | n/a | |
CVE-2021-25831 | A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. An attacker must request the conversion of the crafted file from PPTT into PPTX format. Using the chain of two other bugs related to improper string handling, a remote attacker can obtain remote code execution on DocumentServer. | Unknown | N/A | n/a | |
CVE-2021-25832 | A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v6.0.0. Using this vulnerability, an attacker is able to gain remote code executions on DocumentServer. | Unknown | N/A | n/a | |
CVE-2021-25833 | A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21. The file extension is controlled by an attacker through the request data and leads to arbitrary file overwriting. Using this vulnerability, a remote attacker can obtain remote code execution on DocumentServer. | Unknown | N/A | n/a | |
CVE-2021-25834 | Cosmos Network Ethermint <= v0.4.0 is affected by a transaction replay vulnerability in the EVM module. If the victim sends a very large nonce transaction, the attacker can replay the transaction through the application. | Unknown | N/A | n/a | |
CVE-2021-25835 | Cosmos Network Ethermint <= v0.4.0 is affected by a cross-chain transaction replay vulnerability in the EVM module. Since ethermint uses the same chainIDEpoch and signature schemes with ethereum for compatibility, a verified signature in ethereum is still valid in ethermint with the same msg content and chainIDEpoch, which enables "cross-chain transaction replay" attack. | Unknown | N/A | n/a | |
CVE-2021-25836 | Cosmos Network Ethermint <= v0.4.0 is affected by cache lifecycle inconsistency in the EVM module. The bytecode set in a FAILED transaction wrongfully remains in memory(stateObject.code) and is further written to persistent store at the Endblock stage, which may be utilized to build honeypot contracts. | Unknown | N/A | n/a | |
CVE-2021-25837 | Cosmos Network Ethermint <= v0.4.0 is affected by cache lifecycle inconsistency in the EVM module. Due to the inconsistency between the Storage caching cycle and the Tx processing cycle, Storage changes caused by a failed transaction are improperly reserved in memory. Although the bad storage cache data will be discarded at EndBlock, it is still valid in the current block, which enables many possible attacks such as an "arbitrary mint token". | Unknown | N/A | n/a | |
CVE-2021-25838 | The Import function in MintHCM RELEASE 3.0.8 allows an attacker to execute a cross-site scripting (XSS) payload in file-upload. | Unknown | N/A | n/a | |
CVE-2021-25839 | A weak password requirement vulnerability exists in the Create New User function of MintHCM RELEASE 3.0.8, which could lead an attacker to easier password brute-forcing. | Unknown | N/A | n/a | |
CVE-2021-25845 | Improper validation of the ChassisID TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows attackers to cause a denial of service due to a NULL pointer dereference via a crafted lldp packet. | Unknown | N/A | n/a | |
CVE-2021-25846 | Improper validation of the ChassisID TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows attackers to cause a denial of service due to a negative number passed to the memcpy function via a crafted lldp packet. | Unknown | N/A | n/a | |
CVE-2021-25847 | Improper validation of the length field of LLDP-MED TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows information disclosure to attackers due to controllable loop counter variable via a crafted lldp packet. | Unknown | N/A | n/a | |
CVE-2021-25848 | Improper validation of the length field of LLDP-MED TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows information disclosure to attackers due to using fixed loop counter variable without checking the actual available length via a crafted lldp packet. | Unknown | N/A | n/a | |
CVE-2021-25849 | An integer underflow was discovered in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, improper validation of the PortID TLV leads to Denial of Service via a crafted lldp packet. | Unknown | N/A | n/a | |
CVE-2021-25856 | An issue was discovered in pcmt superMicro-CMS version 3.11, allows attackers to delete files via crafted image file in images.php. | Unknown | N/A | n/a | |
CVE-2021-25857 | An issue was discovered in pcmt superMicro-CMS version 3.11, allows authenticated attackers to execute arbitrary code via the font_type parameter to setup.php. | Unknown | N/A | n/a | |
CVE-2021-25863 | Open5GS 2.1.3 listens on 0.0.0.0:3000 and has a default password of 1423 for the admin account. | Unknown | N/A | n/a | |
CVE-2021-25864 | node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in file hue-magic.js, to fetch an arbitrary file. | Unknown | N/A | n/a | |
CVE-2021-25874 | AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter which allows a remote unauthenticated attacker to retrieve databases information such as application passwords hashes. | Unknown | N/A | n/a | |
CVE-2021-25875 | AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the searchPhrase parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator. | Unknown | N/A | n/a | |
CVE-2021-25876 | AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the u parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator. | Unknown | N/A | n/a | |
CVE-2021-25877 | AVideo/YouPHPTube 10.0 and prior is affected by Insecure file write. An administrator privileged user is able to write files on filesystem using flag and code variables in file save.php. | Unknown | N/A | n/a | |
CVE-2021-25878 | AVideo/YouPHPTube 10.0 and prior is affected by multiple reflected Cross Script Scripting vulnerabilities via the videoName parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator. | Unknown | N/A | n/a | |
CVE-2021-25893 | Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the setText parameter of /magnoliaAuthor/.magnolia/. | Unknown | N/A | n/a | |
CVE-2021-25894 | Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the /magnoliaPublic/travel/members/login.html mgnlUserId parameter. | Unknown | N/A | n/a | |
CVE-2021-25898 | An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. Passwords are stored in unencrypted source-code text files. This was noted when accessing the svc-login.php file. The value is used to authenticate a high-privileged user upon authenticating with the server. | Unknown | N/A | n/a | |
CVE-2021-25899 | An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. An unauthenticated attacker can send a crafted HTTP request to perform a blind time-based SQL Injection. The vulnerable parameter is param1. | Unknown | N/A | n/a | |
CVE-2021-25900 | An issue was discovered in the smallvec crate before 0.6.14 and 1.x before 1.6.1 for Rust. There is a heap-based buffer overflow in SmallVec::insert_many. | Unknown | N/A | n/a | |
CVE-2021-25901 | An issue was discovered in the lazy-init crate through 2021-01-17 for Rust. Lazy lacks a Send bound, leading to a data race. | Unknown | N/A | n/a | |
CVE-2021-25902 | An issue was discovered in the glsl-layout crate before 0.4.0 for Rust. When a panic occurs, map_array can perform a double drop. | Unknown | N/A | n/a | |
CVE-2021-25903 | An issue was discovered in the cache crate through 2021-01-01 for Rust. A raw pointer is dereferenced. | Unknown | N/A | n/a | |
CVE-2021-25904 | An issue was discovered in the av-data crate before 0.3.0 for Rust. A raw pointer is dereferenced, leading to a read of an arbitrary memory address, sometimes causing a segfault. | Unknown | N/A | n/a | |
CVE-2021-25905 | An issue was discovered in the bra crate before 0.1.1 for Rust. It lacks soundness because it can read uninitialized memory. | Unknown | N/A | n/a | |
CVE-2021-25906 | An issue was discovered in the basic_dsp_matrix crate before 0.9.2 for Rust. When a TransformContent panic occurs, a double drop can be performed. | Unknown | N/A | n/a | |
CVE-2021-25907 | An issue was discovered in the containers crate before 0.9.11 for Rust. When a panic occurs, a util::{mutate,mutate2} double drop can be performed. | Unknown | N/A | n/a | |
CVE-2021-25908 | An issue was discovered in the fil-ocl crate through 2021-01-04 for Rust. From |
Unknown | N/A | n/a |
vunerability-insight.com © 2023 - 2025. All Rights Reserved.
Vulnerability Data Repositories v