Common Vulnerabilities and Exposures (CVE) is a critical tool for maintaining software security, providing a standardized way to track and manage vulnerabilities across systems. Organizations should regularly monitor CVE databases, assess the impact of vulnerabilities, and apply patches promptly to reduce the risk of exploitation.
CVE (Common Vulnerabilities and Exposures) is a public database that provides a standardized method for identifying, tracking, and referencing publicly disclosed security vulnerabilities in software and hardware.
Each vulnerability receives a unique identifier called a CVE ID (e.g., CVE-2023-12345), making it easier to reference specific vulnerabilities across different tools and databases.
Total Search Results: 158437
CVE ID | Description | Severity | Published Date | Affected Vendor | Action |
---|---|---|---|---|---|
CVE-2021-26418 | Microsoft SharePoint Server Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-26419 | Scripting Engine Memory Corruption Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-26420 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-26421 | Skype for Business and Lync Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-26422 | Skype for Business and Lync Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-26423 | .NET Core and Visual Studio Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-26424 | Windows TCP/IP Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-26425 | Windows Event Tracing Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-26426 | Windows User Account Profile Picture Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-26427 | Microsoft Exchange Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-26428 | Azure Sphere Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-26429 | Azure Sphere Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-26430 | Azure Sphere Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-26431 | Windows Recovery Environment Agent Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-26432 | Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-26433 | Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-26434 | Visual Studio Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-26435 | Windows Scripting Engine Memory Corruption Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-26436 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-26437 | Visual Studio Code Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-26439 | Microsoft Edge for Android Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-26441 | Storage Spaces Controller Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-26442 | Windows HTTP.sys Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-26443 | Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-26444 | Azure RTOS Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-26461 | Apache Nuttx Versions prior to 10.1.0 are vulnerable to integer wrap-around in functions malloc, realloc and memalign. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution. | Unknown | N/A | Apache Software Foundation | |
CVE-2021-26471 | In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1, the http API located at /sgwebservice_o.php accepts a command argument. Using this command argument an unauthenticated attacker can execute arbitrary shell commands. | Unknown | N/A | n/a | |
CVE-2021-26472 | In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 installed on Windows, the http API located at /consumerweb/secure/download.php. Using this command argument an unauthenticated attacker can execute arbitrary OS commands with SYSTEM privileges. | Unknown | N/A | n/a | |
CVE-2021-26473 | In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 the http API located at /sgwebservice_o.php action logFilePath allows an attacker to write arbitrary files in the context of the web server process. These files can then be executed remotely by calling the file via the web server. | Unknown | N/A | n/a | |
CVE-2021-26474 | Various Vembu products allow an attacker to execute a (non-blind) http-only Cross Site Request Forgery (Other products or versions of products in this family may be affected too.) | Unknown | N/A | n/a | |
CVE-2021-26475 | EPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI. | Unknown | N/A | n/a | |
CVE-2021-26476 | EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI. | Unknown | N/A | n/a | |
CVE-2021-26504 | Directory Traversal vulnerability in Foddy node-red-contrib-huemagic version 3.0.0, allows remote attackers to gain sensitive information via crafted request in res.sendFile API in hue-magic.js. | Unknown | N/A | n/a | |
CVE-2021-26505 | Prototype pollution vulnerability in MrSwitch hello.js version 1.18.6, allows remote attackers to execute arbitrary code via hello.utils.extend function. | Unknown | N/A | n/a | |
CVE-2021-26528 | The mg_http_serve_file function in Cesanta Mongoose HTTP server 7.0 is vulnerable to remote OOB write attack via connection request after exhausting memory pool. | Unknown | N/A | n/a | |
CVE-2021-26529 | The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 and 6.7-6.18 (compiled with mbedTLS support) is vulnerable to remote OOB write attack via connection request after exhausting memory pool. | Unknown | N/A | n/a | |
CVE-2021-26530 | The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 (compiled with OpenSSL support) is vulnerable to remote OOB write attack via connection request after exhausting memory pool. | Unknown | N/A | n/a | |
CVE-2021-26539 | Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypass hostname whitelist validation set by the "allowedIframeHostnames" option. | Unknown | N/A | n/a | |
CVE-2021-26540 | Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with "/\\example.com". | Unknown | N/A | n/a | |
CVE-2021-26541 | The gitlog function in src/index.ts in gitlog before 4.0.4 has a command injection vulnerability. | Unknown | N/A | n/a | |
CVE-2021-26543 | The "gitDiff" function in Wayfair git-parse <=1.0.4 has a command injection vulnerability. Clients of the git-parse library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability. The issue has been resolved in version 1.0.5. | Unknown | N/A | n/a | |
CVE-2021-26544 | Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicious user could use this flaw to access logs and results of other users' sessions and run jobs with their privileges. This issue is fixed in Livy 0.7.1-incubating. | Unknown | N/A | Apache Software Foundation | |
CVE-2021-26549 | An XSS issue was discovered in SmartFoxServer 2.17.0. Input passed to the AdminTool console is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML code in a user's browser session in context of an affected site. | Unknown | N/A | n/a | |
CVE-2021-26550 | An issue was discovered in SmartFoxServer 2.17.0. Cleartext password disclosure can occur via /config/server.xml. | Unknown | N/A | n/a | |
CVE-2021-26551 | An issue was discovered in SmartFoxServer 2.17.0. An attacker can execute arbitrary Python code, and bypass the javashell.py protection mechanism, by creating /config/ConsoleModuleUnlock.txt and editing /config/admin/admintool.xml to enable the Console module. | Unknown | N/A | n/a | |
CVE-2021-26556 | When Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileged access. | Unknown | N/A | Octopus Deploy | |
CVE-2021-26557 | When Octopus Tentacle is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileged access. | Unknown | N/A | Octopus Deploy | |
CVE-2021-26558 | Deserialization of Untrusted Data vulnerability of Apache ShardingSphere-UI allows an attacker to inject outer link resources. This issue affects Apache ShardingSphere-UI Apache ShardingSphere-UI version 4.1.1 and later versions; Apache ShardingSphere-UI versions prior to 5.0.0. | Unknown | N/A | Apache Software Foundation | |
CVE-2021-26559 | Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configurations including sensitive information even when `[webserver] expose_config` is set to `False` in `airflow.cfg`. This allowed a privilege escalation attack. This issue affects Apache Airflow 2.0.0. | Unknown | N/A | Apache Software Foundation | |
CVE-2021-26560 | Cleartext transmission of sensitive information vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to spoof servers via an HTTP session. | Unknown | N/A | Synology | |
CVE-2021-26561 | Stack-based buffer overflow vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary code via syno_finder_site HTTP header. | Unknown | N/A | Synology | |
CVE-2021-26562 | Out-of-bounds write vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary code via syno_finder_site HTTP header. | Unknown | N/A | Synology | |
CVE-2021-26563 | Incorrect authorization vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows local users to execute arbitrary code via unspecified vectors. | Unknown | N/A | Synology | |
CVE-2021-26564 | Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to spoof servers via an HTTP session. | Unknown | N/A | Synology | |
CVE-2021-26565 | Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to obtain sensitive information via an HTTP session. | Unknown | N/A | Synology | |
CVE-2021-26566 | Insertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary commands via inbound QuickConnect traffic. | Unknown | N/A | Synology | |
CVE-2021-26567 | Stack-based buffer overflow vulnerability in frontend/main.c in faad2 before 2.2.7.1 allow local attackers to execute arbitrary code via filename and pathname options. | Unknown | N/A | github/knik0 | |
CVE-2021-26569 | Race Condition within a Thread vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via crafted web requests. | Unknown | N/A | Synology | |
CVE-2021-26570 | The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webifc_setadconfig function. | Unknown | N/A | n/a | |
CVE-2021-26571 | The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgetactivexcfg function. | Unknown | N/A | n/a | |
CVE-2021-26572 | The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgetactivexcfg function. | Unknown | N/A | n/a | |
CVE-2021-26573 | The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgeneratesslcfg function. | Unknown | N/A | n/a | |
CVE-2021-26574 | The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a path traversal vulnerability in libifc.so webdeletevideofile function. | Unknown | N/A | n/a | |
CVE-2021-26575 | The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a path traversal vulnerability in libifc.so webdeletesolvideofile function. | Unknown | N/A | n/a | |
CVE-2021-26576 | The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so uploadsshkey function. | Unknown | N/A | n/a | |
CVE-2021-26577 | The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so uploadsshkey function. | Unknown | N/A | n/a | |
CVE-2021-26578 | A potential security vulnerability has been identified in HPE Network Orchestrator (NetO) version(s): Prior to 2.5. The vulnerability could be remotely exploited with SQL injection. | Unknown | N/A | n/a | |
CVE-2021-26579 | A security vulnerability in HPE Unified Data Management (UDM) could allow the local disclosure of privileged information (CWE-321: Use of Hard-coded Cryptographic Key in a product). HPE has provided updates to versions 1.2009.0 and 1.2101.0 of HPE Unified Data Management (UDM). Version 1.2103.0 of HPE Unified Data Management (UDM) removes all hard-coded cryptographic keys. | Unknown | N/A | n/a | |
CVE-2021-26580 | A potential security vulnerability has been identified in HPE iLO Amplifier Pack. The vulnerability could be remotely exploited to allow Cross-Site Scripting (XSS). HPE has provided the following software update to resolve the vulnerability in HPE iLO Amplifier Pack: HPE iLO Amplifier Pack 1.95 or later. | Unknown | N/A | n/a | |
CVE-2021-26581 | A potential security vulnerability has been identified in HPE Superdome Flex server. A denial of service attack can be remotely exploited leaving hung connections to the BMC web interface. The monarch BMC must be rebooted to recover from this situation. Other BMC management is not impacted. HPE has made the following software update to resolve the vulnerability in HPE Superdome Flex Server: Superdome Flex Server Firmware 3.30.142 or later. | Unknown | N/A | n/a | |
CVE-2021-26582 | A security vulnerability in HPE IceWall SSO Domain Gateway Option (Dgfw) module version 10.0 on RHEL 5/6/7, version 10.0 on HP-UX 11i v3, version 10.0 on Windows and 11.0 on Windows could be exploited remotely to allow cross-site scripting (XSS). | Unknown | N/A | n/a | |
CVE-2021-26583 | A potential security vulnerability was identified in HPE iLO Amplifier Pack. The vulnerabilities could be remotely exploited to allow remote code execution. | Unknown | N/A | n/a | |
CVE-2021-26584 | A security vulnerability in HPE OneView for VMware vCenter (OV4VC) could be exploited remotely to allow Cross-Site Scripting. HPE has released the following software update to resolve the vulnerability in HPE OneView for VMware vCenter (OV4VC). | Unknown | N/A | n/a | |
CVE-2021-26585 | A potential vulnerability has been identified in HPE OneView Global Dashboard release 2.31 which could lead to a local disclosure of privileged information. HPE has provided an update to OneView Global Dashboard. The issue is resolved in 2.32. | Unknown | N/A | n/a | |
CVE-2021-26586 | A potential security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software. The vulnerability could be remotely exploited to disclose sensitive information. HPE has made software updates available to resolve the vulnerability in the HPE Edgeline Infrastructure Manager (EIM). | Unknown | N/A | n/a | |
CVE-2021-26587 | A potential DOM-based Cross Site Scripting security vulnerability has been identified in HPE StoreOnce. The vulnerability could be remotely exploited to cause an elevation of privilege leading to partial impact to confidentiality, availability, and integrity. HPE has made the following software update - HPE StoreOnce 4.3.0, to resolve the vulnerability in HPE StoreOnce. | Unknown | N/A | n/a | |
CVE-2021-26588 | A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low complexity issue to execute code as administrator. This vulnerability impacts completely the confidentiality, integrity, availability of the array. HPE has made the following software updates and mitigation information to resolve the vulnerability in 3PAR, Primera and Alletra 9000 firmware. | Unknown | N/A | n/a | |
CVE-2021-26589 | A potential security vulnerability has been identified in HPE Superdome Flex Servers. The vulnerability could be remotely exploited to allow Cross Site Scripting (XSS) because the Session Cookie is missing an HttpOnly Attribute. HPE has provided a firmware update to resolve the vulnerability in HPE Superdome Flex Servers. | Unknown | N/A | n/a | |
CVE-2021-26593 | In Directus 8.x through 8.8.1, an attacker can see all users in the CMS using the API /users/{id}. For each call, they get in response a lot of information about the user (such as email address, first name, and last name) but also the secret for 2FA if one exists. This secret can be regenerated. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | Unknown | N/A | n/a | |
CVE-2021-26594 | In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any control by the back end. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | Unknown | N/A | n/a | |
CVE-2021-26595 | In Directus 8.x through 8.8.1, an attacker can learn sensitive information such as the version of the CMS, the PHP version used by the site, and the name of the DBMS, simply by view the result of the api-aa, called automatically upon a connection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | Unknown | N/A | n/a | |
CVE-2021-26596 | An issue was discovered in Nokia NetAct 18A. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims. Here, the /netact/sct filename parameter is used. | Unknown | N/A | n/a | |
CVE-2021-26597 | An issue was discovered in Nokia NetAct 18A. A remote user, authenticated to the NOKIA NetAct Web Page, can visit the Site Configuration Tool web site section and arbitrarily upload potentially dangerous files without restrictions via the /netact/sct dir parameter in conjunction with the operation=upload value. | Unknown | N/A | n/a | |
CVE-2021-26598 | ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, able to have a security token). | Unknown | N/A | n/a | |
CVE-2021-26599 | ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection. | Unknown | N/A | n/a | |
CVE-2021-26600 | ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==). | Unknown | N/A | n/a | |
CVE-2021-26601 | ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal. | Unknown | N/A | n/a | |
CVE-2021-26603 | A heap overflow issue was found in ARK library of bandisoft Co., Ltd when the Ark_DigPathA function parsed a file path. This vulnerability is due to missing support for string length check. | Unknown | N/A | bandisoft | |
CVE-2021-26605 | An improper input validation vulnerability in the service of ezPDFReader allows attacker to execute arbitrary command. This issue occurred when the ezPDF launcher received and executed crafted input values through JSON-RPC communication. | Unknown | N/A | unidocs | |
CVE-2021-26606 | A vulnerability in PKI Security Solution of Dream Security could allow arbitrary command execution. This vulnerability is due to insufficient validation of the authorization certificate. An attacker could exploit this vulnerability by sending a crafted HTTP request an affected program. A successful exploit could allow the attacker to remotely execute arbitrary code on a target system. | Unknown | N/A | Dream Security Co.,Ltd | |
CVE-2021-26607 | An Improper input validation in execDefaultBrowser method of NEXACRO17 allows a remote attacker to execute arbitrary command on affected systems. | Unknown | N/A | TOBESOFT | |
CVE-2021-26608 | An arbitrary file download and execution vulnerability was found in the HShell.dll of handysoft Co., Ltd groupware ActiveX module. This issue is due to missing support for integrity check of download URL or downloaded file hash. | Unknown | N/A | handysoft | |
CVE-2021-26609 | A vulnerability was found in Mangboard(WordPress plugin). A SQL-Injection vulnerability was found in order_type parameter. The order_type parameter makes a SQL query using unfiltered data. This vulnerability allows a remote attacker to steal user information. | Unknown | N/A | Mangboard | |
CVE-2021-26610 | The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary code. | Unknown | N/A | NHN COMMERCE | |
CVE-2021-26611 | HejHome GKW-IC052 IP Camera contained a hard-coded credentials vulnerability. This issue allows remote attackers to operate the IP Camera.(reboot, factory reset, snapshot etc..) | Unknown | N/A | Goqual | |
CVE-2021-26612 | An improper input validation leading to arbitrary file creation was discovered in copy method of Nexacro platform. Remote attackers use copy method to execute arbitrary command after the file creation included malicious code. | Unknown | N/A | TOBESOFT | |
CVE-2021-26613 | improper input validation vulnerability in nexacro permits copying file to the startup folder using rename method. | Unknown | N/A | tobesoft co., ltd | |
CVE-2021-26614 | ius_get.cgi in IpTime C200 camera allows remote code execution. A remote attacker may send a crafted parameters to the exposed vulnerable web service interface which invokes the arbitrary shell command. | Unknown | N/A | EFM networks & multimedia | |
CVE-2021-26615 | ARK library allows attackers to execute remote code via the parameter(path value) of Ark_NormalizeAndDupPAthNameW function because of an integer overflow. | Unknown | N/A | bandisoft | |
CVE-2021-26616 | An OS command injection was found in SecuwaySSL, when special characters injection on execute command with runCommand arguments. | Unknown | N/A | secuwiz co., ltd |
vunerability-insight.com © 2023 - 2025. All Rights Reserved.
Vulnerability Data Repositories v