Common Vulnerabilities and Exposures (CVE) is a critical tool for maintaining software security, providing a standardized way to track and manage vulnerabilities across systems. Organizations should regularly monitor CVE databases, assess the impact of vulnerabilities, and apply patches promptly to reduce the risk of exploitation.
CVE (Common Vulnerabilities and Exposures) is a public database that provides a standardized method for identifying, tracking, and referencing publicly disclosed security vulnerabilities in software and hardware.
Each vulnerability receives a unique identifier called a CVE ID (e.g., CVE-2023-12345), making it easier to reference specific vulnerabilities across different tools and databases.
Total Search Results: 158437
CVE ID | Description | Severity | Published Date | Affected Vendor | Action |
---|---|---|---|---|---|
CVE-2021-36905 | Multiple Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Quiz And Survey Master plugin <= 7.3.4 on WordPress. | Unknown | N/A | ExpressTech | |
CVE-2021-36906 | Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 on WordPress. | Unknown | N/A | ExpressTech | |
CVE-2021-36908 | Cross-Site Request Forgery (CSRF) vulnerability in WebFactory Ltd. WP Reset PRO plugin <=Â 5.98 versions. | Unknown | N/A | WebFactory Ltd. | |
CVE-2021-36909 | Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authenticated user to wipe the entire database regardless of their authorization. It leads to a complete website reset and takeover. | Unknown | N/A | WebFactory Ltd. | |
CVE-2021-36910 | Authenticated (admin user role) Stored Cross-Site Scripting (XSS) in WP-Appbox (WordPress plugin) <= 4.3.20. | Unknown | N/A | Marcel Schmilgeit | |
CVE-2021-36911 | Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Comment Engine Pro plugin (versions <= 1.0), could be exploited by users with Editor or higher role. | Unknown | N/A | @rex1989 | |
CVE-2021-36912 | Stored Cross-Site Scripting (XSS) vulnerability in Andrea Pernici News Sitemap for Google plugin <= 1.0.16 on WordPress, attackers must have contributor or higher user role. | Unknown | N/A | Andrea Pernici | |
CVE-2021-36913 | Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <= 2.4.0 at WordPress allows attackers to change options and inject scripts into the footer HTML. Requires an additional extension (plugin) AccessiBe. | Unknown | N/A | Qube One | |
CVE-2021-36914 | Cross-Site Request Forgery (CSRF) vulnerability leading to Reflected Cross-Site Scripting (XSS) in CalderaWP License Manager (WordPress plugin) <= 1.2.11. | Unknown | N/A | Desertsnowman, Shelob9 | |
CVE-2021-36915 | Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder plugin <= 3.6.0 at WordPress allows uploading the JSON file and updating the options. Requires Import and Export add-on. | Unknown | N/A | Cozmoslabs | |
CVE-2021-36916 | The SQL injection vulnerability in the Hide My WP WordPress plugin (versions <= 6.2.3) is possible because of how the IP address is retrieved and used inside a SQL query. The function "hmwp_get_user_ip" tries to retrieve the IP address from multiple headers, including IP address headers that the user can spoof, such as "X-Forwarded-For." As a result, the malicious payload supplied in one of these IP address headers will be directly inserted into the SQL query, making SQL injection possible. | Unknown | N/A | wpWave | |
CVE-2021-36917 | WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can then be used to deactivate the plugin. | Unknown | N/A | wpWave | |
CVE-2021-36919 | Multiple Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilities in WordPress Awesome Support plugin (versions <= 6.0.6), vulnerable parameters (&id, &assignee). | Unknown | N/A | Awesome Support | |
CVE-2021-3692 | yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator | Unknown | N/A | yiisoft | |
CVE-2021-36920 | Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress plugin Download Monitor (versions <= 4.4.6). | Unknown | N/A | WPChill | |
CVE-2021-36921 | AIMANAGER before B115 on MONITORAPP Application Insight Web Application Firewall (AIWAF) devices with Manager 2.1.0 has Improper Authentication. An attacker can gain administrative access by modifying the response to an authentication check request. | Unknown | N/A | n/a | |
CVE-2021-36922 | RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve unauthorized access to USB devices (Escalation of Privileges, Denial of Service, Code Execution, and Information Disclosure) via a crafted Device IO Control packet to a device. | Unknown | N/A | n/a | |
CVE-2021-36923 | RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve unauthorized access to USB device privileged IN and OUT instructions (leading to Escalation of Privileges, Denial of Service, Code Execution, and Information Disclosure) via a crafted Device IO Control packet to a device. | Unknown | N/A | n/a | |
CVE-2021-36924 | RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve a pool overflow (leading to Escalation of Privileges, Denial of Service, and Code Execution) via a crafted Device IO Control packet to a device. | Unknown | N/A | n/a | |
CVE-2021-36925 | RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve an arbitrary read or write operation from/to physical memory (leading to Escalation of Privileges, Denial of Service, Code Execution, and Information Disclosure) via a crafted Device IO Control packet to a device. | Unknown | N/A | n/a | |
CVE-2021-36926 | Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36927 | Windows Digital TV Tuner device registration application Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36928 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36929 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-3693 | LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure. | Unknown | N/A | ledgersmb | |
CVE-2021-36930 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36931 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36932 | Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36933 | Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36934 | An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker must have the ability to execute code on a victim system to exploit this vulnerability. After installing this security update, you must manually delete all shadow copies of system files, including the SAM database, to fully mitigate this vulnerabilty. Simply installing this security update will not fully mitigate this vulnerability. See KB5005357- Delete Volume Shadow Copies. |
Unknown | N/A | Microsoft | |
CVE-2021-36936 | Windows Print Spooler Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36937 | Windows Media MPEG-4 Video Decoder Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36938 | Windows Cryptographic Primitives Library Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-3694 | LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure. | Unknown | N/A | ledgersmb | |
CVE-2021-36940 | Microsoft SharePoint Server Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36941 | Microsoft Word Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36942 | Windows LSA Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36943 | Azure CycleCloud Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36945 | Windows 10 Update Assistant Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36946 | Microsoft Dynamics Business Central Cross-site Scripting Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36947 | Windows Print Spooler Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36948 | Windows Update Medic Service Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36949 | Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-3695 | A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform some triage over the heap layout to achieve signifcant results, also the values written into the memory are repeated three times in a row making difficult to produce valid payloads. This flaw affects grub2 versions prior grub-2.12. | Unknown | N/A | n/a | |
CVE-2021-36950 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36952 | Visual Studio Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36953 | Windows TCP/IP Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36954 | Windows Bind Filter Driver Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36955 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36956 | Azure Sphere Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36957 | Windows Desktop Bridge Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36958 | A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. |
Unknown | N/A | Microsoft | |
CVE-2021-36959 | Windows Authenticode Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-3696 | A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an attacker control the encoding and positioning of corrupted Huffman entries to achieve results such as arbitrary code execution and/or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12. | Unknown | N/A | n/a | |
CVE-2021-36960 | Windows SMB Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36961 | Windows Installer Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36962 | Windows Installer Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36963 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36964 | Windows Event Tracing Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36965 | Windows WLAN AutoConfig Service Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36966 | Windows Subsystem for Linux Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36967 | Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36968 | Windows DNS Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36969 | Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-3697 | A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data corruption and eventual code execution or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12. | Unknown | N/A | n/a | |
CVE-2021-36970 | Windows Print Spooler Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36972 | Windows SMB Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36973 | Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36974 | Windows SMB Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36975 | Win32k Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-36976 | libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block). | Unknown | N/A | n/a | |
CVE-2021-36977 | matio (aka MAT File I/O Library) 1.5.20 and 1.5.21 has a heap-based buffer overflow in H5MM_memcpy (called from H5MM_malloc and H5C_load_entry), related to use of HDF5 1.12.0. | Unknown | N/A | n/a | |
CVE-2021-36978 | QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow in Pl_ASCII85Decoder::write (called from Pl_AES_PDF::flush and Pl_AES_PDF::finish) when a certain downstream write fails. | Unknown | N/A | n/a | |
CVE-2021-36979 | Unicorn Engine 1.0.2 has an out-of-bounds write in tb_flush_armeb (called from cpu_arm_exec_armeb and tcg_cpu_exec_armeb). | Unknown | N/A | n/a | |
CVE-2021-3698 | A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality. | Unknown | N/A | n/a | |
CVE-2021-36980 | Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_decode) during the decoding of a RAW_ENCAP action. | Unknown | N/A | n/a | |
CVE-2021-36981 | In the server in SerNet verinice before 1.22.2, insecure Java deserialization allows remote authenticated attackers to execute arbitrary code. | Unknown | N/A | n/a | |
CVE-2021-36982 | AIMANAGER before B115 on MONITORAPP Application Insight Web Application Firewall (AIWAF) devices with Manager 2.1.0 allows OS Command Injection because of missing input validation on one of the parameters of an HTTP request. | Unknown | N/A | n/a | |
CVE-2021-36983 | replay-sorcery-kms in Replay Sorcery 0.6.0 allows a local attacker to gain root privileges via a symlink attack on /tmp/replay-sorcery or /tmp/replay-sorcery/device.sock. | Unknown | N/A | n/a | |
CVE-2021-36985 | There is a Code injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may exhaust system resources and cause the system to restart. | Unknown | N/A | Huawei | |
CVE-2021-36986 | There is a vulnerability of tampering with the kernel in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions. | Unknown | N/A | Huawei | |
CVE-2021-36987 | There is a issue that nodes in the linked list being freed for multiple times in Huawei Smartphone due to race conditions. Successful exploitation of this vulnerability can cause the system to restart. | Unknown | N/A | Huawei | |
CVE-2021-36988 | There is a Parameter verification issue in Huawei Smartphone.Successful exploitation of this vulnerability can affect service integrity. | Unknown | N/A | Huawei | |
CVE-2021-36989 | There is a Kernel crash vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions. | Unknown | N/A | Huawei | |
CVE-2021-36990 | There is a vulnerability of tampering with the kernel in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions. | Unknown | N/A | Huawei | |
CVE-2021-36991 | There is an Unauthorized file access vulnerability in Huawei Smartphone due to unstandardized path input.Successful exploitation of this vulnerability by creating malicious file paths can cause unauthorized file access. | Unknown | N/A | Huawei | |
CVE-2021-36992 | There is a Public key verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality. | Unknown | N/A | Huawei | |
CVE-2021-36993 | There is a Memory leaks vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability. | Unknown | N/A | Huawei | |
CVE-2021-36994 | There is a issue that trustlist strings being repeatedly inserted into the linked list in Huawei Smartphone due to race conditions. Successful exploitation of this vulnerability can cause exceptions when managing the system trustlist. | Unknown | N/A | Huawei | |
CVE-2021-36995 | There is an Unauthorized file access vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability by modifying soft links may tamper with the files restored from backups. | Unknown | N/A | Huawei | |
CVE-2021-36996 | There is an Improper verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause transmission of certain virtual information. | Unknown | N/A | Huawei | |
CVE-2021-36997 | There is a Low memory error in Huawei Smartphone due to the unlimited size of images to be parsed.Successful exploitation of this vulnerability may cause the Gallery or Files app to exit unexpectedly. | Unknown | N/A | Huawei | |
CVE-2021-36998 | There is an Improper verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may allow attempts to read an array that is out of bounds. | Unknown | N/A | Huawei | |
CVE-2021-36999 | There is a Buffer overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability by sending malicious images and inducing users to open the images may cause remote code execution. | Unknown | N/A | Huawei | |
CVE-2021-3700 | A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c. This issue occurs when serializing large amounts of buffered write data in the case of a slow or blocked destination. | Unknown | N/A | n/a | |
CVE-2021-37001 | There is a Register tampering vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may allow the register value to be modified. | Unknown | N/A | Huawei | |
CVE-2021-37002 | There is a Memory out-of-bounds access vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause malicious code to be executed. | Unknown | N/A | Huawei | |
CVE-2021-37003 | There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash. | Unknown | N/A | Huawei | |
CVE-2021-37004 | There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash. | Unknown | N/A | Huawei | |
CVE-2021-37005 | There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash. | Unknown | N/A | Huawei |
vunerability-insight.com © 2023 - 2025. All Rights Reserved.
Vulnerability Data Repositories v