Common Vulnerabilities and Exposures (CVE) is a critical tool for maintaining software security, providing a standardized way to track and manage vulnerabilities across systems. Organizations should regularly monitor CVE databases, assess the impact of vulnerabilities, and apply patches promptly to reduce the risk of exploitation.
CVE (Common Vulnerabilities and Exposures) is a public database that provides a standardized method for identifying, tracking, and referencing publicly disclosed security vulnerabilities in software and hardware.
Each vulnerability receives a unique identifier called a CVE ID (e.g., CVE-2023-12345), making it easier to reference specific vulnerabilities across different tools and databases.
Total Search Results: 158437
CVE ID | Description | Severity | Published Date | Affected Vendor | Action |
---|---|---|---|---|---|
CVE-2021-4218 | A flaw was found in the Linux kernel’s implementation of reading the SVC RDMA counters. Reading the counter sysctl panics the system. This flaw allows a local attacker with local access to cause a denial of service while the system reboots. The issue is specific to CentOS/RHEL. | Unknown | N/A | n/a | |
CVE-2021-42183 | MasaCMS 7.2.1 is affected by a path traversal vulnerability in /index.cfm/_api/asset/image/. | Unknown | N/A | n/a | |
CVE-2021-42185 | wdja v2.1 is affected by a SQL injection vulnerability in the foreground search function. | Unknown | N/A | n/a | |
CVE-2021-4219 | A flaw was found in ImageMagick. The vulnerability occurs due to improper use of open functions and leads to a denial of service. This flaw allows an attacker to crash the system. | Unknown | N/A | n/a | |
CVE-2021-42192 | Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation. | Unknown | N/A | n/a | |
CVE-2021-42194 | The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's input directly into the simplexml_ load_ String function, which itself does not prohibit external entities, triggering a XML external entity (XXE) injection vulnerability. | Unknown | N/A | n/a | |
CVE-2021-42195 | An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function handleEditText() located in swfdump.c. It allows an attacker to cause code Execution. | Unknown | N/A | n/a | |
CVE-2021-42196 | An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function traits_parse() located in abc.c. It allows an attacker to cause Denial of Service. | Unknown | N/A | n/a | |
CVE-2021-42197 | An issue was discovered in swftools through 20201222 through a memory leak in the swftools when swfdump is used. It allows an attacker to cause code execution. | Unknown | N/A | n/a | |
CVE-2021-42198 | An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function swf_GetBits() located in rfxswf.c. It allows an attacker to cause Denial of Service. | Unknown | N/A | n/a | |
CVE-2021-42199 | An issue was discovered in swftools through 20201222. A heap buffer overflow exists in the function swf_FontExtract_DefineTextCallback() located in swftext.c. It allows an attacker to cause code execution. | Unknown | N/A | n/a | |
CVE-2021-42200 | An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function main() located in swfdump.c. It allows an attacker to cause Denial of Service. | Unknown | N/A | n/a | |
CVE-2021-42201 | An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function swf_GetD64() located in rfxswf.c. It allows an attacker to cause code execution. | Unknown | N/A | n/a | |
CVE-2021-42202 | An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function swf_DeleteFilter() located in swffilter.c. It allows an attacker to cause Denial of Service. | Unknown | N/A | n/a | |
CVE-2021-42203 | An issue was discovered in swftools through 20201222. A heap-use-after-free exists in the function swf_FontExtract_DefineTextCallback() located in swftext.c. It allows an attacker to cause code execution. | Unknown | N/A | n/a | |
CVE-2021-42204 | An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function swf_GetBits() located in rfxswf.c. It allows an attacker to cause code execution. | Unknown | N/A | n/a | |
CVE-2021-42205 | ELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple manufacturers, allows local users to cause a system crash by sending a certain IOCTL request, because that request is handled twice. | Unknown | N/A | n/a | |
CVE-2021-4221 | If a domain name contained a RTL character, it would cause the domain to be rendered to the right of the path. This could lead to user confusion and spoofing attacks. *This bug only affects Firefox for Android. Other operating systems are unaffected.* *Note*: Due to a clerical error this advisory was not included in the original announcement, and was added in Feburary 2022. This vulnerability affects Firefox < 92. |
Unknown | N/A | Mozilla | |
CVE-2021-42216 | A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php. | Unknown | N/A | n/a | |
CVE-2021-42218 | OMPL v1.5.2 contains a memory leak in VFRRT.cpp | Unknown | N/A | n/a | |
CVE-2021-42219 | Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sending an excessive amount of messages to a node. This is caused by missing memory in the component /ethash/algorithm.go. | Unknown | N/A | n/a | |
CVE-2021-4222 | The WP-Paginate WordPress plugin before 2.1.4 does not sanitise and escape its preset settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed | Unknown | N/A | Unknown | |
CVE-2021-42220 | A Cross Site Scripting (XSS) vulnerability exists in Dolibarr before 14.0.3 via the ticket creation flow. Exploitation requires that an admin copies the payload into a box. | Unknown | N/A | n/a | |
CVE-2021-42223 | Cross Site Scripting (XSS).vulnerability exists in Online DJ Booking Management System 1.0 in view-booking-detail.php. | Unknown | N/A | n/a | |
CVE-2021-42224 | SQL Injection vulnerability exists in IFSC Code Finder Project 1.0 via the searchifsccode POST parameter in /search.php. | Unknown | N/A | n/a | |
CVE-2021-42227 | Cross SIte Scripting (XSS) vulnerability exists in KindEditor 4.1.x via a Google search inurl:/examples/uploadbutton.html and then the .html file on the website that uses this editor (the file suffix is allowed). | Unknown | N/A | n/a | |
CVE-2021-42228 | A Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x, as demonstrated by examples/uploadbutton.html. | Unknown | N/A | n/a | |
CVE-2021-42230 | Seowon 130-SLC router all versions as of 2021-09-15 is vulnerable to Remote Code Execution via the queriesCnt parameter. | Unknown | N/A | n/a | |
CVE-2021-42232 | TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnerability is caused by the program taking part of the received data packet as part of the command. This will cause an attacker to execute arbitrary commands on the router. | Unknown | N/A | n/a | |
CVE-2021-42233 | The Simple Blog plugin in Wondercms 3.4.1 is vulnerable to stored cross-site scripting (XSS) vulnerability. When any user opens a particular blog hosted on an attackers' site, XSS may occur. | Unknown | N/A | n/a | |
CVE-2021-42235 | SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality. | Unknown | N/A | n/a | |
CVE-2021-42237 | Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability. | Unknown | N/A | n/a | |
CVE-2021-42242 | A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor. | Unknown | N/A | n/a | |
CVE-2021-42244 | A cross-site scripting (XSS) vulnerability in PaquitoSoftware Notimoo v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted title or message in a notification. | Unknown | N/A | n/a | |
CVE-2021-42245 | FlatCore-CMS 2.0.9 has a cross-site scripting (XSS) vulnerability in pages.edit.php through meta tags and content sections. | Unknown | N/A | n/a | |
CVE-2021-4225 | The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attempts to prevent PHP and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that on Windows servers, the security checks in place were insufficient, enabling bad actors to potentially upload backdoors on vulnerable sites. | Unknown | N/A | Unknown | |
CVE-2021-42250 | Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs. | Unknown | N/A | Apache Software Foundation | |
CVE-2021-42252 | An issue was discovered in aspeed_lpc_ctrl_mmap in drivers/soc/aspeed/aspeed-lpc-ctrl.c in the Linux kernel before 5.14.6. Local attackers able to access the Aspeed LPC control interface could overwrite memory in the kernel and potentially execute privileges, aka CID-b49a0e69a7b1. This occurs because a certain comparison uses values that are not memory sizes. | Unknown | N/A | n/a | |
CVE-2021-42254 | BeyondTrust Privilege Management prior to version 21.6 creates a Temporary File in a Directory with Insecure Permissions. | Unknown | N/A | n/a | |
CVE-2021-42255 | AppGuard Enterprise before 6.7.100.1 creates a Temporary File in a Directory with Insecure Permissions. Local users can gain SYSTEM privileges because a repair operation relies on the %TEMP% directory of an unprivileged user. | Unknown | N/A | n/a | |
CVE-2021-42257 | check_smart before 6.9.1 allows unintended drive access by an unprivileged user because it only checks for a substring match of a device path (the /dev/bus substring and a number), aka an unanchored regular expression. | Unknown | N/A | n/a | |
CVE-2021-42258 | BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for example, use the txtID (aka username) parameter. Successful exploitation can include the ability to execute arbitrary code as MSSQLSERVER$ via xp_cmdshell. | Unknown | N/A | n/a | |
CVE-2021-4226 | RSFirewall tries to identify the original IP address by looking at different HTTP headers. A bypass is possible due to the way it is implemented. | Unknown | N/A | Unknown | |
CVE-2021-42260 | TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case. It can be triggered by a crafted XML message and leads to a denial of service. | Unknown | N/A | n/a | |
CVE-2021-42261 | Revisor Video Management System (VMS) before 2.0.0 has a directory traversal vulnerability. Successful exploitation could allow an attacker to traverse the file system to access files or directories that are outside of restricted directory on the remote server. This could lead to the disclosure of sensitive data on the vulnerable server. | Unknown | N/A | n/a | |
CVE-2021-42262 | An issue was discovered in Softing OPC UA C++ SDK before 5.70. An invalid XML element in the type dictionary makes the OPC/UA client crash due to an out-of-memory condition. | Unknown | N/A | n/a | |
CVE-2021-42263 | Adobe Premiere Pro 15.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Unknown | N/A | Adobe | |
CVE-2021-42264 | Adobe Premiere Pro 15.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Unknown | N/A | Adobe | |
CVE-2021-42265 | Adobe Premiere Pro versions 22.0 (and earlier) and 15.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Unknown | N/A | Adobe | |
CVE-2021-42266 | Adobe Animate version 21.0.9 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious FLA file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. | Unknown | N/A | Adobe | |
CVE-2021-42267 | Adobe Animate version 21.0.9 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious FLA file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. | Unknown | N/A | Adobe | |
CVE-2021-42268 | Adobe Animate version 21.0.9 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted FLA file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Unknown | N/A | Adobe | |
CVE-2021-42269 | Adobe Animate version 21.0.9 (and earlier) are affected by a use-after-free vulnerability in the processing of a malformed FLA file that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Unknown | N/A | Adobe | |
CVE-2021-4227 | The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source editor, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page to the comment section | Unknown | N/A | Unknown | |
CVE-2021-42270 | Adobe Animate version 21.0.9 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious BMP file. | Unknown | N/A | Adobe | |
CVE-2021-42271 | Adobe Animate version 21.0.9 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious BMP file. | Unknown | N/A | Adobe | |
CVE-2021-42272 | Adobe Animate version 21.0.9 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious GIF file. | Unknown | N/A | Adobe | |
CVE-2021-42274 | Windows Hyper-V Discrete Device Assignment (DDA) Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42275 | Microsoft COM for Windows Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42276 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42277 | Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42278 | Active Directory Domain Services Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42279 | Chakra Scripting Engine Memory Corruption Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-4228 | Use of hard-coded TLS certificate by default allows an attacker to perform Man-in-the-Middle (MitM) attacks even in the presence of the HTTPS connection. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.00.0. | Unknown | N/A | Lanner Inc | |
CVE-2021-42280 | Windows Feedback Hub Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42282 | Active Directory Domain Services Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42283 | NTFS Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42284 | Windows Hyper-V Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42285 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42286 | Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42287 | Active Directory Domain Services Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42288 | Windows Hello Security Feature Bypass Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-4229 | A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This issue affects the crypto mining component which introduces a backdoor. Upgrading to version 0.7.30, 0.8.1 and 1.0.1 is able to address this issue. It is recommended to upgrade the affected component. | Unknown | N/A | unspecified | |
CVE-2021-42291 | Active Directory Domain Services Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42292 | Microsoft Excel Security Feature Bypass Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42293 | Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42294 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42295 | Visual Basic for Applications Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42296 | Microsoft Word Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42297 | Windows 10 Update Assistant Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42298 | Microsoft Defender Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42299 | Microsoft Surface Pro 3 Security Feature Bypass Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-4230 | A vulnerability has been found in Airfield Online and classified as problematic. This vulnerability affects the path /backups/ of the MySQL backup handler. An attacker is able to get access to sensitive data without proper authentication. It is recommended to the change the configuration settings. | Unknown | N/A | unspecified | |
CVE-2021-42300 | Azure Sphere Tampering Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42301 | Azure RTOS Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42302 | Azure RTOS Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42303 | Azure RTOS Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42304 | Azure RTOS Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42305 | Microsoft Exchange Server Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42306 | An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential on an Azure AD Application or Service Principal (which is not recommended). This vulnerability allows a user or service in the tenant with application read access to read the private key data that was added to the application. Azure AD addressed this vulnerability by preventing disclosure of any private key values added to the application. Microsoft has identified services that could manifest this vulnerability, and steps that customers should take to be protected. Refer to the FAQ section for more information. For more details on this issue, please refer to the MSRC Blog Entry. | Unknown | N/A | Microsoft | |
CVE-2021-42307 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42308 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42309 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-4231 | A vulnerability was found in Angular up to 11.0.4/11.1.0-next.2. It has been classified as problematic. Affected is the handling of comments. The manipulation leads to cross site scripting. It is possible to launch the attack remotely but it might require an authentication first. Upgrading to version 11.0.5 and 11.1.0-next.3 is able to address this issue. The name of the patch is ba8da742e3b243e8f43d4c63aa842b44e14f2b09. It is recommended to upgrade the affected component. | Unknown | N/A | unspecified | |
CVE-2021-42310 | Microsoft Defender for IoT Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42311 | Microsoft Defender for IoT Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42312 | Microsoft Defender for IoT Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42313 | Microsoft Defender for IoT Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42314 | Microsoft Defender for IoT Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2021-42315 | Microsoft Defender for IoT Remote Code Execution Vulnerability | Unknown | N/A | Microsoft |
vunerability-insight.com © 2023 - 2025. All Rights Reserved.
Vulnerability Data Repositories v