Search Results (361837 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-31174 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2024-11-21 5.5 Medium
Microsoft Excel Information Disclosure Vulnerability
CVE-2021-31171 1 Microsoft 2 Sharepoint Foundation, Sharepoint Server 2024-11-21 4.1 Medium
Microsoft SharePoint Information Disclosure Vulnerability
CVE-2021-31170 1 Microsoft 10 Windows 10, Windows 10 1803, Windows 10 1809 and 7 more 2024-11-21 7.8 High
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2021-31169 1 Microsoft 6 Windows 10, Windows 10 1809, Windows 10 20h2 and 3 more 2024-11-21 7.8 High
Windows Container Manager Service Elevation of Privilege Vulnerability
CVE-2021-31168 1 Microsoft 6 Windows 10, Windows 10 1809, Windows 10 20h2 and 3 more 2024-11-21 7.8 High
Windows Container Manager Service Elevation of Privilege Vulnerability
CVE-2021-31167 1 Microsoft 9 Windows 10, Windows 10 1809, Windows 10 1909 and 6 more 2024-11-21 7.8 High
Windows Container Manager Service Elevation of Privilege Vulnerability
CVE-2021-31165 1 Microsoft 6 Windows 10, Windows 10 1809, Windows 10 20h2 and 3 more 2024-11-21 7.8 High
Windows Container Manager Service Elevation of Privilege Vulnerability
CVE-2021-31164 1 Apache 1 Unomi 2024-11-21 7.5 High
Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements.
CVE-2021-31162 3 Fedoraproject, Redhat, Rust-lang 4 Fedora, Devtools, Enterprise Linux and 1 more 2024-11-21 9.8 Critical
In the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter function if freeing the element panics.
CVE-2021-31159 1 Zohocorp 1 Manageengine Servicedesk Plus Msp 2024-11-21 5.3 Medium
Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732.
CVE-2021-31158 1 Couchbase 1 Couchbase Server 2024-11-21 6.5 Medium
In the Query Engine in Couchbase Server 6.5.x and 6.6.x through 6.6.1, Common Table Expression queries were not correctly checking the user's permissions, allowing read-access to resources beyond what those users were explicitly allowed to access.
CVE-2021-31155 1 Umask Project 1 Umask 2024-11-21 7.8 High
Failure to normalize the umask in please before 0.4 allows a local attacker to gain full root privileges if they are allowed to execute at least one command.
CVE-2021-31154 1 Pleaseedit Project 1 Pleaseedit 2024-11-21 7.8 High
pleaseedit in please before 0.4 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack.
CVE-2021-31153 1 Please Project 1 Please 2024-11-21 3.3 Low
please before 0.4 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option.
CVE-2021-31152 1 Multilaser 2 Ac1200 Re018, Ac1200 Re018 Firmware 2024-11-21 8.8 High
Multilaser Router AC1200 V02.03.01.45_pt contains a cross-site request forgery (CSRF) vulnerability. An attacker can enable remote access, change passwords, and perform other actions through misconfigured requests, entries, and headers.
CVE-2021-31013 1 Apple 3 Ipados, Iphone Os, Macos 2024-11-21 5.5 Medium
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.1, iOS 15.2 and iPadOS 15.2, macOS Big Sur 11.6.2. Processing a maliciously crafted font may result in the disclosure of process memory.
CVE-2021-31009 1 Apple 3 Ipados, Iphone Os, Macos 2024-11-21 9.8 Critical
Multiple issues were addressed by removing HDF5. This issue is fixed in iOS 15.2 and iPadOS 15.2, macOS Monterey 12.1. Multiple issues in HDF5.
CVE-2021-31008 1 Apple 6 Ipados, Iphone Os, Macos and 3 more 2024-11-21 8.8 High
A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 15.1, tvOS 15.1, iOS 15 and iPadOS 15, macOS Monterey 12.0.1, watchOS 8.1. Processing maliciously crafted web content may lead to code execution.
CVE-2021-31007 1 Apple 5 Ipados, Iphone Os, Macos and 2 more 2024-11-21 5.5 Medium
Description: A permissions issue was addressed with improved validation. This issue is fixed in iOS 15.1 and iPadOS 15.1, tvOS 15.1, macOS Big Sur 11.6.2, watchOS 8.1, macOS Monterey 12.1. A malicious application may be able to bypass Privacy preferences.
CVE-2021-31006 1 Apple 3 Macos, Tvos, Watchos 2024-11-21 5.5 Medium
Description: A permissions issue was addressed with improved validation. This issue is fixed in watchOS 7.6, tvOS 14.7, macOS Big Sur 11.5. A malicious application may be able to bypass certain Privacy preferences.