Search

Search Results (381470 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-41390 1 Ericsson 1 Enterprise Content Management 2024-11-21 8.0 High
In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Injection.
CVE-2021-41388 2 Apple, Netskope 2 Macos, Netskope 2024-11-21 7.8 High
Netskope client prior to 89.x on macOS is impacted by a local privilege escalation vulnerability. The XPC implementation of nsAuxiliarySvc process does not perform validation on new connections before accepting the connection. Thus any low privileged user can connect and call external methods defined in XPC service as root, elevating their privilege to the highest level.
CVE-2021-41387 1 Seatd Project 1 Seatd 2024-11-21 8.8 High
seatd-launch in seatd 0.6.x before 0.6.2 allows privilege escalation because it uses execlp and may be installed setuid root.
CVE-2021-41385 1 Securonix 1 Snypr 2024-11-21 6.5 Medium
The third party intelligence connector in Securonix SNYPR 6.3.1 Build 184295_0302 allows an authenticated user to obtain access to server configuration details via SSRF.
CVE-2021-41383 1 Netgear 2 R6020, R6020 Firmware 2024-11-21 7.2 High
setup.cgi on NETGEAR R6020 1.0.0.48 devices allows an admin to execute arbitrary shell commands via shell metacharacters in the ntp_server field.
CVE-2021-41382 1 Plasticscm 1 Plastic Scm 2024-11-21 7.5 High
Plastic SCM before 10.0.16.5622 mishandles the WebAdmin server management interface.
CVE-2021-41381 1 Payara 1 Micro Community 2024-11-21 7.5 High
Payara Micro Community 5.2021.6 and below allows Directory Traversal.
CVE-2021-41380 1 Realvnc 1 Vnc Viewer 2024-11-21 6.5 Medium
RealVNC Viewer 6.21.406 allows remote VNC servers to cause a denial of service (application crash) via crafted RFB protocol data. NOTE: It is asserted that this issue requires social engineering a user into connecting to a fake VNC Server. The VNC Viewer application they are using will then hang, until terminated, but no memory leak occurs - the resources are freed once the hung process is terminated and the resource usage is constant during the hang. Only the process that is connected to the fake Server is affected. This is an application bug, not a security issue
CVE-2021-41365 1 Microsoft 1 Defender For Iot 2024-11-21 8.8 High
Microsoft Defender for IoT Remote Code Execution Vulnerability
CVE-2021-41363 1 Microsoft 1 Intune Management Extension 2024-11-21 4.2 Medium
Intune Management Extension Security Feature Bypass Vulnerability
CVE-2021-41361 1 Microsoft 5 Windows Server 2004, Windows Server 2016, Windows Server 2019 and 2 more 2024-11-21 5.4 Medium
Active Directory Federation Server Spoofing Vulnerability
CVE-2021-41360 1 Microsoft 1 Hevc Video Extensions 2024-11-21 7.8 High
HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2021-41355 2 Microsoft, Redhat 6 .net, Powershell, Powershell Core and 3 more 2024-11-21 5.7 Medium
.NET Core and Visual Studio Information Disclosure Vulnerability
CVE-2021-41354 1 Microsoft 1 Dynamics 365 2024-11-21 5.4 Medium
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2021-41353 1 Microsoft 1 Dynamics 365 2024-11-21 5.4 Medium
Microsoft Dynamics 365 (on-premises) Spoofing Vulnerability
CVE-2021-41352 1 Microsoft 1 System Center Operations Manager 2024-11-21 7.5 High
SCOM Information Disclosure Vulnerability
CVE-2021-41350 1 Microsoft 1 Exchange Server 2024-11-21 6.5 Medium
Microsoft Exchange Server Spoofing Vulnerability
CVE-2021-41348 1 Microsoft 1 Exchange Server 2024-11-21 8 High
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2021-41347 1 Microsoft 14 Windows 10, Windows 10 1507, Windows 10 1607 and 11 more 2024-11-21 7.8 High
Windows AppX Deployment Service Elevation of Privilege Vulnerability
CVE-2021-41346 1 Microsoft 7 Windows 10, Windows 10 1809, Windows 10 20h2 and 4 more 2024-11-21 5.3 Medium
Console Window Host Security Feature Bypass Vulnerability