Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by NVD-CWE-noinfo
Total 22706 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-41374 1 Microsoft 1 Azure Sphere 2021-11-10 2.1 LOW 5.5 MEDIUM
Azure Sphere Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-41375, CVE-2021-41376.
CVE-2021-40442 1 Microsoft 7 365 Apps, Excel, Office and 4 more 2021-11-10 6.8 MEDIUM 7.8 HIGH
Microsoft Excel Remote Code Execution Vulnerability
CVE-2021-38665 1 Microsoft 11 Remote Desktop, Windows 10, Windows 11 and 8 more 2021-11-10 4.3 MEDIUM 6.5 MEDIUM
Remote Desktop Protocol Client Information Disclosure Vulnerability
CVE-2021-41351 1 Microsoft 4 Edge, Windows 10, Windows 11 and 1 more 2021-11-10 4.3 MEDIUM 4.3 MEDIUM
Microsoft Edge (Chrome based) Spoofing on IE Mode
CVE-2021-41349 1 Microsoft 1 Exchange Server 2021-11-10 4.3 MEDIUM 6.5 MEDIUM
Microsoft Exchange Server Spoofing Vulnerability This CVE ID is unique from CVE-2021-42305.
CVE-2021-41356 1 Microsoft 5 Windows 10, Windows 11, Windows Server 2016 and 2 more 2021-11-10 5.0 MEDIUM 7.5 HIGH
Windows Denial of Service Vulnerability
CVE-2020-7484 2 Microsoft, Schneider-electric 4 Windows 7, Windows Nt, Windows Xp and 1 more 2021-11-10 4.3 MEDIUM 7.5 HIGH
**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability with the former 'password' feature could allow a denial of service attack if the user is not following documented guidelines pertaining to dedicated TriStation connection and key-switch protection. This vulnerability was discovered and remediated in versions v4.9.1 and v4.10.1 on May 30, 2013. This feature is not present in version v4.9.1 and v4.10.1 through current. Therefore, the vulnerability is not present in these versions.
CVE-2014-0564 7 Adobe, Apple, Google and 4 more 14 Air Desktop Runtime, Air Sdk, Flash Player and 11 more 2021-11-10 10.0 HIGH N/A
Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0558.
CVE-2021-43192 2 Apple, Jetbrains 2 Iphone Os, Youtrack Mobile 2021-11-10 5.0 MEDIUM 5.3 MEDIUM
In JetBrains YouTrack Mobile before 2021.2, iOS URL scheme hijacking is possible.
CVE-2021-43193 1 Jetbrains 1 Teamcity 2021-11-10 7.5 HIGH 9.8 CRITICAL
In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible.
CVE-2021-43194 1 Jetbrains 1 Teamcity 2021-11-10 5.0 MEDIUM 5.3 MEDIUM
In JetBrains TeamCity before 2021.1.2, user enumeration was possible.
CVE-2021-38666 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2021-11-10 6.8 MEDIUM 8.8 HIGH
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2021-43180 1 Jetbrains 1 Hub 2021-11-10 5.0 MEDIUM 7.5 HIGH
In JetBrains Hub before 2021.1.13690, information disclosure via avatar metadata is possible.
CVE-2021-43182 1 Jetbrains 1 Hub 2021-11-10 5.0 MEDIUM 7.5 HIGH
In JetBrains Hub before 2021.1.13415, a DoS via user information is possible.
CVE-2021-43191 3 Apple, Google, Jetbrains 3 Iphone Os, Android, Youtrack Mobile 2021-11-10 5.0 MEDIUM 5.3 MEDIUM
JetBrains YouTrack Mobile before 2021.2, is missing the security screen on Android and iOS.
CVE-2021-41222 1 Google 1 Tensorflow 2021-11-10 2.1 LOW 5.5 MEDIUM
TensorFlow is an open source platform for machine learning. In affected versions the implementation of `SplitV` can trigger a segfault is an attacker supplies negative arguments. This occurs whenever `size_splits` contains more than one value and at least one value is negative. The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, TensorFlow 2.5.2, and TensorFlow 2.4.4, as these are also affected and still in supported range.
CVE-2021-26443 1 Microsoft 5 Windows 10, Windows 11, Windows Server 2016 and 2 more 2021-11-10 7.7 HIGH 9.0 CRITICAL
Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
CVE-2013-2070 2 Debian, F5 2 Debian Linux, Nginx 2021-11-10 5.8 MEDIUM N/A
http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sensitive information from worker process memory via a crafted proxy response, a similar vulnerability to CVE-2013-2028.
CVE-2011-4963 2 F5, Microsoft 2 Nginx, Windows 2021-11-10 5.0 MEDIUM N/A
nginx/Windows 1.3.x before 1.3.1 and 1.2.x before 1.2.1 allows remote attackers to bypass intended access restrictions and access restricted files via (1) a trailing . (dot) or (2) certain "$index_allocation" sequences in a request.
CVE-2009-4487 1 F5 1 Nginx 2021-11-10 6.8 MEDIUM N/A
nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.