Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by NVD-CWE-noinfo
Total 22706 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-43190 2 Google, Jetbrains 2 Android, Youtrack Mobile 2021-11-10 5.0 MEDIUM 5.3 MEDIUM
In JetBrains YouTrack Mobile before 2021.2, task hijacking on Android is possible.
CVE-2021-29843 1 Ibm 1 Mq Appliance 2021-11-09 4.0 MEDIUM 6.5 MEDIUM
IBM MQ 9.1 LTS, 9.1 CD, 9.2 LTS, and 9.2CD is vulnerable to a denial of service attack caused by an issue processing message properties. IBM X-Force ID: 205203.
CVE-2021-43195 1 Jetbrains 1 Teamcity 2021-11-09 5.0 MEDIUM 5.3 MEDIUM
In JetBrains TeamCity before 2021.1.2, some HTTP security headers were missing.
CVE-2021-43200 1 Jetbrains 1 Teamcity 2021-11-09 7.5 HIGH 9.8 CRITICAL
In JetBrains TeamCity before 2021.1.2, permission checks in the Agent Push functionality were insufficient.
CVE-2021-43201 1 Jetbrains 1 Teamcity 2021-11-09 5.0 MEDIUM 5.3 MEDIUM
In JetBrains TeamCity before 2021.1.3, a newly created project could take settings from an already deleted project.
CVE-2021-43413 1 Gnu 1 Hurd 2021-11-09 9.0 HIGH 8.8 HIGH
An issue was discovered in GNU Hurd before 0.9 20210404-9. A single pager port is shared among everyone who mmaps a file, allowing anyone to modify any files that they can read. This can be trivially exploited to get full root access.
CVE-2021-24816 1 Phoenix Media Rename Project 1 Phoenix Media Rename 2021-11-09 4.0 MEDIUM 4.3 MEDIUM
The Phoenix Media Rename WordPress plugin before 3.4.4 does not have capability checks in its phoenix_media_rename AJAX action, which could allow users with Author roles to rename any uploaded media files, including ones they do not own.
CVE-2014-8756 1 Panasonic 2 Network Camera Recorder, Network Camera Recorder Firmware 2021-11-09 6.8 MEDIUM N/A
The NcrCtl4.NcrNet.1 control in Panasonic Network Camera Recorder before 4.04R03 allows remote attackers to execute arbitrary code via a crafted GetVOLHeader method call, which writes null bytes to an arbitrary address.
CVE-2021-37850 1 Eset 3 Cyber Security, Endpoint Antivirus, Endpoint Security 2021-11-09 2.1 LOW 5.5 MEDIUM
ESET was made aware of a vulnerability in its consumer and business products for macOS that enables a user logged on to the system to stop the ESET daemon, effectively disabling the protection of the ESET security product until a system reboot.
CVE-2007-2583 3 Canonical, Debian, Oracle 3 Ubuntu Linux, Debian Linux, Mysql 2021-11-08 4.0 MEDIUM N/A
The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL pointer dereference.
CVE-2012-4838 1 Ibm 2 Flex System Chassis Management Module, Integrated Management Module Ii 2021-11-08 1.9 LOW N/A
IBM Flex System Chassis Management Module (CMM) and Integrated Management Module 2 (IMM2) allow local users to obtain sensitive information about (1) local accounts, (2) SSH private keys, (3) SSL/TLS private keys, (4) SNMPv3 communities, and (5) LDAP credentials by leveraging unspecified side effects of service or maintenance activity.
CVE-2020-23565 1 Irfanview 1 Irfanview 2021-11-08 6.8 MEDIUM 7.8 HIGH
Irfanview v4.53 allows attackers to execute arbitrary code via a crafted JPEG 2000 file. Related to a "Data from Faulting Address controls Branch Selection starting at JPEG2000!ShowPlugInSaveOptions_W+0x0000000000032850".
CVE-2021-39895 1 Gitlab 1 Gitlab 2021-11-08 2.1 LOW 4.5 MEDIUM
In all versions of GitLab CE/EE since version 8.0, an attacker can set the pipeline schedules to be active in a project export so when an unsuspecting owner imports that project, pipelines are active by default on that project. Under specialized conditions, this may lead to information disclosure if the project is imported from an untrusted source.
CVE-2021-39901 1 Gitlab 1 Gitlab 2021-11-08 4.0 MEDIUM 2.7 LOW
In all versions of GitLab CE/EE since version 11.10, an admin of a group can see the SCIM token of that group by visiting a specific endpoint.
CVE-2021-39905 1 Gitlab 1 Gitlab 2021-11-08 4.0 MEDIUM 4.3 MEDIUM
An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with
CVE-2021-36925 1 Realtek 1 Rtsupx Usb Utility Driver 2021-11-08 7.2 HIGH 7.8 HIGH
RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve an arbitrary read or write operation from/to physical memory (leading to Escalation of Privileges, Denial of Service, Code Execution, and Information Disclosure) via a crafted Device IO Control packet to a device.
CVE-2019-8994 1 Tibco 2 Activematrix Business Process Management, Silver Fabric Enabler 2021-11-05 4.9 MEDIUM 4.6 MEDIUM
The workspace client of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, and TIBCO Silver Fabric Enabler for ActiveMatrix BPM contains vulnerabilities where an authenticated user can change settings that can theoretically adversely impact other users. Affected releases are TIBCO Software Inc.'s TIBCO ActiveMatrix BPM: versions up to and including 4.2.0, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric: versions up to and including 4.2.0, and TIBCO Silver Fabric Enabler for ActiveMatrix BPM: versions up to and including 1.4.1.
CVE-2021-30841 1 Apple 6 Ipados, Iphone Os, Mac Os X and 3 more 2021-11-05 6.8 MEDIUM 7.8 HIGH
This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted dfont file may lead to arbitrary code execution.
CVE-2021-30842 1 Apple 6 Ipados, Iphone Os, Mac Os X and 3 more 2021-11-05 6.8 MEDIUM 7.8 HIGH
This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted dfont file may lead to arbitrary code execution.
CVE-2021-30843 1 Apple 6 Ipados, Iphone Os, Mac Os X and 3 more 2021-11-05 6.8 MEDIUM 7.8 HIGH
This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted dfont file may lead to arbitrary code execution.