Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by NVD-CWE-noinfo
Total 22706 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-26430 1 Microsoft 1 Azure Sphere 2021-08-27 2.1 LOW 4.4 MEDIUM
Azure Sphere Denial of Service Vulnerability
CVE-2021-23413 1 Jszip Project 1 Jszip 2021-08-27 5.0 MEDIUM 5.3 MEDIUM
This affects the package jszip before 3.7.0. Crafting a new zip file with filenames set to Object prototype values (e.g __proto__, toString, etc) results in a returned object with a modified prototype instance.
CVE-2019-15592 1 Gitlab 1 Gitlab 2021-08-27 4.0 MEDIUM 4.3 MEDIUM
GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.
CVE-2021-35394 1 Realtek 1 Realtek Jungle Sdk 2021-08-26 10.0 HIGH 9.8 CRITICAL
Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command injection vulnerability that can be exploited by remote unauthenticated attackers.
CVE-2017-7728 1 Ismartalarm 2 Cubeone, Cubeone Firmware 2021-08-25 7.5 HIGH 9.8 CRITICAL
On iSmartAlarm cube devices, there is authentication bypass leading to remote execution of commands (e.g., setting the alarm on/off), related to incorrect cryptography.
CVE-2021-29983 2 Google, Mozilla 2 Android, Firefox 2021-08-25 4.3 MEDIUM 6.5 MEDIUM
Firefox for Android could get stuck in fullscreen mode and not exit it even after normal interactions that should cause it to exit. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 91.
CVE-2021-36958 1 Microsoft 1 Windows 2021-08-24 9.3 HIGH 7.8 HIGH
Windows Print Spooler Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-36936, CVE-2021-36947.
CVE-2021-37707 1 Shopware 1 Shopware 2021-08-24 5.0 MEDIUM 7.5 HIGH
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability that allows manipulation of product reviews via API. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.
CVE-2021-34534 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2021-08-23 5.1 MEDIUM 7.5 HIGH
Windows MSHTML Platform Remote Code Execution Vulnerability
CVE-2021-34535 1 Microsoft 9 Remote Desktop, Windows 10, Windows 7 and 6 more 2021-08-23 6.8 MEDIUM 8.8 HIGH
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2021-34530 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2021-08-23 6.8 MEDIUM 7.8 HIGH
Windows Graphics Component Remote Code Execution Vulnerability
CVE-2021-34533 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2021-08-23 6.8 MEDIUM 7.8 HIGH
Windows Graphics Component Font Parsing Remote Code Execution Vulnerability
CVE-2021-38546 1 Creative 8 Pebble, Pebble Firmware, Pebble Plus and 5 more 2021-08-23 4.3 MEDIUM 5.9 MEDIUM
CREATIVE Pebble devices through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. The power indicator LED of the speakers is connected directly to the power line, as a result, the intensity of a device's power indicator LED is correlative to the power consumption. The sound played by the speakers affects their power consumption and as a result is also correlative to the light intensity of the LEDs. By analyzing measurements obtained from an electro-optical sensor directed at the power indicator LEDs of the speakers, we can recover the sound played by them.
CVE-2021-38547 1 Logitech 4 S120, S120 Firmware, Z120 and 1 more 2021-08-23 4.3 MEDIUM 5.9 MEDIUM
Logitech Z120 and S120 speakers through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. The power indicator LED of the speakers is connected directly to the power line, as a result, the intensity of a device's power indicator LED is correlative to the power consumption. The sound played by the speakers affects their power consumption and as a result is also correlative to the light intensity of the LEDs. By analyzing measurements obtained from an electro-optical sensor directed at the power indicator LEDs of the speakers, we can recover the sound played by them.
CVE-2021-38545 1 Raspberrypi 4 Raspberry Pi 3 Model B\+, Raspberry Pi 3 Model B\+ Firmware, Raspberry Pi 4 Model B and 1 more 2021-08-23 4.3 MEDIUM 5.9 MEDIUM
Raspberry Pi 3 B+ and 4 B devices through 2021-08-09, in certain specific use cases in which the device supplies power to audio-output equipment, allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. We assume that the Raspberry Pi supplies power to some speakers. The power indicator LED of the Raspberry Pi is connected directly to the power line, as a result, the intensity of a device's power indicator LED is correlative to the power consumption. The sound played by the speakers affects the Raspberry Pi's power consumption and as a result is also correlative to the light intensity of the LED. By analyzing measurements obtained from an electro-optical sensor directed at the power indicator LED of the Raspberry Pi, we can recover the sound played by the speakers.
CVE-2021-38548 1 Jbl 2 Go 2, Go 2 Firmware 2021-08-23 4.3 MEDIUM 5.9 MEDIUM
JBL Go 2 devices through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. The power indicator LED of the speakers is connected directly to the power line, as a result, the intensity of a device's power indicator LED is correlative to the power consumption. The sound played by the speakers affects their power consumption and as a result is also correlative to the light intensity of the LEDs. By analyzing measurements obtained from an electro-optical sensor directed at the power indicator LEDs of the speakers, we can recover the sound played by them.
CVE-2021-38544 1 Sony 4 Srs-xb33, Srs-xb33 Firmware, Srs-xb43 and 1 more 2021-08-23 4.3 MEDIUM 5.9 MEDIUM
Sony SRS-XB33 and SRS-XB43 devices through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. The power indicator LED of the speakers is connected directly to the power line, as a result, the intensity of a device's power indicator LED is correlative to the power consumption. The sound played by the speakers affects their power consumption and as a result is also correlative to the light intensity of the LEDs. By analyzing measurements obtained from an electro-optical sensor directed at the power indicator LEDs of the speakers, we can recover the sound played by them.
CVE-2021-38543 1 Tp-link 2 Ue330, Ue330 Firmware 2021-08-23 4.3 MEDIUM 5.9 MEDIUM
TP-Link UE330 USB splitter devices through 2021-08-09, in certain specific use cases in which the device supplies power to audio-output equipment, allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. We assume that the USB splitter supplies power to some speakers. The power indicator LED of the USB splitter is connected directly to the power line, as a result, the intensity of the USB splitter's power indicator LED is correlative to its power consumption. The sound played by the connected speakers affects the USB splitter's power consumption and as a result is also correlative to the light intensity of the LED. By analyzing measurements obtained from an electro-optical sensor directed at the power indicator LED of the USB splitter, we can recover the sound played by the connected speakers.
CVE-2021-28121 1 Virtual Robots.txt Project 1 Virtual Robots.txt 2021-08-23 7.5 HIGH 9.8 CRITICAL
Virtual Robots.txt before 1.10 does not block HTML tags in the robots.txt field.
CVE-2021-26432 1 Microsoft 6 Windows 10, Windows 8.1, Windows Rt 8.1 and 3 more 2021-08-23 7.5 HIGH 9.8 CRITICAL
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability