Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by NVD-CWE-noinfo
Total 22706 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-20440 1 Ibm 1 Api Connect 2021-03-17 4.0 MEDIUM 4.3 MEDIUM
IBM API Connect 10.0.0.0, and 2018.4.1.0 through 2018.4.1.13 does not restrict member registration to the intended recepient. An attacker who is a valid user in the user registry used by API Manager can use a stolen invitation link and register themselves as a member of an API provider organization. IBM X-Force ID: 196536.
CVE-2020-23160 1 Pyres 2 Termod4, Termod4 Firmware 2021-03-17 9.0 HIGH 8.8 HIGH
Remote code execution in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to arbitrary commands as root on the devices.
CVE-2021-27059 1 Microsoft 1 Office 2021-03-16 8.5 HIGH 6.8 MEDIUM
Microsoft Office Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-24108, CVE-2021-27057.
CVE-2021-27066 1 Microsoft 1 Windows Admin Center 2021-03-16 4.0 MEDIUM 4.3 MEDIUM
Windows Admin Center Security Feature Bypass Vulnerability
CVE-2021-27055 1 Microsoft 3 365 Apps, Office, Visio 2021-03-16 6.8 MEDIUM 7.0 HIGH
Microsoft Visio Security Feature Bypass Vulnerability
CVE-2021-27076 1 Microsoft 3 Business Productivity Servers, Sharepoint Foundation, Sharepoint Server 2021-03-16 6.5 MEDIUM 8.8 HIGH
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2021-27081 1 Microsoft 1 Visual Studio Code Eslint Extension 2021-03-16 9.3 HIGH 7.8 HIGH
Visual Studio Code ESLint Extension Remote Code Execution Vulnerability
CVE-2021-27082 1 Microsoft 1 Quantum Development Kit 2021-03-16 9.3 HIGH 7.8 HIGH
Quantum Development Kit for Visual Studio Code Remote Code Execution Vulnerability
CVE-2021-27084 1 Microsoft 1 Visual Studio Code 2021-03-16 9.3 HIGH 7.8 HIGH
Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability
CVE-2021-27083 1 Microsoft 1 Remote Development 2021-03-16 9.3 HIGH 7.8 HIGH
Remote Development Extension for Visual Studio Code Remote Code Execution Vulnerability
CVE-2021-27058 1 Microsoft 1 365 Apps 2021-03-15 9.3 HIGH 7.8 HIGH
Microsoft Office ClickToRun Remote Code Execution Vulnerability
CVE-2021-27060 1 Microsoft 1 Visual Studio Code 2021-03-15 6.8 MEDIUM 7.8 HIGH
Visual Studio Code Remote Code Execution Vulnerability
CVE-2021-25830 1 Onlyoffice 1 Document Server 2021-03-15 7.5 HIGH 9.8 CRITICAL
A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13. An attacker must request the conversion of the crafted file from DOCT into DOCX format. Using the chain of two other bugs related to improper string handling, an attacker can achieve remote code execution on DocumentServer.
CVE-2021-25831 1 Onlyoffice 1 Document Server 2021-03-15 7.5 HIGH 9.8 CRITICAL
A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. An attacker must request the conversion of the crafted file from PPTT into PPTX format. Using the chain of two other bugs related to improper string handling, a remote attacker can obtain remote code execution on DocumentServer.
CVE-2014-8991 2 Oracle, Pypa 2 Solaris, Pip 2021-03-15 2.1 LOW N/A
pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.
CVE-2021-26861 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2021-03-12 6.8 MEDIUM 7.8 HIGH
Windows Graphics Component Remote Code Execution Vulnerability
CVE-2021-26879 1 Microsoft 5 Windows 10, Windows 8.1, Windows Server 2012 and 2 more 2021-03-12 5.0 MEDIUM 7.5 HIGH
Windows NAT Denial of Service Vulnerability
CVE-2021-26881 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2021-03-12 6.5 MEDIUM 8.8 HIGH
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2020-6522 4 Debian, Fedoraproject, Google and 1 more 5 Debian Linux, Fedora, Chrome and 2 more 2021-03-12 6.8 MEDIUM 9.6 CRITICAL
Inappropriate implementation in external protocol handlers in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
CVE-2020-6519 4 Debian, Fedoraproject, Google and 1 more 5 Debian Linux, Fedora, Chrome and 2 more 2021-03-12 4.3 MEDIUM 6.5 MEDIUM
Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.