Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-21935 1 Motorola 2 Cx2, Cx2 Firmware 2022-05-03 7.5 HIGH 9.8 CRITICAL
A command injection vulnerability in HNAP1/GetNetworkTomographySettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to execute arbitrary code.
CVE-2021-22125 1 Fortinet 1 Fortisandbox 2022-05-03 9.0 HIGH 7.2 HIGH
An instance of improper neutralization of special elements in the sniffer module of FortiSandbox before 3.2.2 may allow an authenticated administrator to execute commands on the underlying system's shell via altering the content of its configuration file.
CVE-2021-33911 1 Zohocorp 1 Manageengine Admanager Plus 2022-05-03 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine ADManager Plus before 7110 allows remote code execution.
CVE-2021-34449 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2022-05-03 4.6 MEDIUM 7.8 HIGH
Win32k Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-34516.
CVE-2021-34445 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2022-05-03 4.6 MEDIUM 7.8 HIGH
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-33761, CVE-2021-33773, CVE-2021-34456.
CVE-2021-33784 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2022-05-03 4.6 MEDIUM 7.8 HIGH
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2021-33774 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2022-05-03 4.6 MEDIUM 7.8 HIGH
Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2021-33773 1 Microsoft 6 Windows 10, Windows 8.1, Windows Rt 8.1 and 3 more 2022-05-03 4.6 MEDIUM 7.8 HIGH
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-33761, CVE-2021-34445, CVE-2021-34456.
CVE-2021-33771 1 Microsoft 7 Windows 10, Windows 8.1, Windows Rt 8.1 and 4 more 2022-05-03 7.2 HIGH 7.8 HIGH
Windows Kernel Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-31979, CVE-2021-34514.
CVE-2021-33768 1 Microsoft 1 Exchange Server 2022-05-03 5.2 MEDIUM 8.0 HIGH
Microsoft Exchange Server Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-34470, CVE-2021-34523.
CVE-2021-33767 1 Microsoft 1 Open Enclave Software Development Kit 2022-05-03 4.6 MEDIUM 6.7 MEDIUM
Open Enclave SDK Elevation of Privilege Vulnerability
CVE-2021-33761 1 Microsoft 6 Windows 10, Windows 8.1, Windows Rt 8.1 and 3 more 2022-05-03 4.6 MEDIUM 7.8 HIGH
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-33773, CVE-2021-34445, CVE-2021-34456.
CVE-2021-33759 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2022-05-03 4.6 MEDIUM 7.8 HIGH
Windows Desktop Bridge Elevation of Privilege Vulnerability
CVE-2021-33744 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2022-05-03 7.2 HIGH 6.7 MEDIUM
Windows Secure Kernel Mode Security Feature Bypass Vulnerability
CVE-2021-33743 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2022-05-03 4.6 MEDIUM 7.8 HIGH
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2021-31979 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2022-05-03 7.2 HIGH 7.8 HIGH
Windows Kernel Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-33771, CVE-2021-34514.
CVE-2021-36716 1 Segment 1 Is-email 2022-05-03 5.0 MEDIUM 7.5 HIGH
A ReDoS (regular expression denial of service) flaw was found in the Segment is-email package before 1.0.1 for Node.js. An attacker that is able to provide crafted input to the isEmail(input) function may cause an application to consume an excessive amount of CPU.
CVE-2021-33687 1 Sap 1 Netweaver Application Server Java 2022-05-03 4.0 MEDIUM 4.9 MEDIUM
SAP NetWeaver AS JAVA (Enterprise Portal), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50 reveals sensitive information in one of their HTTP requests, an attacker can use this in conjunction with other attacks such as XSS to steal this information.
CVE-2021-36124 1 Echobh 1 Sharecare 2022-05-03 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Echo ShareCare 8.15.5. It does not perform authentication or authorization checks when accessing a subset of sensitive resources, leading to the ability for unauthenticated users to access pages that are vulnerable to attacks such as SQL injection.
CVE-2020-20215 1 Mikrotik 1 Routeros 2022-05-03 4.0 MEDIUM 6.5 MEDIUM
Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/diskd process. An authenticated remote attacker can cause a Denial of Service due to invalid memory access.