Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-23987 1 Mozilla 3 Firefox, Firefox Esr, Thunderbird 2022-05-03 6.8 MEDIUM 8.8 HIGH
Mozilla developers and community members reported memory safety bugs present in Firefox 86 and Firefox ESR 78.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.
CVE-2021-23983 1 Mozilla 1 Firefox 2022-05-03 4.3 MEDIUM 6.5 MEDIUM
By causing a transition on a parent node by removing a CSS rule, an invalid property for a marker could have been applied, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 87.
CVE-2021-23981 1 Mozilla 3 Firefox, Firefox Esr, Thunderbird 2022-05-03 5.8 MEDIUM 8.1 HIGH
A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memory corruption and a potentially exploitable information leak or crash. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.
CVE-2021-26579 1 Hpe 1 Unified Data Management 2022-05-03 2.1 LOW 5.5 MEDIUM
A security vulnerability in HPE Unified Data Management (UDM) could allow the local disclosure of privileged information (CWE-321: Use of Hard-coded Cryptographic Key in a product). HPE has provided updates to versions 1.2009.0 and 1.2101.0 of HPE Unified Data Management (UDM). Version 1.2103.0 of HPE Unified Data Management (UDM) removes all hard-coded cryptographic keys.
CVE-2021-22172 1 Gitlab 1 Gitlab 2022-05-03 4.0 MEDIUM 4.3 MEDIUM
Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccessible on the releases page
CVE-2021-25370 1 Google 1 Android 2022-05-03 4.9 MEDIUM 4.4 MEDIUM
An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic.
CVE-2021-3027 1 Librit 1 Passhport 2022-05-03 4.0 MEDIUM 6.5 MEDIUM
app/views_mod/user/user.py in LibrIT PaSSHport through 2.5 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided search filter because user input gets no sanitization.
CVE-2021-3119 1 Zetetic 1 Sqlcipher 2022-05-03 5.0 MEDIUM 7.5 HIGH
Zetetic SQLCipher 4.x before 4.4.3 has a NULL pointer dereferencing issue related to sqlcipher_export in crypto.c and sqlite3StrICmp in sqlite3.c. This may allow an attacker to perform a remote denial of service attack. For example, an SQL injection can be used to execute the crafted SQL command sequence, which causes a segmentation fault.
CVE-2021-27928 4 Debian, Galeracluster, Mariadb and 1 more 4 Debian Linux, Wsrep, Mariadb and 1 more 2022-05-03 9.0 HIGH 7.2 HIGH
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL. An untrusted search path leads to eval injection, in which a database SUPER user can execute OS commands after modifying wsrep_provider and wsrep_notify_cmd. NOTE: this does not affect an Oracle product.
CVE-2021-27070 1 Microsoft 2 Windows 10, Windows Server 2016 2022-05-03 9.3 HIGH 7.8 HIGH
Windows 10 Update Assistant Elevation of Privilege Vulnerability
CVE-2021-26901 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2022-05-03 7.2 HIGH 7.8 HIGH
Windows Event Tracing Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-26872, CVE-2021-26898.
CVE-2021-26900 1 Microsoft 2 Windows 10, Windows Server 2016 2022-05-03 7.2 HIGH 7.8 HIGH
Windows Win32k Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-26863, CVE-2021-26875, CVE-2021-27077.
CVE-2021-26899 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2022-05-03 7.2 HIGH 7.8 HIGH
Windows UPnP Device Host Elevation of Privilege Vulnerability
CVE-2021-26898 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2022-05-03 7.2 HIGH 7.8 HIGH
Windows Event Tracing Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-26872, CVE-2021-26901.
CVE-2021-26891 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2022-05-03 4.6 MEDIUM 7.8 HIGH
Windows Container Execution Agent Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-26865.
CVE-2021-26890 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2022-05-03 4.6 MEDIUM 7.8 HIGH
Application Virtualization Remote Code Execution Vulnerability
CVE-2021-26889 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2022-05-03 4.6 MEDIUM 7.8 HIGH
Windows Update Stack Elevation of Privilege Vulnerability
CVE-2021-26887 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2022-05-03 4.6 MEDIUM 7.8 HIGH
Microsoft Windows Folder Redirection Elevation of Privilege Vulnerability
CVE-2021-26885 1 Microsoft 1 Windows 10 2022-05-03 4.6 MEDIUM 7.8 HIGH
Windows WalletService Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-26871.
CVE-2021-26882 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2022-05-03 4.6 MEDIUM 7.8 HIGH
Remote Access API Elevation of Privilege Vulnerability