Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-41833 1 Zohocorp 1 Manageengine Patch Connect Plus 2021-11-15 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution.
CVE-2020-23887 1 Xnview 1 Xnview Mp 2021-11-15 4.3 MEDIUM 5.5 MEDIUM
XnView MP v0.96.4 was discovered to contain a heap overflow which allows attackers to cause a denial of service (DoS) via a crafted ico file. Related to a Read Access Violation starting at USER32!SmartStretchDIBits+0x33.
CVE-2021-42322 1 Microsoft 1 Visual Studio Code 2021-11-15 4.6 MEDIUM 7.8 HIGH
Visual Studio Code Elevation of Privilege Vulnerability
CVE-2021-42319 1 Microsoft 2 Visual Studio 2017, Visual Studio 2019 2021-11-15 2.1 LOW 5.5 MEDIUM
Visual Studio Elevation of Privilege Vulnerability
CVE-2013-7109 2021-11-15 N/A N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVE-2019-18914 1 Hp 755 Digital Sender Flow 8500 Fn2 Document Capture Workstation L2762a, Futuresmart 3, Futuresmart 4 and 752 more 2021-11-15 4.3 MEDIUM 6.1 MEDIUM
A potential security vulnerability has been identified for certain HP printers and MFPs that would allow redirection page Cross-Site Scripting in a client’s browser by clicking on a third-party malicious link.
CVE-2021-42305 1 Microsoft 1 Exchange Server 2021-11-15 4.3 MEDIUM 6.5 MEDIUM
Microsoft Exchange Server Spoofing Vulnerability This CVE ID is unique from CVE-2021-41349.
CVE-2009-3587 3 Broadcom, Ca, Linux 33 Anti-virus, Anti-virus For The Enterprise, Anti-virus Sdk and 30 more 2021-11-15 9.3 HIGH N/A
Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted RAR archive file that triggers heap corruption, a different vulnerability than CVE-2009-3588.
CVE-2009-3519 1 Oracle 2 Opensolaris, Solaris 2021-11-15 4.9 MEDIUM N/A
Multiple memory leaks in the IP module in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_109, allow local users to cause a denial of service (memory consumption) via vectors related to (1) M_DATA, (2) M_PROTO, (3) M_PCPROTO, and (4) M_SIG STREAMS messages.
CVE-2017-14023 1 Siemens 2 Simatic Pcs7, Simatic Wincc 2021-11-15 4.0 MEDIUM 4.9 MEDIUM
An Improper Input Validation issue was discovered in Siemens SIMATIC PCS 7 V8.1 prior to V8.1 SP1 with WinCC V7.3 Upd 13, and V8.2 all versions. The improper input validation vulnerability has been identified, which may allow an authenticated remote attacker who is a member of the administrators group to crash services by sending specially crafted messages to the DCOM interface.
CVE-2021-42316 1 Microsoft 1 Dynamics 365 2021-11-15 6.5 MEDIUM 8.8 HIGH
Microsoft Dynamics 365 (on-premises) Remote Code Execution Vulnerability
CVE-2021-43208 1 Microsoft 1 3d Viewer 2021-11-15 6.8 MEDIUM 7.8 HIGH
3D Viewer Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-43209.
CVE-2021-43575 1 Knx 1 Engineering Tool Software 6 2021-11-15 2.1 LOW 5.5 MEDIUM
** DISPUTED ** KNX ETS6 through 6.0.0 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project information, a similar issue to CVE-2021-36799. NOTE: The vendor disputes this because it is not the responsibility of the ETS to securely store cryptographic key material when it is not being exported.
CVE-2008-5915 1 Google 1 Chrome 2021-11-15 2.1 LOW N/A
An unspecified function in the JavaScript implementation in Google Chrome creates and exposes a "temporary footprint" when there is a current login to a web site, which makes it easier for remote attackers to trick a user into acting upon a spoofed pop-up message, aka an "in-session phishing attack." NOTE: as of 20090116, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.
CVE-2010-1731 2 Google, Htc 2 Chrome, Hero 2021-11-15 4.3 MEDIUM N/A
Google Chrome on the HTC Hero allows remote attackers to cause a denial of service (application crash) via JavaScript that writes <marquee> sequences in an infinite loop.
CVE-2009-1598 1 Google 1 Chrome 2021-11-15 9.3 HIGH N/A
Google Chrome executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF file, which might allow remote attackers to bypass intended Adobe Acrobat JavaScript restrictions on accessing the document object, as demonstrated by a web site that permits PDF uploads by untrusted users, and therefore has a shared document.domain between the web site and this javascript: URI. NOTE: the researcher reports that Adobe's position is "a PDF file is active content."
CVE-2021-42303 1 Microsoft 1 Azure Real Time Operating System 2021-11-15 7.2 HIGH 6.8 MEDIUM
Azure RTOS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42302, CVE-2021-42304.
CVE-2019-18916 1 Hp 10 Color Laserjet Pro Mfp M277 B3q10a, Color Laserjet Pro Mfp M277 B3q10a Firmware, Color Laserjet Pro Mfp M277 B3q10v and 7 more 2021-11-15 4.6 MEDIUM 7.8 HIGH
A potential security vulnerability has been identified for HP LaserJet Solution Software (for certain HP LaserJet Printers) which may lead to unauthorized elevation of privilege on the client.
CVE-2021-42304 1 Microsoft 1 Azure Real Time Operating System 2021-11-15 7.2 HIGH 6.8 MEDIUM
Azure RTOS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42302, CVE-2021-42303.
CVE-2021-42302 1 Microsoft 1 Azure Real Time Operating System 2021-11-15 7.2 HIGH 6.8 MEDIUM
Azure RTOS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42303, CVE-2021-42304.