Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-14124 1 Mi 2 Ax3600, Ax3600 Firmware 2021-09-27 7.5 HIGH 9.8 CRITICAL
There is a buffer overflow in librsa.so called by getwifipwdurl interface, resulting in code execution on Xiaomi router AX3600 with ROM version =rom< 1.1.12.
CVE-2021-39239 1 Apache 1 Jena 2021-09-27 5.0 MEDIUM 7.5 HIGH
A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including exposing the contents of local files to a remote server.
CVE-2020-21481 1 Rgcms Project 1 Rgcms 2021-09-27 6.5 MEDIUM 7.2 HIGH
An arbitrary file upload vulnerability in RGCMS v1.06 allows attackers to execute arbitrary code via a crafted .txt file which is later changed to a PHP file.
CVE-2020-21482 1 Rgcms Project 1 Rgcms 2021-09-27 3.5 LOW 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in RGCMS v1.06 allows attackers to obtain the administrator's cookie via a crafted payload in the Name field under the Message Board module
CVE-2021-33693 1 Sap 1 Cloud Connector 2021-09-27 7.7 HIGH 6.8 MEDIUM
SAP Cloud Connector, version - 2.0, allows an authenticated administrator to modify a configuration file to inject malicious codes that could potentially lead to OS command execution.
CVE-2021-40966 1 Tinyfilemanager Project 1 Tinyfilemanager 2021-09-27 3.5 LOW 5.4 MEDIUM
A Stored XSS exists in TinyFileManager All version up to and including 2.4.6 in /tinyfilemanager.php when the server is given a file that contains HTML and javascript in its name. A malicious user can upload a file with a malicious filename containing javascript code and it will run on any user browser when they access the server.
CVE-2020-14119 1 Mi 1 Ax3600 2021-09-27 10.0 HIGH 9.8 CRITICAL
There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under administrator authority on Xiaomi router AX3600 with rom versionrom< 1.1.12
CVE-2021-40965 1 Tinyfilemanager Project 1 Tinyfilemanager 2021-09-27 9.3 HIGH 8.8 HIGH
A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload files and run OS commands by inducing the Administrator user to browse a URL controlled by an attacker.
CVE-2021-39206 2 Envoyproxy, Pomerium 2 Envoy, Pomerium 2021-09-27 5.0 MEDIUM 8.6 HIGH
Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, contains two authorization related vulnerabilities CVE-2021-32777 and CVE-2021-32779. This may lead to incorrect routing or authorization policy decisions. With specially crafted requests, incorrect authorization or routing decisions may be made by Pomerium. Pomerium v0.14.8 and v0.15.1 contain an upgraded envoy binary with these vulnerabilities patched. This issue can only be triggered when using path prefix based policy. Removing any such policies should provide mitigation.
CVE-2021-39204 2 Envoyproxy, Pomerium 2 Envoy, Pomerium 2021-09-27 5.0 MEDIUM 7.5 HIGH
Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, incorrectly handles resetting of HTTP/2 streams with excessive complexity. This can lead to high CPU utilization when a large number of streams are reset. This can result in a DoS condition. Pomerium versions 0.14.8 and 0.15.1 contain an upgraded envoy binary with this vulnerability patched.
CVE-2021-38652 1 Microsoft 2 Sharepoint Enterprise Server, Sharepoint Foundation 2021-09-27 3.5 LOW 3.5 LOW
Microsoft SharePoint Server Spoofing Vulnerability This CVE ID is unique from CVE-2021-38651.
CVE-2021-20433 2 Ibm, Linux 2 Security Guardium, Linux Kernel 2021-09-27 4.0 MEDIUM 6.5 MEDIUM
IBM Security Guardium 11.3 could allow a an authenticated user to obtain sensitive information that could be used in further attacks against the system. IBM X-Force ID: 196345.
CVE-2021-38651 1 Microsoft 3 Sharepoint Enterprise Server, Sharepoint Foundation, Sharepoint Server 2021-09-27 3.5 LOW 3.5 LOW
Microsoft SharePoint Server Spoofing Vulnerability This CVE ID is unique from CVE-2021-38652.
CVE-2021-38632 1 Microsoft 4 Windows 10, Windows Server 2016, Windows Server 2019 and 1 more 2021-09-27 2.1 LOW 4.6 MEDIUM
BitLocker Security Feature Bypass Vulnerability
CVE-2021-38624 1 Microsoft 4 Windows 10, Windows Server 2016, Windows Server 2019 and 1 more 2021-09-27 4.0 MEDIUM 6.5 MEDIUM
Windows Key Storage Provider Security Feature Bypass Vulnerability
CVE-2021-38650 1 Microsoft 2 365 Apps, Office 2021-09-27 4.3 MEDIUM 3.5 LOW
Microsoft Office Spoofing Vulnerability
CVE-2021-40669 1 Wuzhicms 1 Wuzhicms 2021-09-27 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords parameter under the coreframe/app/promote/admin/index.php file.
CVE-2021-23051 1 F5 11 Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager, Big-ip Advanced Web Application Firewall and 8 more 2021-09-27 5.0 MEDIUM 7.5 HIGH
On BIG-IP versions 15.1.0.4 through 15.1.3, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP on Amazon Web Services (AWS) systems, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. This is due to an incomplete fix for CVE-2020-5862. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2005-2410 1 Gnome 1 Networkmanager 2021-09-27 7.5 HIGH N/A
Format string vulnerability in the nm_info_handler function in Network Manager may allow remote attackers to execute arbitrary code via format string specifiers in a Wireless Access Point identifier, which is not properly handled in a syslog call.
CVE-2020-14130 1 Mi 1 Xiaomi 2021-09-27 5.0 MEDIUM 5.3 MEDIUM
Some js interfaces in the Xiaomi community were exposed, causing sensitive functions to be maliciously called on Xiaomi community app Affected Version <3.0.210809