Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-38586 1 Cpanel 1 Cpanel 2021-08-20 2.1 LOW 4.4 MEDIUM
In cPanel before 98.0.1, /scripts/cpan_config performs unsafe operations on files (SEC-589).
CVE-2021-36932 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2021-08-20 5.0 MEDIUM 7.5 HIGH
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-26433, CVE-2021-36926, CVE-2021-36933.
CVE-2021-36936 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2021-08-20 7.5 HIGH 9.8 CRITICAL
Windows Print Spooler Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-36947, CVE-2021-36958.
CVE-2021-36933 1 Microsoft 6 Windows 10, Windows 8.1, Windows Rt 8.1 and 3 more 2021-08-20 5.0 MEDIUM 7.5 HIGH
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-26433, CVE-2021-36926, CVE-2021-36932.
CVE-2021-36937 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2021-08-20 6.8 MEDIUM 7.8 HIGH
Windows Media MPEG-4 Video Decoder Remote Code Execution Vulnerability
CVE-2021-36941 1 Microsoft 2 365 Apps, Office 2021-08-20 6.8 MEDIUM 7.8 HIGH
Microsoft Word Remote Code Execution Vulnerability
CVE-2021-36940 1 Microsoft 2 Sharepoint Enterprise Server, Sharepoint Server 2021-08-20 4.0 MEDIUM 4.3 MEDIUM
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2021-36938 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2021-08-20 2.1 LOW 5.5 MEDIUM
Windows Cryptographic Primitives Library Information Disclosure Vulnerability
CVE-2021-36945 1 Microsoft 1 Windows 10 Update Assistant 2021-08-20 6.8 MEDIUM 7.8 HIGH
Windows 10 Update Assistant Elevation of Privilege Vulnerability
CVE-2021-36943 1 Microsoft 1 Azure Cyclecloud 2021-08-20 4.6 MEDIUM 7.8 HIGH
Azure CycleCloud Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-33762.
CVE-2021-38087 1 Acronis 1 Cyber Protect 2021-08-20 4.3 MEDIUM 6.1 MEDIUM
Reflected cross-site scripting (XSS) was possible on the login page in Acronis Cyber Protect 15 prior to build 27009.
CVE-2021-36948 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2021-08-20 4.6 MEDIUM 7.8 HIGH
Windows Update Medic Service Elevation of Privilege Vulnerability
CVE-2021-36947 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2021-08-20 6.5 MEDIUM 8.8 HIGH
Windows Print Spooler Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-36936, CVE-2021-36958.
CVE-2021-36946 1 Microsoft 2 Dynamics 365 Business Central, Dynamics Nav 2021-08-20 3.5 LOW 5.4 MEDIUM
Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
CVE-2021-36949 1 Microsoft 2 Azure Active Directory Connect, Azure Active Directory Connect Provisioning Agent 2021-08-20 4.9 MEDIUM 7.1 HIGH
Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability
CVE-2021-34537 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2021-08-20 5.2 MEDIUM 8.0 HIGH
Windows Bluetooth Driver Elevation of Privilege Vulnerability
CVE-2021-36926 1 Microsoft 6 Windows 10, Windows 8.1, Windows Rt 8.1 and 3 more 2021-08-20 5.0 MEDIUM 7.5 HIGH
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-26433, CVE-2021-36932, CVE-2021-36933.
CVE-2021-37626 1 Contao 1 Contao 2021-08-20 6.5 MEDIUM 7.2 HIGH
Contao is an open source CMS that allows you to create websites and scalable web applications. In affected versions it is possible to load PHP files by entering insert tags in the Contao back end. Installations are only affected if they have untrusted back end users who have the rights to modify fields that are shown in the front end. Update to Contao 4.4.56, 4.9.18 or 4.11.7 to resolve. If you cannot update then disable the login for untrusted back end users.
CVE-2021-36788 1 Yoast 1 Yoast Seo 2021-08-20 3.5 LOW 5.4 MEDIUM
The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS.
CVE-2021-36789 1 Dated News Project 1 Dated News 2021-08-20 7.5 HIGH 9.8 CRITICAL
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection.