| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-31207 | Med | 0.72 | 6.6 | 1.00 | KEV | May 11, 2021 | Microsoft Exchange Server Security Feature Bypass Vulnerability | |
| CVE-2021-31166 | Cri | 0.87 | 9.8 | 1.00 | KEV | May 11, 2021 | HTTP Protocol Stack Remote Code Execution Vulnerability | |
| CVE-2021-28664 | Hig | 0.70 | 8.8 | 0.05 | KEV | May 10, 2021 | The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0,… | |
| CVE-2021-28663 | Hig | 0.70 | 8.8 | 0.12 | KEV | May 10, 2021 | The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29p0, and Midgard r4p0… | |
| CVE-2021-31755 | Cri | 0.83 | 9.8 | 0.86 | KEV | May 7, 2021 | An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request. | |
| CVE-2021-1906 | Med | 0.52 | 6.2 | 0.01 | KEV | May 7, 2021 | Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon… | |
| CVE-2021-1905 | Hig | 0.67 | 8.4 | 0.01 | KEV | May 7, 2021 | Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon… | |
| CVE-2021-32030 | Cri | 0.84 | 9.8 | 0.99 | KEV | May 6, 2021 | The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This… | |
| CVE-2021-1498 | Cri | 0.87 | 9.8 | 1.00 | KEV | May 6, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this… | |
| CVE-2021-1497 | Cri | 0.87 | 9.8 | 1.00 | KEV | May 6, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this… | |
| CVE-2021-21551 | Hig | 0.77 | 8.8 | 0.53 | KEV | May 4, 2021 | Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required. | |
| CVE-2021-20090 | Cri | 0.84 | 9.8 | 1.00 | KEV | Apr 29, 2021 | A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote attackers to bypass authentication. | |
| CVE-2021-21224 | Hig | 0.74 | 8.8 | 0.56 | KEV | Apr 26, 2021 | Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. | |
| CVE-2021-21220 | Hig | 0.78 | 8.8 | 0.69 | KEV | Apr 26, 2021 | Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2021-21206 | Hig | 0.70 | 8.8 | 0.09 | KEV | Apr 26, 2021 | Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2021-22205 | Cri | 0.87 | 10.0 | 1.00 | KEV | Apr 23, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution. | |
| CVE-2021-22204 | Med | 0.23 | 6.8 | 1.00 | KEV | Apr 23, 2021 | Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image | |
| CVE-2021-22893 | Cri | 0.87 | 10.0 | 0.47 | KEV | Apr 23, 2021 | Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code… | |
| CVE-2021-20023 | Med | 0.54 | 4.9 | 0.50 | KEV | Apr 20, 2021 | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host. | |
| CVE-2021-3493 | Hig | 0.19 | 8.8 | 0.49 | KEV | Apr 17, 2021 | The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu… | |
| CVE-2020-2509 | Cri | 0.78 | 9.8 | 0.33 | KEV | Apr 17, 2021 | A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build… | |
| CVE-2021-28310 | Hig | 0.63 | 7.8 | 0.08 | KEV | Apr 13, 2021 | Win32k Elevation of Privilege Vulnerability | |
| CVE-2021-20022 | Hig | 0.66 | 7.2 | 0.17 | KEV | Apr 9, 2021 | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host. | |
| CVE-2021-20021 | Cri | 0.88 | 9.8 | 0.83 | KEV | Apr 9, 2021 | A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. | |
| CVE-2021-1879 | Med | 0.52 | 6.1 | 0.07 | KEV | Apr 2, 2021 | This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS 7.3.3. Processing maliciously crafted web content may lead to universal cross site scripting. Apple is aware of a report that this issue… | |
| CVE-2021-1871 | Cri | 0.76 | 9.8 | 0.07 | KEV | Apr 2, 2021 | A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a… | |
| CVE-2021-1870 | Cri | 0.76 | 9.8 | 0.08 | KEV | Apr 2, 2021 | A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a… | |
| CVE-2021-1789 | Hig | 0.70 | 8.8 | 0.13 | KEV | Apr 2, 2021 | A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. Processing maliciously crafted web… | |
| CVE-2021-1782 | Hig | 0.58 | 7.0 | 0.02 | KEV | Apr 2, 2021 | A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application may be able to elevate privileges. Apple… | |
| CVE-2021-22991 | Cri | 0.81 | 9.8 | 0.61 | KEV | Mar 31, 2021 | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traffic Management Microkernel (TMM) URI normalization, which… | |
| CVE-2021-21975 | Hig | 0.76 | 7.5 | 0.78 | KEV | Mar 31, 2021 | Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials. | |
| CVE-2021-22986 | Cri | 0.93 | 9.8 | 1.00 | KEV | Mar 31, 2021 | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution… | |
| CVE-2021-25372 | Med | 0.52 | 6.1 | 0.01 | KEV | Mar 26, 2021 | An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access. | |
| CVE-2021-25371 | Med | 0.52 | 6.1 | 0.01 | KEV | Mar 26, 2021 | A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP. | |
| CVE-2021-25370 | Med | 0.52 | 6.1 | 0.01 | KEV | Mar 26, 2021 | An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic. | |
| CVE-2021-25369 | Med | 0.52 | 6.2 | 0.01 | KEV | Mar 26, 2021 | An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace. | |
| CVE-2021-22506 | Hig | 0.63 | 7.5 | 0.26 | KEV | Mar 26, 2021 | Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage. | |
| CVE-2021-21193 | Hig | 0.70 | 8.8 | 0.10 | KEV | Mar 16, 2021 | Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2021-27085 | Hig | 0.69 | 8.8 | 0.04 | KEV | Mar 11, 2021 | Internet Explorer Remote Code Execution Vulnerability | |
| CVE-2021-27059 | Hig | 0.62 | 7.6 | 0.03 | KEV | Mar 11, 2021 | Microsoft Office Remote Code Execution Vulnerability | |
| CVE-2021-26411 | Hig | 0.82 | 8.8 | 0.81 | KEV | Mar 11, 2021 | Internet Explorer Memory Corruption Vulnerability | |
| CVE-2021-21166 | Hig | 0.71 | 8.8 | 0.24 | KEV | Mar 9, 2021 | Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2021-25337 | Med | 0.41 | 4.4 | 0.03 | KEV | Mar 4, 2021 | Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files. | |
| CVE-2021-22681 | Cri | 0.78 | 9.8 | 0.61 | KEV | Mar 3, 2021 | Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580;… | |
| CVE-2021-27065 | Hig | 0.80 | 7.8 | 1.00 | KEV | Mar 3, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| CVE-2021-26858 | Hig | 0.76 | 7.8 | 0.90 | KEV | Mar 3, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| CVE-2021-26857 | Hig | 0.76 | 7.8 | 0.94 | KEV | Mar 3, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| CVE-2021-26855 | Cri | 0.88 | 9.1 | 1.00 | KEV | Mar 3, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| CVE-2021-27878 | Hig | 0.80 | 8.8 | 0.24 | KEV | Mar 1, 2021 | An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an… | |
| CVE-2021-27877 | Hig | 0.79 | 8.2 | 0.65 | KEV | Mar 1, 2021 | An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer used in current versions of the product, but hadn't yet been disabled. An attacker could remotely… |
- risk 0.72cvss 6.6epss 1.00
Microsoft Exchange Server Security Feature Bypass Vulnerability
- risk 0.87cvss 9.8epss 1.00
HTTP Protocol Stack Remote Code Execution Vulnerability
- risk 0.70cvss 8.8epss 0.05
The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0,…
- risk 0.70cvss 8.8epss 0.12
The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29p0, and Midgard r4p0…
- risk 0.83cvss 9.8epss 0.86
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.
- risk 0.52cvss 6.2epss 0.01
Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…
- risk 0.67cvss 8.4epss 0.01
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…
- risk 0.84cvss 9.8epss 0.99
The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This…
- risk 0.87cvss 9.8epss 1.00
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this…
- risk 0.87cvss 9.8epss 1.00
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this…
- risk 0.77cvss 8.8epss 0.53
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.
- risk 0.84cvss 9.8epss 1.00
A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote attackers to bypass authentication.
- risk 0.74cvss 8.8epss 0.56
Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
- risk 0.78cvss 8.8epss 0.69
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- risk 0.70cvss 8.8epss 0.09
Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- risk 0.87cvss 10.0epss 1.00
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
- risk 0.23cvss 6.8epss 1.00
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
- risk 0.87cvss 10.0epss 0.47
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code…
- risk 0.54cvss 4.9epss 0.50
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
- risk 0.19cvss 8.8epss 0.49
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu…
- risk 0.78cvss 9.8epss 0.33
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build…
- risk 0.63cvss 7.8epss 0.08
Win32k Elevation of Privilege Vulnerability
- risk 0.66cvss 7.2epss 0.17
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
- risk 0.88cvss 9.8epss 0.83
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
- risk 0.52cvss 6.1epss 0.07
This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS 7.3.3. Processing maliciously crafted web content may lead to universal cross site scripting. Apple is aware of a report that this issue…
- risk 0.76cvss 9.8epss 0.07
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a…
- risk 0.76cvss 9.8epss 0.08
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a…
- risk 0.70cvss 8.8epss 0.13
A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. Processing maliciously crafted web…
- risk 0.58cvss 7.0epss 0.02
A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application may be able to elevate privileges. Apple…
- risk 0.81cvss 9.8epss 0.61
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traffic Management Microkernel (TMM) URI normalization, which…
- risk 0.76cvss 7.5epss 0.78
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.
- risk 0.93cvss 9.8epss 1.00
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution…
- risk 0.52cvss 6.1epss 0.01
An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.
- risk 0.52cvss 6.1epss 0.01
A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.
- risk 0.52cvss 6.1epss 0.01
An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic.
- risk 0.52cvss 6.2epss 0.01
An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.
- risk 0.63cvss 7.5epss 0.26
Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage.
- risk 0.70cvss 8.8epss 0.10
Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- risk 0.69cvss 8.8epss 0.04
Internet Explorer Remote Code Execution Vulnerability
- risk 0.62cvss 7.6epss 0.03
Microsoft Office Remote Code Execution Vulnerability
- risk 0.82cvss 8.8epss 0.81
Internet Explorer Memory Corruption Vulnerability
- risk 0.71cvss 8.8epss 0.24
Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- risk 0.41cvss 4.4epss 0.03
Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files.
- risk 0.78cvss 9.8epss 0.61
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580;…
- risk 0.80cvss 7.8epss 1.00
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.76cvss 7.8epss 0.90
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.76cvss 7.8epss 0.94
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.88cvss 9.1epss 1.00
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.80cvss 8.8epss 0.24
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an…
- risk 0.79cvss 8.2epss 0.65
An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer used in current versions of the product, but hadn't yet been disabled. An attacker could remotely…