Search Results (34967 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-26870 1 Microsoft 10 Windows 10, Windows 10 1803, Windows 10 1809 and 7 more 2024-11-21 7.8 High
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2021-26869 1 Microsoft 19 Windows 10, Windows 10 1507, Windows 10 1607 and 16 more 2024-11-21 5.5 Medium
Windows ActiveX Installer Service Information Disclosure Vulnerability
CVE-2021-26867 1 Microsoft 7 Windows 10, Windows 10 1809, Windows 10 1909 and 4 more 2024-11-21 9.9 Critical
Windows Hyper-V Remote Code Execution Vulnerability
CVE-2021-26865 1 Microsoft 10 Windows 10, Windows 10 1607, Windows 10 1809 and 7 more 2024-11-21 8.8 High
Windows Container Execution Agent Elevation of Privilege Vulnerability
CVE-2021-26864 1 Microsoft 10 Windows 10, Windows 10 1607, Windows 10 1809 and 7 more 2024-11-21 8.4 High
Windows Virtual Registry Provider Elevation of Privilege Vulnerability
CVE-2021-26861 1 Microsoft 20 Windows 10, Windows 10 1507, Windows 10 1607 and 17 more 2024-11-21 7.8 High
Windows Graphics Component Remote Code Execution Vulnerability
CVE-2021-26860 1 Microsoft 9 Windows 10, Windows 10 1809, Windows 10 1909 and 6 more 2024-11-21 7.8 High
Windows App-V Overlay Filter Elevation of Privilege Vulnerability
CVE-2021-26859 1 Microsoft 1 Power Bi Report Server 2024-11-21 7.7 High
Microsoft Power BI Information Disclosure Vulnerability
CVE-2021-26854 1 Microsoft 1 Exchange Server 2024-11-21 6.6 Medium
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-26786 1 Playtuber Project 1 Playtuber 2024-11-21 8.8 High
An issue was discoverered in in customercentric-selling-poland PlayTube, allows authenticated attackers to execute arbitrary code via the purchace code to the config.php.
CVE-2021-26734 1 Zscaler 1 Client Connector 2024-11-21 4.4 Medium
Zscaler Client Connector Installer on Windows before version 3.4.0.124 improperly handled directory junctions during uninstallation. A local adversary may be able to delete folders in an elevated context.
CVE-2021-26717 1 Digium 2 Asterisk, Certified Asterisk 2024-11-21 7.5 High
An issue was discovered in Sangoma Asterisk 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6. When re-negotiating for T.38, if the initial remote response was delayed just enough, Asterisk would send both audio and T.38 in the SDP. If this happened, and the remote responded with a declined T.38 stream, then Asterisk would crash.
CVE-2021-26701 3 Fedoraproject, Microsoft, Redhat 8 Fedora, .net, .net Core and 5 more 2024-11-21 8.1 High
.NET Core Remote Code Execution Vulnerability
CVE-2021-26688 2 Google, Lg 2 Android, Wing 2024-11-21 9.8 Critical
An issue was discovered on LG Wing mobile devices with Android OS 10 software. The biometric sensor has weak security properties. The LG ID is LVE-SMP-200030 (February 2021).
CVE-2021-26687 1 Google 1 Android 2024-11-21 9.8 Critical
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. In preloaded applications, the HostnameVerified default is mishandled. The LG ID is LVE-SMP-200029 (February 2021).
CVE-2021-26677 2 Arubanetworks, Microsoft 2 Clearpass Policy Manager, Windows 2024-11-21 7.8 High
A local authenticated escalation of privilege vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in ClearPass OnGuard could allow local authenticated users on a Windows platform to elevate their privileges. A successful exploit could allow an attacker to execute arbitrary code with SYSTEM level privileges.
CVE-2021-26676 3 Debian, Intel, Opensuse 3 Debian Linux, Connman, Leap 2024-11-21 6.5 Medium
gdhcp in ConnMan before 1.39 could be used by network-adjacent attackers to leak sensitive stack information, allowing further exploitation of bugs in gdhcp.
CVE-2021-26614 1 Iptime 2 C200, C200 Firmware 2024-11-21 7.5 High
ius_get.cgi in IpTime C200 camera allows remote code execution. A remote attacker may send a crafted parameters to the exposed vulnerable web service interface which invokes the arbitrary shell command.
CVE-2021-26588 1 Hpe 19 3par Os, 3par Storeserv 10400, 3par Storeserv 10800 and 16 more 2024-11-21 9.8 Critical
A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low complexity issue to execute code as administrator. This vulnerability impacts completely the confidentiality, integrity, availability of the array. HPE has made the following software updates and mitigation information to resolve the vulnerability in 3PAR, Primera and Alletra 9000 firmware.
CVE-2021-26586 1 Hp 1 Edgeline Infrastructure Management 2024-11-21 7.5 High
A potential security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software. The vulnerability could be remotely exploited to disclose sensitive information. HPE has made software updates available to resolve the vulnerability in the HPE Edgeline Infrastructure Manager (EIM).