Total
34640 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2021-38669 | 1 Microsoft | 2 Edge, Edge Chromium | 2024-11-21 | 7.5 HIGH | 6.4 MEDIUM |
|
Microsoft Edge (Chromium-based) Tampering Vulnerability
|
|||||
| CVE-2021-38666 | 1 Microsoft | 10 Windows 10, Windows 11, Windows 7 and 7 more | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
Remote Desktop Client Remote Code Execution Vulnerability
|
|||||
| CVE-2021-38663 | 1 Microsoft | 11 Windows 10, Windows 11, Windows 7 and 8 more | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
Windows exFAT File System Information Disclosure Vulnerability
|
|||||
| CVE-2021-38662 | 1 Microsoft | 11 Windows 10, Windows 11, Windows 7 and 8 more | 2024-11-21 | 4.9 MEDIUM | 5.5 MEDIUM |
|
Windows Fast FAT File System Driver Information Disclosure Vulnerability
|
|||||
| CVE-2021-38661 | 1 Microsoft | 1 Hevc Video Extensions | 2024-11-21 | 6.8 MEDIUM | 7.8 HIGH |
|
HEVC Video Extensions Remote Code Execution Vulnerability
|
|||||
| CVE-2021-38660 | 1 Microsoft | 1 Excel | 2024-11-21 | 6.8 MEDIUM | 7.8 HIGH |
|
Microsoft Office Graphics Remote Code Execution Vulnerability
|
|||||
| CVE-2021-38659 | 1 Microsoft | 1 365 Apps | 2024-11-21 | 6.8 MEDIUM | 7.8 HIGH |
|
Microsoft Office Graphics Remote Code Execution Vulnerability
|
|||||
| CVE-2021-38657 | 1 Microsoft | 1 365 Apps | 2024-11-21 | 2.1 LOW | 6.1 MEDIUM |
|
Microsoft Office Graphics Component Information Disclosure Vulnerability
|
|||||
| CVE-2021-38652 | 1 Microsoft | 2 Sharepoint Enterprise Server, Sharepoint Foundation | 2024-11-21 | 3.5 LOW | 7.6 HIGH |
|
Microsoft SharePoint Server Spoofing Vulnerability
|
|||||
| CVE-2021-38651 | 1 Microsoft | 3 Sharepoint Enterprise Server, Sharepoint Foundation, Sharepoint Server | 2024-11-21 | 3.5 LOW | 7.6 HIGH |
|
Microsoft SharePoint Server Spoofing Vulnerability
|
|||||
| CVE-2021-38650 | 1 Microsoft | 2 365 Apps, Office | 2024-11-21 | 4.3 MEDIUM | 7.6 HIGH |
|
Microsoft Office Spoofing Vulnerability
|
|||||
| CVE-2021-38644 | 1 Microsoft | 1 Mpeg-2 Video Extension | 2024-11-21 | 6.8 MEDIUM | 7.8 HIGH |
|
Microsoft MPEG-2 Video Extension Remote Code Execution Vulnerability
|
|||||
| CVE-2021-38642 | 2 Apple, Microsoft | 2 Iphone Os, Edge | 2024-11-21 | 4.0 MEDIUM | 6.1 MEDIUM |
|
Microsoft Edge for iOS Spoofing Vulnerability
|
|||||
| CVE-2021-38641 | 2 Google, Microsoft | 2 Android, Edge | 2024-11-21 | 4.0 MEDIUM | 6.1 MEDIUM |
|
Microsoft Edge for Android Spoofing Vulnerability
|
|||||
| CVE-2021-38637 | 1 Microsoft | 4 Windows 10, Windows Server 2016, Windows Server 2019 and 1 more | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
Windows Storage Information Disclosure Vulnerability
|
|||||
| CVE-2021-38636 | 1 Microsoft | 9 Windows 10, Windows 7, Windows 8.1 and 6 more | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability
|
|||||
| CVE-2021-38635 | 1 Microsoft | 9 Windows 10, Windows 7, Windows 8.1 and 6 more | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability
|
|||||
| CVE-2021-38632 | 1 Microsoft | 4 Windows 10, Windows Server 2016, Windows Server 2019 and 1 more | 2024-11-21 | 2.1 LOW | 5.7 MEDIUM |
|
BitLocker Security Feature Bypass Vulnerability
|
|||||
| CVE-2021-38631 | 1 Microsoft | 10 Windows 10, Windows 11, Windows 7 and 7 more | 2024-11-21 | 2.1 LOW | 4.4 MEDIUM |
|
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
|
|||||
| CVE-2021-38629 | 1 Microsoft | 9 Windows 10, Windows 7, Windows 8.1 and 6 more | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
|
Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability
|
|||||
| CVE-2021-38591 | 1 Google | 1 Android | 2024-11-21 | 2.1 LOW | 3.3 LOW |
|
An issue was discovered on LG mobile devices with Android OS P and Q software for mt6762/mt6765/mt6883. Attackers can change some of the NvRAM content by leveraging the misconfiguration of a debug command. The LG ID is LVE-SMP-210005 (August 2021).
|
|||||
| CVE-2021-38589 | 1 Cpanel | 1 Cpanel | 2024-11-21 | 5.5 MEDIUM | 8.1 HIGH |
|
In cPanel before 96.0.13, scripts/fix-cpanel-perl does not properly restrict the overwriting of files (SEC-588).
|
|||||
| CVE-2021-38586 | 1 Cpanel | 1 Cpanel | 2024-11-21 | 2.1 LOW | 4.4 MEDIUM |
|
In cPanel before 98.0.1, /scripts/cpan_config performs unsafe operations on files (SEC-589).
|
|||||
| CVE-2021-38573 | 1 Foxitsoftware | 2 Foxit Reader, Phantompdf | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because a CombineFiles pathname is not validated.
|
|||||
| CVE-2021-38572 | 1 Foxitsoftware | 2 Foxit Reader, Phantompdf | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because the extractPages pathname is not validated.
|
|||||
| CVE-2021-38565 | 1 Foxitsoftware | 2 Pdf Editor, Pdf Reader | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
An issue was discovered in Foxit PDF Reader before 11.0.1 and PDF Editor before 11.0.1. It allows writing to arbitrary files via submitForm.
|
|||||
| CVE-2021-38549 | 1 Benda | 2 Miracase Hmub500, Miracase Hmub500 Firmware | 2024-11-21 | 4.3 MEDIUM | 5.9 MEDIUM |
|
MIRACASE MHUB500 USB splitters through 2021-08-09, in certain specific use cases in which the device supplies power to audio-output equipment, allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. We assume that the USB splitter supplies power to some speakers. The power indicator LED of the USB splitter is connected directly to the power line, as a result, the intensity of the USB splitter's power indi ...
Show More |
|||||
| CVE-2021-38548 | 1 Jbl | 2 Go 2, Go 2 Firmware | 2024-11-21 | 4.3 MEDIUM | 5.9 MEDIUM |
|
JBL Go 2 devices through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. The power indicator LED of the speakers is connected directly to the power line, as a result, the intensity of a device's power indicator LED is correlative to the power consumption. The sound played by the speakers affects their power consumption and as a result is also correlative to the light intensity of the LE ...
Show More |
|||||
| CVE-2021-38547 | 1 Logitech | 4 S120, S120 Firmware, Z120 and 1 more | 2024-11-21 | 4.3 MEDIUM | 5.9 MEDIUM |
|
Logitech Z120 and S120 speakers through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. The power indicator LED of the speakers is connected directly to the power line, as a result, the intensity of a device's power indicator LED is correlative to the power consumption. The sound played by the speakers affects their power consumption and as a result is also correlative to the light inte ...
Show More |
|||||
| CVE-2021-38546 | 1 Creative | 8 Pebble, Pebble Firmware, Pebble Plus and 5 more | 2024-11-21 | 4.3 MEDIUM | 5.9 MEDIUM |
|
CREATIVE Pebble devices through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. The power indicator LED of the speakers is connected directly to the power line, as a result, the intensity of a device's power indicator LED is correlative to the power consumption. The sound played by the speakers affects their power consumption and as a result is also correlative to the light intensity of ...
Show More |
|||||
| CVE-2021-38545 | 1 Raspberrypi | 4 Raspberry Pi 3 Model B\+, Raspberry Pi 3 Model B\+ Firmware, Raspberry Pi 4 Model B and 1 more | 2024-11-21 | 4.3 MEDIUM | 5.9 MEDIUM |
|
Raspberry Pi 3 B+ and 4 B devices through 2021-08-09, in certain specific use cases in which the device supplies power to audio-output equipment, allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. We assume that the Raspberry Pi supplies power to some speakers. The power indicator LED of the Raspberry Pi is connected directly to the power line, as a result, the intensity of a device's power indicator ...
Show More |
|||||
| CVE-2021-38544 | 1 Sony | 4 Srs-xb33, Srs-xb33 Firmware, Srs-xb43 and 1 more | 2024-11-21 | 4.3 MEDIUM | 5.9 MEDIUM |
|
Sony SRS-XB33 and SRS-XB43 devices through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. The power indicator LED of the speakers is connected directly to the power line, as a result, the intensity of a device's power indicator LED is correlative to the power consumption. The sound played by the speakers affects their power consumption and as a result is also correlative to the light i ...
Show More |
|||||
| CVE-2021-38543 | 1 Tp-link | 2 Ue330, Ue330 Firmware | 2024-11-21 | 4.3 MEDIUM | 5.9 MEDIUM |
|
TP-Link UE330 USB splitter devices through 2021-08-09, in certain specific use cases in which the device supplies power to audio-output equipment, allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. We assume that the USB splitter supplies power to some speakers. The power indicator LED of the USB splitter is connected directly to the power line, as a result, the intensity of the USB splitter's power ...
Show More |
|||||
| CVE-2021-38539 | 1 Netgear | 24 D8500, D8500 Firmware, R6400 and 21 more | 2024-11-21 | 6.5 MEDIUM | 6.3 MEDIUM |
|
Certain NETGEAR devices are affected by privilege escalation. This affects D8500 before 1.0.3.44, R6400v2 before 1.0.2.66, R6700 before 1.0.2.6, R6700v3 before 1.0.2.66, R6900 before 1.0.2.4, R6900P before 1.3.2.126, R7000 before 1.0.9.42, R7000P before 1.3.2.126, R7100LG before 1.0.0.50, R7300DST before 1.0.0.70, R7900 before 1.0.3.10, R8300 before 1.0.2.130, and R8500 before 1.0.2.130.
|
|||||
| CVE-2021-38532 | 1 Netgear | 2 Wac104, Wac104 Firmware | 2024-11-21 | 6.5 MEDIUM | 6.8 MEDIUM |
|
NETGEAR WAC104 devices before 1.0.4.15 are affected by incorrect configuration of security settings.
|
|||||
| CVE-2021-38531 | 1 Netgear | 24 Ac2100, Ac2100 Firmware, Ac2400 and 21 more | 2024-11-21 | 6.5 MEDIUM | 4.7 MEDIUM |
|
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.42, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6260 before 1.1.0.78, R6700v2 before 1.2.0.76, R6800 before 1.2.0.76, R6900v2 before 1.2.0.76, R7450 before 1.2.0.76, AC2100 before 1.2.0.76, and AC2400 before 1.2.0.76.
|
|||||
| CVE-2021-38515 | 1 Netgear | 8 R6400, R6400 Firmware, R6700 and 5 more | 2024-11-21 | 5.0 MEDIUM | 7.4 HIGH |
|
Certain NETGEAR devices are affected by denial of service. This affects R6400v2 before 1.0.4.98, R6700v3 before 1.0.4.98, R7900 before 1.0.3.18, and R8000 before 1.0.4.46.
|
|||||
| CVE-2021-38514 | 1 Netgear | 148 D3600, D3600 Firmware, D6000 and 145 more | 2024-11-21 | 4.0 MEDIUM | 2.4 LOW |
|
Certain NETGEAR devices are affected by authentication bypass. This affects D3600 before 1.0.0.72, D6000 before 1.0.0.72, D6100 before 1.0.0.63, D6200 before 1.1.00.34, D6220 before 1.0.0.48, D6400 before 1.0.0.86, D7000 before 1.0.1.70, D7000v2 before 1.0.0.52, D7800 before 1.0.1.56, D8500 before 1.0.3.44, DC112A before 1.0.0.42, DGN2200v4 before 1.0.0.108, DGND2200Bv4 before 1.0.0.108, EX2700 before 1.0.1.48, EX3700 before 1.0.0.76, EX3800 before 1.0.0.76, EX6000 before 1.0.0.38, EX6100 before ...
Show More |
|||||
| CVE-2021-38513 | 1 Netgear | 22 Cbr40, Cbr40 Firmware, Eax20 and 19 more | 2024-11-21 | 10.0 HIGH | 9.6 CRITICAL |
|
Certain NETGEAR devices are affected by authentication bypass. This affects RBK852 before 3.2.10.11, RBR850 before 3.2.10.11, RBS850 before 3.2.10.11, CBR40 before 2.5.0.10, EAX20 before 1.0.0.48, MK62 before 1.0.6.110, MR60 before 1.0.6.110, MS60 before 1.0.6.110, RBK752 before 3.2.10.10, RBR750 before 3.2.10.10, and RBS750 before 3.2.10.10.
|
|||||
| CVE-2021-38510 | 2 Apple, Mozilla | 4 Macos, Firefox, Firefox Esr and 1 more | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
The executable file warning was not presented when downloading .inetloc files, which, due to a flaw in Mac OS, can run commands on a user's computer.*Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
|
|||||