Search Results (35531 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-36959 1 Microsoft 20 Windows 10, Windows 10 1507, Windows 10 1607 and 17 more 2024-11-21 5.5 Medium
Windows Authenticode Spoofing Vulnerability
CVE-2021-36958 1 Microsoft 18 Windows, Windows 10 1507, Windows 10 1607 and 15 more 2024-11-21 7.8 High
<p>A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</p>
CVE-2021-36956 1 Microsoft 1 Azure Sphere 2024-11-21 4.4 Medium
Azure Sphere Information Disclosure Vulnerability
CVE-2021-36953 1 Microsoft 23 Windows 10, Windows 10 1507, Windows 10 1607 and 20 more 2024-11-21 7.5 High
Windows TCP/IP Denial of Service Vulnerability
CVE-2021-36947 1 Microsoft 19 Windows 10, Windows 10 1507, Windows 10 1607 and 16 more 2024-11-21 8.8 High
Windows Print Spooler Remote Code Execution Vulnerability
CVE-2021-36940 1 Microsoft 2 Sharepoint Enterprise Server, Sharepoint Server 2024-11-21 7.6 High
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2021-36938 1 Microsoft 6 Windows 10, Windows 10 1507, Windows 10 1607 and 3 more 2024-11-21 5.5 Medium
Windows Cryptographic Primitives Library Information Disclosure Vulnerability
CVE-2021-36937 1 Microsoft 19 Windows 10, Windows 10 1507, Windows 10 1607 and 16 more 2024-11-21 7.8 High
Windows Media MPEG-4 Video Decoder Remote Code Execution Vulnerability
CVE-2021-36936 1 Microsoft 19 Windows 10, Windows 10 1507, Windows 10 1607 and 16 more 2024-11-21 8.8 High
Windows Print Spooler Remote Code Execution Vulnerability
CVE-2021-36933 1 Microsoft 15 Windows 10, Windows 10 1507, Windows 10 1607 and 12 more 2024-11-21 7.5 High
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
CVE-2021-36932 1 Microsoft 17 Windows 10, Windows 10 1507, Windows 10 1607 and 14 more 2024-11-21 7.5 High
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
CVE-2021-36929 1 Microsoft 1 Edge Chromium 2024-11-21 6.3 Medium
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2021-36926 1 Microsoft 15 Windows 10, Windows 10 1507, Windows 10 1607 and 12 more 2024-11-21 7.5 High
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
CVE-2021-36925 1 Realtek 1 Rtsupx Usb Utility Driver 2024-11-21 7.8 High
RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve an arbitrary read or write operation from/to physical memory (leading to Escalation of Privileges, Denial of Service, Code Execution, and Information Disclosure) via a crafted Device IO Control packet to a device.
CVE-2021-36923 1 Realtek 1 Rtsupx Usb Utility Driver 2024-11-21 7.8 High
RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve unauthorized access to USB device privileged IN and OUT instructions (leading to Escalation of Privileges, Denial of Service, Code Execution, and Information Disclosure) via a crafted Device IO Control packet to a device.
CVE-2021-36922 1 Realtek 1 Rtsupx Usb Utility Driver 2024-11-21 7.8 High
RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve unauthorized access to USB devices (Escalation of Privileges, Denial of Service, Code Execution, and Information Disclosure) via a crafted Device IO Control packet to a device.
CVE-2021-36809 1 Sophos 1 Ssl Vpn Client 2024-11-21 6.1 Medium
A local attacker can overwrite arbitrary files on the system with VPN client logs using administrator privileges, potentially resulting in a denial of service and data loss, in all versions of Sophos SSL VPN client.
CVE-2021-36797 1 Victronenergy 1 Venus Os 2024-11-21 6.8 Medium
In Victron Energy Venus OS through 2.72, root access is granted by default to anyone with physical access to the device. NOTE: the vendor disagrees with the reporter's opinion about an alleged "security best practices" violation
CVE-2021-36794 1 Siren 1 Investigate 2024-11-21 9.8 Critical
In Siren Investigate before 11.1.4, when enabling the cluster feature of the Siren Alert application, TLS verifications are disabled globally in the Siren Investigate main process.
CVE-2021-36791 1 Dated News Project 1 Dated News 2024-11-21 5.3 Medium
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows Information Disclosure of application registration data.