Export limit exceeded: 35470 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (35470 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2021-43955 | 1 Atlassian | 2 Crucible, Fisheye | 2024-11-21 | 4.3 Medium |
| The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote attackers to obtain information about installation directories via information disclosure vulnerability. | ||||
| CVE-2021-43947 | 1 Atlassian | 4 Data Center, Jira, Jira Data Center and 1 more | 2024-11-21 | 7.2 High |
| Affected versions of Atlassian Jira Server and Data Center allow remote attackers with administrator privileges to execute arbitrary code via a Remote Code Execution (RCE) vulnerability in the Email Templates feature. This issue bypasses the fix of https://jira.atlassian.com/browse/JSDSERVER-8665. The affected versions are before version 8.13.15, and from version 8.14.0 before 8.20.3. | ||||
| CVE-2021-43908 | 1 Microsoft | 1 Visual Studio Code | 2024-11-21 | 4.3 Medium |
| Visual Studio Code Spoofing Vulnerability | ||||
| CVE-2021-43907 | 1 Microsoft | 1 Windows Subsystem For Linux | 2024-11-21 | 9.8 Critical |
| Visual Studio Code WSL Extension Remote Code Execution Vulnerability | ||||
| CVE-2021-43899 | 1 Microsoft | 2 Wireless Display Adapter, Wireless Display Adapter Firmware | 2024-11-21 | 9.8 Critical |
| Microsoft 4K Wireless Display Adapter Remote Code Execution Vulnerability | ||||
| CVE-2021-43896 | 1 Microsoft | 2 Cbl Mariner, Powershell | 2024-11-21 | 5.5 Medium |
| Microsoft PowerShell Spoofing Vulnerability | ||||
| CVE-2021-43892 | 1 Microsoft | 1 Biztalk Esb Toolkit | 2024-11-21 | 7.4 High |
| Microsoft BizTalk ESB Toolkit Spoofing Vulnerability | ||||
| CVE-2021-43891 | 1 Microsoft | 1 Visual Studio Code | 2024-11-21 | 7.8 High |
| Visual Studio Code Remote Code Execution Vulnerability | ||||
| CVE-2021-43889 | 1 Microsoft | 1 Defender For Iot | 2024-11-21 | 7.2 High |
| Microsoft Defender for IoT Remote Code Execution Vulnerability | ||||
| CVE-2021-43888 | 1 Microsoft | 1 Defender For Iot | 2024-11-21 | 7.5 High |
| Microsoft Defender for IoT Information Disclosure Vulnerability | ||||
| CVE-2021-43883 | 1 Microsoft | 24 Windows 10, Windows 10 1507, Windows 10 1607 and 21 more | 2024-11-21 | 7.8 High |
| Windows Installer Elevation of Privilege Vulnerability | ||||
| CVE-2021-43880 | 1 Microsoft | 2 Windows 11, Windows 11 21h2 | 2024-11-21 | 5.5 Medium |
| Windows Mobile Device Management Elevation of Privilege Vulnerability | ||||
| CVE-2021-43877 | 1 Microsoft | 3 Asp.net Core, Visual Studio 2019, Visual Studio 2022 | 2024-11-21 | 8.8 High |
| ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability | ||||
| CVE-2021-43876 | 1 Microsoft | 2 Sharepoint Enterprise Server, Sharepoint Server | 2024-11-21 | 8.8 High |
| Microsoft SharePoint Elevation of Privilege Vulnerability | ||||
| CVE-2021-43857 | 1 Gerapy | 1 Gerapy | 2024-11-21 | 9.8 Critical |
| Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched in version 0.9.8. | ||||
| CVE-2021-43803 | 2 Nodejs, Vercel | 2 Node.js, Next.js | 2024-11-21 | 7.5 High |
| Next.js is a React framework. In versions of Next.js prior to 12.0.5 or 11.1.3, invalid or malformed URLs could lead to a server crash. In order to be affected by this issue, the deployment must use Next.js versions above 11.1.0 and below 12.0.5, Node.js above 15.0.0, and next start or a custom server. Deployments on Vercel are not affected, along with similar environments where invalid requests are filtered before reaching Next.js. Versions 12.0.5 and 11.1.3 contain patches for this issue. | ||||
| CVE-2021-43745 | 1 Trillium Notes Project | 1 Trillum Notes | 2024-11-21 | 5.5 Medium |
| A Denial of Service vulnerabilty exists in Trilium Notes 0.48.6 in the setupPage function | ||||
| CVE-2021-43578 | 1 Jenkins | 1 Squash Tm Publisher | 2024-11-21 | 8.1 High |
| Jenkins Squash TM Publisher (Squash4Jenkins) Plugin 1.0.0 and earlier implements an agent-to-controller message that does not implement any validation of its input, allowing attackers able to control agent processes to replace arbitrary files on the Jenkins controller file system with an attacker-controlled JSON string. | ||||
| CVE-2021-43565 | 2 Golang, Redhat | 9 Ssh, Acm, Advanced Cluster Security and 6 more | 2024-11-21 | 7.5 High |
| The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an attacker to panic an SSH server. | ||||
| CVE-2021-43540 | 1 Mozilla | 1 Firefox | 2024-11-21 | 6.5 Medium |
| WebExtensions with the correct permissions were able to create and install ServiceWorkers for third-party websites that would not have been uninstalled with the extension. This vulnerability affects Firefox < 95. | ||||