CVE-Datenbank
Archiv bekannter Schwachstellen (CVEs) mit CVSS-Wert, Schweregrad, betroffenen Produkten und Herstellern. Nach Jahr und Schweregrad filterbar.
- CVE-2021-43890Hoch7.1
We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emotet/Trickbot/Bazaloader. An attacker could craft a malicious attachment to be used in phishing campaigns. The attacker would then have to convince the user to open the specially crafted attachment. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Please see the Security Updates table for the link to the updated app. Alternatively you can download and install the Installer using the links provided in the FAQ section. Please see the Mitigations and Workaround sections for important information about steps you can take to protect your system from this vulnerability. December 27 2023 Update: In recent months, Microsoft Threat Intelligence has seen an increase in activity from threat actors leveraging social engineering and phishing techniques to target Windows OS users and utilizing the ms-appinstaller URI scheme. To address this increase in activity, we have updated the App Installer to disable the ms-appinstaller protocol by default and recommend other potential mitigations.
- CVE-2021-43226Hoch7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2021-45046Kritisch9.0
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.
- CVE-2021-39935Mittel6.8
Ein Problem wurde in GitLab CE/EE entdeckt, das alle Versionen ab 10.5 vor 14.3.6, alle Versionen ab 14.4 vor 14.4.4, alle Versionen ab 14.5 vor 14.5.2 betrifft. Nicht autorisierte externe Benutzer konnten serverseitige Anfragen über die CI Lint API durchführen
- CVE-2021-44515Kritisch9.8
Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3. For MSP builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For MSP builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3.
- CVE-2021-44228Kritisch10.0
Apache Log4j2 2.0-beta9 bis 2.15.0 (mit Ausnahme der Security-Releases 2.12.2, 2.12.3 und 2.3.1) JNDI-Funktionen, die in Konfiguration, Log-Meldungen und Parametern verwendet werden, schützen nicht vor vom Angreifer kontrollierten LDAP- und anderen JNDI-bezogenen Endpunkten. Ein Angreifer, der Log-Meldungen oder Log-Meldungsparameter kontrollieren kann, kann beliebigen Code ausführen, der von LDAP-Servern geladen wird, wenn Message Lookup Substitution aktiviert ist. Ab log4j 2.15.0 ist dieses Verhalten standardmäßig deaktiviert. Ab Version 2.16.0 (zusammen mit 2.12.2, 2.12.3 und 2.3.1) wurde diese Funktionalität vollständig entfernt. Beachten Sie, dass diese Schwachstelle spezifisch für log4j-core ist und log4net, log4cxx oder andere Apache Logging Services-Projekte nicht betrifft.
- CVE-2021-44529Kritisch9.8
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
- CVE-2021-27860Kritisch9.8
A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory identifier for this vulnerability is FPSA006.
- CVE-2021-20038Kritisch9.8
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute code as a 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances firmware 10.2.0.8-37sv, 10.2.1.1-19sv, 10.2.1.2-24sv and earlier versions.
- CVE-2021-43798Hoch7.5
Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.
- CVE-2021-23758Hoch8.1
Alle Versionen des Pakets ajaxpro.2 sind anfällig für Deserialization of Untrusted Data aufgrund der Möglichkeit der Deserialisierung beliebiger .NET-Klassen, die zur Erlangung von Remote Code Execution missbraucht werden kann.
- CVE-2021-44077Kritisch9.8
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.
- CVE-2021-38003Hoch8.8
Unangemessene Implementierung in V8 in Google Chrome vor 95.0.4638.69 ermöglichte es einem Remote-Angreifer, über eine speziell erstellte HTML-Seite potenziell Heap-Corruption auszunutzen.
- CVE-2021-38000Mittel6.1
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page.
- CVE-2021-44026Kritisch9.8
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
- CVE-2021-41277Kritisch10.0
Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the application.
- CVE-2021-42321Hoch8.8
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2021-42292Hoch7.8
Microsoft Excel Security Feature Bypass Vulnerability
- CVE-2021-42287Hoch7.5
Schwachstelle zur Erhöhung von Berechtigungen in Active Directory Domain Services
- CVE-2021-42278Hoch7.5
Active Directory Domain Services-Schwachstelle zur Erhöhung von Berechtigungen
This product uses the NVD API but is not endorsed or certified by the NVD.