Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.3

    MEDIUM
    CVE-2021-34418

    The login routine of the web console in the Zoom On-Premise Meeting Connector before version 4.6.239.20200613, Zoom On-Premise Meeting Connector MMR before version 4.6.239.20200613, Zoom On-Premise Recording Connector before version 3.8.42.20200905, Zoom ... Read more

    • EPSS Score: %0.18
    • Published: Nov. 11, 2021
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2021-34417

    The network proxy page on the web portal for the Zoom On-Premise Meeting Connector Controller before version 4.6.365.20210703, Zoom On-Premise Meeting Connector MMR before version 4.6.365.20210703, Zoom On-Premise Recording Connector before version 3.8.45... Read more

    • EPSS Score: %0.49
    • Published: Nov. 11, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-34416

    The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360.20210325, Zoom on-premise Meeting Connector MMR before version 4.6.360.20210325, Zoom on-premise Recording Connector before version 3.8... Read more

    • EPSS Score: %1.58
    • Published: Sep. 27, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-34415

    The Zone Controller service in the Zoom On-Premise Meeting Connector Controller before version 4.6.358.20210205 does not verify the cnt field sent in incoming network packets, which leads to exhaustion of resources and system crash.... Read more

    Affected Products : meeting_connector
    • EPSS Score: %0.37
    • Published: Sep. 27, 2021
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-34414

    The network proxy page on the web portal for the Zoom on-premise Meeting Connector Controller before version 4.6.348.20201217, Zoom on-premise Meeting Connector MMR before version 4.6.348.20201217, Zoom on-premise Recording Connector before version 3.8.42... Read more

    • EPSS Score: %1.59
    • Published: Sep. 27, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-34413

    All versions of the Zoom Plugin for Microsoft Outlook for MacOS before 5.3.52553.0918 contain a Time-of-check Time-of-use (TOC/TOU) vulnerability during the plugin installation process. This could allow a standard user to write their own malicious applica... Read more

    Affected Products : zoom_plugin_for_microsoft_outlook
    • EPSS Score: %0.40
    • Published: Sep. 27, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-34412

    During the installation process for all versions of the Zoom Client for Meetings for Windows before 5.4.0, it is possible to launch Internet Explorer. If the installer was launched with elevated privileges such as by SCCM this can result in a local privil... Read more

    Affected Products : meetings
    • EPSS Score: %0.13
    • Published: Sep. 27, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-34411

    During the installation process forZoom Rooms for Conference Room for Windows before version 5.3.0 it is possible to launch Internet Explorer with elevated privileges. If the installer was launched with elevated privileges such as by SCCM this can result ... Read more

    Affected Products : rooms
    • EPSS Score: %0.04
    • Published: Sep. 27, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-34410

    A user-writable application bundle unpacked during the install for all versions of the Zoom Plugin for Microsoft Outlook for Mac before 5.0.25611.0521 allows for privilege escalation to root.... Read more

    Affected Products : zoom_plugin_for_microsoft_outlook
    • EPSS Score: %0.04
    • Published: Sep. 27, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-34409

    It was discovered that the installation packages of the Zoom Client for Meetings for MacOS (Standard and for IT Admin) installation before version 5.2.0, Zoom Client Plugin for Sharing iPhone/iPad before version 5.2.0, and Zoom Rooms for Conference before... Read more

    Affected Products : rooms meetings screen_sharing
    • EPSS Score: %0.12
    • Published: Sep. 27, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-34408

    The Zoom Client for Meetings for Windows in all versions before version 5.3.2 writes log files to a user writable directory as a privileged user during the installation or update of the client. This could allow for potential privilege escalation if a link... Read more

    Affected Products : meetings
    • EPSS Score: %0.14
    • Published: Sep. 27, 2021
    • Modified: Nov. 21, 2024
  • 4.7

    MEDIUM
    CVE-2021-34406

    NVIDIA Tegra kernel driver contains a vulnerability in NVHost, where a specific race condition can lead to a null pointer dereference, which may lead to a system reboot.... Read more

    Affected Products : android shield_experience
    • EPSS Score: %0.04
    • Published: Jan. 18, 2022
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2021-34405

    NVIDIA Linux distributions contain a vulnerability in TrustZone’s TEE_Malloc function, where an unchecked return value causing a null pointer dereference may lead to denial of service.... Read more

    Affected Products : android shield_experience
    • EPSS Score: %0.04
    • Published: Jan. 18, 2022
    • Modified: Nov. 21, 2024
  • 7.6

    HIGH
    CVE-2021-34404

    Android images for T210 provided by NVIDIA contain a vulnerability in BROM, where failure to limit access to AHB-DMA when BROM fails may allow an unprivileged attacker with physical access to cause denial of service or impact integrity and confidentiality... Read more

    Affected Products : android shield_experience
    • EPSS Score: %0.05
    • Published: Jan. 18, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-34403

    NVIDIA Linux distributions contain a vulnerability in nvmap ioctl, which allows any user with a local account to exploit a use-after-free condition, leading to code privilege escalation, loss of confidentiality and integrity, or denial of service.... Read more

    Affected Products : android shield_experience
    • EPSS Score: %0.06
    • Published: Jan. 18, 2022
    • Modified: Nov. 21, 2024
  • 6.7

    MEDIUM
    CVE-2021-34402

    NVIDIA Tegra kernel driver contains a vulnerability in NVIDIA NVDEC, where a user with high privileges might be able to read from or write to a memory location that is outside the intended boundary of the buffer, which may lead to denial of service, Infor... Read more

    Affected Products : android shield_experience
    • EPSS Score: %0.12
    • Published: Jan. 18, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-34401

    NVIDIA Linux kernel distributions contain a vulnerability in nvmap NVGPU_IOCTL_CHANNEL_SET_ERROR_NOTIFIER, where improper access control may lead to code execution, compromised integrity, or denial of service.... Read more

    Affected Products : android shield_experience
    • EPSS Score: %0.05
    • Published: Jan. 18, 2022
    • Modified: Nov. 21, 2024
  • 4.4

    MEDIUM
    CVE-2021-34400

    NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed memory, which may lead to information disclosure.... Read more

    • EPSS Score: %0.06
    • Published: Nov. 20, 2021
    • Modified: Nov. 21, 2024
  • 4.4

    MEDIUM
    CVE-2021-34399

    NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed registers, which may lead to information disclosure.... Read more

    • EPSS Score: %0.06
    • Published: Nov. 20, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-34398

    NVIDIA DCGM, all versions prior to 2.2.9, contains a vulnerability in the DIAG module where any user can inject shared libraries into the DCGM server, which is usually running as root, which may lead to privilege escalation, total loss of confidentiality ... Read more

    Affected Products : data_center_gpu_manager
    • EPSS Score: %0.04
    • Published: Aug. 13, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 291275 Results