Total CVEs

157

Critical

13

Important

109

Exploited

4

Publicly Disclosed

9

All CVEs this month 157

CVE Title Severity CVSS Product Exploited Disclosed Diffed
ADV210003 Mitigating NTLM Relay Attacks on Active Directory Certificate Services (AD CS) Moderate - Windows NTLM - Yes -
CVE-2021-30541 Chromium: CVE-2021-30541 Use after free in V8 8.8 Microsoft Edge (Chromium-based) - - -
CVE-2021-30559 Chromium: CVE-2021-30559 Out of bounds write in ANGLE 8.8 Microsoft Edge (Chromium-based) - - -
CVE-2021-30560 Chromium: CVE-2021-30560 Use after free in Blink XSLT 8.8 Microsoft Edge (Chromium-based) - - -
CVE-2021-30561 Chromium: CVE-2021-30561 Type Confusion in V8 8.8 Microsoft Edge (Chromium-based) - - -
CVE-2021-30562 Chromium: CVE-2021-30562 Use after free in WebSerial 8.8 Microsoft Edge (Chromium-based) - - -
CVE-2021-30563 Chromium: CVE-2021-30563 Type Confusion in V8 8.8 Microsoft Edge (Chromium-based) - - -
CVE-2021-30564 Chromium: CVE-2021-30564 Heap buffer overflow in WebXR 8.8 Microsoft Edge (Chromium-based) - - -
CVE-2021-30565 Chromium: CVE-2021-30565 Out of bounds write in Tab Groups 8.8 Microsoft Edge (Chromium-based) - - -
CVE-2021-30566 Chromium: CVE-2021-30566 Stack buffer overflow in Printing 8.8 Microsoft Edge (Chromium-based) - - -
CVE-2021-30567 Chromium: CVE-2021-30567 Use after free in DevTools 8.8 Microsoft Edge (Chromium-based) - - -
CVE-2021-30568 Chromium: CVE-2021-30568 Heap buffer overflow in WebGL 8.8 Microsoft Edge (Chromium-based) - - -
CVE-2021-30569 Chromium: CVE-2021-30569 Use after free in sqlite 8.8 Microsoft Edge (Chromium-based) - - -
CVE-2021-30571 Chromium: CVE-2021-30571 Insufficient policy enforcement in DevTools 9.6 Microsoft Edge (Chromium-based) - - -
CVE-2021-30572 Chromium: CVE-2021-30572 Use after free in Autofill 8.8 Microsoft Edge (Chromium-based) - - -
CVE-2021-30573 Chromium: CVE-2021-30573 Use after free in GPU 8.8 Microsoft Edge (Chromium-based) - - -
CVE-2021-30574 Chromium: CVE-2021-30574 Use after free in protocol handling 8.8 Microsoft Edge (Chromium-based) - - -
CVE-2021-30575 Chromium: CVE-2021-30575 Out of bounds read in Autofill 8.8 Microsoft Edge (Chromium-based) - - -
CVE-2021-30576 Chromium: CVE-2021-30576 Use after free in DevTools 8.8 Microsoft Edge (Chromium-based) - - -
CVE-2021-30577 Chromium: CVE-2021-30577 Insufficient policy enforcement in Installer 7.8 Microsoft Edge (Chromium-based) - - -
CVE-2021-30578 Chromium: CVE-2021-30578 Uninitialized Use in Media 8.8 Microsoft Edge (Chromium-based) - - -
CVE-2021-30579 Chromium: CVE-2021-30579 Use after free in UI framework 8.8 Microsoft Edge (Chromium-based) - - -
CVE-2021-30580 Chromium: CVE-2021-30580 Insufficient policy enforcement in Android intents 6.5 Microsoft Edge (Chromium-based) - - -
CVE-2021-30581 Chromium: CVE-2021-30581 Use after free in DevTools 8.8 Microsoft Edge (Chromium-based) - - -
CVE-2021-30582 Chromium: CVE-2021-30582 Inappropriate implementation in Animation 6.5 Microsoft Edge (Chromium-based) - - -
CVE-2021-30583 Chromium: CVE-2021-30583 Insufficient policy enforcement in image handling on Windows 6.5 Microsoft Edge (Chromium-based) - - -
CVE-2021-30584 Chromium: CVE-2021-30584 Incorrect security UI in Downloads 6.5 Microsoft Edge (Chromium-based) - - -
CVE-2021-30585 Chromium: CVE-2021-30585 Use after free in sensor handling 8.8 Microsoft Edge (Chromium-based) - - -
CVE-2021-30586 Chromium: CVE-2021-30586 Use after free in dialog box handling on Windows 8.8 Microsoft Edge (Chromium-based) - - -
CVE-2021-30587 Chromium: CVE-2021-30587 Inappropriate implementation in Compositing on Windows 4.3 Microsoft Edge (Chromium-based) - - -
CVE-2021-30588 Chromium: CVE-2021-30588 Type Confusion in V8 8.8 Microsoft Edge (Chromium-based) - - -
CVE-2021-30589 Chromium: CVE-2021-30589 Insufficient validation of untrusted input in Sharing 4.3 Microsoft Edge (Chromium-based) - - -
CVE-2021-31183 Windows TCP/IP Driver Denial of Service Vulnerability Important 7.5 Windows TCP/IP - - -
CVE-2021-31196 Microsoft Exchange Server Remote Code Execution Vulnerability Important 7.2 Microsoft Exchange Server - - -
CVE-2021-31206 Microsoft Exchange Server Remote Code Execution Vulnerability Important 7.6 Microsoft Exchange Server - - -
CVE-2021-31947 HEVC Video Extensions Remote Code Execution Vulnerability Important 7.8 Microsoft Windows Codecs Library - - -
CVE-2021-31961 Windows InstallService Elevation of Privilege Vulnerability Important 6.1 Windows Installer - - -
CVE-2021-31979 Windows Kernel Elevation of Privilege Vulnerability Important 7.8 Windows Kernel Yes - -
CVE-2021-31984 Power BI Remote Code Execution Vulnerability Important 7.6 Power BI - - -
CVE-2021-32740 Regular Expression Denial of Service in Addressable templates Important 7.5 Mariner - - -
CVE-2021-33740 Windows Media Remote Code Execution Vulnerability Critical 7.8 Microsoft Windows Codecs Library - - -
CVE-2021-33743 Windows Projected File System Elevation of Privilege Vulnerability Important 7.8 Windows Projected File System - - -
CVE-2021-33744 Windows Secure Kernel Mode Security Feature Bypass Vulnerability Important 5.3 Windows Secure Kernel Mode - - -
CVE-2021-33745 Windows DNS Server Denial of Service Vulnerability Important 6.5 Role: DNS Server - - -
CVE-2021-33746 Windows DNS Server Remote Code Execution Vulnerability Important 8 Windows DNS - - -
CVE-2021-33749 Windows DNS Snap-in Remote Code Execution Vulnerability Important 8.8 Role: DNS Server - - -
CVE-2021-33750 Windows DNS Snap-in Remote Code Execution Vulnerability Important 8.8 Role: DNS Server - - -
CVE-2021-33751 Windows Storage Spaces Controller Elevation of Privilege Vulnerability Important 7 Windows Storage Spaces Controller - - -
CVE-2021-33752 Windows DNS Snap-in Remote Code Execution Vulnerability Important 8.8 Role: DNS Server - - -
CVE-2021-33753 Microsoft Bing Search Spoofing Vulnerability Important 4.7 Microsoft Bing - - -
CVE-2021-33754 Windows DNS Server Remote Code Execution Vulnerability Important 8 Windows DNS - - -
CVE-2021-33755 Windows Hyper-V Denial of Service Vulnerability Important 6.3 Role: Windows Hyper-V - - -
CVE-2021-33756 Windows DNS Snap-in Remote Code Execution Vulnerability Important 8.8 Role: DNS Server - - -
CVE-2021-33757 Windows Security Account Manager Remote Protocol Security Feature Bypass Vulnerability Important 5.3 Windows Security Account Manager - - -
CVE-2021-33758 Windows Hyper-V Denial of Service Vulnerability Important 7.7 Role: Windows Hyper-V - - -
CVE-2021-33759 Windows Desktop Bridge Elevation of Privilege Vulnerability Important 7.8 Windows Desktop Bridge - - -
CVE-2021-33760 Media Foundation Information Disclosure Vulnerability Important 5.5 Microsoft Windows Codecs Library - - Yes
CVE-2021-33761 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability Important 7.8 Windows Remote Access Connection Manager - - -
CVE-2021-33763 Windows Remote Access Connection Manager Information Disclosure Vulnerability Important 5.5 Windows Remote Access Connection Manager - - -
CVE-2021-33764 Windows Key Distribution Center Information Disclosure Vulnerability Important 5.9 Windows Key Distribution Center - - -
CVE-2021-33765 Windows Installer Spoofing Vulnerability Important 6.2 Windows Installer - - -
CVE-2021-33766 Microsoft Exchange Server Information Disclosure Vulnerability Important 7.3 Microsoft Exchange Server - - -
CVE-2021-33767 Open Enclave SDK Elevation of Privilege Vulnerability Important 8.2 OpenEnclave - - -
CVE-2021-33768 Microsoft Exchange Server Elevation of Privilege Vulnerability Important 8 Microsoft Exchange Server - - -
CVE-2021-33771 Windows Kernel Elevation of Privilege Vulnerability Important 7.8 Windows Kernel Yes - -
CVE-2021-33772 Windows TCP/IP Driver Denial of Service Vulnerability Important 7.5 Windows TCP/IP - - -
CVE-2021-33773 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability Important 7.8 Windows Remote Access Connection Manager - - -
CVE-2021-33774 Windows Event Tracing Elevation of Privilege Vulnerability Important 7 Windows Event Tracing - - -
CVE-2021-33775 HEVC Video Extensions Remote Code Execution Vulnerability Important 7.8 Microsoft Windows Codecs Library - - -
CVE-2021-33776 HEVC Video Extensions Remote Code Execution Vulnerability Important 7.8 Microsoft Windows Codecs Library - - -
CVE-2021-33777 HEVC Video Extensions Remote Code Execution Vulnerability Important 7.8 Microsoft Windows Codecs Library - - -
CVE-2021-33778 HEVC Video Extensions Remote Code Execution Vulnerability Important 7.8 Microsoft Windows Codecs Library - - -
CVE-2021-33779 Windows AD FS Security Feature Bypass Vulnerability Important 8.1 Active Directory Federation Services (AD FS) - Yes -
CVE-2021-33780 Windows DNS Server Remote Code Execution Vulnerability Important 8.8 Role: DNS Server - - -
CVE-2021-33781 Azure AD Security Feature Bypass Vulnerability Important 8.1 Windows Active Directory - Yes -
CVE-2021-33782 Windows Authenticode Spoofing Vulnerability Important 5.5 Windows Authenticode - - -
CVE-2021-33783 Windows SMB Information Disclosure Vulnerability Important 6.5 Windows SMB - - -
CVE-2021-33784 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Important 7.8 Windows Cloud Files Mini Filter Driver - - -
CVE-2021-33785 Windows AF_UNIX Socket Provider Denial of Service Vulnerability Important 7.5 Windows AF_UNIX Socket Provider - - -
CVE-2021-33786 Windows LSA Security Feature Bypass Vulnerability Important 8.1 Windows Local Security Authority Subsystem Service (LSASS) - - -
CVE-2021-33788 Windows LSA Denial of Service Vulnerability Important 7.5 Windows Local Security Authority Subsystem Service (LSASS) - - -
CVE-2021-33910 basic/unit-name.c in systemd prior to 246.15 247.8 248.5 and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash. Moderate 5.5 Mariner - - -
CVE-2021-34438 Windows Font Driver Host Remote Code Execution Vulnerability Important 7.8 Microsoft Graphics Component - - -
CVE-2021-34439 Microsoft Windows Media Foundation Remote Code Execution Vulnerability Critical 7.8 Microsoft Windows Media Foundation - - -
CVE-2021-34440 GDI+ Information Disclosure Vulnerability Important 5.5 Microsoft Graphics Component - - -
CVE-2021-34441 Microsoft Windows Media Foundation Remote Code Execution Vulnerability Important 7.8 Microsoft Windows Media Foundation - - -
CVE-2021-34442 Windows DNS Server Remote Code Execution Vulnerability Important 8.8 Role: DNS Server - - -
CVE-2021-34444 Windows DNS Server Denial of Service Vulnerability Important 6.5 Role: DNS Server - - -
CVE-2021-34445 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability Important 7.8 Windows Remote Access Connection Manager - - -
CVE-2021-34446 Windows HTML Platforms Security Feature Bypass Vulnerability Important 8 Windows HTML Platform - - -
CVE-2021-34447 Windows MSHTML Platform Remote Code Execution Vulnerability Important 6.8 Windows MSHTML Platform - - -
CVE-2021-34448 Scripting Engine Memory Corruption Vulnerability Critical 6.8 Microsoft Scripting Engine Yes - -
CVE-2021-34449 Win32k Elevation of Privilege Vulnerability Important 7 Windows Win32K - - -
CVE-2021-34450 Windows Hyper-V Remote Code Execution Vulnerability Critical 8.5 Role: Windows Hyper-V - - -
CVE-2021-34451 Microsoft Office Online Server Spoofing Vulnerability Important 5.3 Microsoft Office - - -
CVE-2021-34452 Microsoft Word Remote Code Execution Vulnerability Important 7.8 Microsoft Office - - -
CVE-2021-34454 Windows Remote Access Connection Manager Information Disclosure Vulnerability Important 5.5 Windows Shell - - -
CVE-2021-34455 Windows File History Service Elevation of Privilege Vulnerability Important 7.8 Windows File History Service - - -
CVE-2021-34456 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability Important 7.8 Windows Remote Access Connection Manager - - -
CVE-2021-34457 Windows Remote Access Connection Manager Information Disclosure Vulnerability Important 5.5 Windows Remote Access Connection Manager - - -
CVE-2021-34458 Windows Kernel Remote Code Execution Vulnerability Critical 9.9 Windows Kernel - - -
CVE-2021-34459 Windows AppContainer Elevation Of Privilege Vulnerability Important 7.8 Windows AppContainer - - -
CVE-2021-34460 Windows Storage Spaces Controller Elevation of Privilege Vulnerability Important 7.8 Windows Storage Spaces Controller - - -
CVE-2021-34461 Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability Important 7.8 Windows Kernel - - -
CVE-2021-34462 Windows AppX Deployment Extensions Elevation of Privilege Vulnerability Important 7 Windows AppX Deployment Extensions - - -
CVE-2021-34464 Microsoft Defender Remote Code Execution Vulnerability Critical 7.8 Microsoft Defender - - -
CVE-2021-34466 Windows Hello Security Feature Bypass Vulnerability Important 5.7 Windows Hello - - -
CVE-2021-34467 Microsoft SharePoint Server Remote Code Execution Vulnerability Important 7.1 Microsoft Office SharePoint - - -
CVE-2021-34468 Microsoft SharePoint Server Remote Code Execution Vulnerability Important 7.1 Microsoft Office SharePoint - - -
CVE-2021-34469 Microsoft Office Security Feature Bypass Vulnerability Important 8.2 Microsoft Office - - -
CVE-2021-34470 Microsoft Exchange Server Elevation of Privilege Vulnerability Important 8 Microsoft Exchange Server - - -
CVE-2021-34473 Microsoft Exchange Server Remote Code Execution Vulnerability Critical 9.1 Microsoft Exchange Server - Yes -
CVE-2021-34474 Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability Critical 8 Dynamics Business Central Control - - -
CVE-2021-34476 Bowser.sys Denial of Service Vulnerability Important 7.5 Common Internet File System - - -
CVE-2021-34477 Visual Studio Code .NET Runtime Elevation of Privilege Vulnerability Important 7.8 Visual Studio Code - .NET Runtime - - -
CVE-2021-34479 Microsoft Visual Studio Spoofing Vulnerability Important 7.8 Visual Studio Code - - -
CVE-2021-34481 Windows Print Spooler Remote Code Execution Vulnerability Important 8.8 Windows Print Spooler Components - Yes -
CVE-2021-34488 Windows Console Driver Elevation of Privilege Vulnerability Important 7.8 Windows Console Driver - - -
CVE-2021-34489 DirectWrite Remote Code Execution Vulnerability Important 7.8 Microsoft Graphics Component - - -
CVE-2021-34490 Windows TCP/IP Driver Denial of Service Vulnerability Important 7.5 Windows TCP/IP - - -
CVE-2021-34491 Win32k Information Disclosure Vulnerability Important 5.5 Windows Win32K - - -
CVE-2021-34492 Windows Certificate Spoofing Vulnerability Important 8.1 Windows PFX Encryption - Yes -
CVE-2021-34493 Windows Partition Management Driver Elevation of Privilege Vulnerability Important 6.7 Windows Partition Management Driver - - -
CVE-2021-34494 Windows DNS Server Remote Code Execution Vulnerability Critical 8.8 Role: DNS Server - - -
CVE-2021-34496 Windows GDI Information Disclosure Vulnerability Important 5.5 Microsoft Graphics Component - - -
CVE-2021-34497 Windows MSHTML Platform Remote Code Execution Vulnerability Critical 6.8 Windows MSHTML Platform - - -
CVE-2021-34498 Windows GDI Elevation of Privilege Vulnerability Important 7.8 Microsoft Graphics Component - - -
CVE-2021-34499 Windows DNS Server Denial of Service Vulnerability Important 6.5 Windows DNS - - -
CVE-2021-34500 Windows Kernel Memory Information Disclosure Vulnerability Important 6.3 Windows Kernel - - -
CVE-2021-34501 Microsoft Excel Remote Code Execution Vulnerability Important 7.8 Microsoft Office Excel - - -
CVE-2021-34503 Microsoft Windows Media Foundation Remote Code Execution Vulnerability Critical 7.8 Microsoft Windows Media Foundation - - Yes
CVE-2021-34504 Windows Address Book Remote Code Execution Vulnerability Important 7.8 Windows Address Book - - -
CVE-2021-34507 Windows Remote Assistance Information Disclosure Vulnerability Important 6.5 Windows Remote Assistance - - -
CVE-2021-34508 Windows Kernel Remote Code Execution Vulnerability Important 8.8 Windows Kernel - - -
CVE-2021-34509 Storage Spaces Controller Information Disclosure Vulnerability Important 5.5 Windows Storage Spaces Controller - - -
CVE-2021-34510 Windows Storage Spaces Controller Elevation of Privilege Vulnerability Important 7.8 Windows Storage Spaces Controller - - -
CVE-2021-34511 Windows Installer Elevation of Privilege Vulnerability Important 7.8 Windows Installer - - -
CVE-2021-34512 Windows Storage Spaces Controller Elevation of Privilege Vulnerability Important 7.8 Windows Storage Spaces Controller - - -
CVE-2021-34513 Windows Storage Spaces Controller Elevation of Privilege Vulnerability Important 7.8 Windows Storage Spaces Controller - - -
CVE-2021-34514 Windows Kernel Elevation of Privilege Vulnerability Important 7.8 Windows Kernel - - -
CVE-2021-34516 Win32k Elevation of Privilege Vulnerability Important 7.8 Windows Win32K - - -
CVE-2021-34517 Microsoft SharePoint Server Spoofing Vulnerability Important 5.3 Microsoft Office SharePoint - - -
CVE-2021-34518 Microsoft Excel Remote Code Execution Vulnerability Important 7.8 Microsoft Office Excel - - -
CVE-2021-34519 Microsoft SharePoint Server Information Disclosure Vulnerability Moderate 5.3 Microsoft Office SharePoint - - -
CVE-2021-34520 Microsoft SharePoint Server Remote Code Execution Vulnerability Important 8.1 Microsoft Office SharePoint - - -
CVE-2021-34521 Raw Image Extension Remote Code Execution Vulnerability Important 7.8 Microsoft Windows Codecs Library - - -
CVE-2021-34522 Microsoft Defender Remote Code Execution Vulnerability Critical 7.8 Microsoft Defender - - -
CVE-2021-34523 Microsoft Exchange Server Elevation of Privilege Vulnerability Important 9 Microsoft Exchange Server - Yes -
CVE-2021-34525 Windows DNS Server Remote Code Execution Vulnerability Important 8.8 Role: DNS Server - - -
CVE-2021-34527 Windows Print Spooler Remote Code Execution Vulnerability Critical 8.8 Windows Print Spooler Components Yes Yes -
CVE-2021-34528 Visual Studio Code Remote Code Execution Vulnerability Important 7.8 Visual Studio Code - - -
CVE-2021-34529 Visual Studio Code Remote Code Execution Vulnerability Important 7.8 Visual Studio Code - - -
CVE-2021-34558 The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange allowing a malicious TLS server to cause a TLS client to panic. Moderate 6.5 Mariner - - -
CVE-2021-36928 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Important 6 Microsoft Edge (Chromium-based) - - -
CVE-2021-36929 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability Important 6.3 Microsoft Edge (Chromium-based) - - -
CVE-2021-36931 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Important 4.4 Microsoft Edge (Chromium-based) - - -
CVE-2021-36934 Windows Elevation of Privilege Vulnerability Important 7.8 Microsoft Windows - Yes -

Threat Categories 7

Threat Category CVEs Critical
Remote Code Execution 46 13
Elevation of Privilege 35 -
Unknown 34 -
Information Disclosure 15 -
Denial of Service 11 -
Security Feature Bypass 8 -
Spoofing 8 -

Affected Products 55

Product CVEs Exploited
Microsoft Edge (Chromium-based) 34 -
Role: DNS Server 10 -
Microsoft Windows Codecs Library 8 -
Microsoft Exchange Server 7 -
Windows Kernel 7 2
Windows Remote Access Connection Manager 6 -
Windows Storage Spaces Controller 6 -
Microsoft Graphics Component 5 -
Microsoft Office SharePoint 5 -
Mariner 3 -
Microsoft Office 3 -
Microsoft Windows Media Foundation 3 -
Role: Windows Hyper-V 3 -
Visual Studio Code 3 -
Windows DNS 3 -
Windows Installer 3 -
Windows TCP/IP 3 -
Windows Win32K 3 -
Microsoft Defender 2 -
Microsoft Office Excel 2 -
Windows Local Security Authority Subsystem Service (LSASS) 2 -
Windows MSHTML Platform 2 -
Windows Print Spooler Components 2 1
Active Directory Federation Services (AD FS) 1 -
Common Internet File System 1 -
Dynamics Business Central Control 1 -
Microsoft Bing 1 -
Microsoft Scripting Engine 1 1
Microsoft Windows 1 -
OpenEnclave 1 -
Power BI 1 -
Visual Studio Code - .NET Runtime 1 -
Windows AF_UNIX Socket Provider 1 -
Windows Active Directory 1 -
Windows Address Book 1 -
Windows AppContainer 1 -
Windows AppX Deployment Extensions 1 -
Windows Authenticode 1 -
Windows Cloud Files Mini Filter Driver 1 -
Windows Console Driver 1 -
Windows Desktop Bridge 1 -
Windows Event Tracing 1 -
Windows File History Service 1 -
Windows HTML Platform 1 -
Windows Hello 1 -
Windows Key Distribution Center 1 -
Windows NTLM 1 -
Windows PFX Encryption 1 -
Windows Partition Management Driver 1 -
Windows Projected File System 1 -
Windows Remote Assistance 1 -
Windows SMB 1 -
Windows Secure Kernel Mode 1 -
Windows Security Account Manager 1 -
Windows Shell 1 -