CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2021-20133

    Last Modified: 21 Nov 2024

    Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 are affected by an absolute path traversal vulnerability that allows a remote, authenticated attacker to set the "message of the day" banner to any file on the system, allowing them to read all or some of the contents of those files. Such sensitive information as hashed credentials, hardcoded plaintext passwords for other services, configuration files, and private keys can be disclosed in this fashion. Improper handling of filenames that identify virtual resources, such as "/dev/urandom" allows an attacker to effect a denial of service attack against the command line interfaces of the Quagga services (zebra and ripd).

    Published: 30 Dec 2021
    8.8
    High

    CVE-2021-20132

    Last Modified: 21 Nov 2024

    Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 use default hard-coded credentials, which can allow a remote attacker to gain administrative access to the zebra or ripd those services. Both are running with root privileges on the router (i.e., as the "admin" user, UID 0).

    Published: 30 Dec 2021
    8.8
    High

    CVE-2021-45379

    Last Modified: 21 Nov 2024

    Glewlwyd 2.0.0, fixed in 2.6.1 is affected by an incorrect access control vulnerability. One user can attempt to log in as another user without its password.

    Published: 30 Dec 2021
    6.1
    Medium

    CVE-2021-38876

    Last Modified: 21 Nov 2024

    IBM i 7.2, 7.3, and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 208404.

    Published: 30 Dec 2021
    6.5
    Medium

    CVE-2020-29292

    Last Modified: 21 Nov 2024

    iBall WRD12EN 1.0.0 devices allow cross-site request forgery (CSRF) attacks as demonstrated by enabling DNS settings or modifying the range for IP addresses.

    Published: 30 Dec 2021
    3.7
    Low

    CVE-2021-43862

    Last Modified: 21 Nov 2024

    jQuery Terminal Emulator is a plugin for creating command line interpreters in your applications. Versions prior to 2.31.1 contain a low impact and limited cross-site scripting (XSS) vulnerability. The code for XSS payload is always visible, but an attacker can use other techniques to hide the code the victim sees. If the application uses the `execHash` option and executes code from URL, the attacker can use this URL to execute their code. The scope is limited because the javascript attribute used is added to span tag, so no automatic execution like with `onerror` on images is possible. This issue is fixed in version 2.31.1. As a workaround, the user can use formatting that wrap whole user input and its no op. The code for this workaround is available in the GitHub Security Advisory. The fix will only work when user of the library is not using different formatters (e.g. to highlight code in different way).

    Published: 30 Dec 2021
    7.2
    High

    CVE-2021-43861

    Last Modified: 21 Nov 2024

    Mermaid is a Javascript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. Prior to version 8.13.8, malicious diagrams can run javascript code at diagram readers' machines. Users should upgrade to version 8.13.8 to receive a patch. There are no known workarounds aside from upgrading.

    Published: 30 Dec 2021
    6.1
    Medium

    CVE-2021-45815

    Last Modified: 21 Nov 2024

    Quectel UC20 UMTS/HSPA+ UC20 6.3.14 is affected by a Cross Site Scripting (XSS) vulnerability.

    Published: 30 Dec 2021
    6.1
    Medium

    CVE-2021-45818

    Last Modified: 21 Nov 2024

    SAFARI Montage 8.7.32 is affected by a CRLF injection vulnerability which can lead to HTTP response splitting.

    Published: 30 Dec 2021
    9.8
    Critical

    CVE-2021-45427

    Last Modified: 21 Nov 2024

    Emerson XWEB 300D EVO 3.0.7--3ee403 is affected by: unauthenticated arbitrary file deletion due to path traversal. An attacker can browse and delete files without any authentication due to incorrect access control and directory traversal.

    Published: 30 Dec 2021
    7.5
    High

    CVE-2021-4188

    Last Modified: 21 Nov 2024

    mruby is vulnerable to NULL Pointer Dereference

    Published: 30 Dec 2021
    8.8
    High

    CVE-2021-43876

    Last Modified: 21 Nov 2024

    Microsoft SharePoint Elevation of Privilege Vulnerability

    Published: 29 Dec 2021
    6.1
    Medium

    CVE-2021-36724

    Last Modified: 21 Nov 2024

    ForeScout - SecureConnector Local Service DoS - A low privilaged user which doesn't have permissions to shutdown the secure connector service writes a large amount of characters in the installationPath. This will cause the buffer to overflow and override the stack cookie causing the service to crash.

    Published: 29 Dec 2021
    5.4
    Medium

    CVE-2021-25993

    Last Modified: 30 Apr 2025

    In Requarks wiki.js, versions 2.0.0-beta.147 to 2.5.255 are affected by Stored XSS vulnerability, where a low privileged (editor) user can upload a SVG file that contains malicious JavaScript while uploading assets in the page. That will send the JWT tokens to the attacker’s server and will lead to account takeover when accessed by the victim.

    Published: 29 Dec 2021
    7.5
    High

    CVE-2021-45885

    Last Modified: 21 Nov 2024

    An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8). Under a specific update-migration scenario, the first SSH password change does not properly clear the old password.

    Published: 29 Dec 2021
    5.4
    Medium

    CVE-2021-4175

    Last Modified: 21 Nov 2024

    livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 29 Dec 2021
    6.1
    Medium

    CVE-2021-4176

    Last Modified: 21 Nov 2024

    livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 29 Dec 2021
    7.1
    High

    CVE-2021-36722

    Last Modified: 21 Nov 2024

    Emuse - eServices / eNvoice SQL injection can be used in various ways ranging from bypassing login authentication or dumping the whole database to full RCE on the affected endpoints. The SQLi caused by CWE-209: Generation of Error Message Containig Sensetive Information, showing parts of the aspx code and the webroot location , information an attacker can leverage to further compromise the host.

    Published: 29 Dec 2021
    6.1
    Medium

    CVE-2021-36723

    Last Modified: 21 Nov 2024

    Emuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of identification mechanisms and predictable IDs an attacker can scrape all the files on the service.

    Published: 29 Dec 2021
    7.1
    High

    CVE-2021-38688

    Last Modified: 21 Nov 2024

    An improper authentication vulnerability has been reported to affect Android App Qfile. If exploited, this vulnerability allows attackers to compromise app and access information We have already fixed this vulnerability in the following versions of Qfile: Qfile 3.0.0.1105 and later

    Published: 29 Dec 2021
    8.1
    High

    CVE-2021-38687

    Last Modified: 21 Nov 2024

    A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of Surveillance Station: QTS 5.0.0 (64 bit): Surveillance Station 5.2.0.4.2 ( 2021/10/26 ) and later QTS 5.0.0 (32 bit): Surveillance Station 5.2.0.3.2 ( 2021/10/26 ) and later QTS 4.3.6 (64 bit): Surveillance Station 5.1.5.4.6 ( 2021/10/26 ) and later QTS 4.3.6 (32 bit): Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later QTS 4.3.3: Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later

    Published: 29 Dec 2021
    5.3
    Medium

    CVE-2021-38680

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Kazoo Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Kazoo Server: Kazoo Server 4.11.20 and later

    Published: 29 Dec 2021
    4.9
    Medium

    CVE-2021-35035

    Last Modified: 21 Nov 2024

    A cleartext storage of sensitive information vulnerability in the Zyxel NBG6604 firmware could allow a remote, authenticated attacker to obtain sensitive information from the configuration file.

    Published: 29 Dec 2021
    7.4
    High

    CVE-2021-35034

    Last Modified: 21 Nov 2024

    An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote attacker to access the device if the correct token can be intercepted.

    Published: 29 Dec 2021
    5.7
    Medium

    CVE-2021-25991

    Last Modified: 30 Apr 2025

    In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme.

    Published: 29 Dec 2021
    5.4
    Medium

    CVE-2021-25990

    Last Modified: 30 Apr 2025

    In “ifme”, versions v7.22.0 to v7.31.4 are vulnerable against self-stored XSS in the contacts field as it allows loading XSS payloads fetched via an iframe.

    Published: 29 Dec 2021
    5.4
    Medium

    CVE-2021-25989

    Last Modified: 30 Apr 2025

    In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability in the markdown editor. It can be exploited by making a victim a Leader of a group which triggers the payload for them.

    Published: 29 Dec 2021
    5.4
    Medium

    CVE-2021-25988

    Last Modified: 30 Apr 2025

    In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability (notifications section) which can be directly triggered by sending an ally request to the admin.

    Published: 29 Dec 2021
    8.8
    High

    CVE-2021-44161

    Last Modified: 21 Nov 2024

    Changing MOTP (Mobile One Time Password) system’s specific function parameter has insufficient validation for user input. A attacker in local area network can perform SQL injection attack to read, modify or delete backend database without authentication.

    Published: 29 Dec 2021
    7.3
    High

    CVE-2021-44160

    Last Modified: 21 Nov 2024

    Carinal Tien Hospital Health Report System’s login page has improper authentication, a remote attacker can acquire another general user’s privilege by modifying the cookie parameter without authentication. The attacker can then perform limited operations on the system or modify data, making the service partially unavailable to the user.

    Published: 29 Dec 2021
    6.3
    Medium

    CVE-2021-4186

    Last Modified: 3 Nov 2025

    Crash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

    Published: 29 Dec 2021
    7.5
    High

    CVE-2021-4185

    Last Modified: 3 Nov 2025

    Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

    Published: 29 Dec 2021
    7.5
    High

    CVE-2021-4184

    Last Modified: 3 Nov 2025

    Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

    Published: 29 Dec 2021
    5.5
    Medium

    CVE-2021-4183

    Last Modified: 21 Nov 2024

    Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file

    Published: 29 Dec 2021
    7.5
    High

    CVE-2021-4182

    Last Modified: 3 Nov 2025

    Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

    Published: 29 Dec 2021
    7.5
    High

    CVE-2021-23727

    Last Modified: 21 Nov 2024

    This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access to, or somehow manipulate the metadata within a celery backend, they could trigger a stored command injection vulnerability and potentially gain further access to the system.

    Published: 29 Dec 2021
    7.5
    High

    CVE-2021-4190

    Last Modified: 3 Nov 2025

    Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture file

    Published: 29 Dec 2021
    7.5
    High

    CVE-2021-4181

    Last Modified: 3 Nov 2025

    Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

    Published: 29 Dec 2021
    7.8
    High

    CVE-2020-22061

    Last Modified: 21 Nov 2024

    SUPERAntispyware v8.0.0.1050 was discovered to contain an issue in the component saskutil64.sys. This issue allows attackers to arbitrarily write data to the device via IOCTL 0x9C402140.

    Published: 28 Dec 2021
    9.1
    Critical

    CVE-2020-22057

    Last Modified: 21 Nov 2024

    The WinRin0x64.sys and WinRing0.sys low-level drivers in EVGA Precision XOC version v6.2.7 were discovered to be configured with the default security descriptor which allows attackers to access sensitive components and data.

    Published: 28 Dec 2021
    9.8
    Critical

    CVE-2020-7883

    Last Modified: 21 Nov 2024

    Printchaser v2.2021.804.1 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged for code execution.

    Published: 28 Dec 2021
    9.8
    Critical

    CVE-2020-7878

    Last Modified: 21 Nov 2024

    An arbitrary file download and execution vulnerability was found in the VideoOffice X2.9 and earlier versions (CVE-2020-7878). This issue is due to missing support for integrity check.

    Published: 28 Dec 2021
    —
    Unknown

    CVE-2016-3736

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: non

    Published: 28 Dec 2021
    —
    Unknown

    CVE-2016-3103

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: non

    Published: 28 Dec 2021
    —
    Unknown

    CVE-2021-23151

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 28 Dec 2021
    —
    Unknown

    CVE-2021-44771

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 28 Dec 2021
    —
    Unknown

    CVE-2021-3095

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-43551. Reason: This candidate is a reservation duplicate of CVE-2021-43551. Notes: All CVE users should reference CVE-2021-43551 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Dec 2021
    —
    Unknown

    CVE-2021-3090

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-43553. Reason: This candidate is a reservation duplicate of CVE-2021-43553. Notes: All CVE users should reference CVE-2021-43553 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Dec 2021
    7.8
    High

    CVE-2021-43554

    Last Modified: 21 Nov 2024

    FATEK WinProladder Versions 3.30_24518 and prior are vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code.

    Published: 28 Dec 2021
    7.8
    High

    CVE-2021-43556

    Last Modified: 21 Nov 2024

    FATEK WinProladder Versions 3.30_24518 and prior are vulnerable to a stack-based buffer overflow while processing project files, which may allow an attacker to execute arbitrary code.

    Published: 28 Dec 2021