CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-42583

    Last Modified: 21 Nov 2024

    A Broken or Risky Cryptographic Algorithm exists in Max Mazurov Maddy before 0.5.2, which is an unnecessary risk that may result in the exposure of sensitive information.

    Published: 28 Dec 2021
    9.8
    Critical

    CVE-2021-45814

    Last Modified: 21 Nov 2024

    Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel with an administrative account.

    Published: 28 Dec 2021
    6.1
    Medium

    CVE-2021-45813

    Last Modified: 21 Nov 2024

    SLICAN WebCTI 1.01 2015 is affected by a Cross Site Scripting (XSS) vulnerability. The attacker can steal the user's session by injecting malicious JavaScript codes which leads to Session Hijacking and cause user's credentials theft.

    Published: 28 Dec 2021
    6.1
    Medium

    CVE-2021-45812

    Last Modified: 21 Nov 2024

    NUUO Network Video Recorder NVRsolo 3.9.1 is affected by a Cross Site Scripting (XSS) vulnerability. An attacker can steal the user's session by injecting malicious JavaScript codes which leads to session hijacking.

    Published: 28 Dec 2021
    6.1
    Medium

    CVE-2021-45903

    Last Modified: 21 Nov 2024

    A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x before 7.12.2, allows a remote attacker to introduce arbitrary JavaScript via attachments upload, a different vulnerability than CVE-2021-39267 and CVE-2021-39268.

    Published: 28 Dec 2021
    9.8
    Critical

    CVE-2019-20082

    Last Modified: 21 Nov 2024

    ASUS RT-N53 3.0.0.4.376.3754 devices have a buffer overflow via a long lan_dns1_x or lan_dns2_x parameter to Advanced_LAN_Content.asp.

    Published: 28 Dec 2021
    8.8
    High

    CVE-2018-17875

    Last Modified: 21 Nov 2024

    A remote code execution issue in the ping command on Poly Trio 8800 5.7.1.4145 devices allows remote authenticated users to execute commands via unspecified vectors.

    Published: 28 Dec 2021
    6.1
    Medium

    CVE-2021-45425

    Last Modified: 21 Nov 2024

    Reflected Cross Site Scripting (XSS) in SAFARI Montage versions 8.3 and 8.5 allows remote attackers to execute JavaScript codes.

    Published: 28 Dec 2021
    9.8
    Critical

    CVE-2021-37400

    Last Modified: 21 Nov 2024

    An attacker may obtain the user credentials from the communication between the PLC and the software. As a result, the PLC user program may be uploaded, altered, and/or downloaded.

    Published: 28 Dec 2021
    9.8
    Critical

    CVE-2021-37401

    Last Modified: 21 Nov 2024

    An attacker may obtain the user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a result, the PLC user program may be uploaded, altered, and/or downloaded.

    Published: 28 Dec 2021
    6.5
    Medium

    CVE-2021-40579

    Last Modified: 21 Nov 2024

    https://www.sourcecodester.com/ Online Enrollment Management System in PHP and PayPal Free Source Code 1.0 is affected by: Incorrect Access Control. The impact is: gain privileges (remote).

    Published: 28 Dec 2021
    6.4
    Medium

    CVE-2021-35032

    Last Modified: 21 Nov 2024

    A vulnerability in the 'libsal.so' of the Zyxel GS1900 series firmware version 2.60 could allow an authenticated local user to execute arbitrary OS commands via a crafted function call.

    Published: 28 Dec 2021
    6.8
    Medium

    CVE-2021-35031

    Last Modified: 21 Nov 2024

    A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow an authenticated LAN user to execute arbitrary OS commands via the GUI of the vulnerable device.

    Published: 28 Dec 2021
    5.4
    Medium

    CVE-2021-4179

    Last Modified: 21 Nov 2024

    livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 28 Dec 2021
    5.3
    Medium

    CVE-2021-4177

    Last Modified: 21 Nov 2024

    livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information

    Published: 28 Dec 2021
    8.1
    High

    CVE-2021-20873

    Last Modified: 21 Nov 2024

    Yappli is an application development platform which provides the function to access a requested URL using Custom URL Scheme. When Android apps are developed with Yappli versions since v7.3.6 and prior to v9.30.0, they are vulnerable to improper authorization in Custom URL Scheme handler, and may be directed to unintended sites via a specially crafted URL.

    Published: 28 Dec 2021
    7.8
    High

    CVE-2021-45908

    Last Modified: 21 Nov 2024

    An issue was discovered in gif2apng 1.9. There is a stack-based buffer overflow involving a while loop. An attacker has little influence over the data written to the stack, making it unlikely that the flow of control can be subverted.

    Published: 28 Dec 2021
    7.8
    High

    CVE-2021-45909

    Last Modified: 21 Nov 2024

    An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow vulnerability in the DecodeLZW function. It allows an attacker to write a large amount of arbitrary data outside the boundaries of a buffer.

    Published: 28 Dec 2021
    7.8
    High

    CVE-2021-45910

    Last Modified: 21 Nov 2024

    An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow within the main function. It allows an attacker to write data outside of the allocated buffer. The attacker has control over a part of the address that data is written to, control over the written data, and (to some extent) control over the amount of data that is written.

    Published: 28 Dec 2021
    7.8
    High

    CVE-2021-45911

    Last Modified: 21 Nov 2024

    An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow in the main function. It allows an attacker to write 2 bytes outside the boundaries of the buffer.

    Published: 28 Dec 2021
    7.8
    High

    CVE-2021-45907

    Last Modified: 21 Nov 2024

    An issue was discovered in gif2apng 1.9. There is a stack-based buffer overflow involving a for loop. An attacker has little influence over the data written to the stack, making it unlikely that the flow of control can be subverted.

    Published: 28 Dec 2021
    6.6
    Medium

    CVE-2021-44832

    Last Modified: 29 May 2026

    Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

    Published: 28 Dec 2021
    5.4
    Medium

    CVE-2021-45904

    Last Modified: 21 Nov 2024

    OpenWrt 21.02.1 allows XSS via the Port Forwards Add Name screen.

    Published: 27 Dec 2021
    5.4
    Medium

    CVE-2021-45905

    Last Modified: 21 Nov 2024

    OpenWrt 21.02.1 allows XSS via the Traffic Rules Name screen.

    Published: 27 Dec 2021
    5.4
    Medium

    CVE-2021-45906

    Last Modified: 21 Nov 2024

    OpenWrt 21.02.1 allows XSS via the NAT Rules Name screen.

    Published: 27 Dec 2021
    9.8
    Critical

    CVE-2020-21238

    Last Modified: 21 Nov 2024

    An issue in the user login box of CSCMS v4.0 allows attackers to hijack user accounts via brute force attacks.

    Published: 27 Dec 2021
    9.8
    Critical

    CVE-2020-21237

    Last Modified: 21 Nov 2024

    An issue in the user login box of LJCMS v1.11 allows attackers to hijack user accounts via brute force attacks.

    Published: 27 Dec 2021
    8.8
    High

    CVE-2020-21236

    Last Modified: 21 Nov 2024

    A vulnerability in /damicms-master/admin.php?s=/Article/doedit of DamiCMS v6.0 allows attackers to compromise and impersonate user accounts via obtaining a user's session cookie.

    Published: 27 Dec 2021
    7.5
    High

    CVE-2021-45884

    Last Modified: 21 Nov 2024

    In Brave Desktop 1.17 through 1.33 before 1.33.106, when CNAME-based adblocking and a proxying extension with a SOCKS fallback are enabled, additional DNS requests are issued outside of the proxying extension using the system's DNS settings, resulting in information disclosure. NOTE: this issue exists because of an incomplete fix for CVE-2021-21323 and CVE-2021-22916.

    Published: 27 Dec 2021
    8.8
    High

    CVE-2021-45896

    Last Modified: 21 Nov 2024

    Nokia FastMile 3TG00118ABAD52 devices allow privilege escalation by an authenticated user via is_ctc_admin=1 to login_web_app.cgi and use of Import Config File.

    Published: 27 Dec 2021
    7.5
    High

    CVE-2020-20948

    Last Modified: 21 Nov 2024

    An arbitrary file download vulnerability in jeecg v3.8 allows attackers to access sensitive files via modification of the "localPath" variable.

    Published: 27 Dec 2021
    5.4
    Medium

    CVE-2020-20946

    Last Modified: 21 Nov 2024

    Qibosoft v7 contains a stored cross-site scripting (XSS) vulnerability in the component /admin/index.php?lfj=friendlink&action=add.

    Published: 27 Dec 2021
    9.1
    Critical

    CVE-2020-20944

    Last Modified: 21 Nov 2024

    An issue in /admin/index.php?lfj=mysql&action=del of Qibosoft v7 allows attackers to arbitrarily delete files.

    Published: 27 Dec 2021
    8.8
    High

    CVE-2020-20945

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) in /admin/index.php?lfj=member&action=editmember of Qibosoft v7 allows attackers to arbitrarily add administrator accounts.

    Published: 27 Dec 2021
    4.3
    Medium

    CVE-2020-20943

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) in /member/post.php?job=postnew&step=post of Qibosoft v7 allows attackers to force victim users into arbitrarily publishing new articles via a crafted URL.

    Published: 27 Dec 2021
    6.1
    Medium

    CVE-2021-45895

    Last Modified: 21 Nov 2024

    Netgen Tags Bundle 3.4.x before 3.4.11 and 4.0.x before 4.0.15 allows XSS in the Tags Admin interface.

    Published: 27 Dec 2021
    9.8
    Critical

    CVE-2021-45890

    Last Modified: 21 Nov 2024

    basic/BasicAuthProvider.java in AuthGuard before 0.9.0 allows authentication via an inactive identifier.

    Published: 27 Dec 2021
    8.1
    High

    CVE-2021-21751

    Last Modified: 21 Nov 2024

    ZTE BigVideo analysis product has an input verification vulnerability. Due to the inconsistency between the front and back verifications when configuring the large screen page, an attacker with high privileges could exploit this vulnerability to tamper with the URL and cause service exception.

    Published: 27 Dec 2021
    7.8
    High

    CVE-2021-21750

    Last Modified: 21 Nov 2024

    ZTE BigVideo Analysis product has a privilege escalation vulnerability. Due to improper management of the timed task modification privilege, an attacker with ordinary user permissions could exploit this vulnerability to gain unauthorized access.

    Published: 27 Dec 2021
    7.8
    High

    CVE-2021-23244

    Last Modified: 21 Nov 2024

    ColorOS pregrant dangerous permissions to apps which are listed in a whitelist xml named default-grant-permissions.But some apps in whitelist is not installed, attacker can disguise app with the same package name to obtain dangerous permission.

    Published: 27 Dec 2021
    5.9
    Medium

    CVE-2021-43550

    Last Modified: 21 Nov 2024

    The use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the exposure of sensitive information, which affects the communications between Patient Information Center iX (PIC iX) Versions C.02 and C.03 and Efficia CM Series Revisions A.01 to C.0x and 4.0.

    Published: 27 Dec 2021
    6.5
    Medium

    CVE-2021-43548

    Last Modified: 21 Nov 2024

    Patient Information Center iX (PIC iX) Versions C.02 and C.03 receives input or data, but does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly.

    Published: 27 Dec 2021
    6.1
    Medium

    CVE-2021-43552

    Last Modified: 21 Nov 2024

    The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from the Patient Information Center iX (PIC iX) Versions B.02, C.02, and C.03.

    Published: 27 Dec 2021
    8.1
    High

    CVE-2021-33017

    Last Modified: 21 Nov 2024

    The standard access path of the IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) requires authentication, but the product has an alternate path or channel that does not require authentication.

    Published: 27 Dec 2021
    8.1
    High

    CVE-2021-32993

    Last Modified: 21 Nov 2024

    IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) contains hard-coded credentials, such as a password or a cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

    Published: 27 Dec 2021
    9.8
    Critical

    CVE-2021-4161

    Last Modified: 21 Nov 2024

    The affected products contain vulnerable firmware, which could allow an attacker to sniff the traffic and decrypt login credential details. This could give an attacker admin rights through the HTTP web server.

    Published: 27 Dec 2021
    6.8
    Medium

    CVE-2021-35232

    Last Modified: 21 Nov 2024

    Hard coded credentials discovered in SolarWinds Web Help Desk product. Through these credentials, the attacker with local access to the Web Help Desk host machine allows to execute arbitrary HQL queries against the database and leverage the vulnerability to steal the password hashes of the users or insert arbitrary data into the database.

    Published: 27 Dec 2021
    9.8
    Critical

    CVE-2021-43857

    Last Modified: 21 Nov 2024

    Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched in version 0.9.8.

    Published: 27 Dec 2021
    8.2
    High

    CVE-2021-43855

    Last Modified: 21 Nov 2024

    Wiki.js is a wiki app built on node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through a SVG file upload made via a custom request with a fake MIME type. By creating a crafted SVG file, a malicious Wiki.js user may stage a stored cross-site scripting attack. This allows the attacker to execute malicious JavaScript when the SVG is viewed directly by other users. Scripts do not execute when loaded inside a page via normal `<img>` tags. The malicious SVG can only be uploaded by crafting a custom request to the server with a fake MIME type. A patch in version 2.5.264 fixes this vulnerability by adding an additional file extension verification check to the optional (enabled by default) SVG sanitization step to all file uploads that match the SVG mime type. As a workaround, disable file upload for all non-trusted users.

    Published: 27 Dec 2021
    8.2
    High

    CVE-2021-43856

    Last Modified: 21 Nov 2024

    Wiki.js is a wiki app built on Node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through non-image file uploads for file types that can be viewed directly inline in the browser. By creating a malicious file which can execute inline JS when viewed in the browser (e.g. XML files), a malicious Wiki.js user may stage a stored cross-site scripting attack. This allows the attacker to execute malicious JavaScript when the file is viewed directly by other users. The file must be opened directly by the user and will not trigger directly in a normal Wiki.js page. A patch in version 2.5.264 fixes this vulnerability by adding an optional (enabled by default) force download flag to all non-image file types, preventing the file from being viewed inline in the browser. As a workaround, disable file upload for all non-trusted users. --- Thanks to @Haxatron for reporting this vulnerability. Initially reported via https://huntr.dev/bounties/266bff09-00d9-43ca-a4bb-bb540642811f/

    Published: 27 Dec 2021