CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-44548

    Last Modified: 21 Nov 2024

    An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC path resulting in an SMB network call being made from the Solr host to another host on the network. If the attacker has wider access to the network, this may lead to SMB attacks, which may result in: * The exfiltration of sensitive data such as OS user hashes (NTLM/LM hashes), * In case of misconfigured systems, SMB Relay Attacks which can lead to user impersonation on SMB Shares or, in a worse-case scenario, Remote Code Execution This issue affects all Apache Solr versions prior to 8.11.1. This issue only affects Windows.

    Published: 23 Dec 2021
    8.8
    High

    CVE-2021-4144

    Last Modified: 21 Nov 2024

    TP-Link wifi router TL-WR802N V4(JP), with firmware version prior to 211202, is vulnerable to OS command injection.

    Published: 23 Dec 2021
    7.5
    High

    CVE-2021-20050

    Last Modified: 21 Nov 2024

    An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, potentially exposing configuration meta-data.

    Published: 23 Dec 2021
    7.5
    High

    CVE-2021-20049

    Last Modified: 21 Nov 2024

    A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the server responses. This vulnerability impacts 10.2.1.2-24sv, 10.2.0.8-37sv and earlier 10.x versions.

    Published: 23 Dec 2021
    8.8
    High

    CVE-2021-4079

    Last Modified: 21 Nov 2024

    Out of bounds write in WebRTC in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via crafted WebRTC packets.

    Published: 23 Dec 2021
    8.8
    High

    CVE-2021-4078

    Last Modified: 21 Nov 2024

    Type confusion in V8 in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 23 Dec 2021
    6.5
    Medium

    CVE-2021-4068

    Last Modified: 21 Nov 2024

    Insufficient data validation in new tab page in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 23 Dec 2021
    8.8
    High

    CVE-2021-4067

    Last Modified: 21 Nov 2024

    Use after free in window manager in Google Chrome on ChromeOS prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 23 Dec 2021
    8.8
    High

    CVE-2021-4066

    Last Modified: 21 Nov 2024

    Integer underflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 23 Dec 2021
    8.8
    High

    CVE-2021-4065

    Last Modified: 21 Nov 2024

    Use after free in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 23 Dec 2021
    8.8
    High

    CVE-2021-4064

    Last Modified: 21 Nov 2024

    Use after free in screen capture in Google Chrome on ChromeOS prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 23 Dec 2021
    8.8
    High

    CVE-2021-4063

    Last Modified: 21 Nov 2024

    Use after free in developer tools in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 23 Dec 2021
    8.8
    High

    CVE-2021-4062

    Last Modified: 21 Nov 2024

    Heap buffer overflow in BFCache in Google Chrome prior to 96.0.4664.93 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

    Published: 23 Dec 2021
    8.8
    High

    CVE-2021-4061

    Last Modified: 21 Nov 2024

    Type confusion in V8 in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 23 Dec 2021
    6.5
    Medium

    CVE-2021-4059

    Last Modified: 21 Nov 2024

    Insufficient data validation in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 23 Dec 2021
    8.8
    High

    CVE-2021-4058

    Last Modified: 21 Nov 2024

    Heap buffer overflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 23 Dec 2021
    8.8
    High

    CVE-2021-4057

    Last Modified: 21 Nov 2024

    Use after free in file API in Google Chrome prior to 96.0.4664.93 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

    Published: 23 Dec 2021
    8.8
    High

    CVE-2021-4056

    Last Modified: 21 Nov 2024

    Type confusion in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 23 Dec 2021
    8.8
    High

    CVE-2021-4055

    Last Modified: 21 Nov 2024

    Heap buffer overflow in extensions in Google Chrome prior to 96.0.4664.93 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.

    Published: 23 Dec 2021
    6.5
    Medium

    CVE-2021-4054

    Last Modified: 21 Nov 2024

    Incorrect security UI in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

    Published: 23 Dec 2021
    8.8
    High

    CVE-2021-4053

    Last Modified: 21 Nov 2024

    Use after free in UI in Google Chrome on Linux prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 23 Dec 2021
    8.8
    High

    CVE-2021-4052

    Last Modified: 21 Nov 2024

    Use after free in web apps in Google Chrome prior to 96.0.4664.93 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.

    Published: 23 Dec 2021
    6.5
    Medium

    CVE-2021-38022

    Last Modified: 21 Nov 2024

    Inappropriate implementation in WebAuthentication in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 23 Dec 2021
    6.5
    Medium

    CVE-2021-38021

    Last Modified: 21 Nov 2024

    Inappropriate implementation in referrer in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 23 Dec 2021
    4.3
    Medium

    CVE-2021-38020

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in contacts picker in Google Chrome on Android prior to 96.0.4664.45 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 23 Dec 2021
    6.5
    Medium

    CVE-2021-38019

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in CORS in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 23 Dec 2021
    6.5
    Medium

    CVE-2021-38018

    Last Modified: 21 Nov 2024

    Inappropriate implementation in navigation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

    Published: 23 Dec 2021
    8.8
    High

    CVE-2021-38017

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in iframe sandbox in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 23 Dec 2021
    8.8
    High

    CVE-2021-38016

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in background fetch in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

    Published: 23 Dec 2021
    8.8
    High

    CVE-2021-38015

    Last Modified: 21 Nov 2024

    Inappropriate implementation in input in Google Chrome prior to 96.0.4664.45 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.

    Published: 23 Dec 2021
    8.8
    High

    CVE-2021-38014

    Last Modified: 21 Nov 2024

    Out of bounds write in Swiftshader in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 23 Dec 2021
    9.6
    Critical

    CVE-2021-38013

    Last Modified: 21 Nov 2024

    Heap buffer overflow in fingerprint recognition in Google Chrome on ChromeOS prior to 96.0.4664.45 allowed a remote attacker who had compromised a WebUI renderer process to potentially perform a sandbox escape via a crafted HTML page.

    Published: 23 Dec 2021
    8.8
    High

    CVE-2021-38012

    Last Modified: 21 Nov 2024

    Type confusion in V8 in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 23 Dec 2021
    8.8
    High

    CVE-2021-38011

    Last Modified: 21 Nov 2024

    Use after free in storage foundation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 23 Dec 2021
    6.5
    Medium

    CVE-2021-38010

    Last Modified: 21 Nov 2024

    Inappropriate implementation in service workers in Google Chrome prior to 96.0.4664.45 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.

    Published: 23 Dec 2021
    6.5
    Medium

    CVE-2021-38009

    Last Modified: 21 Nov 2024

    Inappropriate implementation in cache in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 23 Dec 2021
    8.8
    High

    CVE-2021-38008

    Last Modified: 21 Nov 2024

    Use after free in media in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 23 Dec 2021
    8.8
    High

    CVE-2021-38007

    Last Modified: 21 Nov 2024

    Type confusion in V8 in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 23 Dec 2021
    8.8
    High

    CVE-2021-38006

    Last Modified: 21 Nov 2024

    Use after free in storage foundation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 23 Dec 2021
    8.8
    High

    CVE-2021-38005

    Last Modified: 21 Nov 2024

    Use after free in loader in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 23 Dec 2021
    5.5
    Medium

    CVE-2023-23006

    Last Modified: 19 Mar 2025

    In the Linux kernel before 5.15.13, drivers/net/ethernet/mellanox/mlx5/core/steering/dr_domain.c misinterprets the mlx5_get_uars_page return value (expects it to be NULL in the error case, whereas it is actually an error pointer).

    Published: 23 Dec 2021
    7.5
    High

    CVE-2021-23772

    Last Modified: 21 Nov 2024

    This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12. The unsafe handling of file names during upload using UploadFormFiles method may enable attackers to write to arbitrary locations outside the designated target folder.

    Published: 23 Dec 2021
    7.4
    High

    CVE-2021-44273

    Last Modified: 21 Nov 2024

    e2guardian v5.4.x <= v5.4.3r is affected by missing SSL certificate validation in the SSL MITM engine. In standalone mode (i.e., acting as a proxy or a transparent proxy), with SSL MITM enabled, e2guardian, if built with OpenSSL v1.1.x, did not validate hostnames in certificates of the web servers that it connected to, and thus was itself vulnerable to MITM attacks.

    Published: 23 Dec 2021
    7.5
    High

    CVE-2021-45462

    Last Modified: 21 Nov 2024

    In Open5GS 2.4.0, a crafted packet from UE can crash SGW-U/UPF.

    Published: 23 Dec 2021
    6.1
    Medium

    CVE-2020-20605

    Last Modified: 21 Nov 2024

    Blog CMS v1.0 contains a cross-site scripting (XSS) vulnerability in the /controller/CommentAdminController.java component.

    Published: 22 Dec 2021
    9.8
    Critical

    CVE-2020-20601

    Last Modified: 21 Nov 2024

    An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet.

    Published: 22 Dec 2021
    5.4
    Medium

    CVE-2020-20600

    Last Modified: 21 Nov 2024

    MetInfo 7.0 beta contains a stored cross-site scripting (XSS) vulnerability in the $name parameter of admin/?n=column&c=index&a=doAddColumn.

    Published: 22 Dec 2021
    6.1
    Medium

    CVE-2020-20598

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the Editing component of lemon V1.10.0 allows attackers to execute arbitrary web scripts or HTML.

    Published: 22 Dec 2021
    6.1
    Medium

    CVE-2020-20597

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the potrtalItemName parameter in \web\PortalController.java of lemon V1.10.0 allows attackers to execute arbitrary web scripts or HTML.

    Published: 22 Dec 2021
    6.5
    Medium

    CVE-2020-20595

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) in OPMS v1.3 and below allows attackers to arbitrarily add a user account via /user/add.

    Published: 22 Dec 2021