CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2021-21901

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow vulnerability exists in the CMA check_udp_crc function of Garrett Metal Detectors’ iC Module CMA Version 5.0. A specially-crafted packet can lead to a stack-based buffer overflow during a call to memcpy. An attacker can send a malicious packet to trigger this vulnerability.

    Published: 22 Dec 2021
    7.2
    High

    CVE-2021-21895

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability exists in the Web Manager FsTFtp functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to FsTFtp file overwrite. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 22 Dec 2021
    9.1
    Critical

    CVE-2021-21894

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability exists in the Web Manager FsTFtp functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to arbitrary file overwrite FsTFtp file disclosure. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 22 Dec 2021
    9.9
    Critical

    CVE-2021-21892

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow vulnerability exists in the Web Manager FsUnmount functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 22 Dec 2021
    9.1
    Critical

    CVE-2021-21891

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow vulnerability exists in the Web Manager FsBrowseClean functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution in the vulnerable portion of the branch (deletefile). An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 22 Dec 2021
    9.1
    Critical

    CVE-2021-21890

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow vulnerability exists in the Web Manager FsBrowseClean functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution in the vulnerable portion of the branch (deletedir). An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 22 Dec 2021
    6.1
    Medium

    CVE-2021-36885

    Last Modified: 28 Mar 2025

    Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (versions <= 1.2.6.1).

    Published: 22 Dec 2021
    9.9
    Critical

    CVE-2021-21889

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow vulnerability exists in the Web Manager Ping functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 22 Dec 2021
    9.1
    Critical

    CVE-2021-21888

    Last Modified: 21 Nov 2024

    An OS command injection vulnerability exists in the Web Manager SslGenerateCertificate functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 22 Dec 2021
    9.1
    Critical

    CVE-2021-21887

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow vulnerability exists in the Web Manager SslGenerateCSR functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 22 Dec 2021
    7.2
    High

    CVE-2021-21885

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability exists in the Web Manager FsMove functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially crafted HTTP request can lead to local file inclusion. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 22 Dec 2021
    4.3
    Medium

    CVE-2021-21886

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability exists in the Web Manager FSBrowsePage functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially crafted HTTP request can lead to information disclosure. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 22 Dec 2021
    9.1
    Critical

    CVE-2021-21884

    Last Modified: 21 Nov 2024

    An OS command injection vulnerability exists in the Web Manager SslGenerateCSR functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 22 Dec 2021
    9.9
    Critical

    CVE-2021-21883

    Last Modified: 21 Nov 2024

    An OS command injection vulnerability exists in the Web Manager Diagnostics: Ping functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 22 Dec 2021
    8.8
    High

    CVE-2021-21882

    Last Modified: 21 Nov 2024

    An OS command injection vulnerability exists in the Web Manager FsUnmount functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 22 Dec 2021
    9.9
    Critical

    CVE-2021-21881

    Last Modified: 21 Nov 2024

    An OS command injection vulnerability exists in the Web Manager Wireless Network Scanner functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 22 Dec 2021
    7.2
    High

    CVE-2021-21880

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability exists in the Web Manager FsCopyFile functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to local file inclusion. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 22 Dec 2021
    8.8
    High

    CVE-2021-21879

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability exists in the Web Manager File Upload functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary file overwrite. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 22 Dec 2021
    4.9
    Medium

    CVE-2021-21878

    Last Modified: 21 Nov 2024

    A local file inclusion vulnerability exists in the Web Manager Applications and FsBrowse functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted series of HTTP requests can lead to local file inclusion. An attacker can make a series of authenticated HTTP requests to trigger this vulnerability.

    Published: 22 Dec 2021
    9.1
    Critical

    CVE-2021-21877

    Last Modified: 21 Nov 2024

    Specially-crafted HTTP requests can lead to arbitrary command execution in “GET” requests. An attacker can make authenticated HTTP requests to trigger this vulnerability.

    Published: 22 Dec 2021
    9.1
    Critical

    CVE-2021-21875

    Last Modified: 21 Nov 2024

    A specially-crafted HTTP request can lead to arbitrary command execution in EC keypasswd parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 22 Dec 2021
    9.1
    Critical

    CVE-2021-21876

    Last Modified: 21 Nov 2024

    Specially-crafted HTTP requests can lead to arbitrary command execution in PUT requests. An attacker can make authenticated HTTP requests to trigger this vulnerability.

    Published: 22 Dec 2021
    9.1
    Critical

    CVE-2021-21874

    Last Modified: 21 Nov 2024

    A specially-crafted HTTP request can lead to arbitrary command execution in DSA keypasswd parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 22 Dec 2021
    9.1
    Critical

    CVE-2021-21873

    Last Modified: 21 Nov 2024

    A specially-crafted HTTP request can lead to arbitrary command execution in RSA keypasswd parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 22 Dec 2021
    9.9
    Critical

    CVE-2021-21872

    Last Modified: 21 Nov 2024

    An OS command injection vulnerability exists in the Web Manager Diagnostics: Traceroute functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 22 Dec 2021
    7.5
    High

    CVE-2021-45266

    Last Modified: 21 Nov 2024

    A null pointer dereference vulnerability exists in gpac 1.1.0 via the lsr_read_anim_values_ex function, which causes a segmentation fault and application crash.

    Published: 22 Dec 2021
    9.8
    Critical

    CVE-2021-43157

    Last Modified: 29 Oct 2025

    Projectsworlds Online Shopping System PHP 1.0 is vulnerable to SQL injection via the id parameter in cart_remove.php.

    Published: 22 Dec 2021
    4.3
    Medium

    CVE-2021-43158

    Last Modified: 29 Oct 2025

    In ProjectWorlds Online Shopping System PHP 1.0, a CSRF vulnerability in cart_remove.php allows a remote attacker to remove any product in the customer's cart.

    Published: 22 Dec 2021
    9.8
    Critical

    CVE-2021-44659

    Last Modified: 21 Nov 2024

    Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve a Server Side Request Forgery (SSRF). NOTE: the vendor's position is that the observed behavior is not a vulnerability, because the product's design allows an admin to configure outbound requests

    Published: 22 Dec 2021
    9.8
    Critical

    CVE-2021-43155

    Last Modified: 21 Nov 2024

    Projectsworlds Online Book Store PHP v1.0 is vulnerable to SQL injection via the "bookisbn" parameter in cart.php.

    Published: 22 Dec 2021
    6.5
    Medium

    CVE-2021-43156

    Last Modified: 21 Nov 2024

    In ProjectWorlds Online Book Store PHP 1.0 a CSRF vulnerability in admin_delete.php allows a remote attacker to delete any book.

    Published: 22 Dec 2021
    9.8
    Critical

    CVE-2021-43631

    Last Modified: 21 Nov 2024

    Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the appointment_no parameter in payment.php.

    Published: 22 Dec 2021
    8.8
    High

    CVE-2021-43630

    Last Modified: 21 Nov 2024

    Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in add_patient.php. As a result, an authenticated malicious user can compromise the databases system and in some cases leverage this vulnerability to get remote code execution on the remote web server.

    Published: 22 Dec 2021
    9.8
    Critical

    CVE-2021-43629

    Last Modified: 21 Nov 2024

    Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in admin_home.php.

    Published: 22 Dec 2021
    9.8
    Critical

    CVE-2021-43628

    Last Modified: 21 Nov 2024

    Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the email parameter in hms-staff.php.

    Published: 22 Dec 2021
    5.5
    Medium

    CVE-2021-45260

    Last Modified: 21 Nov 2024

    A null pointer dereference vulnerability exists in gpac 1.1.0 in the lsr_read_id.part function, which causes a segmentation fault and application crash.

    Published: 22 Dec 2021
    5.5
    Medium

    CVE-2021-45259

    Last Modified: 21 Nov 2024

    An Invalid pointer reference vulnerability exists in gpac 1.1.0 via the gf_svg_node_del function, which causes a segmentation fault and application crash.

    Published: 22 Dec 2021
    5.5
    Medium

    CVE-2021-45258

    Last Modified: 21 Nov 2024

    A stack overflow vulnerability exists in gpac 1.1.0 via the gf_bifs_dec_proto_list function, which causes a segmentation fault and application crash.

    Published: 22 Dec 2021
    6.5
    Medium

    CVE-2021-39013

    Last Modified: 21 Nov 2024

    IBM Cloud Pak for Security (CP4S) 1.7.2.0, 1.7.1.0, and 1.7.0.0 could allow an authenticated user to obtain sensitive information in HTTP responses that could be used in further attacks against the system. IBM X-Force ID: 213651.

    Published: 22 Dec 2021
    8.8
    High

    CVE-2021-45419

    Last Modified: 21 Nov 2024

    Certain Starcharge products are affected by Improper Input Validation. The affected products include: Nova 360 Cabinet <= 1.3.0.0.7b102 - Fixed: Beta1.3.0.1.0 and Titan 180 Premium <= 1.3.0.0.6 - Fixed: 1.3.0.0.9.

    Published: 22 Dec 2021
    —
    Unknown

    CVE-2021-4114

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2021. Notes: none

    Published: 22 Dec 2021
    —
    Unknown

    CVE-2021-4113

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2021. Notes: none

    Published: 22 Dec 2021
    8.8
    High

    CVE-2021-45418

    Last Modified: 21 Nov 2024

    Certain Starcharge products are vulnerable to Directory Traversal via main.cgi. The affected products include: Nova 360 Cabinet <=1.3.0.0.6 - Fixed: 1.3.0.0.9 and Titan 180 Premium <=1.3.0.0.7b102 - Fixed: Beta1.3.0.1.0.

    Published: 22 Dec 2021
    8.1
    High

    CVE-2021-36750

    Last Modified: 21 Nov 2024

    ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names).

    Published: 22 Dec 2021
    9.8
    Critical

    CVE-2021-40612

    Last Modified: 21 Nov 2024

    An issue was discovered in Opmantek Open-AudIT after 3.5.0. Without authentication, a vulnerability in code_igniter/application/controllers/util.php allows an attacker perform command execution without echoes.

    Published: 22 Dec 2021
    4.6
    Medium

    CVE-2021-40836

    Last Modified: 21 Nov 2024

    A vulnerability affecting F-Secure antivirus engine was discovered whereby scanning MS outlook .pst files can lead to denial-of-service. The vulnerability can be exploited remotely by an attacker. A successful attack will result in denial-of-service of the antivirus engine.

    Published: 22 Dec 2021
    9.8
    Critical

    CVE-2021-45459

    Last Modified: 21 Nov 2024

    lib/cmd.js in the node-windows package before 1.0.0-beta.6 for Node.js allows command injection via the PID parameter.

    Published: 22 Dec 2021
    9.8
    Critical

    CVE-2021-44029

    Last Modified: 21 Nov 2024

    An issue was discovered in Quest KACE Desktop Authority before 11.2. This vulnerability allows attackers to execute remote code through a deserialization exploitation in the RadAsyncUpload function of ASP.NET AJAX. An attacker can leverage this vulnerability when the encryption keys are known (due to the presence of CVE-2017-11317, CVE-2017-11357, or other means). A default setting for the type whitelisting feature in more current versions of ASP.NET AJAX prevents exploitation.

    Published: 22 Dec 2021
    9.8
    Critical

    CVE-2021-44031

    Last Modified: 21 Nov 2024

    An issue was discovered in Quest KACE Desktop Authority before 11.2. /dacomponentui/profiles/profileitems/outlooksettings/Insertimage.aspx contains a vulnerability that could allow pre-authentication remote code execution. An attacker could upload a .ASP file to reside at /images/{GUID}/{filename}.

    Published: 22 Dec 2021
    6.1
    Medium

    CVE-2021-44030

    Last Modified: 21 Nov 2024

    Quest KACE Desktop Authority before 11.2 allows XSS because it does not prevent untrusted HTML from reaching the jQuery.htmlPrefilter method of jQuery.

    Published: 22 Dec 2021