CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2021-44028

    Last Modified: 21 Nov 2024

    XXE can occur in Quest KACE Desktop Authority before 11.2 because the log4net configuration file might be controlled by an attacker, a related issue to CVE-2018-1285.

    Published: 22 Dec 2021
    7.3
    High

    CVE-2021-43804

    Last Modified: 4 Nov 2025

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected versions if the incoming RTCP BYE message contains a reason's length, this declared length is not checked against the actual received packet size, potentially resulting in an out-of-bound read access. This issue affects all users that use PJMEDIA and RTCP. A malicious actor can send a RTCP BYE message with an invalid reason length. Users are advised to upgrade as soon as possible. There are no known workarounds.

    Published: 22 Dec 2021
    9.8
    Critical

    CVE-2021-40394

    Last Modified: 21 Nov 2024

    An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit 71493260). A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 22 Dec 2021
    6.5
    Medium

    CVE-2021-4209

    Last Modified: 21 Nov 2024

    A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances.

    Published: 22 Dec 2021
    5.5
    Medium

    CVE-2021-4219

    Last Modified: 21 Nov 2024

    A flaw was found in ImageMagick. The vulnerability occurs due to improper use of open functions and leads to a denial of service. This flaw allows an attacker to crash the system.

    Published: 22 Dec 2021
    5.5
    Medium

    CVE-2021-45256

    Last Modified: 21 Nov 2024

    A Null Pointer Dereference vulnerability existfs in nasm 2.16rc0 via asm/preproc.c.

    Published: 22 Dec 2021
    5.5
    Medium

    CVE-2021-45257

    Last Modified: 21 Nov 2024

    An infinite loop vulnerability exists in nasm 2.16rc0 via the gpaste_tokens function.

    Published: 22 Dec 2021
    5.5
    Medium

    CVE-2021-45261

    Last Modified: 21 Nov 2024

    An Invalid Pointer vulnerability exists in GNU patch 2.7 via the another_hunk function, which causes a Denial of Service.

    Published: 22 Dec 2021
    5.5
    Medium

    CVE-2021-45262

    Last Modified: 21 Nov 2024

    An invalid free vulnerability exists in gpac 1.1.0 via the gf_sg_command_del function, which causes a segmentation fault and application crash.

    Published: 22 Dec 2021
    5.5
    Medium

    CVE-2021-45263

    Last Modified: 21 Nov 2024

    An invalid free vulnerability exists in gpac 1.1.0 via the gf_svg_delete_attribute_value function, which causes a segmentation fault and application crash.

    Published: 22 Dec 2021
    5.5
    Medium

    CVE-2021-45267

    Last Modified: 21 Nov 2024

    An invalid memory address dereference vulnerability exists in gpac 1.1.0 via the svg_node_start function, which causes a segmentation fault and application crash.

    Published: 22 Dec 2021
    5.5
    Medium

    CVE-2022-25309

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow flaw was found in the Fribidi package and affects the fribidi_cap_rtl_to_unicode() function of the fribidi-char-sets-cap-rtl.c file. This flaw allows an attacker to pass a specially crafted file to the Fribidi application with the '--caprtl' option, leading to a crash and causing a denial of service.

    Published: 22 Dec 2021
    5.5
    Medium

    CVE-2022-25310

    Last Modified: 21 Nov 2024

    A segmentation fault (SEGV) flaw was found in the Fribidi package and affects the fribidi_remove_bidi_marks() function of the lib/fribidi.c file. This flaw allows an attacker to pass a specially crafted file to Fribidi, leading to a crash and causing a denial of service.

    Published: 22 Dec 2021
    9.8
    Critical

    CVE-2021-40393

    Last Modified: 21 Nov 2024

    An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit 71493260). A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 22 Dec 2021
    7.8
    High

    CVE-2022-25308

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow flaw was found in the Fribidi package. This flaw allows an attacker to pass a specially crafted file to the Fribidi application, which leads to a possible memory leak or a denial of service.

    Published: 22 Dec 2021
    7.3
    High

    CVE-2021-37706

    Last Modified: 4 Nov 2025

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected versions if the incoming STUN message contains an ERROR-CODE attribute, the header length is not checked before performing a subtraction operation, potentially resulting in an integer underflow scenario. This issue affects all users that use STUN. A malicious actor located within the victim’s network may forge and send a specially crafted UDP (STUN) message that could remotely execute arbitrary code on the victim’s machine. Users are advised to upgrade as soon as possible. There are no known workarounds.

    Published: 22 Dec 2021
    8.1
    High

    CVE-2021-43851

    Last Modified: 21 Nov 2024

    Anuko Time Tracker is an open source, web-based time tracking application written in PHP. SQL injection vulnerability exist in multiple files in Time Tracker version 1.19.33.5606 and prior due to not properly checking of the "group" and "status" parameters in POST requests. Group parameter is posted along when navigating between organizational subgroups (groups.php file). Status parameter is used in multiple files to change a status of an entity such as making a project, task, or user inactive. This issue has been patched in version 1.19.33.5607. An upgrade is highly recommended. If an upgrade is not practical, introduce ttValidStatus function as in the latest version and start using it user input check blocks wherever status field is used. For groups.php fix, introduce ttValidInteger function as in the latest version and use it in the access check block in the file.

    Published: 21 Dec 2021
    5.5
    Medium

    CVE-2021-44927

    Last Modified: 21 Nov 2024

    A null pointer dereference vulnerability exists in gpac 1.1.0 in the gf_sg_vrml_mf_append function, which causes a segmentation fault and application crash.

    Published: 21 Dec 2021
    5.5
    Medium

    CVE-2021-44926

    Last Modified: 21 Nov 2024

    A null pointer dereference vulnerability exists in gpac 1.1.0-DEV in the gf_node_get_tag function, which causes a segmentation fault and application crash.

    Published: 21 Dec 2021
    5.5
    Medium

    CVE-2021-44925

    Last Modified: 21 Nov 2024

    A null pointer dereference vulnerability exists in gpac 1.1.0 in the gf_svg_get_attribute_name function, which causes a segmentation fault and application crash.

    Published: 21 Dec 2021
    5.5
    Medium

    CVE-2021-44924

    Last Modified: 21 Nov 2024

    An infinite loop vulnerability exists in gpac 1.1.0 in the gf_log function, which causes a Denial of Service.

    Published: 21 Dec 2021
    5.5
    Medium

    CVE-2021-44923

    Last Modified: 18 Mar 2025

    A null pointer dereference vulnerability exists in gpac 1.1.0 in the gf_dump_vrml_dyn_field.isra function, which causes a segmentation fault and application crash.

    Published: 21 Dec 2021
    5.5
    Medium

    CVE-2021-44922

    Last Modified: 21 Nov 2024

    A null pointer dereference vulnerability exists in gpac 1.1.0 in the BD_CheckSFTimeOffset function, which causes a segmentation fault and application crash.

    Published: 21 Dec 2021
    5.5
    Medium

    CVE-2021-44921

    Last Modified: 21 Nov 2024

    A null pointer dereference vulnerability exists in gpac 1.1.0 in the gf_isom_parse_movie_boxes_internal function, which causes a segmentation fault and application crash.

    Published: 21 Dec 2021
    5.5
    Medium

    CVE-2021-44920

    Last Modified: 21 Nov 2024

    An invalid memory address dereference vulnerability exists in gpac 1.1.0 in the dump_od_to_saf.isra function, which causes a segmentation fault and application crash.

    Published: 21 Dec 2021
    5.5
    Medium

    CVE-2021-44919

    Last Modified: 21 Nov 2024

    A Null Pointer Dereference vulnerability exists in the gf_sg_vrml_mf_alloc function in gpac 1.1.0-DEV, which causes a segmentation fault and application crash.

    Published: 21 Dec 2021
    5.5
    Medium

    CVE-2021-44918

    Last Modified: 21 Nov 2024

    A Null Pointer Dereference vulnerability exists in gpac 1.1.0 in the gf_node_get_field function, which can cause a segmentation fault and application crash.

    Published: 21 Dec 2021
    5.4
    Medium

    CVE-2021-38966

    Last Modified: 21 Nov 2024

    IBM Cloud Pak for Automation 21.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 212357.

    Published: 21 Dec 2021
    6.5
    Medium

    CVE-2021-38900

    Last Modified: 21 Nov 2024

    IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 could allow a privileged user to obtain highly sensitive information due to improper access controls. IBM X-Force ID: 209607.

    Published: 21 Dec 2021
    5.4
    Medium

    CVE-2021-38893

    Last Modified: 21 Nov 2024

    IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 209512.

    Published: 21 Dec 2021
    7.8
    High

    CVE-2021-44859

    Last Modified: 21 Nov 2024

    An out-of-bounds read vulnerability exists when reading a TGA file using Open Design Alliance Drawings SDK before 2022.12. The specific issue exists after loading TGA files. An unchecked input data from a crafted TGA file leads to an out-of-bounds read. An attacker can leverage this vulnerability to execute code in the context of the current process.

    Published: 21 Dec 2021
    7.8
    High

    CVE-2021-44860

    Last Modified: 21 Nov 2024

    An out-of-bounds read vulnerability exists when reading a TIF file using Open Design Alliance Drawings SDK before 2022.12. The specific issue exists after loading TIF files. An unchecked input data from a crafted TIF file leads to an out-of-bounds read. An attacker can leverage this vulnerability to execute code in the context of the current process.

    Published: 21 Dec 2021
    7.8
    High

    CVE-2021-44423

    Last Modified: 21 Nov 2024

    An out-of-bounds read vulnerability exists when reading a BMP file using Open Design Alliance (ODA) Drawings Explorer before 2022.12. The specific issue exists after loading BMP files. Unchecked input data from a crafted BMP file leads to an out-of-bounds read. An attacker can leverage this vulnerability to execute code in the context of the current process.

    Published: 21 Dec 2021
    7.8
    High

    CVE-2021-44422

    Last Modified: 21 Nov 2024

    An Improper Input Validation Vulnerability exists when reading a BMP file using Open Design Alliance Drawings SDK before 2022.12. Crafted data in a BMP file can trigger a write operation past the end of an allocated buffer, or lead to a heap-based buffer overflow. An attacker can leverage this vulnerability to execute code in the context of the current process.

    Published: 21 Dec 2021
    7.3
    High

    CVE-2021-27451

    Last Modified: 21 Nov 2024

    Mesa Labs AmegaView Versions 3.0 and prior’s passcode is generated by an easily reversible algorithm, which may allow an attacker to gain access to the device.

    Published: 21 Dec 2021
    10
    Critical

    CVE-2021-27447

    Last Modified: 21 Nov 2024

    Mesa Labs AmegaView version 3.0 is vulnerable to a command injection, which may allow an attacker to remotely execute arbitrary code.

    Published: 21 Dec 2021
    7.3
    High

    CVE-2021-27453

    Last Modified: 21 Nov 2024

    Mesa Labs AmegaView Versions 3.0 uses default cookies that could be set to bypass authentication to the web application, which may allow an attacker to gain access.

    Published: 21 Dec 2021
    9.9
    Critical

    CVE-2021-27449

    Last Modified: 21 Nov 2024

    Mesa Labs AmegaView Versions 3.0 and prior has a command injection vulnerability that can be exploited to execute commands in the web server.

    Published: 21 Dec 2021
    7.8
    High

    CVE-2021-27445

    Last Modified: 21 Nov 2024

    Mesa Labs AmegaView Versions 3.0 and prior has insecure file permissions that could be exploited to escalate privileges on the device.

    Published: 21 Dec 2021
    5.5
    Medium

    CVE-2021-45293

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in Binaryen 103 due to an Invalid memory address dereference in wasm::WasmBinaryBuilder::visitLet.

    Published: 21 Dec 2021
    8.1
    High

    CVE-2021-44207

    Last Modified: 10 Nov 2025

    Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.

    Published: 21 Dec 2021
    5.4
    Medium

    CVE-2020-19770

    Last Modified: 5 May 2025

    A cross-site scripting (XSS) vulnerability in the system bulletin component of WUZHI CMS v4.1.0 allows attackers to steal the admin's cookie.

    Published: 21 Dec 2021
    7.5
    High

    CVE-2021-45290

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exits in Binaryen 103 due to an assertion abort in wasm::handle_unreachable.

    Published: 21 Dec 2021
    5.5
    Medium

    CVE-2021-45289

    Last Modified: 21 Nov 2024

    A vulnerability exists in GPAC 1.0.1 due to an omission of security-relevant Information, which could cause a Denial of Service. The program terminates with signal SIGKILL.

    Published: 21 Dec 2021
    8.2
    High

    CVE-2021-43587

    Last Modified: 21 Nov 2024

    Dell PowerPath Management Appliance, versions 3.2, 3.1, 3.0 P01, 3.0, and 2.6, use hard-coded cryptographic key. A local high-privileged malicious user may potentially exploit this vulnerability to gain access to secrets and elevate to gain higher privileges.

    Published: 21 Dec 2021
    5.9
    Medium

    CVE-2021-36350

    Last Modified: 21 Nov 2024

    Dell PowerScale OneFS, versions 8.2.2-9.3.0.x, contain an authentication bypass by primary weakness in one of the authentication factors. A remote unauthenticated attacker may potentially exploit this vulnerability and bypass one of the factors of authentication.

    Published: 21 Dec 2021
    5.5
    Medium

    CVE-2021-36341

    Last Modified: 21 Nov 2024

    Dell Wyse Device Agent version 14.5.4.1 and below contain a sensitive data exposure vulnerability. A local authenticated user with low privileges could potentially exploit this vulnerability in order to access sensitive information.

    Published: 21 Dec 2021
    6.5
    Medium

    CVE-2021-36337

    Last Modified: 21 Nov 2024

    Dell Wyse Management Suite version 3.3.1 and prior support insecure Transport Security Protocols TLS 1.0 and TLS 1.1 which are susceptible to Man-In-The-Middle attacks thereby compromising Confidentiality and Integrity of data.

    Published: 21 Dec 2021
    9.8
    Critical

    CVE-2021-36336

    Last Modified: 21 Nov 2024

    Wyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could allow an unauthenticated attacker to execute code on the affected system.

    Published: 21 Dec 2021
    6.7
    Medium

    CVE-2021-36318

    Last Modified: 21 Nov 2024

    Dell EMC Avamar versions 18.2,19.1,19.2,19.3,19.4 contain a plain-text password storage vulnerability. A high privileged user could potentially exploit this vulnerability, leading to a complete outage.

    Published: 21 Dec 2021