CVE Feed

    Dashboard / CVE

    3.3
    Low

    CVE-2021-44182

    Last Modified: 23 Apr 2025

    Adobe Dimension versions 3.4.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious SVG file.

    Published: 20 Dec 2021
    3.3
    Low

    CVE-2021-43763

    Last Modified: 23 Apr 2025

    Adobe Dimension versions 3.4.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious TIF file.

    Published: 20 Dec 2021
    7.8
    High

    CVE-2021-44179

    Last Modified: 23 Apr 2025

    Adobe Dimension versions 3.4.3 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious GIF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 20 Dec 2021
    5.5
    Medium

    CVE-2021-43746

    Last Modified: 23 Apr 2025

    Adobe Premiere Rush versions 1.5.16 (and earlier) allows access to an uninitialized pointer vulnerability that allows remote attackers to disclose sensitive information on affected installations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of MP4 files. The issue results from the lack of proper initialization of memory prior to accessing it.

    Published: 20 Dec 2021
    5.5
    Medium

    CVE-2021-43750

    Last Modified: 23 Apr 2025

    Adobe Premiere Rush versions 1.5.16 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 20 Dec 2021
    7.8
    High

    CVE-2021-43023

    Last Modified: 23 Apr 2025

    Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious EPS/TIFF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 20 Dec 2021
    7.8
    High

    CVE-2021-43025

    Last Modified: 23 Apr 2025

    Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious SVG file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 20 Dec 2021
    3.3
    Low

    CVE-2021-43030

    Last Modified: 23 Apr 2025

    Adobe Premiere Rush versions 1.5.16 (and earlier) allows access to an uninitialized pointer vulnerability that allows remote attackers to disclose arbitrary data on affected installations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of MP4 files. The issue results from the lack of proper initialization of memory prior to accessing it.

    Published: 20 Dec 2021
    5.5
    Medium

    CVE-2021-43749

    Last Modified: 23 Apr 2025

    Adobe Premiere Rush versions 1.5.16 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 20 Dec 2021
    7.8
    High

    CVE-2021-40784

    Last Modified: 23 Apr 2025

    Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 20 Dec 2021
    5.5
    Medium

    CVE-2021-43748

    Last Modified: 23 Apr 2025

    Adobe Premiere Rush versions 1.5.16 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 20 Dec 2021
    7.8
    High

    CVE-2021-43024

    Last Modified: 23 Apr 2025

    Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 20 Dec 2021
    7.8
    High

    CVE-2021-43022

    Last Modified: 23 Apr 2025

    Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious PNG file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 20 Dec 2021
    7.8
    High

    CVE-2021-43747

    Last Modified: 23 Apr 2025

    Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 20 Dec 2021
    7.8
    High

    CVE-2021-43021

    Last Modified: 23 Apr 2025

    Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious EXR file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 20 Dec 2021
    7.8
    High

    CVE-2021-43029

    Last Modified: 23 Apr 2025

    Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 20 Dec 2021
    7.8
    High

    CVE-2021-43028

    Last Modified: 23 Apr 2025

    Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 20 Dec 2021
    7.8
    High

    CVE-2021-40783

    Last Modified: 23 Apr 2025

    Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 20 Dec 2021
    7.8
    High

    CVE-2021-43026

    Last Modified: 23 Apr 2025

    Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious MXF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 20 Dec 2021
    7.5
    High

    CVE-2021-22056

    Last Modified: 21 Nov 2024

    VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary origins and read the full response.

    Published: 20 Dec 2021
    8.8
    High

    CVE-2021-22057

    Last Modified: 21 Nov 2024

    VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 contain an authentication bypass vulnerability. A malicious actor, who has successfully provided first-factor authentication, may be able to obtain second-factor authentication provided by VMware Verify.

    Published: 20 Dec 2021
    8
    High

    CVE-2021-35234

    Last Modified: 21 Nov 2024

    Numerous exposed dangerous functions within Orion Core has allows for read-only SQL injection leading to privileged escalation. An attacker with low-user privileges may steal password hashes and password salt information.

    Published: 20 Dec 2021
    6.8
    Medium

    CVE-2021-35244

    Last Modified: 21 Nov 2024

    The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An attacker with Orion alert management rights could use this vulnerability to perform an unrestricted file upload causing a remote code execution.

    Published: 20 Dec 2021
    6.8
    Medium

    CVE-2021-35248

    Last Modified: 21 Nov 2024

    It has been reported that any Orion user, e.g. guest accounts can query the Orion.UserSettings entity and enumerate users and their basic settings.

    Published: 20 Dec 2021
    6.1
    Medium

    CVE-2021-36887

    Last Modified: 28 Mar 2025

    Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) discovered in tarteaucitron.js – Cookies legislation & GDPR WordPress plugin (versions <= 1.5.4), vulnerable parameters "tarteaucitronEmail" and "tarteaucitronPass".

    Published: 20 Dec 2021
    3.4
    Low

    CVE-2021-36889

    Last Modified: 28 Mar 2025

    Multiple Stored Authenticated Cross-Site Scripting (XSS) vulnerabilities were discovered in tarteaucitron.js – Cookies legislation & GDPR WordPress plugin (versions <= 1.6).

    Published: 20 Dec 2021
    8.8
    High

    CVE-2020-19316

    Last Modified: 21 Nov 2024

    OS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17.

    Published: 20 Dec 2021
    8.8
    High

    CVE-2021-43437

    Last Modified: 21 Nov 2024

    In sourcecodetester Engineers Online Portal as of 10-21-21, an attacker can manipulate the Host header as seen by the web application and cause the application to behave in unexpected ways. Very often multiple websites are hosted on the same IP address. This is where the Host Header comes in. This header specifies which website should process the HTTP request. The web server uses the value of this header to dispatch the request to the specified website. Each website hosted on the same IP address is called a virtual host. And It's possible to send requests with arbitrary Host Headers to the first virtual host.

    Published: 20 Dec 2021
    5.4
    Medium

    CVE-2021-43438

    Last Modified: 21 Nov 2024

    Stored XSS in Signup Form in iResturant 1.0 Allows Remote Attacker to Inject Arbitrary code via NAME and ADDRESS field

    Published: 20 Dec 2021
    9.8
    Critical

    CVE-2021-43439

    Last Modified: 21 Nov 2024

    RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely

    Published: 20 Dec 2021
    5.3
    Medium

    CVE-2021-43441

    Last Modified: 21 Nov 2024

    An HTML Injection Vulnerability in iOrder 1.0 allows the remote attacker to execute Malicious HTML codes via the signup form

    Published: 20 Dec 2021
    6.1
    Medium

    CVE-2021-43440

    Last Modified: 21 Nov 2024

    Multiple Stored XSS Vulnerabilities in the Source Code of iOrder 1.0 allow remote attackers to execute arbitrary code via signup form in the Name and Phone number field.

    Published: 20 Dec 2021
    9.8
    Critical

    CVE-2021-44525

    Last Modified: 21 Nov 2024

    Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authentication is not required.

    Published: 20 Dec 2021
    9.8
    Critical

    CVE-2021-44675

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which authentication is not required.

    Published: 20 Dec 2021
    9.8
    Critical

    CVE-2021-44676

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control details) and modify a few aspects of the application state.

    Published: 20 Dec 2021
    9.6
    Critical

    CVE-2020-8105

    Last Modified: 21 Nov 2024

    OS Command Injection vulnerability in the wirelessConnect handler of Abode iota All-In-One Security Kit allows an attacker to inject commands and gain root access. This issue affects: Abode iota All-In-One Security Kit versions prior to 1.0.2.23_6.9V_dev_t2_homekit_RF_2.0.19_s2_kvsABODE oz.

    Published: 20 Dec 2021
    6.1
    Medium

    CVE-2021-44916

    Last Modified: 21 Nov 2024

    Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad value is passed to the routine via a URL, malicious JavaScript code can be executed in the victim's browser.

    Published: 20 Dec 2021
    7.5
    High

    CVE-2021-41561

    Last Modified: 28 Jul 2025

    Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet files. This issue affects Apache Parquet-MR version 1.9.0 and later versions.

    Published: 20 Dec 2021
    5.3
    Medium

    CVE-2021-44554

    Last Modified: 21 Nov 2024

    Thinfinity VirtualUI before 3.0 allows a malicious actor to enumerate users registered in the OS (Windows) through the /changePassword URI. By accessing the vector, an attacker can determine if a username exists thanks to the message returned; it can be presented in different languages according to the configuration of VirtualUI. Common users are administrator, admin, guest and krgtbt.

    Published: 20 Dec 2021
    5.4
    Medium

    CVE-2021-44263

    Last Modified: 21 Nov 2024

    Gurock TestRail before 7.2.4 mishandles HTML escaping.

    Published: 20 Dec 2021
    7.5
    High

    CVE-2021-42913

    Last Modified: 21 Nov 2024

    The SyncThru Web Service on Samsung SCX-6x55X printers allows an attacker to gain access to a list of SMB users and cleartext passwords by reading the HTML source code. Authentication is not required.

    Published: 20 Dec 2021
    9.8
    Critical

    CVE-2021-44164

    Last Modified: 21 Nov 2024

    Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allows a remote attacker to by-pass file type validation, upload malicious script and execute arbitrary code without authentication, in order to take control of the system or terminate service.

    Published: 20 Dec 2021
    6.1
    Medium

    CVE-2021-44163

    Last Modified: 21 Nov 2024

    Chain Sea ai chatbot backend has improper filtering of special characters in URL parameters, which allows a remote attacker to perform JavaScript injection for XSS (reflected Cross-site scripting) attack without authentication.

    Published: 20 Dec 2021
    7.5
    High

    CVE-2021-44162

    Last Modified: 21 Nov 2024

    Chain Sea ai chatbot system’s specific file download function has path traversal vulnerability. The function has improper filtering of special characters in URL parameters, which allows a remote attacker to download arbitrary system files without authentication.

    Published: 20 Dec 2021
    9.8
    Critical

    CVE-2021-44159

    Last Modified: 21 Nov 2024

    4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary files including webshell files without authentication and execute arbitrary code in order to perform arbitrary system operations or deny of service attack.

    Published: 20 Dec 2021
    9.8
    Critical

    CVE-2021-44732

    Last Modified: 5 Jun 2026

    Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.

    Published: 20 Dec 2021
    6.5
    Medium

    CVE-2021-28712

    Last Modified: 21 Nov 2024

    Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen offers the ability to run PV backends in regular unprivileged guests, typically referred to as "driver domains". Running PV backends in driver domains has one primary security advantage: if a driver domain gets compromised, it doesn't have the privileges to take over the system. However, a malicious driver domain could try to attack other guests via sending events at a high frequency leading to a Denial of Service in the guest due to trying to service interrupts for elongated amounts of time. There are three affected backends: * blkfront patch 1, CVE-2021-28711 * netfront patch 2, CVE-2021-28712 * hvc_xen (console) patch 3, CVE-2021-28713

    Published: 20 Dec 2021
    6.5
    Medium

    CVE-2021-28713

    Last Modified: 21 Nov 2024

    Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen offers the ability to run PV backends in regular unprivileged guests, typically referred to as "driver domains". Running PV backends in driver domains has one primary security advantage: if a driver domain gets compromised, it doesn't have the privileges to take over the system. However, a malicious driver domain could try to attack other guests via sending events at a high frequency leading to a Denial of Service in the guest due to trying to service interrupts for elongated amounts of time. There are three affected backends: * blkfront patch 1, CVE-2021-28711 * netfront patch 2, CVE-2021-28712 * hvc_xen (console) patch 3, CVE-2021-28713

    Published: 20 Dec 2021
    6.5
    Medium

    CVE-2021-28711

    Last Modified: 21 Nov 2024

    Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen offers the ability to run PV backends in regular unprivileged guests, typically referred to as "driver domains". Running PV backends in driver domains has one primary security advantage: if a driver domain gets compromised, it doesn't have the privileges to take over the system. However, a malicious driver domain could try to attack other guests via sending events at a high frequency leading to a Denial of Service in the guest due to trying to service interrupts for elongated amounts of time. There are three affected backends: * blkfront patch 1, CVE-2021-28711 * netfront patch 2, CVE-2021-28712 * hvc_xen (console) patch 3, CVE-2021-28713

    Published: 20 Dec 2021
    8.8
    High

    CVE-2021-3860

    Last Modified: 21 Nov 2024

    JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged authenticated user due to incomplete validation when performing an SQL query.

    Published: 20 Dec 2021