CVE Feed

    Dashboard / CVE

    8.2
    High

    CVE-2021-44224

    Last Modified: 21 Nov 2024

    A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included).

    Published: 20 Dec 2021
    9.8
    Critical

    CVE-2021-44790

    Last Modified: 1 May 2025

    A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.

    Published: 20 Dec 2021
    4.3
    Medium

    CVE-2021-4180

    Last Modified: 21 Nov 2024

    An information exposure flaw in openstack-tripleo-heat-templates allows an external user to discover the internal IP or hostname. An attacker could exploit this by checking the www_authenticate_uri parameter (which is visible to all end users) in configuration files. This would give sensitive information which may aid in additional system exploitation. This flaw affects openstack-tripleo-heat-templates versions prior to 11.6.1.

    Published: 20 Dec 2021
    8.8
    High

    CVE-2021-45041

    Last Modified: 21 Nov 2024

    SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resource_id and start_date.

    Published: 19 Dec 2021
    8.8
    High

    CVE-2021-43083

    Last Modified: 21 Nov 2024

    Apache PLC4X - PLC4C (Only the C language implementation was effected) was vulnerable to an unsigned integer underflow flaw inside the tcp transport. Users should update to 0.9.1, which addresses this issue. However, in order to exploit this vulnerability, a user would have to actively connect to a mallicious device which could send a response with invalid content. Currently we consider the probability of this being exploited as quite minimal, however this could change in the future, especially with the industrial networks growing more and more together.

    Published: 19 Dec 2021
    7.8
    High

    CVE-2021-4136

    Last Modified: 21 Nov 2024

    vim is vulnerable to Heap-based Buffer Overflow

    Published: 19 Dec 2021
    8.8
    High

    CVE-2021-4131

    Last Modified: 21 Nov 2024

    livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)

    Published: 18 Dec 2021
    8.8
    High

    CVE-2021-4130

    Last Modified: 21 Nov 2024

    snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)

    Published: 18 Dec 2021
    5.9
    Medium

    CVE-2021-45105

    Last Modified: 25 Aug 2026

    Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

    Published: 18 Dec 2021
    4
    Medium

    CVE-2023-23003

    Last Modified: 20 Mar 2025

    In the Linux kernel before 5.16, tools/perf/util/expr.c lacks a check for the hashmap__new return value.

    Published: 18 Dec 2021
    7.5
    High

    CVE-2021-41500

    Last Modified: 21 Nov 2024

    Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholmod.getfactor, cvxopt.cholmod.solve, cvxopt.cholmod.spsolve), which allows attackers to conduct Denial of Service attacks by construct fake Capsule objects.

    Published: 17 Dec 2021
    7.5
    High

    CVE-2021-41499

    Last Modified: 21 Nov 2024

    Buffer Overflow Vulnerability exists in ajaxsoundstudio.com n Pyo < 1.03 in the Server_debug function, which allows remote attackers to conduct DoS attacks by deliberately passing on an overlong audio file name.

    Published: 17 Dec 2021
    7.5
    High

    CVE-2021-41498

    Last Modified: 21 Nov 2024

    Buffer overflow in ajaxsoundstudio.com Pyo &lt and 1.03 in the Server_jack_init function. which allows attackers to conduct Denial of Service attacks by arbitrary constructing a overlong server name.

    Published: 17 Dec 2021
    7.5
    High

    CVE-2021-41497

    Last Modified: 21 Nov 2024

    Null pointer reference in CMS_Conservative_increment_obj in RaRe-Technologies bounter version 1.01 and 1.10, allows attackers to conduct Denial of Service attacks by inputting a huge width of hash bucket.

    Published: 17 Dec 2021
    9.8
    Critical

    CVE-2021-23803

    Last Modified: 21 Nov 2024

    This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the security of the application. When the template is set to allow/disallow the use of certain functions, adding control characters (x00-x08) after the function will bypass these restrictions.

    Published: 17 Dec 2021
    7.5
    High

    CVE-2021-23797

    Last Modified: 21 Nov 2024

    All versions of package http-server-node are vulnerable to Directory Traversal via use of --path-as-is.

    Published: 17 Dec 2021
    6.7
    Medium

    CVE-2021-23814

    Last Modified: 17 Jun 2025

    This affects versions of the package unisharp/laravel-filemanager before 2.6.2. The upload() function does not sufficiently validate the file type when uploading. An attacker may be able to reproduce the following steps: 1. Install a package with a web Laravel application. 2. Navigate to the Upload window 3. Upload an image file, then capture the request 4. Edit the request contents with a malicious file (webshell) 5. Enter the path of file uploaded on URL - Remote Code Execution **Note:** Prevention for bad extensions can be done by using a whitelist in the config file(lfm.php). Corresponding document can be found in [here](https://unisharp.github.io/laravel-filemanager/configfolder-categories).

    Published: 17 Dec 2021
    5.3
    Medium

    CVE-2021-43838

    Last Modified: 21 Nov 2024

    jsx-slack is a library for building JSON objects for Slack Block Kit surfaces from JSX. In versions prior to 4.5.1 users are vulnerable to a regular expression denial-of-service (ReDoS) attack. If attacker can put a lot of JSX elements into `<blockquote>` tag, an internal regular expression for escaping characters may consume an excessive amount of computing resources. jsx-slack v4.5.1 has patched to a regex for escaping blockquote characters. Users are advised to upgrade as soon as possible.

    Published: 17 Dec 2021
    4.4
    Medium

    CVE-2021-43840

    Last Modified: 21 Nov 2024

    message_bus is a messaging bus for Ruby processes and web clients. In versions prior to 3.3.7 users who deployed message bus with diagnostics features enabled (default off) are vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with `merge_slashes` enabled, the number of steps up the directories that can be read is limited to 3 levels. This issue has been patched in version 3.3.7. Users unable to upgrade should ensure that MessageBus::Diagnostics is disabled.

    Published: 17 Dec 2021
    5.4
    Medium

    CVE-2021-38883

    Last Modified: 21 Nov 2024

    IBM Business Automation Workflow 18.0, 19.0, 20,0 and 21.0 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 209165.

    Published: 17 Dec 2021
    7.5
    High

    CVE-2020-18081

    Last Modified: 21 Nov 2024

    The checkuser function of SEMCMS 3.8 was discovered to contain a vulnerability which allows attackers to obtain the password in plaintext through a SQL query.

    Published: 17 Dec 2021
    9.8
    Critical

    CVE-2020-18078

    Last Modified: 21 Nov 2024

    A vulnerability in /include/web_check.php of SEMCMS v3.8 allows attackers to reset the Administrator account's password.

    Published: 17 Dec 2021
    7.5
    High

    CVE-2020-18077

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in the Virtual Path Mapping component of FTPShell v6.83 allows attackers to cause a denial of service (DoS).

    Published: 17 Dec 2021
    7.1
    High

    CVE-2020-8968

    Last Modified: 21 Nov 2024

    Parallels Remote Application Server (RAS) allows a local attacker to retrieve certain profile password in clear text format by uploading a previously stored cyphered file by Parallels RAS. The confidentiality, availability and integrity of the information of the user could be compromised if an attacker is able to recover the profile password.

    Published: 17 Dec 2021
    7.2
    High

    CVE-2021-40853

    Last Modified: 21 Nov 2024

    TCMAN GIM does not perform an authorization check when trying to access determined resources. A remote attacker could exploit this vulnerability to access URL that require privileges without having them. The exploitation of this vulnerability might allow a remote attacker to obtain sensible information.

    Published: 17 Dec 2021
    6.1
    Medium

    CVE-2021-40852

    Last Modified: 21 Nov 2024

    TCMAN GIM is affected by an open redirect vulnerability. This vulnerability allows the redirection of user navigation to pages controlled by the attacker. The exploitation of this vulnerability might allow a remote attacker to obtain information.

    Published: 17 Dec 2021
    7.5
    High

    CVE-2021-40851

    Last Modified: 21 Nov 2024

    TCMAN GIM is vulnerable to a lack of authorization in all available webservice methods listed in /PC/WebService.asmx. The exploitation of this vulnerability might allow a remote attacker to obtain information.

    Published: 17 Dec 2021
    10
    Critical

    CVE-2021-40850

    Last Modified: 21 Nov 2024

    TCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.asmx.

    Published: 17 Dec 2021
    3.5
    Low

    CVE-2021-37863

    Last Modified: 21 Nov 2024

    Mattermost 6.0 and earlier fails to sufficiently validate parameters during post creation, which allows authenticated attackers to cause a client-side crash of the web application via a maliciously crafted post.

    Published: 17 Dec 2021
    3.7
    Low

    CVE-2021-37862

    Last Modified: 21 Nov 2024

    Mattermost 6.0 and earlier fails to sufficiently validate the email address during registration, which allows attackers to trick users into signing up using attacker-controlled email addresses via crafted invitation token.

    Published: 17 Dec 2021
    5.5
    Medium

    CVE-2021-20607

    Last Modified: 21 Nov 2024

    Integer Underflow vulnerability in Mitsubishi Electric GX Works2 versions 1.606G and prior, Mitsubishi Electric MELSOFT Navigator versions 2.84N and prior and Mitsubishi Electric EZSocket versions 5.4 and prior allows an attacker to cause a DoS condition in the software by getting a user to open malicious project file specially crafted by an attacker.

    Published: 17 Dec 2021
    5.5
    Medium

    CVE-2021-20606

    Last Modified: 21 Nov 2024

    Out-of-bounds Read vulnerability in Mitsubishi Electric GX Works2 versions 1.606G and prior, Mitsubishi Electric MELSOFT Navigator versions 2.84N and prior and Mitsubishi Electric EZSocket versions 5.4 and prior allows an attacker to cause a DoS condition in the software by getting a user to open malicious project file specially crafted by an attacker.

    Published: 17 Dec 2021
    7.5
    High

    CVE-2021-20608

    Last Modified: 21 Nov 2024

    Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric GX Works2 versions 1.606G and prior allows a remote unauthenticated attacker to cause a DoS condition in GX Works2 by getting GX Works2 to read a tampered program file from a Mitsubishi Electric PLC by sending malicious crafted packets to tamper with the program file.

    Published: 17 Dec 2021
    7.5
    High

    CVE-2021-22054

    Last Modified: 1 Oct 2026

    VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.

    Published: 17 Dec 2021
    5.5
    Medium

    CVE-2021-0674

    Last Modified: 21 Nov 2024

    In alac decoder, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06064258; Issue ID: ALPS06064237.

    Published: 17 Dec 2021
    7.8
    High

    CVE-2021-0673

    Last Modified: 21 Nov 2024

    In Audio Aurisys HAL, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05977326; Issue ID: ALPS05977326.

    Published: 17 Dec 2021
    6.7
    Medium

    CVE-2021-0903

    Last Modified: 21 Nov 2024

    In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05656488.

    Published: 17 Dec 2021
    4.4
    Medium

    CVE-2021-0902

    Last Modified: 21 Nov 2024

    In apusys, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05656484.

    Published: 17 Dec 2021
    6.7
    Medium

    CVE-2021-0901

    Last Modified: 21 Nov 2024

    In apusys, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05664618.

    Published: 17 Dec 2021
    4.4
    Medium

    CVE-2021-0900

    Last Modified: 21 Nov 2024

    In apusys, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05672055.

    Published: 17 Dec 2021
    6.7
    Medium

    CVE-2021-0899

    Last Modified: 21 Nov 2024

    In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05672059.

    Published: 17 Dec 2021
    6.7
    Medium

    CVE-2021-0898

    Last Modified: 21 Nov 2024

    In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05672071.

    Published: 17 Dec 2021
    6.7
    Medium

    CVE-2021-0896

    Last Modified: 21 Nov 2024

    In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05671206.

    Published: 17 Dec 2021
    6.7
    Medium

    CVE-2021-0897

    Last Modified: 21 Nov 2024

    In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05670549.

    Published: 17 Dec 2021
    6.7
    Medium

    CVE-2021-0895

    Last Modified: 21 Nov 2024

    In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05672003.

    Published: 17 Dec 2021
    6.7
    Medium

    CVE-2021-0894

    Last Modified: 21 Nov 2024

    In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05672038.

    Published: 17 Dec 2021
    6.7
    Medium

    CVE-2021-0679

    Last Modified: 21 Nov 2024

    In apusys, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05687781.

    Published: 17 Dec 2021
    6.7
    Medium

    CVE-2021-0893

    Last Modified: 21 Nov 2024

    In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05687474.

    Published: 17 Dec 2021
    6.7
    Medium

    CVE-2021-0678

    Last Modified: 21 Nov 2024

    In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05722511.

    Published: 17 Dec 2021
    4.4
    Medium

    CVE-2021-0676

    Last Modified: 21 Nov 2024

    In geniezone driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05863009; Issue ID: ALPS05863009.

    Published: 17 Dec 2021