CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2020-35211

    Last Modified: 21 Nov 2024

    An issue in Atomix v3.1.5 allows unauthorized Atomix nodes to become the lead node in a target cluster via manipulation of the variable terms in RaftContext.

    Published: 16 Dec 2021
    8.2
    High

    CVE-2021-3929

    Last Modified: 28 Feb 2025

    A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021-3750 and, just like it, when the reentrancy write triggers the reset function nvme_ctrl_reset(), data structs will be freed leading to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition or, potentially, executing arbitrary code within the context of the QEMU process on the host.

    Published: 16 Dec 2021
    7.5
    High

    CVE-2021-44858

    Last Modified: 21 Nov 2024

    An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one page set in $wgWhitelistRead.

    Published: 16 Dec 2021
    5.3
    Medium

    CVE-2021-45038

    Last Modified: 21 Nov 2024

    An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. By using an action=rollback query, attackers can view private wiki contents.

    Published: 16 Dec 2021
    4.7
    Medium

    CVE-2021-45096

    Last Modified: 21 Nov 2024

    KNIME Analytics Platform before 4.5.0 is vulnerable to XXE (external XML entity injection) via a crafted workflow file (.knwf), aka AP-17730.

    Published: 16 Dec 2021
    2.9
    Low

    CVE-2021-45097

    Last Modified: 21 Nov 2024

    KNIME Server before 4.12.6 and 4.13.x before 4.13.4 (when installed in unattended mode) keeps the administrator's password in a file without appropriate file access controls, allowing all local users to read its content.

    Published: 16 Dec 2021
    7.5
    High

    CVE-2020-35209

    Last Modified: 21 Nov 2024

    An issue in Atomix v3.1.5 allows unauthorized Atomix nodes to join a target cluster via providing configuration information.

    Published: 16 Dec 2021
    8.1
    High

    CVE-2020-35214

    Last Modified: 21 Nov 2024

    An issue in Atomix v3.1.5 allows a malicious Atomix node to remove states of ONOS storage via abuse of primitive operations.

    Published: 16 Dec 2021
    5.9
    Medium

    CVE-2020-35216

    Last Modified: 21 Nov 2024

    An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false member down event messages.

    Published: 16 Dec 2021
    8.1
    High

    CVE-2021-4125

    Last Modified: 21 Nov 2024

    It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift 4.8, 4.7 and 4.6.

    Published: 16 Dec 2021
    6.6
    Medium

    CVE-2021-42550

    Last Modified: 21 Nov 2024

    In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.

    Published: 16 Dec 2021
    6.5
    Medium

    CVE-2021-44857

    Last Modified: 21 Nov 2024

    An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=mcrundo followed by action=mcrrestore to replace the content of any arbitrary page (that the user doesn't have edit rights for). This applies to any public wiki, or a private wiki that has at least one page set in $wgWhitelistRead.

    Published: 16 Dec 2021
    6.5
    Medium

    CVE-2020-35210

    Last Modified: 21 Nov 2024

    A vulnerability in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via a Raft session flooding attack using Raft OpenSessionRequest messages.

    Published: 16 Dec 2021
    8.1
    High

    CVE-2020-35213

    Last Modified: 21 Nov 2024

    An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false link event messages sent to a master ONOS node.

    Published: 16 Dec 2021
    6.5
    Medium

    CVE-2020-35215

    Last Modified: 21 Nov 2024

    An issue in Atomix v3.1.5 allows attackers to access sensitive information when a malicious Atomix node queries distributed variable primitives which contain the entire primitive lists that ONOS nodes use to share important states.

    Published: 16 Dec 2021
    9.1
    Critical

    CVE-2021-43834

    Last Modified: 21 Nov 2024

    eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows an attacker to authenticate as an existing user, if that user was created using a single sign-on authentication option such as LDAP or SAML. It impacts instances where LDAP or SAML is used for authentication instead of the (default) local password mechanism. Users should upgrade to at least version 4.2.0.

    Published: 15 Dec 2021
    8.1
    High

    CVE-2021-43833

    Last Modified: 21 Nov 2024

    eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows any authenticated user to gain access to arbitrary accounts by setting a specially crafted email address. This vulnerability impacts all instances that have not set an explicit email domain name allowlist. Note that whereas neither administrators nor targeted users are notified of a change, an attacker will need to control an account. The default settings require administrators to validate newly created accounts. The problem has been patched. Users should upgrade to at least version 4.2.0. For users unable to upgrade enabling an email domain allow list (from Sysconfig panel, Security tab) will completely resolve the issue.

    Published: 15 Dec 2021
    6.1
    Medium

    CVE-2021-45018

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability exists in Catfish <=6.3.0 via a Google search in url:/catfishcms/index.php/admin/Index/addmenu.htmland then the .html file on the website that uses this editor (the file suffix is allowed).

    Published: 15 Dec 2021
    8.8
    High

    CVE-2021-45017

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) vulnerability exits in Catfish <=6.1.* when you upload an html file containing CSRF on the website that uses a google editor; you can specify the menu url address as your malicious url address in the Add Menu column.

    Published: 15 Dec 2021
    6.1
    Medium

    CVE-2020-18985

    Last Modified: 21 Nov 2024

    An issue in /domain/service/.ewell-known/caldav of Zimbra Collaboration 8.8.12 allows attackers to redirect users to any arbitrary website of their choosing.

    Published: 15 Dec 2021
    6.1
    Medium

    CVE-2020-18984

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability in the zimbraAdmin/public/secureRequest.jsp component of Zimbra Collaboration 8.8.12 allows unauthenticated attackers to execute arbitrary web scripts or HTML via a host header injection.

    Published: 15 Dec 2021
    9.8
    Critical

    CVE-2021-44350

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php.

    Published: 15 Dec 2021
    6.1
    Medium

    CVE-2021-44116

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability exits in Anchor CMS <=0.12.7 in posts.php. Attackers can use the posts column to upload the title and content containing malicious code to achieve the purpose of obtaining the administrator cookie, thereby achieving other malicious operations.

    Published: 15 Dec 2021
    8.5
    High

    CVE-2021-43836

    Last Modified: 21 Nov 2024

    Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions an attacker can read arbitrary local files via a PHP file include. In a default configuration this also leads to remote code execution. The problem is patched with the Versions 1.6.44, 2.2.18, 2.3.8, 2.4.0. For users unable to upgrade overwrite the service `sulu_route.generator.expression_token_provider` and wrap the translator before passing it to the expression language.

    Published: 15 Dec 2021
    7.2
    High

    CVE-2021-43835

    Last Modified: 21 Nov 2024

    Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions Sulu users who have access to any subset of the admin UI are able to elevate their privilege. Over the API it was possible for them to give themselves permissions to areas which they did not already had. This issue was introduced in 2.0.0-RC1 with the new ProfileController putAction. The versions have been patched in 2.2.18, 2.3.8 and 2.4.0. For users unable to upgrade the only known workaround is to apply a patch to the ProfileController manually.

    Published: 15 Dec 2021
    7.7
    High

    CVE-2021-43831

    Last Modified: 21 Nov 2024

    Gradio is an open source framework for building interactive machine learning models and demos. In versions prior to 2.5.0 there is a vulnerability that affects anyone who creates and publicly shares Gradio interfaces. File paths are not restricted and users who receive a Gradio link can access any files on the host computer if they know the file names or file paths. This is limited only by the host operating system. Paths are opened in read only mode. The problem has been patched in gradio 2.5.0.

    Published: 15 Dec 2021
    5.4
    Medium

    CVE-2021-35490

    Last Modified: 21 Nov 2024

    Thruk before 2.44 allows XSS for a quick command.

    Published: 15 Dec 2021
    8.8
    High

    CVE-2021-43806

    Last Modified: 21 Nov 2024

    Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected versions Tuleap does not sanitize properly user settings when constructing the SQL query to browse and search commits in the CVS repositories. A authenticated malicious user with read access to a CVS repository could execute arbitrary SQL queries. Tuleap instances without an active CVS repositories are not impacted. The following versions contain the fix: Tuleap Community Edition 13.2.99.155, Tuleap Enterprise Edition 13.1-7, and Tuleap Enterprise Edition 13.2-6.

    Published: 15 Dec 2021
    6.7
    Medium

    CVE-2021-41276

    Last Modified: 21 Nov 2024

    Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected versions Tuleap does not sanitize properly the search filter built from the ldap_id attribute of a user during the daily synchronization. A malicious user could force accounts to be suspended or take over another account by forcing the update of the ldap_uid attribute. Note that the malicious user either need to have site administrator capability on the Tuleap instance or be an LDAP operator with the capability to create/modify account. The Tuleap instance needs to have the LDAP plugin activated and enabled for this issue to be exploitable. This issue has been patched in Tuleap Community Edition 13.2.99.31, Tuleap Enterprise Edition 13.1-5, and Tuleap Enterprise Edition 13.2-3.

    Published: 15 Dec 2021
    6.7
    Medium

    CVE-2021-43782

    Last Modified: 21 Nov 2024

    Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. This is a follow up to GHSA-887w-pv2r-x8pm/CVE-2021-41276, the initial fix was incomplete. Tuleap does not sanitize properly the search filter built from the ldap_id attribute of a user during the daily synchronization. A malicious user could force accounts to be suspended or take over another account by forcing the update of the ldap_uid attribute. Note that the malicious user either need to have site administrator capability on the Tuleap instance or be an LDAP operator with the capability to create/modify account. The Tuleap instance needs to have the LDAP plugin activated and enabled for this issue to be exploitable. The following versions contain the fix: Tuleap Community Edition 13.2.99.83, Tuleap Enterprise Edition 13.1-6, and Tuleap Enterprise Edition 13.2-4.

    Published: 15 Dec 2021
    9.8
    Critical

    CVE-2021-36888

    Last Modified: 28 Mar 2025

    Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.1) WordPress plugin.

    Published: 15 Dec 2021
    5.5
    Medium

    CVE-2021-1038

    Last Modified: 21 Nov 2024

    In UserDetailsActivity of AndroidManifest.xml, there is a possible DoS due to a tapjacking/overlay attack. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-183411279

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-1039

    Last Modified: 21 Nov 2024

    In NotificationAccessActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-182808318

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-1040

    Last Modified: 21 Nov 2024

    In onCreate of BluetoothPairingSelectionFragment.java, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-182810085

    Published: 15 Dec 2021
    7.5
    High

    CVE-2021-39646

    Last Modified: 21 Nov 2024

    Product: AndroidVersions: Android kernelAndroid ID: A-201537251References: N/A

    Published: 15 Dec 2021
    9.8
    Critical

    CVE-2021-39644

    Last Modified: 21 Nov 2024

    Product: AndroidVersions: Android kernelAndroid ID: A-199809304References: N/A

    Published: 15 Dec 2021
    6.5
    Medium

    CVE-2021-0976

    Last Modified: 21 Nov 2024

    In toBARK of floor0.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-199680600

    Published: 15 Dec 2021
    9.8
    Critical

    CVE-2021-39645

    Last Modified: 21 Nov 2024

    Product: AndroidVersions: Android kernelAndroid ID: A-199805112References: N/A

    Published: 15 Dec 2021
    4.4
    Medium

    CVE-2021-39647

    Last Modified: 21 Nov 2024

    In mon_smc_load_sp of gs101-sc/plat/samsung/exynos/soc/exynos9845/smc_booting.S, there is a possible reinitialization of TEE due to improper locking. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-198713939References: N/A

    Published: 15 Dec 2021
    6.8
    Medium

    CVE-2021-39639

    Last Modified: 21 Nov 2024

    In TBD of fvp.c, there is a possible way to glitch CPU behavior due to a missing permission check. This could lead to local escalation of privilege with physical access to device internals with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-198291476References: N/A

    Published: 15 Dec 2021
    4.4
    Medium

    CVE-2021-1047

    Last Modified: 21 Nov 2024

    In valid_ipc_dram_addr of cm_access_control.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-197966306References: N/A

    Published: 15 Dec 2021
    3.3
    Low

    CVE-2021-0995

    Last Modified: 21 Nov 2024

    In registerSuggestionConnectionStatusListener of WifiServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-197536547

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-1004

    Last Modified: 21 Nov 2024

    In getConfiguredNetworks of WifiServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-197749180

    Published: 15 Dec 2021
    5
    Medium

    CVE-2021-0973

    Last Modified: 21 Nov 2024

    In isFileUri of UriUtil.java, there is a possible way to bypass ignoring file://URI attachment due to improper handling of case sensitivity. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-197328178

    Published: 15 Dec 2021
    4.4
    Medium

    CVE-2021-1008

    Last Modified: 21 Nov 2024

    In addSubInfo of SubscriptionController.java, there is a possible way to force the user to make a factory reset due to a logic error in the code. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-197327688

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-0999

    Last Modified: 21 Nov 2024

    In the broadcast definition in AndroidManifest.xml, there is a possible way to set the A2DP bluetooth device connection state due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-196858999

    Published: 15 Dec 2021
    5
    Medium

    CVE-2021-1023

    Last Modified: 21 Nov 2024

    In onCreate of RequestIgnoreBatteryOptimizations.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-195963373

    Published: 15 Dec 2021
    6.4
    Medium

    CVE-2021-39642

    Last Modified: 21 Nov 2024

    In synchronous_process_io_entries of lwis_ioctl.c, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-195731663References: N/A

    Published: 15 Dec 2021
    4.4
    Medium

    CVE-2021-1046

    Last Modified: 21 Nov 2024

    In lwis_dpm_update_clock of lwis_device_dpm.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-195609074References: N/A

    Published: 15 Dec 2021
    6.7
    Medium

    CVE-2021-39638

    Last Modified: 21 Nov 2024

    In periodic_io_work_func of lwis_periodic_io.c, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-195607566References: N/A

    Published: 15 Dec 2021