CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2021-42220

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability exists in Dolibarr before 14.0.3 via the ticket creation flow. Exploitation requires that an admin copies the payload into a box.

    Published: 15 Dec 2021
    9.8
    Critical

    CVE-2021-42945

    Last Modified: 21 Nov 2024

    A SQL Injection vulnerability exists in ZZCMS 2021 via the askbigclassid parameter in /admin/ask.php.

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-43326

    Last Modified: 21 Nov 2024

    Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory.

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-43325

    Last Modified: 21 Nov 2024

    Automox Agent 33 on Windows incorrectly sets permissions on a temporary directory. NOTE: this issue exists because of a CVE-2021-43326 regression.

    Published: 15 Dec 2021
    5.4
    Medium

    CVE-2021-41557

    Last Modified: 21 Nov 2024

    Sofico Miles RIA 2020.2 Build 127964T is affected by Stored Cross Site Scripting (XSS). An attacker with access to a user account of the RIA IT or the Fleet role can create a crafted work order in the damage reports section (or change existing work orders). The XSS payload is in the work order number.

    Published: 15 Dec 2021
    9.8
    Critical

    CVE-2021-41844

    Last Modified: 21 Nov 2024

    Crocoblock JetEngine before 2.9.1 does not properly validate and sanitize form data.

    Published: 15 Dec 2021
    5.4
    Medium

    CVE-2021-41871

    Last Modified: 21 Nov 2024

    An issue was discovered in Socomec REMOTE VIEW PRO 2.0.41.4. Improper validation of input into the username field makes it possible to place a stored XSS payload. This is executed if an administrator views the System Event Log.

    Published: 15 Dec 2021
    8.8
    High

    CVE-2021-41870

    Last Modified: 21 Nov 2024

    An issue was discovered in the firmware update form in Socomec REMOTE VIEW PRO 2.0.41.4. An authenticated attacker can bypass a client-side file-type check and upload arbitrary .php files.

    Published: 15 Dec 2021
    7.5
    High

    CVE-2021-4110

    Last Modified: 21 Nov 2024

    mruby is vulnerable to NULL Pointer Dereference

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-45463

    Last Modified: 3 Nov 2025

    load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.

    Published: 15 Dec 2021
    6.6
    Medium

    CVE-2021-22600

    Last Modified: 24 Oct 2025

    A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755

    Published: 15 Dec 2021
    9.8
    Critical

    CVE-2021-43113

    Last Modified: 25 Feb 2026

    iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.

    Published: 15 Dec 2021
    6.5
    Medium

    CVE-2021-20330

    Last Modified: 21 Nov 2024

    An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in a potential denial of service on secondaries. This issue affects MongoDB Server v4.0 versions prior to 4.0.27; MongoDB Server v4.2 versions prior to 4.2.16; MongoDB Server v4.4 versions prior to 4.4.9.

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-39685

    Last Modified: 21 Nov 2024

    In various setup methods of the USB gadget subsystem, there is a possible out of bounds write due to an incorrect flag check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-210292376References: Upstream kernel

    Published: 15 Dec 2021
    4.3
    Medium

    CVE-2021-43827

    Last Modified: 21 Nov 2024

    discourse-footnote is a library providing footnotes for posts in Discourse. ### Impact When posting an inline footnote wrapped in `<a>` tags (e.g. `<a>^[footnote]</a>`, the resulting rendered HTML would include a nested `<a>`, which is stripped by Nokogiri because it is not valid. This then caused a javascript error on topic pages because we were looking for an `<a>` element inside the footnote reference span and getting its ID, and because it did not exist we got a null reference error in javascript. Users are advised to update to version 0.2. As a workaround editing offending posts from the rails console or the database console for self-hosters, or disabling the plugin in the admin panel can mitigate this issue.

    Published: 14 Dec 2021
    6.1
    Medium

    CVE-2021-4108

    Last Modified: 21 Nov 2024

    snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 14 Dec 2021
    4.3
    Medium

    CVE-2021-44942

    Last Modified: 21 Nov 2024

    glFusion CMS 1.7.9 is affected by a Cross Site Request Forgery (CSRF) vulnerability in /public_html/admin/plugins/bad_behavior2/blacklist.php. Using the CSRF vulnerability to trick the administrator to click, an attacker can add a blacklist.

    Published: 14 Dec 2021
    8.2
    High

    CVE-2021-39183

    Last Modified: 21 Nov 2024

    Owncast is an open source, self-hosted live video streaming and chat server. In affected versions inline scripts are executed when Javascript is parsed via a paste action. This issue is patched in 0.0.9 by blocking unsafe-inline Content Security Policy and specifying the script-src. The worker-src is required to be set to blob for the video player.

    Published: 14 Dec 2021
    —
    Unknown

    CVE-2021-44948

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-44942. Reason: This candidate is a duplicate of CVE-2021-44942. Notes: All CVE users should reference CVE-2021-44942 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 14 Dec 2021
    5.3
    Medium

    CVE-2021-34426

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in the Keybase Client for Windows before version 5.6.0 when a user executed the "keybase git lfs-config" command on the command-line. In versions prior to 5.6.0, a malicious actor with write access to a user\'s Git repository could leverage this vulnerability to potentially execute arbitrary Windows commands on a user\'s local system.

    Published: 14 Dec 2021
    4.7
    Medium

    CVE-2021-34425

    Last Modified: 21 Nov 2024

    The Zoom Client for Meetings before version 5.7.3 (for Android, iOS, Linux, macOS, and Windows) contain a server side request forgery vulnerability in the chat\'s "link preview" functionality. In versions prior to 5.7.3, if a user were to enable the chat\'s "link preview" feature, a malicious actor could trick the user into potentially sending arbitrary HTTP GET requests to URLs that the actor cannot reach directly.

    Published: 14 Dec 2021
    7.4
    High

    CVE-2021-43829

    Last Modified: 21 Nov 2024

    PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.7.7 PatrowlManager unrestrictly handle upload files in the findings import feature. This vulnerability is capable of uploading dangerous type of file to server leading to XSS attacks and potentially other forms of code injection. Users are advised to update to 1.7.7 as soon as possible. There are no known workarounds for this issue.

    Published: 14 Dec 2021
    7.4
    High

    CVE-2021-43830

    Last Modified: 21 Nov 2024

    OpenProject is a web-based project management software. OpenProject versions >= 12.0.0 are vulnerable to a SQL injection in the budgets module. For authenticated users with the "Edit budgets" permission, the request to reassign work packages to another budget unsufficiently sanitizes user input in the `reassign_to_id` parameter. The vulnerability has been fixed in version 12.0.4. Versions prior to 12.0.0 are not affected. If you're upgrading from an older version, ensure you are upgrading to at least version 12.0.4. If you are unable to upgrade in a timely fashion, the following patch can be applied: https://github.com/opf/openproject/pull/9983.patch

    Published: 14 Dec 2021
    7.5
    High

    CVE-2021-43828

    Last Modified: 21 Nov 2024

    PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.77 an improper privilege management (IDOR) has been found in PatrowlManager. All imports findings file is placed under /media/imports/<owner_id>/<tmp_file> In that, owner_id is predictable and tmp_file is in format of import_<ownder_id>_<time_created>, for example: import_1_1639213059582.json This filename is predictable and allows anyone without logging in to download all finding import files This vulnerability is capable of allowing unlogged in users to download all finding imports file. Users are advised to update to 1.7.7 as soon as possible. There are no known workarounds.

    Published: 14 Dec 2021
    7.1
    High

    CVE-2021-43051

    Last Modified: 21 Nov 2024

    The Spotfire Server component of TIBCO Software Inc.'s TIBCO Spotfire Server, TIBCO Spotfire Server, and TIBCO Spotfire Server contains a difficult to exploit vulnerability that allows malicious custom API clients with network access to execute internal API operations outside of the scope of those granted to it. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Server: versions 10.10.6 and below, TIBCO Spotfire Server: versions 11.0.0, 11.1.0, 11.2.0, 11.3.0, 11.4.0, and 11.4.1, and TIBCO Spotfire Server: versions 11.5.0 and 11.6.0.

    Published: 14 Dec 2021
    9.9
    Critical

    CVE-2021-43821

    Last Modified: 21 Nov 2024

    Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast before version 9.10 or 10.6 allows references to local file URLs in ingested media packages, allowing attackers to include local files from Opencast's host machines and making them available via the web interface. Before Opencast 9.10 and 10.6, Opencast would open and include local files during ingests. Attackers could exploit this to include most local files the process has read access to, extracting secrets from the host machine. An attacker would need to have the privileges required to add new media to exploit this. But these are often widely given. The issue has been fixed in Opencast 10.6 and 11.0. You can mitigate this issue by narrowing down the read access Opencast has to files on the file system using UNIX permissions or mandatory access control systems like SELinux. This cannot prevent access to files Opencast needs to read though and we highly recommend updating.

    Published: 14 Dec 2021
    7.4
    High

    CVE-2021-43820

    Last Modified: 21 Nov 2024

    Seafile is an open source cloud storage system. A sync token is used in Seafile file syncing protocol to authorize access to library data. To improve performance, the token is cached in memory in seaf-server. Upon receiving a token from sync client or SeaDrive client, the server checks whether the token exist in the cache. However, if the token exists in cache, the server doesn't check whether it's associated with the specific library in the URL. This vulnerability makes it possible to use any valid sync token to access data from any **known** library. Note that the attacker has to first find out the ID of a library which it has no access to. The library ID is a random UUID, which is not possible to be guessed. There are no workarounds for this issue.

    Published: 14 Dec 2021
    6.1
    Medium

    CVE-2018-10228

    Last Modified: 5 Jul 2026

    Cross-site scripting (XSS) vulnerability in /application/controller/admin/theme.php in LimeSurvey 3.6.2+180406 allows remote attackers to inject arbitrary web script or HTML via the changes_cp parameter to the index.php/admin/themes/sa/templatesavechanges URI.

    Published: 14 Dec 2021
    7.5
    High

    CVE-2021-43807

    Last Modified: 21 Nov 2024

    Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast versions prior to 9.10 allow HTTP method spoofing, allowing to change the assumed HTTP method via URL parameter. This allows attackers to turn HTTP GET requests into PUT requests or an HTTP form to send DELETE requests. This bypasses restrictions otherwise put on these types of requests and aids in cross-site request forgery (CSRF) attacks, which would otherwise not be possible. The vulnerability allows attackers to craft links or forms which may change the server state. This issue is fixed in Opencast 9.10 and 10.0. You can mitigate the problem by setting the `SameSite=Strict` attribute for your cookies. If this is a viable option for you depends on your integrations. We strongly recommend updating in any case.

    Published: 14 Dec 2021
    9.8
    Critical

    CVE-2021-40883

    Last Modified: 21 Nov 2024

    A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins.

    Published: 14 Dec 2021
    7.5
    High

    CVE-2021-43388

    Last Modified: 21 Nov 2024

    Unisys Cargo Mobile Application before 1.2.29 uses cleartext to store sensitive information, which might be revealed in a backup. The issue is addressed by ensuring that the allowBackup flag (in the manifest) is False.

    Published: 14 Dec 2021
    6.1
    Medium

    CVE-2021-40882

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability exists in Piwigo 11.5.0 via the system album name and description of the location.

    Published: 14 Dec 2021
    5.4
    Medium

    CVE-2021-44043

    Last Modified: 21 Nov 2024

    An issue was discovered in UiPath App Studio 21.4.4. There is a persistent XSS vulnerability in the file-upload functionality for uploading icons when attempting to create new Apps. An attacker with minimal privileges in the application can build their own App and upload a malicious file containing an XSS payload, by uploading an arbitrary file and modifying the MIME type in a subsequent HTTP request. This then allows the file to be stored and retrieved from the server by other users in the same organization.

    Published: 14 Dec 2021
    9.8
    Critical

    CVE-2021-44041

    Last Modified: 21 Nov 2024

    UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI handler for uipath-assistant://. This allows an attacker to execute code on a victim's machine or capture NTLM credentials by supplying a networked or WebDAV file path.

    Published: 14 Dec 2021
    9.8
    Critical

    CVE-2021-44042

    Last Modified: 21 Nov 2024

    An issue was discovered in UiPath Assistant 21.4.4. User-controlled data supplied to the --process-start argument of the URI handler for uipath-assistant:// is not correctly encoded, resulting in attacker-controlled content being injected into the error message displayed (when the injected content does not match an existing process). A determined attacker could leverage this to execute JavaScript in the context of the Electron application.

    Published: 14 Dec 2021
    7.8
    High

    CVE-2021-38950

    Last Modified: 21 Nov 2024

    IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation attack when SharedBindingsUserId is set to effective. IBM X-ForceID: 211404.

    Published: 14 Dec 2021
    6.1
    Medium

    CVE-2021-39313

    Last Modified: 31 Jan 2025

    The Simple Image Gallery WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in the ~/simple-image-gallery.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.6.

    Published: 14 Dec 2021
    6.1
    Medium

    CVE-2021-39310

    Last Modified: 31 Jan 2025

    The Real WYSIWYG WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of PHP_SELF in the ~/real-wysiwyg.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.0.2.

    Published: 14 Dec 2021
    7.5
    High

    CVE-2021-39312

    Last Modified: 31 Jan 2025

    The True Ranker plugin <= 2.2.2 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be accessed via the src parameter found in the ~/admin/vendor/datatables/examples/resources/examples.php file.

    Published: 14 Dec 2021
    6.1
    Medium

    CVE-2021-39308

    Last Modified: 31 Jan 2025

    The WooCommerce myghpay Payment Gateway WordPess plugin is vulnerable to Reflected Cross-Site Scripting via the clientref parameter found in the ~/processresponse.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.0.

    Published: 14 Dec 2021
    9.8
    Critical

    CVE-2021-4073

    Last Modified: 14 Feb 2025

    The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7.

    Published: 14 Dec 2021
    6.1
    Medium

    CVE-2021-38361

    Last Modified: 14 Feb 2025

    The .htaccess Redirect WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the link parameter found in the ~/htaccess-redirect.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.3.1.

    Published: 14 Dec 2021
    6.1
    Medium

    CVE-2021-39311

    Last Modified: 14 Feb 2025

    The link-list-manager WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the category parameter found in the ~/llm.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.

    Published: 14 Dec 2021
    6.1
    Medium

    CVE-2021-39309

    Last Modified: 14 Feb 2025

    The Parsian Bank Gateway for Woocommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via and parameter due to a var_dump() on $_POST variables found in the ~/vendor/dpsoft/parsian-payment/sample/rollback-payment.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.

    Published: 14 Dec 2021
    6.1
    Medium

    CVE-2021-39314

    Last Modified: 13 Feb 2025

    The WooCommerce EnvioPack WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the dataid parameter found in the ~/includes/functions.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.

    Published: 14 Dec 2021
    6.1
    Medium

    CVE-2021-39318

    Last Modified: 13 Feb 2025

    The H5P CSS Editor WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the h5p-css-file parameter found in the ~/h5p-css-editor.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.

    Published: 14 Dec 2021
    4.8
    Medium

    CVE-2021-41836

    Last Modified: 10 Feb 2025

    The Fathom Analytics WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and escaping via the $site_id parameter found in the ~/fathom-analytics.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 3.0.4. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

    Published: 14 Dec 2021
    6.4
    Medium

    CVE-2021-42367

    Last Modified: 13 Feb 2025

    The Variation Swatches for WooCommerce WordPress plugin is vulnerable to Stored Cross-Site Scripting via several parameters found in the ~/includes/class-menu-page.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.1.1. Due to missing authorization checks on the tawcvs_save_settings function, low-level authenticated users such as subscribers can exploit this vulnerability.

    Published: 14 Dec 2021
    6.1
    Medium

    CVE-2021-39319

    Last Modified: 13 Feb 2025

    The duoFAQ - Responsive, Flat, Simple FAQ WordPess plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in the ~/duogeek/duogeek-panel.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.4.8.

    Published: 14 Dec 2021
    6.1
    Medium

    CVE-2021-39315

    Last Modified: 13 Feb 2025

    The Magic Post Voice WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the ids parameter found in the ~/inc/admin/main.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.

    Published: 14 Dec 2021