CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-43801

    Last Modified: 21 Nov 2024

    Mercurius is a GraphQL adapter for Fastify. Any users from [email protected] to 8.11.1 are subjected to a denial of service attack by sending a malformed JSON to `/graphql` unless they are using a custom error handler. The vulnerability has been fixed in https://github.com/mercurius-js/mercurius/pull/678 and shipped as v8.11.2. As a workaround users may use a custom error handler.

    Published: 13 Dec 2021
    9.1
    Critical

    CVE-2021-39063

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information due to a misconfiguration in access control headers. IBM X-Force ID: 214956.

    Published: 13 Dec 2021
    8.1
    High

    CVE-2021-39057

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 214616.

    Published: 13 Dec 2021
    7.8
    High

    CVE-2021-39050

    Last Modified: 21 Nov 2024

    IBM i2 Analyst's Notebook 9.2.0, 9.2.1, and 9.2.2 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and gain lower level privileges. IBM X-Force ID: 214440.

    Published: 13 Dec 2021
    7.8
    High

    CVE-2021-39049

    Last Modified: 21 Nov 2024

    IBM i2 Analyst's Notebook 9.2.0, 9.2.1, and 9.2.2 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and gain lower level privileges. IBM X-Force ID: 214439.

    Published: 13 Dec 2021
    5.5
    Medium

    CVE-2021-39048

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Client 7.1 and 8.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local attacker could exploit this vulnerability and cause a denial of service. IBM X-Force ID: 214438.

    Published: 13 Dec 2021
    5.5
    Medium

    CVE-2021-38901

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Operations Center 7.1, under special configurations, could allow a local user to obtain highly sensitive information. IBM X-Force ID: 209610.

    Published: 13 Dec 2021
    5.9
    Medium

    CVE-2020-4496

    Last Modified: 21 Nov 2024

    The IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x server connection to an IBM Spectrum Protect Plus workload agent is subject to a man-in-the-middle attack due to improper certificate validation. IBM X-Force ID: 182046.

    Published: 13 Dec 2021
    9.8
    Critical

    CVE-2021-32024

    Last Modified: 9 Sept 2025

    A remote code execution vulnerability in the BMP image codec of BlackBerry QNX SDP version(s) 6.4 to 7.1 could allow an attacker to potentially execute code in the context of the affected process.

    Published: 13 Dec 2021
    9.8
    Critical

    CVE-2021-39065

    Last Modified: 21 Nov 2024

    IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of user-supplied input by the Spectrum Copy Data Management Admin Console login and uploadcertificate function . A remote attacker could inject arbitrary shell commands which would be executed on the affected system. IBM X-Force ID: 214958.

    Published: 13 Dec 2021
    7.5
    High

    CVE-2021-39064

    Last Modified: 21 Nov 2024

    IBM Spectrum Copy Data Management 2.2.13 and earlier has weak authentication and password rules and incorrectly handles default credentials for the Spectrum Copy Data Management Admin console. IBM X-Force ID: 214957.

    Published: 13 Dec 2021
    7.5
    High

    CVE-2021-39058

    Last Modified: 21 Nov 2024

    IBM Spectrum Copy Data Management 2.2.13 and earlier uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 214617.

    Published: 13 Dec 2021
    5.4
    Medium

    CVE-2021-39054

    Last Modified: 21 Nov 2024

    IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 214525.

    Published: 13 Dec 2021
    7.5
    High

    CVE-2021-39053

    Last Modified: 21 Nov 2024

    IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to obtain sensitive information, caused by the improper handling of requests for Spectrum Copy Data Management Admin Console. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 214524.

    Published: 13 Dec 2021
    9.8
    Critical

    CVE-2021-39052

    Last Modified: 21 Nov 2024

    IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to access the Spring Boot console without authorization. IBM X-Force ID: 214523.

    Published: 13 Dec 2021
    7.5
    High

    CVE-2021-38947

    Last Modified: 21 Nov 2024

    IBM Spectrum Copy Data Management 2.2.13 and earlier uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 211242.

    Published: 13 Dec 2021
    6.5
    Medium

    CVE-2020-16155

    Last Modified: 21 Nov 2024

    The CPAN::Checksums package 2.12 for Perl does not uniquely define signed data.

    Published: 13 Dec 2021
    7.8
    High

    CVE-2021-43983

    Last Modified: 21 Nov 2024

    WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to multiple stack-based buffer overflow instances while parsing project files, which may allow an attacker to execute arbitrary code.

    Published: 13 Dec 2021
    7.5
    High

    CVE-2021-40008

    Last Modified: 21 Nov 2024

    There is a memory leak vulnerability in CloudEngine 12800 V200R019C00SPC800, CloudEngine 5800 V200R019C00SPC800, CloudEngine 6800 V200R019C00SPC800 and CloudEngine 7800 V200R019C00SPC800. The software does not sufficiently track and release allocated memory while parse a series of crafted binary messages, which could consume remaining memory. Successful exploit could cause memory exhaust.

    Published: 13 Dec 2021
    6.5
    Medium

    CVE-2021-40007

    Last Modified: 21 Nov 2024

    There is an information leak vulnerability in eCNS280_TD V100R005C10SPC650. The vulnerability is caused by improper log output management. An attacker with the ability to access the log file of device may lead to information disclosure.

    Published: 13 Dec 2021
    9.8
    Critical

    CVE-2021-22279

    Last Modified: 21 Nov 2024

    A Missing Authentication vulnerability in RobotWare for the OmniCore robot controller allows an attacker to read and modify files on the robot controller if the attacker has access to the Connected Services Gateway Ethernet port.

    Published: 13 Dec 2021
    4.3
    Medium

    CVE-2021-39930

    Last Modified: 21 Nov 2024

    Missing authorization in GitLab EE versions between 12.4 and 14.3.6, between 14.4.0 and 14.4.4, and between 14.5.0 and 14.5.2 allowed an attacker to access a user's custom project and group templates

    Published: 13 Dec 2021
    6.5
    Medium

    CVE-2021-39939

    Last Modified: 21 Nov 2024

    An uncontrolled resource consumption vulnerability in GitLab Runner affecting all versions starting from 13.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker triggering a job with a specially crafted docker image to exhaust resources on runner manager

    Published: 13 Dec 2021
    3.7
    Low

    CVE-2021-39941

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to see the default branch name for projects that restrict access to the repository to project members

    Published: 13 Dec 2021
    6.8
    Medium

    CVE-2021-39935

    Last Modified: 4 Feb 2026

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API

    Published: 13 Dec 2021
    4.3
    Medium

    CVE-2021-39917

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression related to quick actions features was susceptible to catastrophic backtracking that could cause a DOS attack.

    Published: 13 Dec 2021
    4.3
    Medium

    CVE-2021-39932

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Using large payloads, the diff feature could be used to trigger high load time for users reviewing code changes.

    Published: 13 Dec 2021
    4.3
    Medium

    CVE-2021-39934

    Last Modified: 21 Nov 2024

    Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.

    Published: 13 Dec 2021
    4.3
    Medium

    CVE-2021-39916

    Last Modified: 21 Nov 2024

    Lack of an access control check in the External Status Check feature allowed any authenticated user to retrieve the configuration of any External Status Check in GitLab EE starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.

    Published: 13 Dec 2021
    4.4
    Medium

    CVE-2021-39919

    Last Modified: 21 Nov 2024

    In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, the reset password token and new user email token are accidentally logged which may lead to information disclosure.

    Published: 13 Dec 2021
    5.3
    Medium

    CVE-2021-39915

    Last Modified: 21 Nov 2024

    Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to see the names of project access tokens on arbitrary projects

    Published: 13 Dec 2021
    4.3
    Medium

    CVE-2021-39933

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression used for handling user input (notes, comments, etc) was susceptible to catastrophic backtracking that could cause a DOS attack.

    Published: 13 Dec 2021
    3.1
    Low

    CVE-2021-39938

    Last Modified: 21 Nov 2024

    A vulnerable regular expression pattern in GitLab CE/EE since version 8.15 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to cause uncontrolled resource consumption leading to Denial of Service via specially crafted deploy Slash commands

    Published: 13 Dec 2021
    5.9
    Medium

    CVE-2021-39937

    Last Modified: 21 Nov 2024

    A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, leads to potential elevated privileges in groups and projects under rare circumstances

    Published: 13 Dec 2021
    3.1
    Low

    CVE-2021-39931

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.11 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under specific condition an unauthorised project member was allowed to delete a protected branches due to a business logic error.

    Published: 13 Dec 2021
    3.5
    Low

    CVE-2021-39936

    Last Modified: 21 Nov 2024

    Improper access control in GitLab CE/EE affecting all versions starting from 10.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker in possession of a deploy token to access a project's disabled wiki.

    Published: 13 Dec 2021
    2.7
    Low

    CVE-2021-39945

    Last Modified: 21 Nov 2024

    Improper access control in the GitLab CE/EE API affecting all versions starting from 9.4 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an author of a Merge Request to approve the Merge Request even after having their project access revoked

    Published: 13 Dec 2021
    7.1
    High

    CVE-2021-39944

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A permissions validation flaw allowed group members with a developer role to elevate their privilege to a maintainer on projects they import

    Published: 13 Dec 2021
    4.3
    Medium

    CVE-2021-39940

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package registry is vulnerable to a regular expression denial of service when a specifically crafted string is sent.

    Published: 13 Dec 2021
    3.1
    Low

    CVE-2021-39918

    Last Modified: 21 Nov 2024

    Incorrect Authorization in GitLab EE affecting all versions starting from 11.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows a user to add comments to a vulnerability which cannot be accessed.

    Published: 13 Dec 2021
    2.6
    Low

    CVE-2021-39910

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab was vulnerable to HTML Injection through the Swagger UI feature.

    Published: 13 Dec 2021
    7.5
    High

    CVE-2021-44965

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in /admin/includes/* directory for PHPGURUKUL Employee Record Management System 1.2 The attacker can retrieve and download sensitive information from the vulnerable server.

    Published: 13 Dec 2021
    9.8
    Critical

    CVE-2021-44966

    Last Modified: 21 Nov 2024

    SQL injection bypass authentication vulnerability in PHPGURUKUL Employee Record Management System 1.2 via index.php. An attacker can log in as an admin account of this system and can destroy, change or manipulate all sensitive information on the system.

    Published: 13 Dec 2021
    4.2
    Medium

    CVE-2021-36169

    Last Modified: 21 Nov 2024

    A Hidden Functionality in Fortinet FortiOS 7.x before 7.0.1, FortiOS 6.4.x before 6.4.7 allows attacker to Execute unauthorized code or commands via specific hex read/write operations.

    Published: 13 Dec 2021
    —
    Unknown

    CVE-2021-45032

    Last Modified: 7 Nov 2023

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 13 Dec 2021
    9.8
    Critical

    CVE-2021-43117

    Last Modified: 21 Nov 2024

    fastadmin v1.2.1 is affected by a file upload vulnerability which allows arbitrary code execution through shell access.

    Published: 13 Dec 2021
    4.7
    Medium

    CVE-2021-42549

    Last Modified: 21 Nov 2024

    Insufficient Input Validation in the search functionality of Wordpress plugin Lets-Box prior to 1.15.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.

    Published: 13 Dec 2021
    4.7
    Medium

    CVE-2021-42548

    Last Modified: 21 Nov 2024

    Insufficient Input Validation in the search functionality of Wordpress plugin Share-one-Drive prior to 1.15.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.

    Published: 13 Dec 2021
    4.7
    Medium

    CVE-2021-42547

    Last Modified: 21 Nov 2024

    Insufficient Input Validation in the search functionality of Wordpress plugin Out-of-the-Box prior to 1.20.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.

    Published: 13 Dec 2021
    4.7
    Medium

    CVE-2021-42546

    Last Modified: 21 Nov 2024

    Insufficient Input Validation in the search functionality of Wordpress plugin Use-Your-Drive prior to 1.18.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.

    Published: 13 Dec 2021