CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-44152

    Last Modified: 21 Nov 2024

    An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or authorization, an unauthenticated user can change the password of any existing user. This allows an attacker to change the password of any known user, thereby preventing valid users from accessing the system and granting the attacker full access to that user's account.

    Published: 13 Dec 2021
    4.9
    Medium

    CVE-2021-45042

    Last Modified: 21 Nov 2024

    In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.

    Published: 13 Dec 2021
    9.8
    Critical

    CVE-2021-44833

    Last Modified: 21 Nov 2024

    The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.

    Published: 12 Dec 2021
    8.8
    High

    CVE-2021-41805

    Last Modified: 21 Nov 2024

    HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default operator:write permissions) in one namespace can be used for unintended privilege escalation in a different namespace.

    Published: 12 Dec 2021
    9.8
    Critical

    CVE-2021-44515

    Last Modified: 31 Oct 2025

    Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3. For MSP builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For MSP builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3.

    Published: 12 Dec 2021
    8.2
    High

    CVE-2021-43818

    Last Modified: 18 Dec 2025

    lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch. There are no known workarounds available.

    Published: 12 Dec 2021
    6
    Medium

    CVE-2021-4158

    Last Modified: 21 Nov 2024

    A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.

    Published: 12 Dec 2021
    5.4
    Medium

    CVE-2021-4097

    Last Modified: 21 Nov 2024

    phpservermon is vulnerable to Improper Neutralization of CRLF Sequences

    Published: 11 Dec 2021
    4.3
    Medium

    CVE-2021-4092

    Last Modified: 21 Nov 2024

    yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF)

    Published: 11 Dec 2021
    8.1
    High

    CVE-2021-41242

    Last Modified: 21 Nov 2024

    OpenOlat is a web-basedlearning management system. A path traversal vulnerability exists in OpenOlat prior to versions 15.5.12 and 16.0.5. By providing a filename that contains a relative path as a parameter in some REST methods, it is possible to create directory structures and write files anywhere on the target system. The attack could be used to write files anywhere in the web root folder or outside, depending on the configuration of the system and the properly configured permission of the application server user. The attack requires an OpenOlat user account, an enabled REST API and the rights on a business object to call the vulnerable REST calls. The problem is fixed in version 15.5.12 and 16.0.5. There is a workaround available. The vulnerability requires the REST module to be enabled. Disabling the REST module or limiting the REST module via some firewall or web-server access rules to be accessed only be trusted systems will mitigate the risk.

    Published: 10 Dec 2021
    6.7
    Medium

    CVE-2020-12890

    Last Modified: 21 Nov 2024

    Improper handling of pointers in the System Management Mode (SMM) handling code may allow for a privileged attacker with physical or administrative access to potentially manipulate the AMD Generic Encapsulated Software Architecture (AGESA) to execute arbitrary code undetected by the operating system.

    Published: 10 Dec 2021
    8.4
    High

    CVE-2021-26340

    Last Modified: 21 Nov 2024

    A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to flush the Translation Lookaside Buffer (TLB) resulting in unexpected behavior inside the virtual machine (VM).

    Published: 10 Dec 2021
    6.5
    Medium

    CVE-2021-23663

    Last Modified: 21 Nov 2024

    All versions of package sey are vulnerable to Prototype Pollution via the deepmerge() function.

    Published: 10 Dec 2021
    6.5
    Medium

    CVE-2021-23700

    Last Modified: 21 Nov 2024

    All versions of package merge-deep2 are vulnerable to Prototype Pollution via the mergeDeep() function.

    Published: 10 Dec 2021
    9.8
    Critical

    CVE-2021-23639

    Last Modified: 21 Nov 2024

    The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matter to parse front matter content, without disabling the JS engine.

    Published: 10 Dec 2021
    6.5
    Medium

    CVE-2021-23561

    Last Modified: 21 Nov 2024

    All versions of package comb are vulnerable to Prototype Pollution via the deepMerge() function.

    Published: 10 Dec 2021
    4.3
    Medium

    CVE-2021-4089

    Last Modified: 21 Nov 2024

    snipe-it is vulnerable to Improper Access Control

    Published: 10 Dec 2021
    8.1
    High

    CVE-2021-27984

    Last Modified: 21 Nov 2024

    In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.

    Published: 10 Dec 2021
    9.8
    Critical

    CVE-2021-27983

    Last Modified: 21 Nov 2024

    Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page.

    Published: 10 Dec 2021
    4.8
    Medium

    CVE-2021-31747

    Last Modified: 21 Nov 2024

    Missing SSL Certificate Validation issue exists in Pluck 4.7.15 in update_applet.php, which could lead to man-in-the-middle attacks.

    Published: 10 Dec 2021
    6.5
    Medium

    CVE-2021-38937

    Last Modified: 21 Nov 2024

    IBM PowerVM Hypervisor FW940, FW950, and FW1010 could allow an authenticated user to cause the system to crash using a specially crafted IBMi Hypervisor call. IBM X-Force ID: 210894.

    Published: 10 Dec 2021
    9.1
    Critical

    CVE-2021-38917

    Last Modified: 21 Nov 2024

    IBM PowerVM Hypervisor FW860, FW940, and FW950 could allow an attacker that gains service access to the FSP can read and write arbitrary host system memory through a series of carefully crafted service procedures. IBM X-Force ID: 210018.

    Published: 10 Dec 2021
    9.8
    Critical

    CVE-2021-31746

    Last Modified: 21 Nov 2024

    Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal and potentially arbitrary code execution.

    Published: 10 Dec 2021
    7.5
    High

    CVE-2021-31745

    Last Modified: 21 Nov 2024

    Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform. Because Pluck does not invalidate prior sessions after a password change, access can be sustained even after an administrator performs regular remediation attempts such as resetting their password.

    Published: 10 Dec 2021
    4.8
    Medium

    CVE-2021-36911

    Last Modified: 28 Mar 2025

    Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Comment Engine Pro plugin (versions <= 1.0), could be exploited by users with Editor or higher role.

    Published: 10 Dec 2021
    7.2
    High

    CVE-2021-29214

    Last Modified: 21 Nov 2024

    A security vulnerability has been identified in HPE StoreServ Management Console (SSMC). An authenticated SSMC administrator could exploit the vulnerability to inject code and elevate their privilege in SSMC. The scope of this vulnerability is limited to SSMC. Note: The arrays being managed are not impacted by this vulnerability. This vulnerability impacts SSMC versions 3.4 GA to 3.8.1.

    Published: 10 Dec 2021
    9.8
    Critical

    CVE-2021-37934

    Last Modified: 21 Nov 2024

    Due to insufficient server-side login-attempt limit enforcement, a vulnerability in /account/login in Huntflow Enterprise before 3.10.14 could allow an unauthenticated, remote user to perform multiple login attempts for brute-force password guessing.

    Published: 10 Dec 2021
    7.5
    High

    CVE-2021-37935

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in the login page of Huntflow Enterprise before 3.10.4 could allow an unauthenticated, remote user to get information about the domain name of the configured LDAP server. An attacker could exploit this vulnerability by requesting the login page and searching for the "isLdap" JavaScript parameter in the HTML source code.

    Published: 10 Dec 2021
    6.1
    Medium

    CVE-2021-3829

    Last Modified: 21 Nov 2024

    openwhyd is vulnerable to URL Redirection to Untrusted Site

    Published: 10 Dec 2021
    4.3
    Medium

    CVE-2021-40834

    Last Modified: 21 Nov 2024

    A user interface overlay vulnerability was discovered in F-secure SAFE Browser for Android. When user click on a specially crafted seemingly legitimate URL SAFE browser goes into full screen and hides the user interface. A remote attacker can leverage this to perform spoofing attack.

    Published: 10 Dec 2021
    7.5
    High

    CVE-2021-37189

    Last Modified: 21 Nov 2024

    An issue was discovered on Digi TransPort Gateway devices through 5.2.13.4. They do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in cleartext over an HTTP session.

    Published: 10 Dec 2021
    8.8
    High

    CVE-2021-37188

    Last Modified: 21 Nov 2024

    An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may load customized firmware (because the bootloader does not verify that it is authentic), changing the behavior of the gateway.

    Published: 10 Dec 2021
    6.5
    Medium

    CVE-2021-37187

    Last Modified: 21 Nov 2024

    An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may read a password file (with reversible passwords) from the device, which allows decoding of other users' passwords.

    Published: 10 Dec 2021
    9.8
    Critical

    CVE-2021-35978

    Last Modified: 21 Nov 2024

    An issue was discovered in Digi TransPort DR64, SR44 VC74, and WR. The ZING protocol allows arbitrary remote command execution with SUPER privileges. This allows an attacker (with knowledge of the protocol) to execute arbitrary code on the controller including overwriting firmware, adding/removing users, disabling the internal firewall, etc.

    Published: 10 Dec 2021
    6.1
    Medium

    CVE-2021-4084

    Last Modified: 21 Nov 2024

    pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 10 Dec 2021
    6.1
    Medium

    CVE-2021-4081

    Last Modified: 21 Nov 2024

    pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 10 Dec 2021
    4.3
    Medium

    CVE-2021-4082

    Last Modified: 21 Nov 2024

    pimcore is vulnerable to Cross-Site Request Forgery (CSRF)

    Published: 10 Dec 2021
    —
    Unknown

    CVE-2021-44787

    Last Modified: 17 Mar 2025

    Not used

    Published: 10 Dec 2021
    —
    Unknown

    CVE-2021-44788

    Last Modified: 17 Mar 2025

    Not used

    Published: 10 Dec 2021
    —
    Unknown

    CVE-2021-44789

    Last Modified: 17 Mar 2025

    Not used

    Published: 10 Dec 2021
    —
    Unknown

    CVE-2021-44784

    Last Modified: 17 Mar 2025

    Not used

    Published: 10 Dec 2021
    —
    Unknown

    CVE-2021-44785

    Last Modified: 17 Mar 2025

    Not used

    Published: 10 Dec 2021
    —
    Unknown

    CVE-2021-44786

    Last Modified: 17 Mar 2025

    Not used

    Published: 10 Dec 2021
    —
    Unknown

    CVE-2021-44781

    Last Modified: 17 Mar 2025

    Not used

    Published: 10 Dec 2021
    —
    Unknown

    CVE-2021-44782

    Last Modified: 17 Mar 2025

    Not used

    Published: 10 Dec 2021
    —
    Unknown

    CVE-2021-44783

    Last Modified: 17 Mar 2025

    Not used

    Published: 10 Dec 2021
    —
    Unknown

    CVE-2021-44780

    Last Modified: 17 Mar 2025

    Not used

    Published: 10 Dec 2021
    4.4
    Medium

    CVE-2020-10710

    Last Modified: 21 Nov 2024

    A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer. This flaw allows an attacker with sufficiently high privileges, such as root, to retrieve the Candlepin plaintext password.

    Published: 10 Dec 2021
    10
    Critical

    CVE-2021-44228

    Last Modified: 11 Aug 2026

    Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

    Published: 10 Dec 2021
    7.5
    High

    CVE-2021-4104

    Last Modified: 28 May 2026

    JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.

    Published: 10 Dec 2021