CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2022-21150

    Last Modified: 27 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 9 Dec 2021
    —
    Unknown

    CVE-2022-21188

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 9 Dec 2021
    7.5
    High

    CVE-2021-43803

    Last Modified: 21 Nov 2024

    Next.js is a React framework. In versions of Next.js prior to 12.0.5 or 11.1.3, invalid or malformed URLs could lead to a server crash. In order to be affected by this issue, the deployment must use Next.js versions above 11.1.0 and below 12.0.5, Node.js above 15.0.0, and next start or a custom server. Deployments on Vercel are not affected, along with similar environments where invalid requests are filtered before reaching Next.js. Versions 12.0.5 and 11.1.3 contain patches for this issue.

    Published: 9 Dec 2021
    —
    Unknown

    CVE-2022-21175

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 9 Dec 2021
    —
    Unknown

    CVE-2022-21171

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 9 Dec 2021
    —
    Unknown

    CVE-2022-21135

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 9 Dec 2021
    —
    Unknown

    CVE-2022-21185

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 9 Dec 2021
    —
    Unknown

    CVE-2022-21206

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 9 Dec 2021
    —
    Unknown

    CVE-2022-21161

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 9 Dec 2021
    9.9
    Critical

    CVE-2021-43802

    Last Modified: 21 Nov 2024

    Etherpad is a real-time collaborative editor. In versions prior to 1.8.16, an attacker can craft an `*.etherpad` file that, when imported, might allow the attacker to gain admin privileges for the Etherpad instance. This, in turn, can be used to install a malicious Etherpad plugin that can execute arbitrary code (including system commands). To gain privileges, the attacker must be able to trigger deletion of `express-session` state or wait for old `express-session` state to be cleaned up. Core Etherpad does not delete any `express-session` state, so the only known attacks require either a plugin that can delete session state or a custom cleanup process (such as a cron job that deletes old `sessionstorage:*` records). The problem has been fixed in version 1.8.16. If users cannot upgrade to 1.8.16 or install patches manually, several workarounds are available. Users may configure their reverse proxies to reject requests to `/p/*/import`, which will block all imports, not just `*.etherpad` imports; limit all users to read-only access; and/or prevent the reuse of `express_sid` cookie values that refer to deleted express-session state. More detailed information and general mitigation strategies may be found in the GitHub Security Advisory.

    Published: 9 Dec 2021
    7.8
    High

    CVE-2021-43982

    Last Modified: 21 Nov 2024

    Delta Electronics CNCSoft Versions 1.01.30 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.

    Published: 9 Dec 2021
    5.8
    Medium

    CVE-2021-37861

    Last Modified: 21 Nov 2024

    Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails.

    Published: 9 Dec 2021
    6.5
    Medium

    CVE-2021-4033

    Last Modified: 21 Nov 2024

    kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)

    Published: 9 Dec 2021
    9.8
    Critical

    CVE-2021-44514

    Last Modified: 21 Nov 2024

    OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories.

    Published: 9 Dec 2021
    9.8
    Critical

    CVE-2021-43608

    Last Modified: 21 Nov 2024

    Doctrine DBAL 3.x before 3.1.4 allows SQL Injection. The escaping of offset and length inputs to the generation of a LIMIT clause was not probably cast to an integer, allowing SQL injection to take place if application developers passed unescaped user input to the DBAL QueryBuilder or any other API that ultimately uses the AbstractPlatform::modifyLimitQuery API.

    Published: 9 Dec 2021
    5.4
    Medium

    CVE-2020-19683

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) exists in ZZZCMS V1.7.1 via an editfile action in save.php.

    Published: 9 Dec 2021
    8.8
    High

    CVE-2020-19682

    Last Modified: 21 Nov 2024

    A Cross Site Request Forgery (CSRF) vulnerability exits in ZZZCMS V1.7.1 via the save_user funciton in save.php.

    Published: 9 Dec 2021
    8.8
    High

    CVE-2021-22568

    Last Modified: 21 Nov 2024

    When using the dart pub publish command to publish a package to a third-party package server, the request would be authenticated with an oauth2 access_token that is valid for publishing on pub.dev. Using these obtained credentials, an attacker can impersonate the user on pub.dev. We recommend upgrading past https://github.com/dart-lang/sdk/commit/d787e78d21e12ec1ef712d229940b1172aafcdf8 or beyond version 2.15.0

    Published: 9 Dec 2021
    7.5
    High

    CVE-2021-39002

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

    Published: 9 Dec 2021
    7.5
    High

    CVE-2021-38951

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available CPU resources. IBM X-Force ID: 211405.

    Published: 9 Dec 2021
    6.5
    Medium

    CVE-2021-38931

    Last Modified: 21 Nov 2024

    IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1, and 11.5 is vulnerable to an information disclosure as a result of a connected user having indirect read access to a table where they are not authorized to select from. IBM X-Force ID: 210418.

    Published: 9 Dec 2021
    5.5
    Medium

    CVE-2021-38926

    Last Modified: 21 Nov 2024

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to gain privileges due to allowing modification of columns of existing tasks. IBM X-Force ID: 210321.

    Published: 9 Dec 2021
    8.7
    High

    CVE-2021-29678

    Last Modified: 21 Nov 2024

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user with DBADM authority to access other databases and read or modify files. IBM X-Force ID: 199914.

    Published: 9 Dec 2021
    7.5
    High

    CVE-2021-20373

    Last Modified: 21 Nov 2024

    IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using the LOAD utility as under certain circumstances the LOAD utility does not enforce directory restrictions. IBM X-Force ID: 199521.

    Published: 9 Dec 2021
    8.1
    High

    CVE-2021-41265

    Last Modified: 7 Mar 2025

    Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentication vulnerability in the REST API. The issue allows for a malicious actor with a carefully crafted request to successfully authenticate and gain access to existing protected REST API endpoints. This only affects non database authentication types and new REST API endpoints. Users should upgrade to Flask-AppBuilder 3.3.4 to receive a patch.

    Published: 9 Dec 2021
    9.8
    Critical

    CVE-2021-43703

    Last Modified: 21 Nov 2024

    An Incorrect Access Control vulnerability exists in zzcms less than or equal to 2019 via admin.php. After disabling JavaScript, you can directly access the administrator console.

    Published: 9 Dec 2021
    8.8
    High

    CVE-2021-40282

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, abd 2021 in dl/dl_download.php. when registering ordinary users.

    Published: 9 Dec 2021
    8.8
    High

    CVE-2021-40281

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 in dl/dl_print.php when registering ordinary users.

    Published: 9 Dec 2021
    7.2
    High

    CVE-2021-40280

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerablitly exits in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/dl_sendmail.php.

    Published: 9 Dec 2021
    4.8
    Medium

    CVE-2021-4038

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) prior to 10.1 Minor 7 allows a remote authenticated administrator to embed a XSS in the administrator interface via specially crafted custom rules containing HTML. NSM did not correctly sanitize custom rule content in all scenarios.

    Published: 9 Dec 2021
    4.6
    Medium

    CVE-2021-41246

    Last Modified: 21 Nov 2024

    Express OpenID Connect is express JS middleware implementing sign on for Express web apps using OpenID Connect. Versions before and including `2.5.1` do not regenerate the session id and session cookie when user logs in. This behavior opens up the application to various session fixation vulnerabilities. Versions `2.5.2` contains a patch for this issue.

    Published: 9 Dec 2021
    7.2
    High

    CVE-2021-40279

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/bad.php.

    Published: 9 Dec 2021
    6.1
    Medium

    CVE-2021-41697

    Last Modified: 21 Nov 2024

    A reflected Cross Site Scripting (XSS) vulnerability exists in Premiumdatingscript 4.2.7.7 via the aerror_description parameter in assets/sources/instagram.php script.

    Published: 9 Dec 2021
    6.5
    Medium

    CVE-2021-41696

    Last Modified: 21 Nov 2024

    An authentication bypass (account takeover) vulnerability exists in Premiumdatingscript 4.2.7.7 due to a weak password reset mechanism in requests\user.php.

    Published: 9 Dec 2021
    7.5
    High

    CVE-2021-21955

    Last Modified: 21 Nov 2024

    An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. Generic network sniffing can lead to password recovery. An attacker can sniff network traffic to trigger this vulnerability.

    Published: 9 Dec 2021
    9.9
    Critical

    CVE-2021-21954

    Last Modified: 21 Nov 2024

    A command execution vulnerability exists in the wifi_country_code_update functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to arbitrary command execution.

    Published: 9 Dec 2021
    9.8
    Critical

    CVE-2021-41695

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability exists in Premiumdatingscript 4.2.7.7 via the ip parameter in connect.php. .

    Published: 9 Dec 2021
    8.8
    High

    CVE-2021-20139

    Last Modified: 21 Nov 2024

    An unauthenticated command injection vulnerability exists in the parameters of operation 3 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.

    Published: 9 Dec 2021
    8.8
    High

    CVE-2021-20138

    Last Modified: 21 Nov 2024

    An unauthenticated command injection vulnerability exists in multiple parameters in the Gryphon Tower router’s web interface at /cgi-bin/luci/rc. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the web interface.

    Published: 9 Dec 2021
    6.1
    Medium

    CVE-2021-20137

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting vulnerability exists in the url parameter of the /cgi-bin/luci/site_access/ page on the Gryphon Tower router's web interface. An attacker could exploit this issue by tricking a user into following a specially crafted link, granting the attacker javascript execution in the context of the victim's browser.

    Published: 9 Dec 2021
    8.8
    High

    CVE-2021-20142

    Last Modified: 21 Nov 2024

    An unauthenticated command injection vulnerability exists in the parameters of operation 41 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.

    Published: 9 Dec 2021
    8.8
    High

    CVE-2021-20141

    Last Modified: 21 Nov 2024

    An unauthenticated command injection vulnerability exists in the parameters of operation 32 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.

    Published: 9 Dec 2021
    8.8
    High

    CVE-2021-20140

    Last Modified: 21 Nov 2024

    An unauthenticated command injection vulnerability exists in the parameters of operation 10 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.

    Published: 9 Dec 2021
    9.8
    Critical

    CVE-2021-41694

    Last Modified: 21 Nov 2024

    An Incorrect Access Control vulnerability exists in Premiumdatingscript 4.2.7.7 via the password change procedure in requests\user.php.

    Published: 9 Dec 2021
    9.8
    Critical

    CVE-2021-20146

    Last Modified: 21 Nov 2024

    An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affiliated with Gryphon's development and infrastructure. At the time of discovery, the ssh key could be used to login to the development server hosted in Amazon Web Services.

    Published: 9 Dec 2021
    7.5
    High

    CVE-2021-20145

    Last Modified: 21 Nov 2024

    Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon homebound VPN network which exposes the LAN interfaces of other users' devices connected to the same service. An attacker could leverage this to make configuration changes to, or otherwise attack victims' devices as though they were on an adjacent network.

    Published: 9 Dec 2021
    8.8
    High

    CVE-2021-20144

    Last Modified: 21 Nov 2024

    An unauthenticated command injection vulnerability exists in the parameters of operation 49 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.

    Published: 9 Dec 2021
    8.8
    High

    CVE-2021-20143

    Last Modified: 21 Nov 2024

    An unauthenticated command injection vulnerability exists in the parameters of operation 48 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.

    Published: 9 Dec 2021
    7.1
    High

    CVE-2021-41449

    Last Modified: 21 Nov 2024

    A path traversal attack in web interfaces of Netgear RAX35, RAX38, and RAX40 routers before v1.0.4.102, allows a remote unauthenticated attacker to gain access to sensitive restricted information, such as forbidden files of the web application, via sending a specially crafted HTTP packet.

    Published: 9 Dec 2021
    6.5
    Medium

    CVE-2021-22565

    Last Modified: 21 Nov 2024

    An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable to upload their TEKs to generate exposure notifications. We recommend upgrading the Exposure Notification server to V1.1.2 or greater.

    Published: 9 Dec 2021