CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-41024

    Last Modified: 21 Nov 2024

    A relative path traversal [CWE-23] vulnerabiltiy in FortiOS versions 7.0.0 and 7.0.1 and FortiProxy verison 7.0.0 may allow an unauthenticated, unauthorized attacker to inject path traversal character sequences to disclose sensitive information of the server via the GET request of the login page.

    Published: 8 Dec 2021
    6.3
    Medium

    CVE-2021-26103

    Last Modified: 21 Nov 2024

    An insufficient verification of data authenticity vulnerability (CWE-345) in the user interface of FortiProxy verison 2.0.3 and below, 1.2.11 and below and FortiGate verison 7.0.0, 6.4.6 and below, 6.2.9 and below of SSL VPN portal may allow a remote, unauthenticated attacker to conduct a cross-site request forgery (CSRF) attack . Only SSL VPN in web mode or full mode are impacted by this vulnerability.

    Published: 8 Dec 2021
    5.3
    Medium

    CVE-2021-32591

    Last Modified: 21 Nov 2024

    A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSandbox before 4.0.1, FortiWeb before 6.3.12, FortiADC before 6.2.1, FortiMail 7.0.1 and earlier may allow an attacker in possession of the password store to compromise the confidentiality of the encrypted secrets.

    Published: 8 Dec 2021
    5.4
    Medium

    CVE-2021-42752

    Last Modified: 21 Nov 2024

    A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.1 and below allows attacker to execute malicious javascript code on victim's host via crafted HTTP requests

    Published: 8 Dec 2021
    8.8
    High

    CVE-2021-42760

    Last Modified: 21 Nov 2024

    A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to disclose sensitive information from DB tables via crafted requests.

    Published: 8 Dec 2021
    6.4
    Medium

    CVE-2021-41029

    Last Modified: 21 Nov 2024

    A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.1 and below allows attacker to store malicious javascript code in the device and trigger it via crafted HTTP requests

    Published: 8 Dec 2021
    8.3
    High

    CVE-2021-43067

    Last Modified: 21 Nov 2024

    A exposure of sensitive information to an unauthorized actor in Fortinet FortiAuthenticator version 6.4.0, version 6.3.2 and below, version 6.2.1 and below, version 6.1.2 and below, version 6.0.7 to 6.0.1 allows attacker to duplicate a target LDAP user 2 factors authentication token via crafted HTTP requests.

    Published: 8 Dec 2021
    9.1
    Critical

    CVE-2021-44557

    Last Modified: 21 Nov 2024

    National Library of the Netherlands multiNER <= c0440948057afc6e3d6b4903a7c05e666b94a3bc is affected by an XML External Entity (XXE) vulnerability in multiNER/ner.py. Since XML parsing resolves external entities, a malicious XML stream could leak internal files and/or cause a DoS.

    Published: 8 Dec 2021
    9.1
    Critical

    CVE-2021-44556

    Last Modified: 21 Nov 2024

    National Library of the Netherlands digger < 6697d1269d981e35e11f240725b16401b5ce3db5 is affected by a XML External Entity (XXE) vulnerability. Since XML parsing resolves external entities, a malicious XML stream could leak internal files and/or cause a DoS.

    Published: 8 Dec 2021
    6.7
    Medium

    CVE-2021-42757

    Last Modified: 16 Oct 2025

    A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.

    Published: 8 Dec 2021
    6.1
    Medium

    CVE-2021-31850

    Last Modified: 21 Nov 2024

    A denial-of-service vulnerability in Database Security (DBS) prior to 4.8.4 allows a remote authenticated administrator to trigger a denial-of-service attack against the DBS server. The configuration of Archiving through the User interface incorrectly allowed the creation of directories and files in Windows system directories and other locations where sensitive data could be overwritten. The former could lead to a DoS, whilst the latter could lead to data destruction on the DBS server.

    Published: 8 Dec 2021
    8.8
    High

    CVE-2021-42758

    Last Modified: 21 Nov 2024

    An improper access control vulnerability [CWE-284] in FortiWLC 8.6.1 and below may allow an authenticated and remote attacker with low privileges to execute any command as an admin user with full access rights via bypassing the GUI restrictions.

    Published: 8 Dec 2021
    8.1
    High

    CVE-2021-36180

    Last Modified: 21 Nov 2024

    Multiple improper neutralization of special elements used in a command vulnerabilities [CWE-77] in FortiWeb management interface 6.4.1 and below, 6.3.15 and below, 6.2.5 and below may allow an authenticated attacker to execute unauthorized code or commands via crafted parameters of HTTP requests.

    Published: 8 Dec 2021
    6.1
    Medium

    CVE-2021-4050

    Last Modified: 21 Nov 2024

    livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 8 Dec 2021
    7.8
    High

    CVE-2021-26110

    Last Modified: 21 Nov 2024

    An improper access control vulnerability [CWE-284] in FortiOS autod daemon 7.0.0, 6.4.6 and below, 6.2.9 and below, 6.0.12 and below and FortiProxy 2.0.1 and below, 1.2.9 and below may allow an authenticated low-privileged attacker to escalate their privileges to super_admin via a specific crafted configuration of fabric automation CLI script and auto-script features.

    Published: 8 Dec 2021
    7.8
    High

    CVE-2021-20047

    Last Modified: 21 Nov 2024

    SonicWall Global VPN client version 4.10.6 (32-bit and 64-bit) and earlier have a DLL Search Order Hijacking vulnerability. Successful exploitation via a local attacker could result in remote code execution in the target system.

    Published: 8 Dec 2021
    9.8
    Critical

    CVE-2021-20045

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in SMA100 sonicfiles RAC_COPY_TO (RacNumber 36) method allows a remote unauthenticated attacker to potentially execute code as the 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

    Published: 8 Dec 2021
    8.8
    High

    CVE-2021-20044

    Last Modified: 21 Nov 2024

    A post-authentication remote command injection vulnerability in SonicWall SMA100 allows a remote authenticated attacker to execute OS system commands in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

    Published: 8 Dec 2021
    8.8
    High

    CVE-2021-20043

    Last Modified: 21 Nov 2024

    A Heap-based buffer overflow vulnerability in SonicWall SMA100 getBookmarks method allows a remote authenticated attacker to potentially execute code as the nobody user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

    Published: 8 Dec 2021
    9.8
    Critical

    CVE-2021-20042

    Last Modified: 21 Nov 2024

    An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

    Published: 8 Dec 2021
    7.5
    High

    CVE-2021-20041

    Last Modified: 21 Nov 2024

    An unauthenticated and remote adversary can consume all of the device's CPU due to crafted HTTP requests sent to SMA100 /fileshare/sonicfiles/sonicfiles resulting in a loop with unreachable exit condition. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

    Published: 8 Dec 2021
    7.5
    High

    CVE-2021-20040

    Last Modified: 21 Nov 2024

    A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload crafted web pages or files as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

    Published: 8 Dec 2021
    8.8
    High

    CVE-2021-20039

    Last Modified: 5 Sept 2025

    Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

    Published: 8 Dec 2021
    9.8
    Critical

    CVE-2021-20038

    Last Modified: 31 Oct 2025

    A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute code as a 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances firmware 10.2.0.8-37sv, 10.2.1.1-19sv, 10.2.1.2-24sv and earlier versions.

    Published: 8 Dec 2021
    6.1
    Medium

    CVE-2021-3370

    Last Modified: 21 Nov 2024

    DouPHP v1.6 was discovered to contain a cross-site scripting (XSS) vulnerability via /admin/cloud.php.

    Published: 8 Dec 2021
    6.1
    Medium

    CVE-2020-22421

    Last Modified: 21 Nov 2024

    74CMS v6.0.4 was discovered to contain a cross-site scripting (XSS) vulnerability via /index.php?m=&c=help&a=help_list&key.

    Published: 8 Dec 2021
    7.5
    High

    CVE-2021-41311

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to modify projects' Users & Roles settings, via a Broken Authentication vulnerability in the /plugins/servlet/project-config/PROJECT/roles endpoint. The affected versions are before version 8.19.1.

    Published: 8 Dec 2021
    5.3
    Medium

    CVE-2021-41309

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Jira Server and Data Center allow a user who has had their Jira Service Management access revoked to export audit logs of another user's Jira Service Management project via a Broken Authentication vulnerability in the /plugins/servlet/audit/resource endpoint. The affected versions of Jira Server and Data Center are before version 8.19.1.

    Published: 8 Dec 2021
    5.5
    Medium

    CVE-2022-2868

    Last Modified: 21 Nov 2024

    libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause a crash if an attacker is able to supply a crafted file to tiffcrop.

    Published: 8 Dec 2021
    9.8
    Critical

    CVE-2021-44529

    Last Modified: 3 Nov 2025

    A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

    Published: 8 Dec 2021
    7.5
    High

    CVE-2021-23450

    Last Modified: 21 Nov 2024

    All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.

    Published: 8 Dec 2021
    7.5
    High

    CVE-2021-44725

    Last Modified: 21 Nov 2024

    KNIME Server before 4.13.4 allows directory traversal in a request for a client profile.

    Published: 8 Dec 2021
    8.8
    High

    CVE-2021-44726

    Last Modified: 21 Nov 2024

    KNIME Server before 4.13.4 allows XSS via the old WebPortal login page.

    Published: 8 Dec 2021
    6.7
    Medium

    CVE-2021-43809

    Last Modified: 3 Nov 2025

    `Bundler` is a package for managing application dependencies in Ruby. In `bundler` versions before 2.2.33, when working with untrusted and apparently harmless `Gemfile`'s, it is not expected that they lead to execution of external code, unless that's explicit in the ruby code inside the `Gemfile` itself. However, if the `Gemfile` includes `gem` entries that use the `git` option with invalid, but seemingly harmless, values with a leading dash, this can be false. To handle dependencies that come from a Git repository instead of a registry, Bundler uses various commands, such as `git clone`. These commands are being constructed using user input (e.g. the repository URL). When building the commands, Bundler versions before 2.2.33 correctly avoid Command Injection vulnerabilities by passing an array of arguments instead of a command string. However, there is the possibility that a user input starts with a dash (`-`) and is therefore treated as an optional argument instead of a positional one. This can lead to Code Execution because some of the commands have options that can be leveraged to run arbitrary executables. Since this value comes from the `Gemfile` file, it can contain any character, including a leading dash. To exploit this vulnerability, an attacker has to craft a directory containing a `Gemfile` file that declares a dependency that is located in a Git repository. This dependency has to have a Git URL in the form of `-u./payload`. This URL will be used to construct a Git clone command but will be interpreted as the upload-pack argument. Then this directory needs to be shared with the victim, who then needs to run a command that evaluates the Gemfile, such as `bundle lock`, inside. This vulnerability can lead to Arbitrary Code Execution, which could potentially lead to the takeover of the system. However, the exploitability is very low, because it requires a lot of user interaction. Bundler 2.2.33 has patched this problem by inserting `--` as an argument before any positional arguments to those Git commands that were affected by this issue. Regardless of whether users can upgrade or not, they should review any untrustred `Gemfile`'s before running any `bundler` commands that may read them, since they can contain arbitrary ruby code.

    Published: 8 Dec 2021
    5.3
    Medium

    CVE-2021-43808

    Last Modified: 21 Nov 2024

    Laravel is a web application framework. Laravel prior to versions 8.75.0, 7.30.6, and 6.20.42 contain a possible cross-site scripting (XSS) vulnerability in the Blade templating engine. A broken HTML element may be clicked and the user taken to another location in their browser due to XSS. This is due to the user being able to guess the parent placeholder SHA-1 hash by trying common names of sections. If the parent template contains an exploitable HTML structure an XSS vulnerability can be exposed. This vulnerability has been patched in versions 8.75.0, 7.30.6, and 6.20.42 by determining the parent placeholder at runtime and using a random hash that is unique to each request.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-43810

    Last Modified: 21 Nov 2024

    Admidio is a free open source user management system for websites of organizations and groups. A cross-site scripting vulnerability is present in Admidio prior to version 4.0.12. The Reflected XSS vulnerability occurs because redirect.php does not properly validate the value of the url parameter. Through this vulnerability, an attacker is capable to execute malicious scripts. This issue is patched in version 4.0.12.

    Published: 7 Dec 2021
    7.2
    High

    CVE-2021-40578

    Last Modified: 21 Nov 2024

    Authenticated Blind & Error-based SQL injection vulnerability was discovered in Online Enrollment Management System in PHP and PayPal Free Source Code 1.0, that allows attackers to obtain sensitive information and execute arbitrary SQL commands via IDNO parameter.

    Published: 7 Dec 2021
    6.1
    Medium

    CVE-2021-42567

    Last Modified: 21 Nov 2024

    Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints.

    Published: 7 Dec 2021
    7.5
    High

    CVE-2021-42717

    Last Modified: 3 Jul 2025

    ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for minutes and consume almost all of the available CPU on the machine. Modsecurity 2 is similarly vulnerable: the affected versions include 2.8.0 through 2.9.4.

    Published: 7 Dec 2021
    8.1
    High

    CVE-2021-43963

    Last Modified: 21 Nov 2024

    An issue was discovered in Couchbase Sync Gateway 2.7.0 through 2.8.2. The bucket credentials used to read and write data in Couchbase Server were insecurely being stored in the metadata within sync documents written to the bucket. Users with read access could use these credentials to obtain write access. (This issue does not affect clusters where Sync Gateway is authenticated with X.509 client certificates. This issue also does not affect clusters where shared bucket access is not enabled on Sync Gateway.)

    Published: 7 Dec 2021
    6.1
    Medium

    CVE-2021-44148

    Last Modified: 21 Nov 2024

    GL.iNet GL-AR150 2.x before 3.x devices, configured as repeaters, allow cgi-bin/router_cgi?action=scanwifi XSS when an attacker creates an SSID with an XSS payload as the name.

    Published: 7 Dec 2021
    7.8
    High

    CVE-2021-44149

    Last Modified: 5 Jun 2026

    An issue was discovered in Trusted Firmware OP-TEE Trusted OS through 3.15.0. The OPTEE-OS CSU driver for NXP i.MX6UL SoC devices lacks security access configuration for wakeup-related registers, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/write operations on Secure World memory. This involves a v cycle.

    Published: 7 Dec 2021
    9.8
    Critical

    CVE-2021-38759

    Last Modified: 21 Nov 2024

    Raspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not changed, attackers can gain administrator privileges.

    Published: 7 Dec 2021
    6.1
    Medium

    CVE-2021-36760

    Last Modified: 21 Nov 2024

    In accountrecoveryendpoint/recoverpassword.do in WSO2 Identity Server 5.7.0, it is possible to perform a DOM-Based XSS attack affecting the callback parameter modifying the URL that precedes the callback parameter. Once the username or password reset procedure is completed, the JavaScript code will be executed. (recoverpassword.do also has an open redirect issue for a similar reason.)

    Published: 7 Dec 2021
    7.1
    High

    CVE-2021-36133

    Last Modified: 5 Jun 2026

    The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/write operations on Secure World memory. This involves a DMA capable peripheral.

    Published: 7 Dec 2021
    6.5
    Medium

    CVE-2021-34544

    Last Modified: 21 Nov 2024

    An issue was discovered in Solar-Log 500 before 2.8.2 Build 52 23.04.2013. In /export.html, email.html, and sms.html, cleartext passwords are stored. This may allow sensitive information to be read by someone with access to the device. Fixed with 3.0.0-60 11.10.2013 for SL 200, 500, 1000 / not existing for SL 250, 300, 1200, 2000, SL 50 Gateway, SL Base.

    Published: 7 Dec 2021
    7.5
    High

    CVE-2021-34543

    Last Modified: 21 Nov 2024

    The web administration server in Solar-Log 500 before 2.8.2 Build 52 does not require authentication, which allows remote attackers to gain administrative privileges by connecting to the server. As a result, the attacker can modify configuration files and change the system status. Fixed with 3.0.0-60 11.10.2013 for SL 200, 500, 1000 / not existing for SL 250, 300, 1200, 2000, SL 50 Gateway, SL Base.

    Published: 7 Dec 2021
    8.1
    High

    CVE-2021-28680

    Last Modified: 21 Nov 2024

    The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side secret_key_base value became publicly known (for instance if it is committed to a public repository by mistake), there are still other protections in place that prevent an attacker from impersonating any user on the site. When masquerading is not used in a plain Devise application, one must know the password salt of the target user if one wants to encrypt and sign a valid session cookie. When devise_masquerade is used, however, an attacker can decide which user the "back" action will go back to without knowing that user's password salt and simply knowing the user ID, by manipulating the session cookie and pretending that a user is already masqueraded by an administrator.

    Published: 7 Dec 2021
    5.4
    Medium

    CVE-2020-27356

    Last Modified: 21 Nov 2024

    The debug-meta-data plugin 1.1.2 for WordPress allows XSS.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-42688

    Last Modified: 21 Nov 2024

    An Integer Overflow vulnerability exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x22005B in the Accops HyWorks Windows Client prior to v 3.2.8.200 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

    Published: 7 Dec 2021