CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2021-42124

    Last Modified: 21 Nov 2024

    An improper access control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform a session takeover.

    Published: 7 Dec 2021
    7.5
    High

    CVE-2021-22956

    Last Modified: 21 Nov 2024

    An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow an attacker with access to NSIP or SNIP with management interface access to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication.

    Published: 7 Dec 2021
    7.5
    High

    CVE-2021-22955

    Last Modified: 21 Nov 2024

    A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server could allow an attacker to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication.

    Published: 7 Dec 2021
    6.5
    Medium

    CVE-2021-44527

    Last Modified: 21 Nov 2024

    A vulnerability found in UniFi Switch firmware Version 5.43.35 and earlier allows a malicious actor who has already gained access to the network to perform a Deny of Service (DoS) attack on the affected switch.This vulnerability is fixed in UniFi Switch firmware 5.76.6 and later.

    Published: 7 Dec 2021
    5.4
    Medium

    CVE-2021-40096

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via modification of the authorisationUrl in some integration configurations.

    Published: 7 Dec 2021
    4.9
    Medium

    CVE-2021-40095

    Last Modified: 21 Nov 2024

    An issue was discovered in SquaredUp for SCOM 5.2.1.6654. The Download Log feature in System / Maintenance was susceptible to a local file inclusion vulnerability (when processing remote input in the log files downloaded by an authenticated administrator user), leading to the ability to read arbitrary files on the server filesystems.

    Published: 7 Dec 2021
    5.4
    Medium

    CVE-2021-40094

    Last Modified: 21 Nov 2024

    A DOM-based XSS vulnerability affects SquaredUp for SCOM 5.2.1.6654. If successfully exploited, this vulnerability may allow attackers to inject malicious code into a user's device.

    Published: 7 Dec 2021
    5.4
    Medium

    CVE-2021-40093

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via dashboard actions.

    Published: 7 Dec 2021
    5.4
    Medium

    CVE-2021-40092

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in Image Tile in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via an SVG file.

    Published: 7 Dec 2021
    6.1
    Medium

    CVE-2021-29116

    Last Modified: 10 Apr 2025

    A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server feature services versions 10.8.1 and 10.9 (only) feature services may allow a remote, unauthenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the user’s browser.

    Published: 7 Dec 2021
    5.3
    Medium

    CVE-2021-29115

    Last Modified: 10 Apr 2025

    An information disclosure vulnerability in the ArcGIS Service Directory in Esri ArcGIS Enterprise versions 10.9.0 and below may allows a remote attacker to view hidden field names in feature layers. This issue may reveal field names, but not not disclose features.

    Published: 7 Dec 2021
    9.8
    Critical

    CVE-2021-29114

    Last Modified: 10 Apr 2025

    A SQL injection vulnerability in feature services provided by Esri ArcGIS Server 10.9 and below allows a remote, unauthenticated attacker to impact the confidentiality, integrity and availability of targeted services via specifically crafted queries.

    Published: 7 Dec 2021
    4.7
    Medium

    CVE-2021-29113

    Last Modified: 10 Apr 2025

    A remote file inclusion vulnerability in the ArcGIS Server help documentation may allow a remote, unauthenticated attacker to inject attacker supplied html into a page.

    Published: 7 Dec 2021
    6.5
    Medium

    CVE-2021-4049

    Last Modified: 21 Nov 2024

    livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)

    Published: 7 Dec 2021
    7.3
    High

    CVE-2021-44420

    Last Modified: 21 Nov 2024

    In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.

    Published: 7 Dec 2021
    7
    High

    CVE-2021-44513

    Last Modified: 21 Nov 2024

    Insecure creation of temporary directories in tmate-ssh-server 2.3.0 allows a local attacker to compromise the integrity of session handling.

    Published: 7 Dec 2021
    7
    High

    CVE-2021-44512

    Last Modified: 21 Nov 2024

    World-writable permissions on the /tmp/tmate/sessions directory in tmate-ssh-server 2.3.0 allow a local attacker to compromise the integrity of session handling, or obtain the read-write session ID from a read-only session symlink in this directory.

    Published: 7 Dec 2021
    7.5
    High

    CVE-2021-43798

    Last Modified: 24 Oct 2025

    Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-43539

    Last Modified: 21 Nov 2024

    Failure to correctly record the location of live pointers across wasm instance calls resulted in a GC occurring within the call not tracing those live pointers. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

    Published: 7 Dec 2021
    6.5
    Medium

    CVE-2021-43536

    Last Modified: 21 Nov 2024

    Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-43537

    Last Modified: 21 Nov 2024

    An incorrect type conversion of sizes from 64bit to 32bit integers allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

    Published: 7 Dec 2021
    6.1
    Medium

    CVE-2021-43543

    Last Modified: 21 Nov 2024

    Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

    Published: 7 Dec 2021
    7.5
    High

    CVE-2021-4076

    Last Modified: 21 Nov 2024

    A flaw exists in tang, a network-based cryptographic binding server, which could result in leak of private keys.

    Published: 7 Dec 2021
    9.8
    Critical

    CVE-2021-4129

    Last Modified: 16 Apr 2025

    Mozilla developers and community members Julian Hector, Randell Jesup, Gabriele Svelto, Tyson Smith, Christian Holler, and Masayuki Nakano reported memory safety bugs present in Firefox 94. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 95, Firefox ESR < 91.4.0, and Thunderbird < 91.4.0.

    Published: 7 Dec 2021
    6.5
    Medium

    CVE-2021-43541

    Last Modified: 21 Nov 2024

    When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

    Published: 7 Dec 2021
    6.5
    Medium

    CVE-2021-43542

    Last Modified: 21 Nov 2024

    Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

    Published: 7 Dec 2021
    4.3
    Medium

    CVE-2021-43546

    Last Modified: 21 Nov 2024

    It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

    Published: 7 Dec 2021
    6.5
    Medium

    CVE-2021-43545

    Last Modified: 21 Nov 2024

    Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

    Published: 7 Dec 2021
    7
    High

    CVE-2021-28703

    Last Modified: 21 Nov 2024

    grant table v2 status pages may remain accessible after de-allocation (take two) Guest get permitted access to certain Xen-owned pages of memory. The majority of such pages remain allocated / associated with a guest for its entire lifetime. Grant table v2 status pages, however, get de-allocated when a guest switched (back) from v2 to v1. The freeing of such pages requires that the hypervisor know where in the guest these pages were mapped. The hypervisor tracks only one use within guest space, but racing requests from the guest to insert mappings of these pages may result in any of them to become mapped in multiple locations. Upon switching back from v2 to v1, the guest would then retain access to a page that was freed and perhaps re-used for other purposes. This bug was fortuitously fixed by code cleanup in Xen 4.14, and backported to security-supported Xen branches as a prerequisite of the fix for XSA-378.

    Published: 7 Dec 2021
    6.5
    Medium

    CVE-2021-43528

    Last Modified: 21 Nov 2024

    Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level privileges, but could be used as a stepping stone to further an attack with other vulnerabilities. This vulnerability affects Thunderbird < 91.4.0.

    Published: 7 Dec 2021
    4.3
    Medium

    CVE-2021-43538

    Last Modified: 21 Nov 2024

    By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

    Published: 7 Dec 2021
    7.5
    High

    CVE-2021-44686

    Last Modified: 4 Nov 2025

    calibre before 5.32.0 contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service) in html_preprocess_rules in ebooks/conversion/preprocess.py.

    Published: 6 Dec 2021
    9.8
    Critical

    CVE-2021-44685

    Last Modified: 21 Nov 2024

    Git-it through 4.4.0 allows OS command injection at the Branches Aren't Just For Birds challenge step. During the verification process, it attempts to run the reflog command followed by the current branch name (which is not sanitized for execution).

    Published: 6 Dec 2021
    9.8
    Critical

    CVE-2021-44684

    Last Modified: 21 Nov 2024

    naholyr github-todos 3.1.0 is vulnerable to command injection. The range argument for the _hook subcommand is concatenated without any validation, and is directly used by the exec function.

    Published: 6 Dec 2021
    9.8
    Critical

    CVE-2021-44677

    Last Modified: 21 Nov 2024

    An issue (1 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited due to deserialization behavior that is inherent to the .NET Remoting service. A malicious attacker can exploit both TCP remoting services and local IPC services on the Enterprise Vault Server. This vulnerability is mitigated by properly configuring the servers and firewall as described in the vendor's security alert for this vulnerability (VTS21-003, ZDI-CAN-14078).

    Published: 6 Dec 2021
    9.8
    Critical

    CVE-2021-44678

    Last Modified: 21 Nov 2024

    An issue (2 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited due to deserialization behavior that is inherent to the .NET Remoting service. A malicious attacker can exploit both TCP remoting services and local IPC services on the Enterprise Vault Server. This vulnerability is mitigated by properly configuring the servers and firewall as described in the vendor's security alert for this vulnerability (VTS21-003, ZDI-CAN-14076).

    Published: 6 Dec 2021
    9.8
    Critical

    CVE-2021-44679

    Last Modified: 21 Nov 2024

    An issue (3 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited due to deserialization behavior that is inherent to the .NET Remoting service. A malicious attacker can exploit both TCP remoting services and local IPC services on the Enterprise Vault Server. This vulnerability is mitigated by properly configuring the servers and firewall as described in the vendor's security alert for this vulnerability (VTS21-003, ZDI-CAN-14074).

    Published: 6 Dec 2021
    9.8
    Critical

    CVE-2021-44680

    Last Modified: 21 Nov 2024

    An issue (4 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited due to deserialization behavior that is inherent to the .NET Remoting service. A malicious attacker can exploit both TCP remoting services and local IPC services on the Enterprise Vault Server. This vulnerability is mitigated by properly configuring the servers and firewall as described in the vendor's security alert for this vulnerability (VTS21-003, ZDI-CAN-14075).

    Published: 6 Dec 2021
    9.8
    Critical

    CVE-2021-44681

    Last Modified: 21 Nov 2024

    An issue (5 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited due to deserialization behavior that is inherent to the .NET Remoting service. A malicious attacker can exploit both TCP remoting services and local IPC services on the Enterprise Vault Server. This vulnerability is mitigated by properly configuring the servers and firewall as described in the vendor's security alert for this vulnerability (VTS21-003, ZDI-CAN-14080).

    Published: 6 Dec 2021
    9.8
    Critical

    CVE-2021-44682

    Last Modified: 21 Nov 2024

    An issue (6 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited due to deserialization behavior that is inherent to the .NET Remoting service. A malicious attacker can exploit both TCP remoting services and local IPC services on the Enterprise Vault Server. This vulnerability is mitigated by properly configuring the servers and firewall as described in the vendor's security alert for this vulnerability (VTS21-003, ZDI-CAN-14079).

    Published: 6 Dec 2021
    9.8
    Critical

    CVE-2021-31632

    Last Modified: 21 Nov 2024

    b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the User login section. This vulnerability allows attackers to execute arbitrary code via a crafted input.

    Published: 6 Dec 2021
    8.8
    High

    CVE-2021-31631

    Last Modified: 21 Nov 2024

    b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page. This vulnerability allows attackers to escalate privileges.

    Published: 6 Dec 2021
    —
    Unknown

    CVE-2021-37298

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 6 Dec 2021
    8.8
    High

    CVE-2021-40313

    Last Modified: 21 Nov 2024

    Piwigo v11.5 was discovered to contain a SQL injection vulnerability via the parameter pwg_token in /admin/batch_manager_global.php.

    Published: 6 Dec 2021
    9.8
    Critical

    CVE-2021-36567

    Last Modified: 21 Nov 2024

    ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\AbstractCache.

    Published: 6 Dec 2021
    9.8
    Critical

    CVE-2021-36564

    Last Modified: 21 Nov 2024

    ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\Adapter.php.

    Published: 6 Dec 2021
    7.2
    High

    CVE-2021-4075

    Last Modified: 21 Nov 2024

    snipe-it is vulnerable to Server-Side Request Forgery (SSRF)

    Published: 6 Dec 2021
    9.8
    Critical

    CVE-2021-40091

    Last Modified: 21 Nov 2024

    An SSRF issue was discovered in SquaredUp for SCOM 5.2.1.6654.

    Published: 6 Dec 2021
    7.5
    High

    CVE-2021-43800

    Last Modified: 21 Nov 2024

    Wiki.js is a wiki app built on Node.js. Prior to version 2.5.254, directory traversal outside of Wiki.js context is possible when a storage module with local asset cache fetching is enabled on a Windows host. A malicious user can potentially read any file on the file system by crafting a special URL that allows for directory traversal. This is only possible on a Wiki.js server running on Windows, when a storage module implementing local asset cache (e.g Local File System or Git) is enabled and that no web application firewall solution (e.g. cloudflare) strips potentially malicious URLs. Commit number 414033de9dff66a327e3f3243234852f468a9d85 fixes this vulnerability by sanitizing the path before it is passed on to the storage module. The sanitization step removes any windows directory traversal sequences from the path. As a workaround, disable any storage module with local asset caching capabilities (Local File System, Git).

    Published: 6 Dec 2021
    6.4
    Medium

    CVE-2021-43781

    Last Modified: 21 Nov 2024

    Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. Invenio-Drafts-Resources prior to versions 0.13.7 and 0.14.6 does not properly check permissions when a record is published. The vulnerability is exploitable in a default installation of InvenioRDM. An authenticated a user is able via REST API calls to publish draft records of other users if they know the record identifier and the draft validates (e.g. all require fields filled out). An attacker is not able to modify the data in the record, and thus e.g. *cannot* change a record from restricted to public. The problem is patched in Invenio-Drafts-Resources v0.13.7 and 0.14.6, which is part of InvenioRDM v6.0.1 and InvenioRDM v7.0 respectively.

    Published: 6 Dec 2021