CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-43931

    Last Modified: 21 Nov 2024

    The authentication algorithm of the WebHMI portal is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.

    Published: 6 Dec 2021
    10
    Critical

    CVE-2021-43936

    Last Modified: 21 Nov 2024

    The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's environment or lead to arbitrary code execution.

    Published: 6 Dec 2021
    6.2
    Medium

    CVE-2021-22170

    Last Modified: 21 Nov 2024

    Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encrypted content

    Published: 6 Dec 2021
    3.1
    Low

    CVE-2021-39890

    Last Modified: 21 Nov 2024

    It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.

    Published: 6 Dec 2021
    8.3
    High

    CVE-2021-36198

    Last Modified: 21 Nov 2024

    Successful exploitation of this vulnerability could allow an unauthorized user to access sensitive data.

    Published: 6 Dec 2021
    8.3
    High

    CVE-2021-35242

    Last Modified: 21 Nov 2024

    Serv-U server responds with valid CSRFToken when the request contains only Session.

    Published: 6 Dec 2021
    8.4
    High

    CVE-2021-35245

    Last Modified: 21 Nov 2024

    When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine.

    Published: 6 Dec 2021
    6.1
    Medium

    CVE-2021-25041

    Last Modified: 21 Nov 2024

    The Photo Gallery by 10Web WordPress plugin before 1.5.68 is vulnerable to Reflected Cross-Site Scripting (XSS) issues via the bwg_album_breadcrumb_0 and shortcode_id GET parameters passed to the bwg_frontend_data AJAX action

    Published: 6 Dec 2021
    9.8
    Critical

    CVE-2021-24943

    Last Modified: 21 Nov 2024

    The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.

    Published: 6 Dec 2021
    6.1
    Medium

    CVE-2021-24939

    Last Modified: 21 Nov 2024

    The LoginWP (Formerly Peter's Login Redirect) WordPress plugin before 3.0.0.5 does not sanitise and escape the rul_login_url and rul_logout_url parameter before outputting them back in attributes in an admin page, leading to a Reflected Cross-Site Scripting issue

    Published: 6 Dec 2021
    6.1
    Medium

    CVE-2021-24938

    Last Modified: 21 Nov 2024

    The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_data AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected cross-Site Scripting issue

    Published: 6 Dec 2021
    6.1
    Medium

    CVE-2021-24935

    Last Modified: 21 Nov 2024

    The WP Google Fonts WordPress plugin before 3.1.5 does not escape the googlefont_ajax_name and googlefont_ajax_family parameter of the googlefont_action AJAx action (available to any authenticated user) before outputing them in attributes, leading Reflected Cross-Site Scripting issues

    Published: 6 Dec 2021
    9.8
    Critical

    CVE-2021-24931

    Last Modified: 21 Nov 2024

    The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an SQL injection.

    Published: 6 Dec 2021
    5.4
    Medium

    CVE-2021-24930

    Last Modified: 21 Nov 2024

    The WordPress Online Booking and Scheduling Plugin WordPress plugin before 20.3.1 does not escape the Staff Full Name field before outputting it back in a page, which could lead to a Stored Cross-Site Scripting issue

    Published: 6 Dec 2021
    6.1
    Medium

    CVE-2021-24924

    Last Modified: 21 Nov 2024

    The Email Log WordPress plugin before 2.4.8 does not escape the d parameter before outputting it back in an attribute in the Log page, leading to a Reflected Cross-Site Scripting issue

    Published: 6 Dec 2021
    7.5
    High

    CVE-2021-24917

    Last Modified: 21 Nov 2024

    The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.

    Published: 6 Dec 2021
    8
    High

    CVE-2021-24914

    Last Modified: 21 Nov 2024

    The Tawk.To Live Chat WordPress plugin before 0.6.0 does not have capability and CSRF checks in the tawkto_setwidget and tawkto_removewidget AJAX actions, available to any authenticated user. The first one allows low-privileged users (including simple subscribers) to change the 'tawkto-embed-widget-page-id' and 'tawkto-embed-widget-widget-id' parameters. Any authenticated user can thus link the vulnerable website to their own Tawk.to instance. Consequently, they will be able to monitor the vulnerable website and interact with its visitors (receive contact messages, answer, ...). They will also be able to display an arbitrary Knowledge Base. The second one will remove the live chat widget from pages.

    Published: 6 Dec 2021
    9.8
    Critical

    CVE-2021-24866

    Last Modified: 21 Nov 2024

    The WP Data Access WordPress plugin before 5.0.0 does not properly sanitise and escape the backup_date parameter before using it a SQL statement, leading to a SQL injection issue and could allow arbitrary table deletion

    Published: 6 Dec 2021
    5.4
    Medium

    CVE-2021-24759

    Last Modified: 21 Nov 2024

    The PDF.js Viewer WordPress plugin before 2.0.2 does not escape some of its shortcode and Gutenberg Block attributes, which could allow users with a role as low as Contributor to to perform Cross-Site Scripting attacks

    Published: 6 Dec 2021
    4.8
    Medium

    CVE-2021-24718

    Last Modified: 21 Nov 2024

    The Contact Form, Survey & Popup Form Plugin for WordPress plugin before 1.5 does not properly sanitize some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 6 Dec 2021
    4.8
    Medium

    CVE-2021-24714

    Last Modified: 21 Nov 2024

    The Import any XML or CSV File to WordPress plugin before 3.6.3 does not escape the Import's Title and Unique Identifier fields before outputting them in admin pages, which could allow high privilege users to perform Cross-Site attacks even when the unfiltered_html capability is disallowed.

    Published: 6 Dec 2021
    7.5
    High

    CVE-2021-43471

    Last Modified: 21 Nov 2024

    In Canon LBP223 printers, the System Manager Mode login does not require an account password or PIN. An attacker can remotely shut down the device after entering the background, creating a denial of service vulnerability.

    Published: 6 Dec 2021
    8.8
    High

    CVE-2021-43469

    Last Modified: 21 Nov 2024

    VINGA WR-N300U 77.102.1.4853 is affected by a command execution vulnerability in the goahead component.

    Published: 6 Dec 2021
    9.8
    Critical

    CVE-2021-43036

    Last Modified: 21 Nov 2024

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest account is weak.

    Published: 6 Dec 2021
    8.8
    High

    CVE-2021-43038

    Last Modified: 21 Nov 2024

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The wguest account could execute commands by injecting into PostgreSQL trigger functions. This allowed privilege escalation from the wguest user to the postgres user.

    Published: 6 Dec 2021
    9.8
    Critical

    CVE-2021-43042

    Last Modified: 21 Nov 2024

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A buffer overflow existed in the vaultServer component. This was exploitable by a remote unauthenticated attacker.

    Published: 6 Dec 2021
    6.5
    Medium

    CVE-2021-43043

    Last Modified: 21 Nov 2024

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The apache user could read arbitrary files such as /etc/shadow by abusing an insecure Sudo rule.

    Published: 6 Dec 2021
    9.8
    Critical

    CVE-2021-43044

    Last Modified: 21 Nov 2024

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak default community.

    Published: 6 Dec 2021
    4.4
    Medium

    CVE-2021-0961

    Last Modified: 21 Nov 2024

    In quota_proc_write of xt_quota2.c, there is a possible way to read kernel memory due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196046570References: Upstream kernel

    Published: 6 Dec 2021
    4.4
    Medium

    CVE-2021-39636

    Last Modified: 21 Nov 2024

    In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables.c, there is a possible way to leak kernel information due to uninitialized data. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-120612905References: Upstream kernel

    Published: 6 Dec 2021
    9.8
    Critical

    CVE-2021-43033

    Last Modified: 21 Nov 2024

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon were vulnerable to arbitrary remote code execution as root. The vulnerability was caused by untrusted input (received by the server) being passed to system calls.

    Published: 6 Dec 2021
    9.8
    Critical

    CVE-2021-43035

    Last Modified: 21 Nov 2024

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabilities were discovered, allowing arbitrary SQL queries to be injected and executed under the postgres superuser account. Remote code execution was possible, leading to full access to the postgres user account.

    Published: 6 Dec 2021
    7.8
    High

    CVE-2021-43037

    Last Modified: 21 Nov 2024

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Unitrends Windows agent was vulnerable to DLL injection and binary planting due to insecure default permissions. This allowed privilege escalation from an unprivileged user to SYSTEM.

    Published: 6 Dec 2021
    6.5
    Medium

    CVE-2021-43039

    Last Modified: 21 Nov 2024

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Samba file sharing service allowed anonymous read/write access.

    Published: 6 Dec 2021
    8.8
    High

    CVE-2021-43041

    Last Modified: 21 Nov 2024

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A crafted HTTP request could induce a format string vulnerability in the privileged vaultServer application.

    Published: 6 Dec 2021
    —
    Unknown

    CVE-2021-44597

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-43857. Reason: This candidate is a reservation duplicate of CVE-2021-43857. Notes: All CVE users should reference CVE-2021-43857 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 6 Dec 2021
    7.8
    High

    CVE-2021-45469

    Last Modified: 21 Nov 2024

    In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when an inode has an invalid last xattr entry.

    Published: 6 Dec 2021
    7.8
    High

    CVE-2021-43034

    Last Modified: 21 Nov 2024

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A world writable file allowed local users to execute arbitrary code as the user apache, leading to privilege escalation.

    Published: 6 Dec 2021
    8.8
    High

    CVE-2021-43040

    Last Modified: 21 Nov 2024

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The privileged vaultServer could be leveraged to create arbitrary writable files, leading to privilege escalation.

    Published: 6 Dec 2021
    6
    Medium

    CVE-2021-43784

    Last Modified: 21 Nov 2024

    runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc, netlink is used internally as a serialization system for specifying the relevant container configuration to the `C` portion of the code (responsible for the based namespace setup of containers). In all versions of runc prior to 1.0.3, the encoder did not handle the possibility of an integer overflow in the 16-bit length field for the byte array attribute type, meaning that a large enough malicious byte array attribute could result in the length overflowing and the attribute contents being parsed as netlink messages for container configuration. This vulnerability requires the attacker to have some control over the configuration of the container and would allow the attacker to bypass the namespace restrictions of the container by simply adding their own netlink payload which disables all namespaces. The main users impacted are those who allow untrusted images with untrusted configurations to run on their machines (such as with shared cloud infrastructure). runc version 1.0.3 contains a fix for this bug. As a workaround, one may try disallowing untrusted namespace paths from your container. It should be noted that untrusted namespace paths would allow the attacker to disable namespace protections entirely even in the absence of this bug.

    Published: 6 Dec 2021
    7.8
    High

    CVE-2021-44048

    Last Modified: 21 Nov 2024

    An out-of-bounds write vulnerability exists when reading a TIF file using Open Design Alliance (ODA) Drawings Explorer before 2022.11. The specific issue exists after loading TIF files. Crafted data in a TIF file can trigger a write operation past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.

    Published: 5 Dec 2021
    7.8
    High

    CVE-2021-44047

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability exists when reading a DWF/DWFX file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists with parsing DWF/DWFX files. Crafted data in a DWF/DWFX file and lack of proper validation of input data can trigger a write operation past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.

    Published: 5 Dec 2021
    7.8
    High

    CVE-2021-44046

    Last Modified: 21 Nov 2024

    An out-of-bounds write vulnerability exists when reading U3D files in Open Design Alliance PRC SDK before 2022.11. An unchecked return value of a function (verifying input data from a U3D file) leads to an out-of-bounds write. An attacker can leverage this vulnerability to execute code in the context of the current process.

    Published: 5 Dec 2021
    7.8
    High

    CVE-2021-44045

    Last Modified: 21 Nov 2024

    An out-of-bounds write vulnerability exists when reading a DGN file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists within the parsing of DGN files. Crafted data in a DGN file and lack of proper validation for the XFAT sectors count can trigger a write operation past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.

    Published: 5 Dec 2021
    7.8
    High

    CVE-2021-44044

    Last Modified: 21 Nov 2024

    An out-of-bounds write vulnerability exists when reading a JPG file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists with parsing JPG files. Crafted data in a JPG (4 extraneous bytes before the marker 0xca) can trigger a write operation past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.

    Published: 5 Dec 2021
    7.5
    High

    CVE-2021-37253

    Last Modified: 21 Nov 2024

    M-Files Web before 20.10.9524.1 allows a denial of service via overlapping ranges (in HTTP requests with crafted Range or Request-Range headers). NOTE: this is disputed because the range behavior is the responsibility of the web server, not the responsibility of the individual web application

    Published: 5 Dec 2021
    4.3
    Medium

    CVE-2021-4005

    Last Modified: 21 Nov 2024

    firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

    Published: 4 Dec 2021
    6.3
    Medium

    CVE-2021-34337

    Last Modified: 6 Feb 2025

    An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this, but can optionally be made to listen on other interfaces.

    Published: 4 Dec 2021
    4.8
    Medium

    CVE-2021-35415

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the course "Title" and "Content" fields.

    Published: 3 Dec 2021
    9.8
    Critical

    CVE-2021-35414

    Last Modified: 21 Nov 2024

    Chamilo LMS v1.11.x was discovered to contain a SQL injection via the doc parameter in main/plagiarism/compilatio/upload.php.

    Published: 3 Dec 2021