CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2021-29719

    Last Modified: 21 Nov 2024

    IBM Cognos Analytics 11.1.7 and 11.2.0 could be vulnerable to client side vulnerabilties due to a web response specifying an incorrect content type. IBM X-Force ID: 201091

    Published: 3 Dec 2021
    6.5
    Medium

    CVE-2021-29716

    Last Modified: 21 Nov 2024

    IBM Cognos Analytics 11.1.7 and 11.2.0 could allow a low level user to reas of the application that privileged user should only be allowed to view. IBM X-Force ID: 201087.

    Published: 3 Dec 2021
    6.1
    Medium

    CVE-2021-20493

    Last Modified: 21 Nov 2024

    IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 197794.

    Published: 3 Dec 2021
    7.5
    High

    CVE-2021-20470

    Last Modified: 21 Nov 2024

    IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196339.

    Published: 3 Dec 2021
    7.5
    High

    CVE-2021-3980

    Last Modified: 21 Nov 2024

    elgg is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor

    Published: 3 Dec 2021
    6.8
    Medium

    CVE-2021-43991

    Last Modified: 21 Nov 2024

    The Kentico Xperience CMS version 13.0 – 13.0.43 is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability (also known as Stored or Second-Order XSS). Persistent XSS vulnerabilities occur when the application stores and retrieves client supplied data without proper handling of dangerous content. This type of XSS vulnerability is exploited by submitting malicious script content to the application which is then retrieved and executed by other application users. The attacker could exploit this to conduct a range of attacks against users of the affected application such as session hijacking, account take over and accessing sensitive data.

    Published: 3 Dec 2021
    9.8
    Critical

    CVE-2021-43676

    Last Modified: 21 Nov 2024

    matyhtf framework v3.0.5 is affected by a path manipulation vulnerability in Smarty.class.php.

    Published: 3 Dec 2021
    9.8
    Critical

    CVE-2021-44278

    Last Modified: 21 Nov 2024

    Librenms 21.11.0 is affected by a path manipulation vulnerability in includes/html/pages/device/showconfig.inc.php.

    Published: 3 Dec 2021
    9.8
    Critical

    CVE-2021-43674

    Last Modified: 21 Nov 2024

    ThinkUp 2.0-beta.10 is affected by a path manipulation vulnerability in Smarty.class.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 3 Dec 2021
    6.1
    Medium

    CVE-2021-43673

    Last Modified: 21 Nov 2024

    dzzoffice 2.02.1_SC_UTF8 is affected by a Cross Site Scripting (XSS) vulnerability in explorerfile.php. The output of the exit function is printed for the user via exit(json_encode($return)).

    Published: 3 Dec 2021
    5.5
    Medium

    CVE-2021-44022

    Last Modified: 21 Nov 2024

    A reachable assertion vulnerability in Trend Micro Apex One could allow an attacker to crash the program on affected installations, leading to a denial-of-service (DoS). Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 3 Dec 2021
    7.8
    High

    CVE-2021-44021

    Last Modified: 21 Nov 2024

    An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar to but not identical to CVE-2021-44019 and 44020.

    Published: 3 Dec 2021
    7.8
    High

    CVE-2021-44020

    Last Modified: 21 Nov 2024

    An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar to but not identical to CVE-2021-44019 and 44021.

    Published: 3 Dec 2021
    7.8
    High

    CVE-2021-44019

    Last Modified: 21 Nov 2024

    An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar to but not identical to CVE-2021-44020 and 44021.

    Published: 3 Dec 2021
    5.5
    Medium

    CVE-2021-43772

    Last Modified: 21 Nov 2024

    Trend Micro Security 2021 v17.0 (Consumer) contains a vulnerability that allows files inside the protected folder to be modified without any detection.

    Published: 3 Dec 2021
    6.1
    Medium

    CVE-2021-4000

    Last Modified: 21 Nov 2024

    showdoc is vulnerable to URL Redirection to Untrusted Site

    Published: 3 Dec 2021
    7
    High

    CVE-2021-4083

    Last Modified: 21 Nov 2024

    A read-after-free memory flaw was found in the Linux kernel's garbage collection for Unix domain socket file handlers in the way users call close() and fget() simultaneously and can potentially trigger a race condition. This flaw allows a local user to crash the system or escalate their privileges on the system. This flaw affects Linux kernel versions prior to 5.16-rc4.

    Published: 3 Dec 2021
    7.8
    High

    CVE-2021-4069

    Last Modified: 21 Nov 2024

    vim is vulnerable to Use After Free

    Published: 3 Dec 2021
    4.8
    Medium

    CVE-2021-25785

    Last Modified: 21 Nov 2024

    Taocms v2.5Beta5 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Management column.

    Published: 2 Dec 2021
    7.2
    High

    CVE-2021-25784

    Last Modified: 21 Nov 2024

    Taocms v2.5Beta5 was discovered to contain a blind SQL injection vulnerability via the function Edit Article.

    Published: 2 Dec 2021
    7.2
    High

    CVE-2021-25783

    Last Modified: 21 Nov 2024

    Taocms v2.5Beta5 was discovered to contain a blind SQL injection vulnerability via the function Article Search.

    Published: 2 Dec 2021
    9.1
    Critical

    CVE-2020-29177

    Last Modified: 21 Nov 2024

    Z-BlogPHP v1.6.1.2100 was discovered to contain an arbitrary file deletion vulnerability via \app_del.php.

    Published: 2 Dec 2021
    7.8
    High

    CVE-2020-29176

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in Z-BlogPHP v1.6.1.2100 allows attackers to execute arbitrary code via a crafted JPG file.

    Published: 2 Dec 2021
    9.8
    Critical

    CVE-2021-28237

    Last Modified: 21 Nov 2024

    LibreDWG v0.12.3 was discovered to contain a heap-buffer overflow via decode_preR13.

    Published: 2 Dec 2021
    7.5
    High

    CVE-2021-28236

    Last Modified: 21 Nov 2024

    LibreDWG v0.12.3 was discovered to contain a NULL pointer dereference via out_dxfb.c.

    Published: 2 Dec 2021
    4.6
    Medium

    CVE-2021-43327

    Last Modified: 21 Nov 2024

    An issue was discovered on Renesas RX65 and RX65N devices. With a VCC glitch, an attacker can extract the security ID key from the device. Then, the protected firmware can be extracted.

    Published: 2 Dec 2021
    9
    Critical

    CVE-2021-40333

    Last Modified: 21 Nov 2024

    Weak Password Requirements vulnerability in Hitachi Energy FOX61x, XCM20 allows an attacker to gain unauthorized access to the Data Communication Network (DCN) routing configuration. This issue affects: Hitachi Energy FOX61x versions prior to R15A. Hitachi Energy XCM20 versions prior to R15A.

    Published: 2 Dec 2021
    8.6
    High

    CVE-2021-40334

    Last Modified: 21 Nov 2024

    Missing Handler vulnerability in the proprietary management protocol (port TCP 5558) of Hitachi Energy FOX61x, XCM20 allows an attacker that exploits the vulnerability by activating SSH on port TCP 5558 to cause disruption to the NMS and NE communication. This issue affects: Hitachi Energy FOX61x versions prior to R15A. Hitachi Energy XCM20 versions prior to R15A.

    Published: 2 Dec 2021
    6.5
    Medium

    CVE-2021-44050

    Last Modified: 21 Nov 2024

    CA Network Flow Analysis (NFA) 21.2.1 and earlier contain a SQL injection vulnerability in the NFA web application, due to insufficient input validation, that could potentially allow an authenticated user to access sensitive data.

    Published: 2 Dec 2021
    7.5
    High

    CVE-2021-43795

    Last Modified: 21 Nov 2024

    Armeria is an open source microservice framework. In affected versions an attacker can access an Armeria server's local file system beyond its restricted directory by sending an HTTP request whose path contains `%2F` (encoded `/`), such as `/files/..%2Fsecrets.txt`, bypassing Armeria's path validation logic. Armeria 1.13.4 or above contains the hardened path validation logic that handles `%2F` properly. This vulnerability can be worked around by inserting a decorator that performs an additional validation on the request path.

    Published: 2 Dec 2021
    4.8
    Medium

    CVE-2015-20106

    Last Modified: 21 Nov 2024

    The ClickBank Affiliate Ads WordPress plugin through 1.20 does not escape its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

    Published: 2 Dec 2021
    9.6
    Critical

    CVE-2015-20105

    Last Modified: 21 Nov 2024

    The ClickBank Affiliate Ads WordPress plugin through 1.20 does not have CSRF check when saving its settings, allowing attacker to make logged in admin change them via a CSRF attack. Furthermore, due to the lack of escaping when they are outputting, it could also lead to Stored Cross-Site Scripting issues

    Published: 2 Dec 2021
    6.8
    Medium

    CVE-2021-44518

    Last Modified: 21 Nov 2024

    An issue was discovered in the eGeeTouch 3rd Generation Travel Padlock application for Android. The lock sends a pairing code before each operation (lock or unlock) activated via the companion app. The code is sent unencrypted, allowing any attacker with the same app (either Android or iOS) to add the lock and take complete control. For successful exploitation, the attacker must be able to touch the lock's power button, and must be able to capture BLE network communication.

    Published: 2 Dec 2021
    6.8
    Medium

    CVE-2021-3944

    Last Modified: 21 Nov 2024

    bookstack is vulnerable to Cross-Site Request Forgery (CSRF)

    Published: 2 Dec 2021
    8.1
    High

    CVE-2021-23264

    Last Modified: 21 Nov 2024

    Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete search indexes.

    Published: 2 Dec 2021
    5.9
    Medium

    CVE-2021-23263

    Last Modified: 21 Nov 2024

    Unauthenticated remote attackers can read textual content via FreeMarker including files /scripts/*, /templates/* and some of the files in /.git/* (non-binary).

    Published: 2 Dec 2021
    4.2
    Medium

    CVE-2021-23262

    Last Modified: 21 Nov 2024

    Authenticated administrators may modify the main YAML configuration file and load a Java class resulting in RCE.

    Published: 2 Dec 2021
    4.5
    Medium

    CVE-2021-23261

    Last Modified: 21 Nov 2024

    Authenticated administrators may override the system configuration file and cause a denial of service.

    Published: 2 Dec 2021
    6.5
    Medium

    CVE-2021-23260

    Last Modified: 21 Nov 2024

    Authenticated users with Site roles may inject XSS scripts via file names that will execute in the browser for this and other users of the same site.

    Published: 2 Dec 2021
    4.2
    Medium

    CVE-2021-23259

    Last Modified: 21 Nov 2024

    Authenticated users with Administrator or Developer roles may execute OS commands by Groovy Script which uses Groovy lib to render a webpage. The groovy script does not have security restrictions, which will cause attackers to execute arbitrary commands remotely(RCE).

    Published: 2 Dec 2021
    4.2
    Medium

    CVE-2021-23258

    Last Modified: 21 Nov 2024

    Authenticated users with Administrator or Developer roles may execute OS commands by SPEL Expression in Spring beans. SPEL Expression does not have security restrictions, which will cause attackers to execute arbitrary commands remotely (RCE).

    Published: 2 Dec 2021
    9.8
    Critical

    CVE-2021-43679

    Last Modified: 21 Nov 2024

    ecshop v2.7.3 is affected by a SQL injection vulnerability in shopex\ecshop\upload\api\client\api.php.

    Published: 2 Dec 2021
    6.1
    Medium

    CVE-2021-43682

    Last Modified: 21 Nov 2024

    thinkphp-bjyblog (last update Jun 4 2021) is affected by a Cross Site Scripting (XSS) vulnerability in AdminBaseController.class.php. The exit function terminates the script and prints a message to the user that contains $_SERVER['HTTP_HOST'].

    Published: 2 Dec 2021
    6.1
    Medium

    CVE-2021-43681

    Last Modified: 21 Nov 2024

    SakuraPanel v1.0.1.1 is affected by a Cross Site Scripting (XSS) vulnerability in /master/core/PostHandler.php. The exit function will terminate the script and print the message $data['proxy_name'].

    Published: 2 Dec 2021
    6.1
    Medium

    CVE-2021-43683

    Last Modified: 21 Nov 2024

    pictshare v1.5 is affected by a Cross Site Scripting (XSS) vulnerability in api/info.php. The exit function will terminate the script and print the message which has $_REQUEST['hash'].

    Published: 2 Dec 2021
    6.1
    Medium

    CVE-2021-43686

    Last Modified: 21 Nov 2024

    nZEDb v0.4.20 is affected by a Cross Site Scripting (XSS) vulnerability in www/pages/api.php. The exit function will terminate the script and print the message which has the input $_GET['t'].

    Published: 2 Dec 2021
    9.8
    Critical

    CVE-2021-26777

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in function SetFirewall in index.cgi in CIRCUTOR COMPACT DC-S BASIC smart metering concentrator Firwmare version CIR_CDC_v1.2.17, allows attackers to execute arbitrary code.

    Published: 2 Dec 2021
    5.9
    Medium

    CVE-2020-27414

    Last Modified: 21 Nov 2024

    Mahavitaran android application 7.50 and prior transmit sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header, MITM or browser history.

    Published: 2 Dec 2021
    6.5
    Medium

    CVE-2021-43791

    Last Modified: 21 Nov 2024

    Zulip is an open source group chat application that combines real-time chat with threaded conversations. In affected versions expiration dates on the confirmation objects associated with email invitations were not enforced properly in the new account registration flow. A confirmation link takes a user to the check_prereg_key_and_redirect endpoint, before getting redirected to POST to /accounts/register/. The problem was that validation was happening in the check_prereg_key_and_redirect part and not in /accounts/register/ - meaning that one could submit an expired confirmation key and be able to register. The issue is fixed in Zulip 4.8. There are no known workarounds and users are advised to upgrade as soon as possible.

    Published: 2 Dec 2021
    8.8
    High

    CVE-2020-36129

    Last Modified: 21 Nov 2024

    AOM v2.0.1 was discovered to contain a stack buffer overflow via the component src/aom_image.c.

    Published: 2 Dec 2021