CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-43565

    Last Modified: 21 Nov 2024

    The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an attacker to panic an SSH server.

    Published: 2 Dec 2021
    6.5
    Medium

    CVE-2020-36130

    Last Modified: 21 Nov 2024

    AOM v2.0.1 was discovered to contain a NULL pointer dereference via the component av1/av1_dx_iface.c.

    Published: 2 Dec 2021
    8.8
    High

    CVE-2020-36131

    Last Modified: 21 Nov 2024

    AOM v2.0.1 was discovered to contain a stack buffer overflow via the component stats/rate_hist.c.

    Published: 2 Dec 2021
    8.8
    High

    CVE-2020-36133

    Last Modified: 21 Nov 2024

    AOM v2.0.1 was discovered to contain a global buffer overflow via the component av1/encoder/partition_search.h.

    Published: 2 Dec 2021
    6.5
    Medium

    CVE-2020-36134

    Last Modified: 21 Nov 2024

    AOM v2.0.1 was discovered to contain a segmentation violation via the component aom_dsp/x86/obmc_sad_avx2.c.

    Published: 2 Dec 2021
    6.5
    Medium

    CVE-2020-36135

    Last Modified: 21 Nov 2024

    AOM v2.0.1 was discovered to contain a NULL pointer dereference via the component rate_hist.c.

    Published: 2 Dec 2021
    6.1
    Medium

    CVE-2020-35037

    Last Modified: 21 Nov 2024

    The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing them in pages, which could lead to Cross-Site Scripting issues

    Published: 1 Dec 2021
    7.2
    High

    CVE-2020-35012

    Last Modified: 21 Nov 2024

    The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection

    Published: 1 Dec 2021
    7.8
    High

    CVE-2021-42711

    Last Modified: 21 Nov 2024

    Barracuda Network Access Client before 5.2.2 creates a Temporary File in a Directory with Insecure Permissions. This file is executed with SYSTEM privileges when an unprivileged user performs a repair operation.

    Published: 1 Dec 2021
    9.8
    Critical

    CVE-2021-33265

    Last Modified: 21 Nov 2024

    D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function FUN_80046eb4 in /formSetPortTr. This vulnerability is triggered via a crafted POST request.

    Published: 1 Dec 2021
    9.8
    Critical

    CVE-2021-33266

    Last Modified: 21 Nov 2024

    D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function FUN_8004776c in /formVirtualApp. This vulnerability is triggered via a crafted POST request.

    Published: 1 Dec 2021
    9.8
    Critical

    CVE-2021-33267

    Last Modified: 21 Nov 2024

    D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function FUN_80034d60 in /formStaticDHCP. This vulnerability is triggered via a crafted POST request.

    Published: 1 Dec 2021
    9.8
    Critical

    CVE-2021-33268

    Last Modified: 21 Nov 2024

    D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function sub_8003183C in /fromLogin. This vulnerability is triggered via a crafted POST request.

    Published: 1 Dec 2021
    9.8
    Critical

    CVE-2021-33269

    Last Modified: 21 Nov 2024

    D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function FUN_8004776c in /formVirtualServ. This vulnerability is triggered via a crafted POST request.

    Published: 1 Dec 2021
    9.8
    Critical

    CVE-2021-33270

    Last Modified: 21 Nov 2024

    D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function FUN_800462c4 in /formAdvFirewall. This vulnerability is triggered via a crafted POST request.

    Published: 1 Dec 2021
    9.8
    Critical

    CVE-2021-33271

    Last Modified: 21 Nov 2024

    D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function sub_80046EB4 in /formSetPortTr. This vulnerability is triggered via a crafted POST request.

    Published: 1 Dec 2021
    9.8
    Critical

    CVE-2021-33274

    Last Modified: 21 Nov 2024

    D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function FUN_80040af8 in /formWlanSetup. This vulnerability is triggered via a crafted POST request.

    Published: 1 Dec 2021
    4.3
    Medium

    CVE-2021-43793

    Last Modified: 21 Nov 2024

    Discourse is an open source discussion platform. In affected versions a vulnerability in the Polls feature allowed users to vote multiple times in a single-option poll. The problem is patched in the latest tests-passed, beta and stable versions of Discourse

    Published: 1 Dec 2021
    5.3
    Medium

    CVE-2021-43794

    Last Modified: 21 Nov 2024

    Discourse is an open source discussion platform. In affected versions an attacker can poison the cache for anonymous (i.e. not logged in) users, such that the users are shown a JSON blob instead of the HTML page. This can lead to a partial denial-of-service. This issue is patched in the latest stable, beta and tests-passed versions of Discourse.

    Published: 1 Dec 2021
    4.3
    Medium

    CVE-2021-43792

    Last Modified: 21 Nov 2024

    Discourse is an open source discussion platform. In affected versions a vulnerability affects users of tag groups who use the "Tags are visible only to the following groups" feature. A tag group may only allow a certain group (e.g. staff) to view certain tags. Users who were tracking or watching the tags via /preferences/tags, then have their staff status revoked will still see notifications related to the tag, but will not see the tag on each topic. This issue has been patched in stable version 2.7.11. Users are advised to upgrade as soon as possible.

    Published: 1 Dec 2021
    8.8
    High

    CVE-2021-43137

    Last Modified: 21 Nov 2024

    Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in my-profile.php. Chaining to this both vulnerabilities leads to account takeover.

    Published: 1 Dec 2021
    9.8
    Critical

    CVE-2021-43451

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability exists in PHPGURUKUL Employee Record Management System 1.2 via the Email POST parameter in /forgetpassword.php.

    Published: 1 Dec 2021
    4.3
    Medium

    CVE-2021-29863

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.3 and 7.4 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. This vulnerability is due to an incomplete fix for CVE-2020-4786. IBM X-Force ID: 206087.

    Published: 1 Dec 2021
    6.1
    Medium

    CVE-2021-29849

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 205281.

    Published: 1 Dec 2021
    5.9
    Medium

    CVE-2021-29779

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.3 and 7.4 could allow an attacker to obtain sensitive information due to the server performing key exchange without entity authentication on inter-host communications using man in the middle techniques. IBM X-Force ID: 203033.

    Published: 1 Dec 2021
    7.5
    High

    CVE-2021-20400

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196074.

    Published: 1 Dec 2021
    7.7
    High

    CVE-2021-42776

    Last Modified: 21 Nov 2024

    CloverDX Server before 5.11.2 and and 5.12.x before 5.12.1 allows XXE during configuration import.

    Published: 1 Dec 2021
    9.8
    Critical

    CVE-2021-43527

    Last Modified: 21 Nov 2024

    NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted. This vulnerability affects NSS < 3.73 and NSS < 3.68.1.

    Published: 1 Dec 2021
    6.1
    Medium

    CVE-2021-43687

    Last Modified: 21 Nov 2024

    chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability in /plugin/jcapture/applet.php if an attacker passes a message hex2bin in the cookie.

    Published: 1 Dec 2021
    9.9
    Critical

    CVE-2021-26334

    Last Modified: 21 Nov 2024

    The AMDPowerProfiler.sys driver of AMD μProf tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation and ring-0 code execution by the lower privileged user.

    Published: 1 Dec 2021
    7.5
    High

    CVE-2021-20611

    Last Modified: 21 Nov 2024

    Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, MELSEC iQ-R Series R08/16/32/120SFCPU, MELSEC iQ-R Series R08/16/32/120PCPU, MELSEC iQ-R Series R08/16/32/120PSFCPU, MELSEC iQ-R Series R16/32/64MTCPU, MELSEC iQ-R Series R12CCPU-V, MELSEC Q Series Q03UDECPU, MELSEC Q Series Q04/06/10/13/20/26/50/100UDEHCPU, MELSEC Q Series Q03/04/06/13/26UDVCPU, MELSEC Q Series Q04/06/13/26UDPVCPU, MELSEC Q Series Q12DCCPU-V, MELSEC Q Series Q24DHCCPU-V(G), MELSEC Q Series Q24/26DHCCPU-LS, MELSEC Q Series MR-MQ100, MELSEC Q Series Q172/173DCPU-S1, MELSEC Q Series Q172/173DSCPU, MELSEC Q Series Q170MCPU, MELSEC Q Series Q170MSCPU(-S1), MELSEC L Series L02/06/26CPU(-P), MELSEC L Series L26CPU-(P)BT and MELIPC Series MI5122-VW allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by sending specially crafted packets. System reset is required for recovery.

    Published: 1 Dec 2021
    7.5
    High

    CVE-2021-20610

    Last Modified: 21 Nov 2024

    Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, MELSEC iQ-R Series R08/16/32/120SFCPU, MELSEC iQ-R Series R08/16/32/120PCPU, MELSEC iQ-R Series R08/16/32/120PSFCPU, MELSEC iQ-R Series R16/32/64MTCPU, MELSEC iQ-R Series R12CCPU-V, MELSEC Q Series Q03UDECPU, MELSEC Q Series Q04/06/10/13/20/26/50/100UDEHCPU, MELSEC Q Series Q03/04/06/13/26UDVCPU, MELSEC Q Series Q04/06/13/26UDPVCPU, MELSEC Q Series Q12DCCPU-V, MELSEC Q Series Q24DHCCPU-V(G), MELSEC Q Series Q24/26DHCCPU-LS, MELSEC Q Series MR-MQ100, MELSEC Q Series Q172/173DCPU-S1, MELSEC Q Series Q172/173DSCPU, MELSEC Q Series Q170MCPU, MELSEC Q Series Q170MSCPU(-S1), MELSEC L Series L02/06/26CPU(-P), MELSEC L Series L26CPU-(P)BT and MELIPC Series MI5122-VW allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by sending specially crafted packets. System reset is required for recovery.

    Published: 1 Dec 2021
    7.5
    High

    CVE-2021-20609

    Last Modified: 21 Nov 2024

    Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, MELSEC iQ-R Series R08/16/32/120SFCPU, MELSEC iQ-R Series R08/16/32/120PCPU, MELSEC iQ-R Series R08/16/32/120PSFCPU, MELSEC iQ-R Series R16/32/64MTCPU, MELSEC iQ-R Series R12CCPU-V, MELSEC Q Series Q03UDECPU, MELSEC Q Series Q04/06/10/13/20/26/50/100UDEHCPU, MELSEC Q Series Q03/04/06/13/26UDVCPU, MELSEC Q Series Q04/06/13/26UDPVCPU, MELSEC Q Series Q12DCCPU-V, MELSEC Q Series Q24DHCCPU-V(G), MELSEC Q Series Q24/26DHCCPU-LS, MELSEC Q Series MR-MQ100, MELSEC Q Series Q172/173DCPU-S1, MELSEC Q Series Q172/173DSCPU, MELSEC Q Series Q170MCPU, MELSEC Q Series Q170MSCPU(-S1), MELSEC L Series L02/06/26CPU(-P), MELSEC L Series L26CPU-(P)BT and MELIPC Series MI5122-VW allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by sending specially crafted packets. System reset is required for recovery.

    Published: 1 Dec 2021
    7.3
    High

    CVE-2020-10627

    Last Modified: 21 Nov 2024

    Insulet Omnipod Insulin Management System insulin pump product ID 19191 and 40160 is designed to communicate using a wireless RF with an Insulet manufactured Personal Diabetes Manager device. This wireless RF communication protocol does not properly implement authentication or authorization. An attacker with access to one of the affected insulin pump models may be able to modify and/or intercept data. This vulnerability could also allow attackers to change pump settings and control insulin delivery.

    Published: 1 Dec 2021
    8.1
    High

    CVE-2021-44480

    Last Modified: 21 Nov 2024

    Wokka Lokka Q50 devices through 2021-11-30 allow remote attackers (who know the SIM phone number and password) to listen to a device's surroundings via a callback in an SMS command, as demonstrated by the 123456 and 523681 default passwords.

    Published: 1 Dec 2021
    9.8
    Critical

    CVE-2021-43685

    Last Modified: 21 Nov 2024

    libretime hv3.0.0-alpha.10 is affected by a path manipulation vulnerability in /blob/master/legacy/application/modules/rest/controllers/ShowImageController.php through the rename function.

    Published: 1 Dec 2021
    6.1
    Medium

    CVE-2021-44479

    Last Modified: 21 Nov 2024

    NXP Kinetis K82 devices have a buffer over-read via a crafted wlength value in a GET Status-Other request during use of USB In-System Programming (ISP) mode. This discloses protected flash memory.

    Published: 1 Dec 2021
    6.1
    Medium

    CVE-2021-40154

    Last Modified: 21 Nov 2024

    NXP LPC55S69 devices before A3 have a buffer over-read via a crafted wlength value in a GET Descriptor Configuration request during use of USB In-System Programming (ISP) mode. This discloses protected flash memory.

    Published: 1 Dec 2021
    6.1
    Medium

    CVE-2021-43689

    Last Modified: 21 Nov 2024

    manage (last update Oct 24, 2017) is affected by a Cross Site Scripting (XSS) vulnerability in Application/Home/Controller/GoodsController.class.php. The exit function will terminate the script and print a message which have values from $_POST.

    Published: 1 Dec 2021
    8.8
    High

    CVE-2021-4112

    Last Modified: 21 Nov 2024

    A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the isolated environment.

    Published: 1 Dec 2021
    5.4
    Medium

    CVE-2021-25967

    Last Modified: 30 Apr 2025

    In CKAN, versions 2.9.0 to 2.9.3 are affected by a stored XSS vulnerability via SVG file upload of users’ profile picture. This allows low privileged application users to store malicious scripts in their profile picture. These scripts are executed in a victim’s browser when they open the malicious profile picture

    Published: 1 Dec 2021
    6.1
    Medium

    CVE-2021-44277

    Last Modified: 21 Nov 2024

    Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/common/alert-log.inc.php.

    Published: 1 Dec 2021
    6.1
    Medium

    CVE-2021-44279

    Last Modified: 21 Nov 2024

    Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/forms/poller-groups.inc.php.

    Published: 1 Dec 2021
    2.3
    Low

    CVE-2021-3923

    Last Modified: 24 Feb 2025

    A flaw was found in the Linux kernel's implementation of RDMA over infiniband. An attacker with a privileged local account can leak kernel stack information when issuing commands to the /dev/infiniband/rdma_cm device node. While this access is unlikely to leak sensitive user information, it can be further used to defeat existing kernel protection mechanisms.

    Published: 1 Dec 2021
    9.8
    Critical

    CVE-2021-44280

    Last Modified: 21 Nov 2024

    attendance management system 1.0 is affected by a SQL injection vulnerability in admin/incFunctions.php through the makeSafe function.

    Published: 1 Dec 2021
    6.1
    Medium

    CVE-2021-43690

    Last Modified: 21 Nov 2024

    YurunProxy v0.01 is affected by a Cross Site Scripting (XSS) vulnerability in src/Client.php. The exit function will terminate the script and print a message which have values from the socket_read.

    Published: 1 Dec 2021
    7.8
    High

    CVE-2021-4041

    Last Modified: 21 Nov 2024

    A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interface.run_command, can lead to parameters getting executed as host's shell command. A developer could unintentionally write code that gets executed in the host rather than the virtual environment.

    Published: 1 Dec 2021
    7.8
    High

    CVE-2021-32592

    Last Modified: 21 Nov 2024

    An unsafe search path vulnerability in FortiClientWindows 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x and FortiClientEMS 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x may allow an attacker to perform a DLL Hijack attack on affected devices via a malicious OpenSSL engine library in the search path.

    Published: 1 Dec 2021
    5.9
    Medium

    CVE-2021-3964

    Last Modified: 21 Nov 2024

    elgg is vulnerable to Authorization Bypass Through User-Controlled Key

    Published: 1 Dec 2021
    6.1
    Medium

    CVE-2021-3983

    Last Modified: 21 Nov 2024

    kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 1 Dec 2021