CVE Feed

    Dashboard / CVE

    9
    Critical

    CVE-2021-3985

    Last Modified: 21 Nov 2024

    kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 1 Dec 2021
    6.1
    Medium

    CVE-2021-3989

    Last Modified: 21 Nov 2024

    showdoc is vulnerable to URL Redirection to Untrusted Site

    Published: 1 Dec 2021
    6.5
    Medium

    CVE-2021-3990

    Last Modified: 21 Nov 2024

    showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

    Published: 1 Dec 2021
    6.5
    Medium

    CVE-2021-3992

    Last Modified: 21 Nov 2024

    kimai2 is vulnerable to Improper Access Control

    Published: 1 Dec 2021
    9.6
    Critical

    CVE-2021-3994

    Last Modified: 21 Nov 2024

    django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 1 Dec 2021
    6.5
    Medium

    CVE-2021-3993

    Last Modified: 21 Nov 2024

    showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

    Published: 1 Dec 2021
    4.3
    Medium

    CVE-2021-4015

    Last Modified: 21 Nov 2024

    firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

    Published: 1 Dec 2021
    8.8
    High

    CVE-2021-4017

    Last Modified: 21 Nov 2024

    showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

    Published: 1 Dec 2021
    5.4
    Medium

    CVE-2021-4018

    Last Modified: 21 Nov 2024

    snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 1 Dec 2021
    7.4
    High

    CVE-2021-34599

    Last Modified: 21 Nov 2024

    Affected versions of CODESYS Git in Versions prior to V1.1.0.0 lack certificate validation in HTTPS handshakes. CODESYS Git does not implement certificate validation by default, so it does not verify that the server provides a valid and trusted HTTPS certificate. Since the certificate of the server to which the connection is made is not properly verified, the server connection is vulnerable to a man-in-the-middle attack.

    Published: 1 Dec 2021
    8.8
    High

    CVE-2021-20864

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11 and prior, WRC-1900GST firmware v1.03 and prior, WRC-2533GST firmware v1.03 and prior, WRC-2533GSTA firmware v1.03 and prior, WRC-2533GST2 firmware v1.25 and prior, WRC-2533GST2SP firmware v1.25 and prior, WRC-2533GST2-G firmware v1.25 and prior, and EDWRC-2533GST2 firmware v1.25 and prior) allows a network-adjacent unauthenticated attacker to bypass access restriction, and to start the telnet service and execute an arbitrary OS command via unspecified vectors.

    Published: 1 Dec 2021
    8
    High

    CVE-2021-20863

    Last Modified: 21 Nov 2024

    OS command injection vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11 and prior, WRC-1900GST firmware v1.03 and prior, WRC-2533GST firmware v1.03 and prior, WRC-2533GSTA firmware v1.03 and prior, WRC-2533GST2 firmware v1.25 and prior, WRC-2533GST2SP firmware v1.25 and prior, WRC-2533GST2-G firmware v1.25 and prior, and EDWRC-2533GST2 firmware v1.25 and prior) allows a network-adjacent authenticated attackers to execute an arbitrary OS command with the root privilege via unspecified vectors.

    Published: 1 Dec 2021
    4.3
    Medium

    CVE-2021-20862

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11 and prior, WRC-1900GST firmware v1.03 and prior, WRC-2533GST firmware v1.03 and prior, WRC-2533GSTA firmware v1.03 and prior, WRC-2533GST2 firmware v1.25 and prior, WRC-2533GST2SP firmware v1.25 and prior, WRC-2533GST2-G firmware v1.25 and prior, and EDWRC-2533GST2 firmware v1.25 and prior) allows a network-adjacent unauthenticated attacker to bypass access restriction, and to obtain anti-CSRF tokens and change the product's settings via unspecified vectors.

    Published: 1 Dec 2021
    8.8
    High

    CVE-2021-20861

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11 and prior, WRC-1900GST firmware v1.03 and prior, WRC-2533GST firmware v1.03 and prior, WRC-2533GSTA firmware v1.03 and prior, WRC-2533GST2 firmware v1.25 and prior, WRC-2533GST2SP firmware v1.25 and prior, WRC-2533GST2-G firmware v1.25 and prior, and EDWRC-2533GST2 firmware v1.25 and prior) allows a network-adjacent authenticated attacker to bypass access restriction and to access the management screen of the product via unspecified vectors.

    Published: 1 Dec 2021
    8.8
    High

    CVE-2021-20860

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11 and prior, WRC-1900GST firmware v1.03 and prior, WRC-2533GST firmware v1.03 and prior, WRC-2533GSTA firmware v1.03 and prior, WRC-2533GST2 firmware v1.25 and prior, WRC-2533GST2SP firmware v1.25 and prior, WRC-2533GST2-G firmware v1.25 and prior, and EDWRC-2533GST2 firmware v1.25 and prior) allows a remote authenticated attacker to hijack the authentication of an administrator via a specially crafted page.

    Published: 1 Dec 2021
    8
    High

    CVE-2021-20859

    Last Modified: 21 Nov 2024

    ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11 and prior, WRC-1900GST firmware v1.03 and prior, WRC-2533GST firmware v1.03 and prior, WRC-2533GSTA firmware v1.03 and prior, WRC-2533GST2 firmware v1.25 and prior, WRC-2533GST2SP firmware v1.25 and prior, WRC-2533GST2-G firmware v1.25 and prior, and EDWRC-2533GST2 firmware v1.25 and prior) allows a network-adjacent authenticated attacker to execute an arbitrary OS command via unspecified vectors.

    Published: 1 Dec 2021
    5.4
    Medium

    CVE-2021-20858

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in ELECOM LAN router WRC-2533GHBK-I firmware v1.20 and prior allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

    Published: 1 Dec 2021
    5.4
    Medium

    CVE-2021-20857

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in ELECOM LAN router WRC-2533GHBK-I firmware v1.20 and prior allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

    Published: 1 Dec 2021
    5.4
    Medium

    CVE-2021-20856

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

    Published: 1 Dec 2021
    5.4
    Medium

    CVE-2021-20855

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

    Published: 1 Dec 2021
    6.8
    Medium

    CVE-2021-20854

    Last Modified: 21 Nov 2024

    ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-adjacent attacker with an administrator privilege to execute arbitrary OS commands via unspecified vectors.

    Published: 1 Dec 2021
    6.8
    Medium

    CVE-2021-20853

    Last Modified: 21 Nov 2024

    ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-adjacent attacker with an administrator privilege to execute arbitrary OS commands via unspecified vectors.

    Published: 1 Dec 2021
    6.8
    Medium

    CVE-2021-20852

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-adjacent attacker with an administrator privilege to execute an arbitrary OS command via unspecified vectors.

    Published: 1 Dec 2021
    8.8
    High

    CVE-2021-20851

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in Browser and Operating System Finder versions prior to 1.2 allows a remote unauthenticated attacker to hijack the authentication of an administrator via unspecified vectors.

    Published: 1 Dec 2021
    6.1
    Medium

    CVE-2021-20847

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Wi-Fi STATION SH-52A (38JP_1_11G, 38JP_1_11J, 38JP_1_11K, 38JP_1_11L, 38JP_1_26F, 38JP_1_26G, 38JP_1_26J, 38JP_2_03B, and 38JP_2_03C) allows a remote unauthenticated attacker to inject an arbitrary script via WebUI of the device.

    Published: 1 Dec 2021
    8.8
    High

    CVE-2021-43360

    Last Modified: 21 Nov 2024

    Sunnet eHRD e-mail delivery task schedule’s serialization function has inadequate input object validation and restriction, which allows a post-authenticated remote attacker with database access privilege, to execute arbitrary code and control the system or interrupt services.

    Published: 1 Dec 2021
    8.8
    High

    CVE-2021-43359

    Last Modified: 21 Nov 2024

    Sunnet eHRD has broken access control vulnerability, which allows a remote attacker to access account management page after being authenticated as a general user, then perform privilege escalation to execute arbitrary code and control the system or interrupt services.

    Published: 1 Dec 2021
    7.5
    High

    CVE-2021-43358

    Last Modified: 21 Nov 2024

    Sunnet eHRD has inadequate filtering for special characters in URLs, which allows a remote attacker to perform path traversal attacks without authentication, access restricted paths and download system files.

    Published: 1 Dec 2021
    8.8
    High

    CVE-2021-40809

    Last Modified: 21 Nov 2024

    An issue was discovered in Jamf Pro before 10.32.0, aka PI-009921. An account can be granted incorrect privileges in response to authentication that uses specific sign-on workflows.

    Published: 1 Dec 2021
    9.8
    Critical

    CVE-2021-43529

    Last Modified: 19 Mar 2025

    Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with DER-encoded DSA or RSA-PSS signatures.

    Published: 1 Dec 2021
    7.5
    High

    CVE-2021-41039

    Last Modified: 21 Nov 2024

    In versions 1.6 to 2.0.11 of Eclipse Mosquitto, an MQTT v5 client connecting with a large number of user-property properties could cause excessive CPU usage, leading to a loss of performance and possible denial of service.

    Published: 1 Dec 2021
    5.8
    Medium

    CVE-2021-41256

    Last Modified: 21 Nov 2024

    nextcloud news-android is an Android client for the Nextcloud news/feed reader app. In affected versions the Nextcloud News for Android app has a security issue by which a malicious application installed on the same device can send it an arbitrary Intent that gets reflected back, unintentionally giving read and write access to non-exported Content Providers in Nextcloud News for Android. Users should upgrade to version 0.9.9.63 or higher as soon as possible.

    Published: 30 Nov 2021
    8.1
    High

    CVE-2021-36330

    Last Modified: 21 Nov 2024

    Dell EMC Streaming Data Platform versions before 1.3 contain an Insufficient Session Expiration Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to reuse old session artifacts to impersonate a legitimate user.

    Published: 30 Nov 2021
    6.5
    Medium

    CVE-2021-36329

    Last Modified: 21 Nov 2024

    Dell EMC Streaming Data Platform versions before 1.3 contain an Indirect Object Reference Vulnerability. A remote malicious user may potentially exploit this vulnerability to gain sensitive information.

    Published: 30 Nov 2021
    8.8
    High

    CVE-2021-36328

    Last Modified: 21 Nov 2024

    Dell EMC Streaming Data Platform versions before 1.3 contain a SQL Injection Vulnerability. A remote malicious user may potentially exploit this vulnerability to execute SQL commands to perform unauthorized actions and retrieve sensitive information from the database.

    Published: 30 Nov 2021
    5.3
    Medium

    CVE-2021-36327

    Last Modified: 21 Nov 2024

    Dell EMC Streaming Data Platform versions before 1.3 contain a Server Side Request Forgery Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to perform port scanning of internal networks and make HTTP requests to an arbitrary domain of the attacker's choice.

    Published: 30 Nov 2021
    6.5
    Medium

    CVE-2021-36326

    Last Modified: 21 Nov 2024

    Dell EMC Streaming Data Platform, versions prior to 1.3 contain an SSL Strip Vulnerability in the User Interface (UI). A remote unauthenticated attacker could potentially exploit this vulnerability, leading to a downgrade in the communications between the client and server into an unencrypted format.

    Published: 30 Nov 2021
    4.3
    Medium

    CVE-2021-4026

    Last Modified: 21 Nov 2024

    bookstack is vulnerable to Improper Access Control

    Published: 30 Nov 2021
    —
    Unknown

    CVE-2021-37405

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 30 Nov 2021
    7.2
    High

    CVE-2021-40101

    Last Modified: 21 Nov 2024

    An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password.

    Published: 30 Nov 2021
    —
    Unknown

    CVE-2021-43320

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-41244. Reason: This candidate is a reservation duplicate of CVE-2021-41244. Notes: All CVE users should reference CVE-2021-41244 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 30 Nov 2021
    5.4
    Medium

    CVE-2021-42564

    Last Modified: 21 Nov 2024

    An open redirect through HTML injection in confidential messages in Cryptshare before 5.1.0 allows remote attackers (with permission to provide confidential messages via Cryptshare) to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' substring in the editor parameter.

    Published: 30 Nov 2021
    6.5
    Medium

    CVE-2021-31787

    Last Modified: 21 Nov 2024

    The Bluetooth Classic implementation on Actions ATS2815 chipsets does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service and shutdown of a device by flooding the target device with LMP_features_res packets.

    Published: 30 Nov 2021
    7.5
    High

    CVE-2020-7880

    Last Modified: 21 Nov 2024

    The vulnerabilty was discovered in ActiveX module related to NeoRS remote support program. This issue allows an remote attacker to download and execute remote file. It is because of improper parameter validation of StartNeoRS function in ActiveX.

    Published: 30 Nov 2021
    9.8
    Critical

    CVE-2021-42099

    Last Modified: 21 Nov 2024

    Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.

    Published: 30 Nov 2021
    9.8
    Critical

    CVE-2021-43319

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper validation in the Ping functionality.

    Published: 30 Nov 2021
    6.5
    Medium

    CVE-2021-22095

    Last Modified: 21 Nov 2024

    In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object from the message body, regardless of its size. This can cause an OOM Error with a large message

    Published: 30 Nov 2021
    7.5
    High

    CVE-2021-43296

    Last Modified: 21 Nov 2024

    Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to an SSRF attack in ActionExecutor.

    Published: 30 Nov 2021
    6.1
    Medium

    CVE-2021-43295

    Last Modified: 21 Nov 2024

    Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Accounts module.

    Published: 30 Nov 2021
    8.1
    High

    CVE-2021-26612

    Last Modified: 21 Nov 2024

    An improper input validation leading to arbitrary file creation was discovered in copy method of Nexacro platform. Remote attackers use copy method to execute arbitrary command after the file creation included malicious code.

    Published: 30 Nov 2021