CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-26614

    Last Modified: 21 Nov 2024

    ius_get.cgi in IpTime C200 camera allows remote code execution. A remote attacker may send a crafted parameters to the exposed vulnerable web service interface which invokes the arbitrary shell command.

    Published: 22 Nov 2021
    7.8
    High

    CVE-2021-43582

    Last Modified: 21 Nov 2024

    A Use-After-Free Remote Vulnerability exists when reading a DWG file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists within the parsing of DWG files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process.

    Published: 22 Nov 2021
    8.8
    High

    CVE-2021-43581

    Last Modified: 21 Nov 2024

    An Out-of-Bounds Read vulnerability exists when reading a U3D file using Open Design Alliance PRC SDK before 2022.11. The specific issue exists within the parsing of U3D files. Incorrect use of the LibJpeg source manager inside the U3D library, and crafted data in a U3D file, can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.

    Published: 22 Nov 2021
    4.3
    Medium

    CVE-2021-38378

    Last Modified: 21 Nov 2024

    OX App Suite 7.10.5 allows Information Exposure because a caching mechanism can caused a Modified By response to show a person's name.

    Published: 22 Nov 2021
    6.1
    Medium

    CVE-2021-38377

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results.

    Published: 22 Nov 2021
    5.3
    Medium

    CVE-2021-38376

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.

    Published: 22 Nov 2021
    6.1
    Medium

    CVE-2021-38375

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message.

    Published: 22 Nov 2021
    5.4
    Medium

    CVE-2021-38374

    Last Modified: 21 Nov 2024

    OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL.

    Published: 22 Nov 2021
    7.5
    High

    CVE-2021-38146

    Last Modified: 21 Nov 2024

    The File Download API in Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read arbitrary files via absolute path traversal in the SearchString JSON field in /home/download POST data.

    Published: 22 Nov 2021
    6.1
    Medium

    CVE-2021-33495

    Last Modified: 21 Nov 2024

    OX App Suite 7.10.5 allows XSS via an OX Chat system message.

    Published: 22 Nov 2021
    6.1
    Medium

    CVE-2021-33494

    Last Modified: 21 Nov 2024

    OX App Suite 7.10.5 allows XSS via an OX Chat room title during typing rendering.

    Published: 22 Nov 2021
    7.5
    High

    CVE-2021-43557

    Last Modified: 21 Nov 2024

    The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without verification. The $request_uri is the full original request URI without normalization. This makes it possible to construct a URI to bypass the block list on some occasions. For instance, when the block list contains "^/internal/", a URI like `//internal/` can be used to bypass it. Some other plugins also have the same issue. And it may affect the developer's custom plugin.

    Published: 22 Nov 2021
    6
    Medium

    CVE-2021-33493

    Last Modified: 21 Nov 2024

    The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format.

    Published: 22 Nov 2021
    6.1
    Medium

    CVE-2021-33492

    Last Modified: 21 Nov 2024

    OX App Suite 7.10.5 allows XSS via an OX Chat room name.

    Published: 22 Nov 2021
    6.5
    Medium

    CVE-2021-33491

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.5 allows Directory Traversal via ../ in an OOXML or ODF ZIP archive, because of the mishandling of relative paths in mail addresses in conjunction with auto-configuration DNS records.

    Published: 22 Nov 2021
    6.1
    Medium

    CVE-2021-33490

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature.

    Published: 22 Nov 2021
    6.1
    Medium

    CVE-2021-33489

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file.

    Published: 22 Nov 2021
    6.1
    Medium

    CVE-2021-33488

    Last Modified: 21 Nov 2024

    chat in OX App Suite 7.10.5 has Improper Input Validation. A user can be redirected to a rogue OX Chat server via a development-related hook.

    Published: 22 Nov 2021
    9.8
    Critical

    CVE-2021-44079

    Last Modified: 21 Nov 2024

    In the wazuh-slack active response script in Wazuh 4.2.x before 4.2.5, untrusted user agents are passed to a curl command line, potentially resulting in remote code execution.

    Published: 22 Nov 2021
    6.5
    Medium

    CVE-2020-27545

    Last Modified: 6 Feb 2025

    libdwarf before 20201017 has a one-byte out-of-bounds read because of an invalid pointer dereference via an invalid line table in a crafted object.

    Published: 22 Nov 2021
    8.8
    High

    CVE-2021-4093

    Last Modified: 21 Nov 2024

    A flaw was found in the KVM's AMD code for supporting the Secure Encrypted Virtualization-Encrypted State (SEV-ES). A KVM guest using SEV-ES can trigger out-of-bounds reads and writes in the host kernel via a malicious VMGEXIT for a string I/O instruction (for example, outs or ins) using the exit reason SVM_EXIT_IOIO. This issue results in a crash of the entire system or a potential guest-to-host escape scenario.

    Published: 22 Nov 2021
    8.8
    High

    CVE-2021-28710

    Last Modified: 21 Nov 2024

    certain VT-d IOMMUs may not work in shared page table mode For efficiency reasons, address translation control structures (page tables) may (and, on suitable hardware, by default will) be shared between CPUs, for second-level translation (EPT), and IOMMUs. These page tables are presently set up to always be 4 levels deep. However, an IOMMU may require the use of just 3 page table levels. In such a configuration the lop level table needs to be stripped before inserting the root table's address into the hardware pagetable base register. When sharing page tables, Xen erroneously skipped this stripping. Consequently, the guest is able to write to leaf page table entries.

    Published: 21 Nov 2021
    8.8
    High

    CVE-2021-43415

    Last Modified: 21 Nov 2024

    HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job submission capabilities to bypass the configured allowed image paths. Fixed in 1.0.14, 1.1.8, and 1.2.1.

    Published: 21 Nov 2021
    4.1
    Medium

    CVE-2021-34400

    Last Modified: 21 Nov 2024

    NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed memory, which may lead to information disclosure.

    Published: 20 Nov 2021
    4.1
    Medium

    CVE-2021-34399

    Last Modified: 21 Nov 2024

    NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed registers, which may lead to information disclosure.

    Published: 20 Nov 2021
    4.1
    Medium

    CVE-2021-23219

    Last Modified: 21 Nov 2024

    NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated privileges to access protected information by identifying, exploiting, and loading vulnerable microcode. Such an attack may lead to information disclosure.

    Published: 20 Nov 2021
    7.5
    High

    CVE-2021-23217

    Last Modified: 21 Nov 2024

    NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated privileges to instantiate a DMA write operation only within a specific time window timed to corrupt code execution, which may impact confidentiality, integrity, or availability. The scope impact may extend to other components.

    Published: 20 Nov 2021
    7.5
    High

    CVE-2021-23201

    Last Modified: 21 Nov 2024

    NVIDIA GPU and Tegra hardware contain a vulnerability in an internal microcontroller, which may allow a user with elevated privileges to generate valid microcode by identifying, exploiting, and loading vulnerable microcode. Such an attack could lead to information disclosure, data corruption, or denial of service of the device. The scope may extend to other components.

    Published: 20 Nov 2021
    4.1
    Medium

    CVE-2021-1125

    Last Modified: 21 Nov 2024

    NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to corrupt program data.

    Published: 20 Nov 2021
    4.1
    Medium

    CVE-2021-1105

    Last Modified: 21 Nov 2024

    NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to access debug registers during runtime, which may lead to information disclosure.

    Published: 20 Nov 2021
    4.1
    Medium

    CVE-2021-1088

    Last Modified: 21 Nov 2024

    NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to utilize debug mechanisms with insufficient access control, which may lead to information disclosure.

    Published: 20 Nov 2021
    7.8
    High

    CVE-2021-36340

    Last Modified: 23 May 2025

    Dell EMC SCG 5.00.00.10 and earlier, contain a sensitive information disclosure vulnerability. A local malicious user may exploit this vulnerability to read sensitive information and use it.

    Published: 20 Nov 2021
    6.1
    Medium

    CVE-2021-36322

    Last Modified: 21 Nov 2024

    Dell Networking X-Series firmware versions prior to 3.0.1.8 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary host header values to poison the web-cache or trigger redirections.

    Published: 20 Nov 2021
    7.5
    High

    CVE-2021-36321

    Last Modified: 21 Nov 2024

    Dell Networking X-Series firmware versions prior to 3.0.1.8 contain an improper input validation vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by sending specially crafted data to trigger a denial of service.

    Published: 20 Nov 2021
    7.5
    High

    CVE-2021-36320

    Last Modified: 21 Nov 2024

    Dell Networking X-Series firmware versions prior to 3.0.1.8 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially hijack a session and access the webserver by forging the session ID.

    Published: 20 Nov 2021
    3.3
    Low

    CVE-2021-36319

    Last Modified: 21 Nov 2024

    Dell Networking OS10 versions 10.4.3.x, 10.5.0.x and 10.5.1.x contain an information exposure vulnerability. A low privileged authenticated malicious user can gain access to SNMP authentication failure messages.

    Published: 20 Nov 2021
    4.9
    Medium

    CVE-2021-36310

    Last Modified: 21 Nov 2024

    Dell Networking OS10, versions 10.4.3.x, 10.5.0.x, 10.5.1.x & 10.5.2.x, contain an uncontrolled resource consumption flaw in its API service. A high-privileged API user may potentially exploit this vulnerability, leading to a denial of service.

    Published: 20 Nov 2021
    5.9
    Medium

    CVE-2021-36308

    Last Modified: 21 Nov 2024

    Networking OS10, versions prior to October 2021 with Smart Fabric Services enabled, contains an authentication bypass vulnerability. A remote unauthenticated attacker could exploit this vulnerability to gain access and perform actions on the affected system.

    Published: 20 Nov 2021
    8.8
    High

    CVE-2021-36307

    Last Modified: 21 Nov 2024

    Networking OS10, versions prior to October 2021 with RESTCONF API enabled, contains a privilege escalation vulnerability. A malicious low privileged user with specific access to the API could potentially exploit this vulnerability to gain admin privileges on the affected system.

    Published: 20 Nov 2021
    8.1
    High

    CVE-2021-36306

    Last Modified: 21 Nov 2024

    Networking OS10, versions prior to October 2021 with RESTCONF API enabled, contains an authentication bypass vulnerability. A remote unauthenticated attacker could exploit this vulnerability to gain access and perform actions on the affected system.

    Published: 20 Nov 2021
    5.3
    Medium

    CVE-2021-38681

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Ragic Cloud DB. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already disabled and removed Ragic Cloud DB from the QNAP App Center, pending a security patch from Ragic.

    Published: 20 Nov 2021
    6.8
    Medium

    CVE-2021-34358

    Last Modified: 21 Nov 2024

    We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and later

    Published: 20 Nov 2021
    4.2
    Medium

    CVE-2021-39198

    Last Modified: 21 Nov 2024

    OroCRM is an open source Client Relationship Management (CRM) application. Affected versions we found to suffer from a vulnerability which could an attacker is able to disqualify any Lead with a Cross-Site Request Forgery (CSRF) attack. There are no workarounds that address this vulnerability and all users are advised to update their package.

    Published: 19 Nov 2021
    9.8
    Critical

    CVE-2021-41280

    Last Modified: 21 Nov 2024

    Sharetribe Go is a source available marketplace software. In affected versions operating system command injection is possible on installations of Sharetribe Go, that do not have a secret AWS Simple Notification Service (SNS) notification token configured via the `sns_notification_token` configuration parameter. This configuration parameter is unset by default. The vulnerability has been patched in version 10.2.1. Users who are unable to upgrade should set the`sns_notification_token` configuration parameter to a secret value.

    Published: 19 Nov 2021
    5.9
    Medium

    CVE-2021-23433

    Last Modified: 21 Nov 2024

    The package algoliasearch-helper before 3.6.2 are vulnerable to Prototype Pollution due to use of the merge function in src/SearchParameters/index.jsSearchParameters._parseNumbers without any protection against prototype properties. Note that this vulnerability is only exploitable if the implementation allows users to define arbitrary search patterns.

    Published: 19 Nov 2021
    9.8
    Critical

    CVE-2021-40391

    Last Modified: 21 Nov 2024

    An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of Gerbv 2.7.0, dev (commit b5f1eacd), and the forked version of Gerbv (commit 71493260). A specially-crafted drill file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 19 Nov 2021
    5.9
    Medium

    CVE-2021-26248

    Last Modified: 2 Apr 2026

    Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

    Published: 19 Nov 2021
    5.9
    Medium

    CVE-2021-42744

    Last Modified: 2 Apr 2026

    Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

    Published: 19 Nov 2021
    5.9
    Medium

    CVE-2021-26262

    Last Modified: 2 Apr 2026

    Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

    Published: 19 Nov 2021
    4.8
    Medium

    CVE-2021-36884

    Last Modified: 28 Mar 2025

    Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered in WordPress Backup Migration plugin <= 1.1.5 versions.

    Published: 19 Nov 2021