CVE Feed

    Dashboard / CVE

    7.3
    High

    CVE-2021-43555

    Last Modified: 21 Nov 2024

    mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vulnerable to a path traversal payload. This vulnerability may allow an attacker to plant files on the file system in arbitrary locations or overwrite existing files, resulting in remote code execution.

    Published: 19 Nov 2021
    7.2
    High

    CVE-2021-22968

    Last Modified: 21 Nov 2024

    A bypass of adding remote files in Concrete CMS (previously concrete5) File Manager leads to remote code execution in Concrete CMS (concrete5) versions 8.5.6 and below.The external file upload feature stages files in the public directory even if they have disallowed file extensions. They are stored in a directory with a random name, but it's possible to stall the uploads and brute force the directory name. You have to be an admin with the ability to upload files, but this bug gives you the ability to upload restricted file types and execute them depending on server configuration.To fix this, a check for allowed file extensions was added before downloading files to a tmp directory.Concrete CMS Security Team gave this a CVSS v3.1 score of 5.4 AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:H/A:NThis fix is also in Concrete version 9.0.0

    Published: 19 Nov 2021
    7.5
    High

    CVE-2021-22967

    Last Modified: 21 Nov 2024

    In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowed to Add Message to a Conversation.To remediate this, a check was added to verify a user has permissions to view files before attaching the files to a message in "add / edit message”.Concrete CMS security team gave this a CVSS v3.1 score of 4.3 AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NCredit for discovery Adrian H

    Published: 19 Nov 2021
    7.5
    High

    CVE-2021-22965

    Last Modified: 21 Nov 2024

    A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial of service when a malformed request is sent to the device.

    Published: 19 Nov 2021
    7.5
    High

    CVE-2021-22951

    Last Modified: 21 Nov 2024

    Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) prior to version 8.5.7. Concrete CMS now checks to see if a file has a password in view_inline and, if it does, the file is not rendered.For version 8.5.6, the following mitigations were put in place a. restricting file types for view_inline to images only b. putting a warning in the file manager to advise users.Credit for discovery: "Solar Security Research Team"Concrete CMS security team CVSS scoring is 5.3: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NThis fix is also in Concrete version 9.0.0

    Published: 19 Nov 2021
    8.8
    High

    CVE-2021-22966

    Last Modified: 21 Nov 2024

    Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below. If a group is granted "view" permissions on the bulkupdate page, then users in that group can escalate to being an administrator with a specially crafted curl. Fixed by adding a check for group permissions before allowing a group to be moved. Concrete CMS Security team CVSS scoring: 7.1 AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:HCredit for discovery: "Adrian Tiron from FORTBRIDGE ( https://www.fortbridge.co.uk/ )"This fix is also in Concrete version 9.0.0

    Published: 19 Nov 2021
    7.5
    High

    CVE-2021-22970

    Last Modified: 21 Nov 2024

    Concrete CMS (formerly concrete5) versions 8.5.6 and below and version 9.0.0 allow local IP importing causing the system to be vulnerable toa. SSRF attacks on the private LAN servers by reading files from the local LAN. An attacker can pivot in the private LAN and exploit local network appsandb. SSRF Mitigation Bypass through DNS RebindingConcrete CMS security team gave this a CVSS score of 3.5 AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:NConcrete CMS is maintaining Concrete version 8.5.x until 1 May 2022 for security fixes.This CVE is shared with HackerOne Reports https://hackerone.com/reports/1364797 and https://hackerone.com/reports/1360016Reporters: Adrian Tiron from FORTBRIDGE (https://www.fortbridge.co.uk/ ) and Bipul Jaiswal

    Published: 19 Nov 2021
    5.3
    Medium

    CVE-2021-22969

    Last Modified: 21 Nov 2024

    Concrete CMS (formerly concrete5) versions below 8.5.7 has a SSRF mitigation bypass using DNS Rebind attack giving an attacker the ability to fetch cloud IAAS (ex AWS) IAM keys.To fix this Concrete CMS no longer allows downloads from the local network and specifies the validated IP when downloading rather than relying on DNS.Discoverer: Adrian Tiron from FORTBRIDGE ( https://www.fortbridge.co.uk/ )The Concrete CMS team gave this a CVSS 3.1 score of 3.5 AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N . Please note that Cloud IAAS provider mis-configurations are not Concrete CMS vulnerabilities. A mitigation for this vulnerability is to make sure that the IMDS configurations are according to a cloud provider's best practices.This fix is also in Concrete version 9.0.0

    Published: 19 Nov 2021
    7.8
    High

    CVE-2021-42254

    Last Modified: 21 Nov 2024

    BeyondTrust Privilege Management prior to version 21.6 creates a Temporary File in a Directory with Insecure Permissions.

    Published: 19 Nov 2021
    7.5
    High

    CVE-2021-41569

    Last Modified: 21 Nov 2024

    SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the appstart.sas file, allows end-users of the application to access the sample.webcsf1.sas program, which contains user-controlled macro variables that are passed to the DS2CSF macro. Users can escape the context of the configured user-controllable variable and append additional functions native to the macro but not included as variables within the library. This includes a function that retrieves files from the host OS.

    Published: 19 Nov 2021
    7.5
    High

    CVE-2021-44037

    Last Modified: 21 Nov 2024

    Team Password Manager (aka TeamPasswordManager) before 10.135.236 allows password-reset poisoning.

    Published: 19 Nov 2021
    8.8
    High

    CVE-2021-44036

    Last Modified: 21 Nov 2024

    Team Password Manager (aka TeamPasswordManager) before 10.135.236 has a CSRF vulnerability during import.

    Published: 19 Nov 2021
    7.8
    High

    CVE-2021-29329

    Last Modified: 21 Nov 2024

    OpenSource Moddable v10.5.0 was discovered to contain a stack overflow in the fxBinaryExpressionNodeDistribute function at /moddable/xs/sources/xsTree.c.

    Published: 19 Nov 2021
    7.1
    High

    CVE-2021-29328

    Last Modified: 21 Nov 2024

    OpenSource Moddable v10.5.0 was discovered to contain buffer over-read in the fxDebugThrow function at /moddable/xs/sources/xsDebug.c.

    Published: 19 Nov 2021
    7.8
    High

    CVE-2021-29327

    Last Modified: 21 Nov 2024

    OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow in the fx_ArrayBuffer function at /moddable/xs/sources/xsDataView.c.

    Published: 19 Nov 2021
    7.8
    High

    CVE-2021-29326

    Last Modified: 21 Nov 2024

    OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow in the fxIDToString function at /moddable/xs/sources/xsSymbol.c.

    Published: 19 Nov 2021
    7.8
    High

    CVE-2021-29325

    Last Modified: 21 Nov 2024

    OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow in the fx_String_prototype_repeat function at /moddable/xs/sources/xsString.c.

    Published: 19 Nov 2021
    5.5
    Medium

    CVE-2021-29323

    Last Modified: 21 Nov 2024

    OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow via the component /modules/network/wifi/esp/modwifi.c.

    Published: 19 Nov 2021
    7.8
    High

    CVE-2021-29324

    Last Modified: 21 Nov 2024

    OpenSource Moddable v10.5.0 was discovered to contain a stack overflow via the component /moddable/xs/sources/xsScript.c.

    Published: 19 Nov 2021
    9.1
    Critical

    CVE-2021-22028

    Last Modified: 21 Nov 2024

    In versions of Greenplum database prior to 5.28.6 and 6.14.0, greenplum database contains a file path traversal vulnerability leading to information disclosure from the file system. A malicious user can read/write information from the file system using this vulnerability.

    Published: 19 Nov 2021
    6.5
    Medium

    CVE-2021-22030

    Last Modified: 21 Nov 2024

    In versions of Greenplum database prior to 5.28.14 and 6.17.0, certain statements execution led to the storage of sensitive(credential) information in the logs of the database. A malicious user with access to logs can read sensitive(credentials) information about users

    Published: 19 Nov 2021
    5.5
    Medium

    CVE-2021-36003

    Last Modified: 23 Apr 2025

    Adobe Audition version 14.2 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose arbitrary memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 19 Nov 2021
    8.8
    High

    CVE-2021-22053

    Last Modified: 21 Nov 2024

    Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within the request URI path during the resolution of view templates. When a request is made at `/hystrix/monitor;[user-provided data]`, the path elements following `hystrix/monitor` are being evaluated as SpringEL expressions, which can lead to code execution.

    Published: 19 Nov 2021
    5.4
    Medium

    CVE-2021-33850

    Last Modified: 21 Nov 2024

    There is a Cross-Site Scripting vulnerability in Microsoft Clarity version 0.3. The XSS payload executes whenever the user changes the clarity configuration in Microsoft Clarity version 0.3. The payload is stored on the configuring project Id page.

    Published: 19 Nov 2021
    6.5
    Medium

    CVE-2021-43408

    Last Modified: 21 Nov 2024

    The "Duplicate Post" WordPress plugin up to and including version 1.1.9 is vulnerable to SQL Injection. SQL injection vulnerabilities occur when client supplied data is included within an SQL Query insecurely. SQL Injection can typically be exploited to read, modify and delete SQL table data. In many cases it also possible to exploit features of SQL server to execute system commands and/or access the local file system. This particular vulnerability can be exploited by any authenticated user who has been granted access to use the Duplicate Post plugin. By default, this is limited to Administrators, however the plugin presents the option to permit access to the Editor, Author, Contributor and Subscriber roles.

    Published: 19 Nov 2021
    9.3
    Critical

    CVE-2021-43409

    Last Modified: 21 Nov 2024

    The “WPO365 | LOGIN” WordPress plugin (up to and including version 15.3) by wpo365.com is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability (also known as Stored or Second-Order XSS). Persistent XSS vulnerabilities occur when the application stores and retrieves client supplied data without proper handling of dangerous content. This type of XSS vulnerability is exploited by submitting malicious script content to the application which is then retrieved and executed by other application users. The attacker could exploit this to conduct a range of attacks against users of the affected application such as session hijacking, account take over and accessing sensitive data. In this case, the XSS payload can be submitted by any anonymous user, the payload then renders and executes when a WordPress administrator authenticates and accesses the WordPress Dashboard. The injected payload can carry out actions on behalf of the administrator including adding other administrative users and changing application settings. This flaw could be exploited to ultimately provide full control of the affected system to the attacker.

    Published: 19 Nov 2021
    6.1
    Medium

    CVE-2021-42363

    Last Modified: 14 Feb 2025

    The Preview E-Mails for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the search_order parameter found in the ~/views/form.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.6.8.

    Published: 19 Nov 2021
    8.8
    High

    CVE-2021-39353

    Last Modified: 14 Feb 2025

    The Easy Registration Forms WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the ajax_add_form function found in the ~/includes/class-form.php file which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 2.1.1.

    Published: 19 Nov 2021
    9.8
    Critical

    CVE-2021-37592

    Last Modified: 21 Nov 2024

    Suricata before 5.0.8 and 6.x before 6.0.4 allows TCP evasion via a client with a crafted TCP/IP stack that can send a certain sequence of segments.

    Published: 19 Nov 2021
    5.4
    Medium

    CVE-2021-3920

    Last Modified: 21 Nov 2024

    grav-plugin-admin is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 19 Nov 2021
    5.4
    Medium

    CVE-2021-3950

    Last Modified: 21 Nov 2024

    django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 19 Nov 2021
    5.3
    Medium

    CVE-2021-4040

    Last Modified: 15 Jun 2026

    A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) condition. This flaw allows an attacker to partially disrupt availability to the broker through a sustained attack of maliciously crafted messages. The highest threat from this vulnerability is system availability.

    Published: 19 Nov 2021
    4.3
    Medium

    CVE-2021-3957

    Last Modified: 21 Nov 2024

    kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)

    Published: 19 Nov 2021
    5.4
    Medium

    CVE-2021-3961

    Last Modified: 21 Nov 2024

    snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 19 Nov 2021
    4.3
    Medium

    CVE-2021-3963

    Last Modified: 21 Nov 2024

    kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)

    Published: 19 Nov 2021
    9.8
    Critical

    CVE-2021-41435

    Last Modified: 21 Nov 2024

    A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS ZenWiFi AX (XT8) before 3.0.0.4.386.45898, and RT-AX68U before 3.0.0.4.386.45911, allows a remote attacker to attempt any number of login attempts via sending a specific HTTP request.

    Published: 19 Nov 2021
    7.5
    High

    CVE-2021-41436

    Last Modified: 21 Nov 2024

    An HTTP request smuggling in web application in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS ZenWiFi AX (XT8) before 3.0.0.4.386.45898, and RT-AX68U before 3.0.0.4.386.45911, allows a remote unauthenticated attacker to DoS via sending a specially crafted HTTP packet.

    Published: 19 Nov 2021
    6.5
    Medium

    CVE-2021-3976

    Last Modified: 21 Nov 2024

    kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)

    Published: 19 Nov 2021
    5.3
    Medium

    CVE-2021-41532

    Last Modified: 21 Nov 2024

    In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any unauthenticated user can access the data from these endpoints.

    Published: 19 Nov 2021
    8.8
    High

    CVE-2021-39236

    Last Modified: 21 Nov 2024

    In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user.

    Published: 19 Nov 2021
    6.5
    Medium

    CVE-2021-39235

    Last Modified: 21 Nov 2024

    In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated users with valid READ block token can do any write operation on the same block.

    Published: 19 Nov 2021
    6.8
    Medium

    CVE-2021-39234

    Last Modified: 21 Nov 2024

    In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific request allowing access those blocks, bypassing other security checks like ACL.

    Published: 19 Nov 2021
    9.1
    Critical

    CVE-2021-39233

    Last Modified: 21 Nov 2024

    In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any client.

    Published: 19 Nov 2021
    8.8
    High

    CVE-2021-39232

    Last Modified: 21 Nov 2024

    In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticated users, not just by admins.

    Published: 19 Nov 2021
    9.1
    Critical

    CVE-2021-39231

    Last Modified: 21 Nov 2024

    In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an attacker to download raw data from Datanode and Ozone manager and modify Ratis replication configuration.

    Published: 19 Nov 2021
    9.8
    Critical

    CVE-2021-36372

    Last Modified: 21 Nov 2024

    In Apache Ozone versions prior to 1.2.0, Initially generated block tokens are persisted to the metadata database and can be retrieved with authenticated users with permission to the key. Authenticated users may use them even after access is revoked.

    Published: 19 Nov 2021
    9.8
    Critical

    CVE-2021-42338

    Last Modified: 21 Nov 2024

    4MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to bypass authentication by code injection in cookie, and arbitrarily manipulate the system or interrupt services by upload and execution of arbitrary files.

    Published: 19 Nov 2021
    6.8
    Medium

    CVE-2021-44033

    Last Modified: 21 Nov 2024

    In Ionic Identity Vault before 5.0.5, the protection mechanism for invalid unlock attempts can be bypassed.

    Published: 19 Nov 2021
    6.1
    Medium

    CVE-2021-44025

    Last Modified: 21 Nov 2024

    Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.

    Published: 19 Nov 2021
    9.8
    Critical

    CVE-2021-44026

    Last Modified: 4 Nov 2025

    Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

    Published: 19 Nov 2021