CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2021-3916

    Last Modified: 21 Nov 2024

    bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    Published: 5 Nov 2021
    6.1
    Medium

    CVE-2021-39412

    Last Modified: 21 Nov 2024

    Multiple Cross Site Scripting (XSS) vulnerabilities exists in PHPGurukul Shopping v3.1 via the (1) callback parameter in (a) server_side/scripts/id_jsonp.php, (b) server_side/scripts/jsonp.php, and (c) scripts/objects_jsonp.php, the (2) value parameter in examples_support/editable_ajax.php, and the (3) PHP_SELF parameter in captcha/index.php.

    Published: 5 Nov 2021
    6.1
    Medium

    CVE-2021-39411

    Last Modified: 21 Nov 2024

    Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the (1) searchdata parameter in (a) doctor/search.php and (b) admin/patient-search.php, and the (2) fromdate and (3) todate parameters in admin/betweendates-detailsreports.php.

    Published: 5 Nov 2021
    7.5
    High

    CVE-2021-42671

    Last Modified: 21 Nov 2024

    An incorrect access control vulnerability exists in Sourcecodester Engineers Online Portal in PHP in nia_munoz_monitoring_system/admin/uploads. An attacker can leverage this vulnerability in order to bypass access controls and access all the files uploaded to the web server without the need of authentication or authorization.

    Published: 5 Nov 2021
    9.8
    Critical

    CVE-2021-42670

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to the announcements_student.php web page. As a result a malicious user can extract sensitive data from the web server and in some cases use this vulnerability in order to get a remote code execution on the remote web server.

    Published: 5 Nov 2021
    9.8
    Critical

    CVE-2021-42669

    Last Modified: 21 Nov 2024

    A file upload vulnerability exists in Sourcecodester Engineers Online Portal in PHP via dashboard_teacher.php, which allows changing the avatar through teacher_avatar.php. Once an avatar gets uploaded it is getting uploaded to the /admin/uploads/ directory, and is accessible by all users. By uploading a php webshell containing "<?php system($_GET["cmd"]); ?>" the attacker can execute commands on the web server with - /admin/uploads/php-webshell?cmd=id.

    Published: 5 Nov 2021
    9.8
    Critical

    CVE-2021-42668

    Last Modified: 21 Nov 2024

    A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter in the my_classmates.php web page.. As a result, an attacker can extract sensitive data from the web server and in some cases can use this vulnerability in order to get a remote code execution on the remote web server.

    Published: 5 Nov 2021
    9.8
    Critical

    CVE-2021-42667

    Last Modified: 21 Nov 2024

    A SQL Injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP in event-management/views. An attacker can leverage this vulnerability in order to manipulate the sql query performed. As a result he can extract sensitive data from the web server and in some cases he can use this vulnerability in order to get a remote code execution on the remote web server.

    Published: 5 Nov 2021
    8.8
    High

    CVE-2021-42666

    Last Modified: 21 Nov 2024

    A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to quiz_question.php, which could let a malicious user extract sensitive data from the web server and in some cases use this vulnerability in order to get a remote code execution on the remote web server.

    Published: 5 Nov 2021
    9.8
    Critical

    CVE-2021-42665

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the login form inside of index.php, which can allow an attacker to bypass authentication.

    Published: 5 Nov 2021
    5.4
    Medium

    CVE-2021-42664

    Last Modified: 21 Nov 2024

    A Stored Cross Site Scripting (XSS) Vulneraibiilty exists in Sourcecodester Engineers Online Portal in PHP via the (1) Quiz title and (2) quiz description parameters to add_quiz.php. An attacker can leverage this vulnerability in order to run javascript commands on the web server surfers behalf, which can lead to cookie stealing and more.

    Published: 5 Nov 2021
    4.3
    Medium

    CVE-2021-42663

    Last Modified: 21 Nov 2024

    An HTML injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the msg parameter to /event-management/index.php. An attacker can leverage this vulnerability in order to change the visibility of the website. Once the target user clicks on a given link he will display the content of the HTML code of the attacker's choice.

    Published: 5 Nov 2021
    5.4
    Medium

    CVE-2021-42662

    Last Modified: 21 Nov 2024

    A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the Holiday reason parameter. An attacker can leverage this vulnerability in order to run javascript commands on the web server surfers behalf, which can lead to cookie stealing and more.

    Published: 5 Nov 2021
    5.4
    Medium

    CVE-2021-26844

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in Power Admin PA Server Monitor 8.2.1.1 allows remote attackers to inject arbitrary web script or HTML via Console.exe.

    Published: 5 Nov 2021
    9.8
    Critical

    CVE-2021-42237

    Last Modified: 10 Nov 2025

    Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.

    Published: 5 Nov 2021
    5.9
    Medium

    CVE-2021-25509

    Last Modified: 21 Nov 2024

    A missing input validation in Samsung Flow Windows application prior to Version 4.8.5.0 allows attackers to overwrite abtraty file in the Windows known folders.

    Published: 5 Nov 2021
    5.3
    Medium

    CVE-2021-25508

    Last Modified: 21 Nov 2024

    Improper privilege management vulnerability in API Key used in SmartThings prior to 1.7.73.22 allows an attacker to abuse the API key without limitation.

    Published: 5 Nov 2021
    5.7
    Medium

    CVE-2021-25507

    Last Modified: 21 Nov 2024

    Improper authorization vulnerability in Samsung Flow mobile application prior to 4.8.03.5 allows Samsung Flow PC application connected with user device to access part of notification data in Secure Folder without authorization.

    Published: 5 Nov 2021
    4
    Medium

    CVE-2021-25506

    Last Modified: 21 Nov 2024

    Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service.

    Published: 5 Nov 2021
    3.3
    Low

    CVE-2021-25505

    Last Modified: 21 Nov 2024

    Improper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication when lockscreen is unlocked.

    Published: 5 Nov 2021
    4
    Medium

    CVE-2021-25504

    Last Modified: 21 Nov 2024

    Intent redirection vulnerability in Group Sharing prior to 10.8.03.2 allows attacker to access contact information.

    Published: 5 Nov 2021
    5
    Medium

    CVE-2021-25503

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in HDCP prior to SMR Nov-2021 Release 1 allows attackers to arbitrary code execution.

    Published: 5 Nov 2021
    7.9
    High

    CVE-2021-25502

    Last Modified: 21 Nov 2024

    A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-2021 Release 1 allows attackers to read ESN value without priviledge.

    Published: 5 Nov 2021
    5.7
    Medium

    CVE-2021-25501

    Last Modified: 21 Nov 2024

    An improper access control vulnerability in SCloudBnRReceiver in SecTelephonyProvider prior to SMR Nov-2021 Release 1 allows untrusted application to call some protected providers.

    Published: 5 Nov 2021
    7.2
    High

    CVE-2021-25500

    Last Modified: 21 Nov 2024

    A missing input validation in HDCP LDFW prior to SMR Nov-2021 Release 1 allows attackers to overwrite TZASC allowing TEE compromise.

    Published: 5 Nov 2021
    9.8
    Critical

    CVE-2021-35368

    Last Modified: 21 Nov 2024

    OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a trailing pathname.

    Published: 5 Nov 2021
    3.7
    Low

    CVE-2021-39898

    Last Modified: 21 Nov 2024

    In all versions of GitLab CE/EE since version 10.6, a project export leaks the external webhook token value which may allow access to the project which it was exported from.

    Published: 4 Nov 2021
    4.3
    Medium

    CVE-2021-39905

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with

    Published: 4 Nov 2021
    1.7
    Low

    CVE-2021-39911

    Last Modified: 12 Jun 2026

    An improper access control flaw in all versions of GitLab CE/EE starting from 13.9 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 exposes private email address of Issue and Merge Requests assignee to Webhook data consumers

    Published: 4 Nov 2021
    5.3
    Medium

    CVE-2021-39907

    Last Modified: 21 Nov 2024

    A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 13.7. The stripping of EXIF data from certain images resulted in high CPU usage.

    Published: 4 Nov 2021
    4.3
    Medium

    CVE-2021-39904

    Last Modified: 12 Jun 2026

    An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a Merge Request creator to resolve discussions and apply suggestions after a project owner has locked the Merge Request

    Published: 4 Nov 2021
    6
    Medium

    CVE-2021-39895

    Last Modified: 21 Nov 2024

    In all versions of GitLab CE/EE since version 8.0, an attacker can set the pipeline schedules to be active in a project export so when an unsuspecting owner imports that project, pipelines are active by default on that project. Under specialized conditions, this may lead to information disclosure if the project is imported from an untrusted source.

    Published: 4 Nov 2021
    7.7
    High

    CVE-2021-22260

    Last Modified: 21 Nov 2024

    A stored Cross-Site Scripting vulnerability in the DataDog integration in all versions of GitLab CE/EE starting from 13.7 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf

    Published: 4 Nov 2021
    2.7
    Low

    CVE-2021-39901

    Last Modified: 21 Nov 2024

    In all versions of GitLab CE/EE since version 11.10, an admin of a group can see the SCIM token of that group by visiting a specific endpoint.

    Published: 4 Nov 2021
    4.4
    Medium

    CVE-2021-39913

    Last Modified: 12 Jun 2026

    Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker with local file system access to obtain system root-level privileges

    Published: 4 Nov 2021
    2.6
    Low

    CVE-2021-39897

    Last Modified: 21 Nov 2024

    Improper access control in GitLab CE/EE version 10.5 and above allowed subgroup members with inherited access to a project from a parent group to still have access even after the subgroup is transferred

    Published: 4 Nov 2021
    5.3
    Medium

    CVE-2021-39912

    Last Modified: 21 Nov 2024

    A potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images was possible to trigger memory exhaustion.

    Published: 4 Nov 2021
    8.7
    High

    CVE-2021-39906

    Last Modified: 21 Nov 2024

    Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf.

    Published: 4 Nov 2021
    5.3
    Medium

    CVE-2021-39909

    Last Modified: 21 Nov 2024

    Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances

    Published: 4 Nov 2021
    6.5
    Medium

    CVE-2021-39903

    Last Modified: 21 Nov 2024

    In all versions of GitLab CE/EE since version 13.0, a privileged user, through an API call, can change the visibility level of a group or a project to a restricted option even after the instance administrator sets that visibility option as restricted in settings.

    Published: 4 Nov 2021
    4.3
    Medium

    CVE-2021-39902

    Last Modified: 21 Nov 2024

    Incorrect Authorization in GitLab CE/EE 13.4 or above allows a user with guest membership in a project to modify the severity of an incident.

    Published: 4 Nov 2021
    3.1
    Low

    CVE-2021-39914

    Last Modified: 21 Nov 2024

    A regular expression denial of service issue in GitLab versions 8.13 to 14.2.5, 14.3.0 to 14.3.3 and 14.4.0 could cause excessive usage of resources when a specially crafted username was used when provisioning a new user

    Published: 4 Nov 2021
    —
    Unknown

    CVE-2021-3896

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-43389. Reason: This candidate is a reservation duplicate of CVE-2021-43389. Notes: All CVE users should reference CVE-2021-43389 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 4 Nov 2021
    7.8
    High

    CVE-2021-42057

    Last Modified: 21 Nov 2024

    Obsidian Dataview through 0.4.12-hotfix1 allows eval injection. The evalInContext function in executes user input, which allows an attacker to craft malicious Markdown files that will execute arbitrary code once opened. NOTE: 0.4.13 provides a mitigation for some use cases.

    Published: 4 Nov 2021
    7.1
    High

    CVE-2021-41248

    Last Modified: 21 Nov 2024

    GraphiQL is the reference implementation of this monorepo, GraphQL IDE, an official project under the GraphQL Foundation. All versions of graphiql older than [email protected] are vulnerable to compromised HTTP schema introspection responses or schema prop values with malicious GraphQL type names, exposing a dynamic XSS attack surface that can allow code injection on operation autocomplete. In order for the attack to take place, the user must load a vulnerable schema in graphiql. There are a number of ways that can occur. By default, the schema URL is not attacker-controllable in graphiql or in its suggested implementations or examples, leaving only very complex attack vectors. If a custom implementation of graphiql's fetcher allows the schema URL to be set dynamically, such as a URL query parameter like ?endpoint= in graphql-playground, or a database provided value, then this custom graphiql implementation is vulnerable to phishing attacks, and thus much more readily available, low or no privelege level xss attacks. The URLs could look like any generic looking graphql schema URL. It should be noted that desktop clients such as Altair, Insomnia, Postwoman, do not appear to be impacted by this. This vulnerability does not impact codemirror-graphql, monaco-graphql or other dependents, as it exists in onHasCompletion.ts in graphiql. It does impact all forks of graphiql, and every released version of graphiql.

    Published: 4 Nov 2021
    5.3
    Medium

    CVE-2021-43398

    Last Modified: 21 Nov 2024

    Crypto++ (aka Cryptopp) 8.6.0 and earlier contains a timing leakage in MakePublicKey(). There is a clear correlation between execution time and private key length, which may cause disclosure of the length information of the private key. This might allow attackers to conduct timing attacks. NOTE: this report is disputed by the vendor and multiple third parties. The execution-time differences are intentional. A user may make a choice of a longer key as a tradeoff between strength and performance. In making this choice, the amount of information leaked to an adversary is of infinitesimal value

    Published: 4 Nov 2021
    7.1
    High

    CVE-2021-41249

    Last Modified: 21 Nov 2024

    GraphQL Playground is a GraphQL IDE for development of graphQL focused applications. All versions of graphql-playground-react older than [email protected] are vulnerable to compromised HTTP schema introspection responses or schema prop values with malicious GraphQL type names, exposing a dynamic XSS attack surface that can allow code injection on operation autocomplete. In order for the attack to take place, the user must load a malicious schema in graphql-playground. There are several ways this can occur, including by specifying the URL to a malicious schema in the endpoint query parameter. If a user clicks on a link to a GraphQL Playground installation that specifies a malicious server, arbitrary JavaScript can run in the user's browser, which can be used to exfiltrate user credentials or other harmful goals. If you are using graphql-playground-react directly in your client app, upgrade to version 1.7.28 or later.

    Published: 4 Nov 2021
    6.5
    Medium

    CVE-2020-21139

    Last Modified: 21 Nov 2024

    EC Cloud E-Commerce System v1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add admin accounts via /admin.html?do=user&act=add.

    Published: 4 Nov 2021
    4.3
    Medium

    CVE-2021-43293

    Last Modified: 21 Nov 2024

    Sonatype Nexus Repository Manager 3.x before 3.36.0 allows a remote authenticated attacker to potentially perform network enumeration via Server Side Request Forgery (SSRF).

    Published: 4 Nov 2021
    7.2
    High

    CVE-2021-43281

    Last Modified: 21 Nov 2024

    MyBB before 1.8.29 allows Remote Code Injection by an admin with the "Can manage settings?" permission. The Admin CP's Settings management module does not validate setting types correctly on insertion and update, making it possible to add settings of supported type "php" with PHP code, executed on Change Settings pages.

    Published: 4 Nov 2021