CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-33800

    Last Modified: 21 Nov 2024

    In Druid 1.2.3, visiting the path with parameter in a certain function can lead to directory traversal.

    Published: 3 Nov 2021
    7.8
    High

    CVE-2020-6931

    Last Modified: 21 Nov 2024

    HP Print and Scan Doctor may potentially be vulnerable to local elevation of privilege.

    Published: 3 Nov 2021
    5.5
    Medium

    CVE-2021-38488

    Last Modified: 21 Nov 2024

    Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter comment of the API events, which may allow an attacker to remotely execute code.

    Published: 3 Nov 2021
    7.8
    High

    CVE-2021-38416

    Last Modified: 21 Nov 2024

    Delta Electronics DIALink versions 1.2.4.0 and prior insecurely loads libraries, which may allow an attacker to use DLL hijacking and takeover the system where the software is installed.

    Published: 3 Nov 2021
    5.5
    Medium

    CVE-2021-38428

    Last Modified: 21 Nov 2024

    Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API schedule, which may allow an attacker to remotely execute code.

    Published: 3 Nov 2021
    7.8
    High

    CVE-2021-38420

    Last Modified: 21 Nov 2024

    Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged user accounts, which may allow an attacker to modify the installation directory and upload malicious files.

    Published: 3 Nov 2021
    5.5
    Medium

    CVE-2021-38407

    Last Modified: 21 Nov 2024

    Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API devices, which may allow an attacker to remotely execute code.

    Published: 3 Nov 2021
    5.9
    Medium

    CVE-2021-38424

    Last Modified: 21 Nov 2024

    The tag interface of Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to an attacker injecting formulas into the tag data. Those formulas may then be executed when it is opened with a spreadsheet application.

    Published: 3 Nov 2021
    5.5
    Medium

    CVE-2021-38403

    Last Modified: 21 Nov 2024

    Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter supplier of the API maintenance, which may allow an attacker to remotely execute code.

    Published: 3 Nov 2021
    7.8
    High

    CVE-2021-38422

    Last Modified: 21 Nov 2024

    Delta Electronics DIALink versions 1.2.4.0 and prior stores sensitive information in cleartext, which may allow an attacker to have extensive access to the application directory and escalate privileges.

    Published: 3 Nov 2021
    8.8
    High

    CVE-2021-38418

    Last Modified: 21 Nov 2024

    Delta Electronics DIALink versions 1.2.4.0 and prior runs by default on HTTP, which may allow an attacker to be positioned between the traffic and perform a machine-in-the-middle attack to access information without authorization.

    Published: 3 Nov 2021
    5.5
    Medium

    CVE-2021-38411

    Last Modified: 21 Nov 2024

    Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter deviceName of the API modbusWriter-Reader, which may allow an attacker to remotely execute code.

    Published: 3 Nov 2021
    7.8
    High

    CVE-2020-28416

    Last Modified: 21 Nov 2024

    HP has identified a security vulnerability with the I.R.I.S. OCR (Optical Character Recognition) software available with HP PageWide and OfficeJet printer software installations that could potentially allow unauthorized local code execution.

    Published: 3 Nov 2021
    6.1
    Medium

    CVE-2021-43141

    Last Modified: 24 Feb 2025

    Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Simple Subscription Website 1.0 via the id parameter in plan_application.

    Published: 3 Nov 2021
    9.8
    Critical

    CVE-2021-43140

    Last Modified: 24 Feb 2025

    SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login.

    Published: 3 Nov 2021
    7.5
    High

    CVE-2020-18263

    Last Modified: 21 Nov 2024

    PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability in the component search.php via the search parameter. This vulnerability allows attackers to access sensitive database information.

    Published: 3 Nov 2021
    9.8
    Critical

    CVE-2020-18262

    Last Modified: 21 Nov 2024

    ED01-CMS v1.0 was discovered to contain a SQL injection in the component cposts.php via the cid parameter.

    Published: 3 Nov 2021
    9.8
    Critical

    CVE-2020-18261

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in the image upload function of ED01-CMS v1.0 allows attackers to execute arbitrary commands.

    Published: 3 Nov 2021
    6.1
    Medium

    CVE-2020-18259

    Last Modified: 21 Nov 2024

    ED01-CMS v1.0 was discovered to contain a reflective cross-site scripting (XSS) vulnerability in the component sposts.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the Post title or Post content fields.

    Published: 3 Nov 2021
    8.7
    High

    CVE-2021-41134

    Last Modified: 21 Nov 2024

    nbdime provides tools for diffing and merging of Jupyter Notebooks. In affected versions a stored cross-site scripting (XSS) issue exists within the Jupyter-owned nbdime project. It appears that when reading the file name and path from disk, the extension does not sanitize the string it constructs before returning it to be displayed. The diffNotebookCheckpoint function within nbdime causes this issue. When attempting to display the name of the local notebook (diffNotebookCheckpoint), nbdime appears to simply append .ipynb to the name of the input file. The NbdimeWidget is then created, and the base string is passed through to the request API function. From there, the frontend simply renders the HTML tag and anything along with it. Users are advised to patch to the most recent version of the affected product.

    Published: 3 Nov 2021
    3.1
    Low

    CVE-2021-23472

    Last Modified: 21 Nov 2024

    This affects versions before 1.19.1 of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a string) even if the escape attribute is set.

    Published: 3 Nov 2021
    5.4
    Medium

    CVE-2021-23784

    Last Modified: 21 Nov 2024

    This affects the package tempura before 0.4.0. If the input to the esc function is of type object (i.e an array) it is returned without being escaped/sanitized, leading to a potential Cross-Site Scripting vulnerability.

    Published: 3 Nov 2021
    5.6
    Medium

    CVE-2021-23509

    Last Modified: 21 Nov 2024

    This affects the package json-ptr before 3.0.0. A type confusion vulnerability can lead to a bypass of CVE-2020-7766 when the user-provided keys used in the pointer parameter are arrays.

    Published: 3 Nov 2021
    5.6
    Medium

    CVE-2021-23624

    Last Modified: 21 Nov 2024

    This affects the package dotty before 0.1.2. A type confusion vulnerability can lead to a bypass of CVE-2021-25912 when the user-provided keys used in the path parameter are arrays.

    Published: 3 Nov 2021
    7.8
    High

    CVE-2020-23680

    Last Modified: 21 Nov 2024

    An issue was discovered in function StartPage in text2pdf.c in pdfcorner text2pdf 1.1, allows attackers to cause denial of service or possibly other undisclosed impacts.

    Published: 3 Nov 2021
    9.8
    Critical

    CVE-2020-23679

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in Renleilei1992 Linux_Network_Project 1.0, allows attackers to execute arbitrary code, via the password field.

    Published: 3 Nov 2021
    5.5
    Medium

    CVE-2021-40985

    Last Modified: 21 Nov 2024

    A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BMP image to image_load_bmp.

    Published: 3 Nov 2021
    9.8
    Critical

    CVE-2020-24000

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the tid parameter to index.php.

    Published: 3 Nov 2021
    6.5
    Medium

    CVE-2021-27836

    Last Modified: 21 Nov 2024

    An issue was discoverered in in function xls_getWorkSheet in xls.c in libxls 1.6.2, allows attackers to cause a denial of service, via a crafted XLS file.

    Published: 3 Nov 2021
    9.8
    Critical

    CVE-2020-24743

    Last Modified: 21 Nov 2024

    An issue was found in /showReports.do Zoho ManageEngine Applications Manager up to 14550, allows attackers to gain escalated privileges via the resourceid parameter.

    Published: 3 Nov 2021
    9.6
    Critical

    CVE-2020-20982

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in shadoweb wdja v1.5.1, allows attackers to execute arbitrary code and gain escalated privileges, via the backurl parameter to /php/passport/index.php.

    Published: 3 Nov 2021
    8.8
    High

    CVE-2021-26786

    Last Modified: 21 Nov 2024

    An issue was discoverered in in customercentric-selling-poland PlayTube, allows authenticated attackers to execute arbitrary code via the purchace code to the config.php.

    Published: 3 Nov 2021
    8.1
    High

    CVE-2020-23109

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in function convert_colorspace in heif_colorconversion.cc in libheif v1.6.2, allows attackers to cause a denial of service and disclose sensitive information, via a crafted HEIF file.

    Published: 3 Nov 2021
    6.1
    Medium

    CVE-2020-23126

    Last Modified: 21 Nov 2024

    Chamilo LMS version 1.11.10 contains an XSS vulnerability in the personal profile edition form, affecting the user him/herself and social network friends.

    Published: 3 Nov 2021
    9.8
    Critical

    CVE-2021-43082

    Last Modified: 21 Nov 2024

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-over-http plugin of Apache Traffic Server allows an attacker to overwrite memory. This issue affects Apache Traffic Server 9.1.0.

    Published: 3 Nov 2021
    7.5
    High

    CVE-2021-41585

    Last Modified: 21 Nov 2024

    Improper Input Validation vulnerability in accepting socket connections in Apache Traffic Server allows an attacker to make the server stop accepting new connections. This issue affects Apache Traffic Server 5.0.0 to 9.1.0.

    Published: 3 Nov 2021
    8.1
    High

    CVE-2021-38161

    Last Modified: 21 Nov 2024

    Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Apache Traffic Server 8.0.0 to 8.0.8.

    Published: 3 Nov 2021
    7.5
    High

    CVE-2021-37149

    Last Modified: 21 Nov 2024

    Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.

    Published: 3 Nov 2021
    7.5
    High

    CVE-2021-37148

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.0.1.

    Published: 3 Nov 2021
    7.5
    High

    CVE-2021-37147

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.

    Published: 3 Nov 2021
    9.8
    Critical

    CVE-2021-43130

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability exists in Sourcecodester Customer Relationship Management System (CRM) 1.0 via the username parameter in customer/login.php.

    Published: 3 Nov 2021
    6.1
    Medium

    CVE-2021-43324

    Last Modified: 21 Nov 2024

    LibreNMS through 21.10.2 allows XSS via a widget title.

    Published: 3 Nov 2021
    5.5
    Medium

    CVE-2021-3736

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel. A memory leak problem was found in mbochs_ioctl in samples/vfio-mdev/mbochs.c in Virtual Function I/O (VFIO) Mediated devices. This flaw could allow a local attacker to leak internal kernel information.

    Published: 3 Nov 2021
    6.7
    Medium

    CVE-2021-36697

    Last Modified: 21 Nov 2024

    With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file contains a Rewrite Rule with a type definition. A normal PHP file can be uploaded with this new "file type" and the code can be executed with an HTTP request.

    Published: 3 Nov 2021
    5.4
    Medium

    CVE-2021-36698

    Last Modified: 21 Nov 2024

    Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.

    Published: 3 Nov 2021
    5.2
    Medium

    CVE-2021-36192

    Last Modified: 21 Nov 2024

    An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in FortiManager 7.0.1 and below, 6.4.6 and below, 6.2.x, 6.0.x, 5.6.0 may allow a FortiGate user to see scripts from other ADOMS.

    Published: 3 Nov 2021
    9.8
    Critical

    CVE-2021-40849

    Last Modified: 21 Nov 2024

    In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited and logged into, resulting in information disclosure (at a minimum) and often escalation of privileges.

    Published: 3 Nov 2021
    7.8
    High

    CVE-2021-40848

    Last Modified: 21 Nov 2024

    In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV files could contain characters that a spreadsheet program could interpret as a command, leading to execution of a malicious string locally on a device, aka CSV injection.

    Published: 3 Nov 2021
    5.3
    Medium

    CVE-2021-33209

    Last Modified: 21 Nov 2024

    An issue was discovered in Fimer Aurora Vision before 2.97.10. The response to a failed login attempt discloses whether the username or password is wrong, helping an attacker to enumerate usernames. This can make a brute-force attack easier.

    Published: 3 Nov 2021
    4.3
    Medium

    CVE-2021-33210

    Last Modified: 21 Nov 2024

    An issue was discovered in Fimer Aurora Vision before 2.97.10. An attacker can (in the WebUI) obtain plant information without authentication by reading the response of APIs from a kiosk view of a plant.

    Published: 3 Nov 2021