CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2020-25881

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in the filename parameter in pathindex.php?r=cms-backend/attachment/delete&sub=&filename=../../../../111.txt&filetype=image/jpeg of the master version of RKCMS. This vulnerability allows for an attacker to perform a directory traversal via a crafted .txt file.

    Published: 29 Oct 2021
    5.5
    Medium

    CVE-2021-1123

    Last Modified: 21 Nov 2024

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can deadlock, which may lead to denial of service.

    Published: 29 Oct 2021
    5.5
    Medium

    CVE-2021-1122

    Last Modified: 21 Nov 2024

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can dereference a NULL pointer, which may lead to denial of service.

    Published: 29 Oct 2021
    5.5
    Medium

    CVE-2021-1121

    Last Modified: 21 Nov 2024

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager kernel driver, where a vGPU can cause resource starvation among other vGPUs hosted on the same GPU, which may lead to denial of service.

    Published: 29 Oct 2021
    7
    High

    CVE-2021-1120

    Last Modified: 21 Nov 2024

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a string provided by the guest OS may not be properly null terminated. The guest OS or attacker has no ability to push content to the plugin through this vulnerability, which may lead to information disclosure, data tampering, unauthorized code execution, and denial of service.

    Published: 29 Oct 2021
    7.1
    High

    CVE-2021-1119

    Last Modified: 21 Nov 2024

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can double-free a pointer, which may lead to denial of service. This flaw may result in a write-what-where condition, allowing an attacker to execute arbitrary code impacting integrity and availability.

    Published: 29 Oct 2021
    7.8
    High

    CVE-2021-1118

    Last Modified: 21 Nov 2024

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where there is the potential to execute privileged operations by the guest OS, which may lead to information disclosure, data tampering, escalation of privileges, and denial of service

    Published: 29 Oct 2021
    6.5
    Medium

    CVE-2020-25873

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability in the component system/manager/class/web/database.php was discovered in Baijiacms V4 which allows attackers to arbitrarily delete folders on the server via the "id" parameter.

    Published: 29 Oct 2021
    4.9
    Medium

    CVE-2020-25872

    Last Modified: 21 Nov 2024

    A vulnerability exists within the FileManagerController.php function in FrogCMS 0.9.5 which allows an attacker to perform a directory traversal attack via a GET request urlencode parameter.

    Published: 29 Oct 2021
    7.2
    High

    CVE-2021-41189

    Last Modified: 21 Nov 2024

    DSpace is an open source turnkey repository application. In version 7.0, any community or collection administrator can escalate their permission up to become system administrator. This vulnerability only exists in 7.0 and does not impact 6.x or below. This issue is patched in version 7.1. As a workaround, users of 7.0 may temporarily disable the ability for community or collection administrators to manage permissions or workflows settings.

    Published: 29 Oct 2021
    7.5
    High

    CVE-2021-41746

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability exists in all versions of Yonyou TurboCRM.via the orgcode parameter in changepswd.php. Attackers can use the vulnerabilities to obtain sensitive database information.

    Published: 29 Oct 2021
    —
    Unknown

    CVE-2021-41748

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-41874. Reason: This candidate is a duplicate of CVE-2021-41874. Notes: All CVE users should reference CVE-2021-41874 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 29 Oct 2021
    9.8
    Critical

    CVE-2021-41646

    Last Modified: 14 Apr 2026

    Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypasses the image upload filters..

    Published: 29 Oct 2021
    8.8
    High

    CVE-2021-41645

    Last Modified: 21 Nov 2024

    Remote Code Execution (RCE) vulnerability exists in Sourcecodester Budget and Expense Tracker System 1.0 that allows a remote malicious user to inject arbitrary code via the image upload field. .

    Published: 29 Oct 2021
    9.8
    Critical

    CVE-2021-41644

    Last Modified: 30 Mar 2026

    Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that bypasses the image upload filters.

    Published: 29 Oct 2021
    9.8
    Critical

    CVE-2021-41643

    Last Modified: 21 Nov 2024

    Remote Code Execution (RCE) vulnerability exists in Sourcecodester Church Management System 1.0 via the image upload field.

    Published: 29 Oct 2021
    9.8
    Critical

    CVE-2021-3756

    Last Modified: 21 Nov 2024

    libmysofa is vulnerable to Heap-based Buffer Overflow

    Published: 29 Oct 2021
    9.8
    Critical

    CVE-2021-41676

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerabilty exists in the oretnom23 Pharmacy Point of Sale System 1.0 in the login function in actions.php.

    Published: 29 Oct 2021
    7.2
    High

    CVE-2021-41675

    Last Modified: 21 Nov 2024

    A Remote Code Execution (RCE) vulnerabilty exists in Sourcecodester E-Negosyo System 1.0 in /admin/produts/controller.php via the doInsert function, which validates images with getImageSizei. .

    Published: 29 Oct 2021
    9.8
    Critical

    CVE-2021-41674

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability exists in Sourcecodester E-Negosyo System 1.0 via the user_email parameter in /admin/login.php.

    Published: 29 Oct 2021
    5
    Medium

    CVE-2021-35237

    Last Modified: 21 Nov 2024

    A missing HTTP header (X-Frame-Options) in Kiwi Syslog Server has left customers vulnerable to click jacking. Clickjacking is an attack that occurs when an attacker uses a transparent iframe in a window to trick a user into clicking on an actionable item, such as a button or link, to another server in which they have an identical webpage. The attacker essentially hijacks the user activity intended for the original server and sends them to the other server. This is an attack on both the user and the server.

    Published: 29 Oct 2021
    8.8
    High

    CVE-2021-39179

    Last Modified: 21 Nov 2024

    DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL Injection vulnerability in the Tracker component in DHIS2 Server allows authenticated remote attackers to execute arbitrary SQL commands via unspecified vectors. This vulnerability affects the `/api/trackedEntityInstances` and `/api/trackedEntityInstances/query` API endpoints in all DHIS2 versions 2.34, 2.35, and 2.36. It also affects versions 2.32 and 2.33 which have reached _end of support_ - exceptional security updates have been added to the latest *end of support* builds for these versions. Versions 2.31 and older are unaffected. The system is vulnerable to attack only from users that are logged in to DHIS2, and there is no known way of exploiting the vulnerability without first being logged in as a DHIS2 user. The vulnerability is not exposed to a non-malicious user - the vulnerability requires a conscious attack to be exploited. A successful exploit of this vulnerability could allow the malicious user to read, edit and delete data in the DHIS2 instance. There are no known exploits of the security vulnerabilities addressed by these patch releases. Security patches are available in DHIS2 versions 2.32-EOS, 2.33-EOS, 2.34.7, 2.35.7, and 2.36.4. There is no straightforward known workaround for DHIS2 instances using the Tracker functionality other than upgrading the affected DHIS2 server to one of the patches in which this vulnerability has been fixed. For implementations which do NOT use Tracker functionality, it may be possible to block all network access to POST to the `/api/trackedEntityInstances`, and `/api/trackedEntityInstances/query` endpoints as a temporary workaround while waiting to upgrade.

    Published: 29 Oct 2021
    4.8
    Medium

    CVE-2021-3441

    Last Modified: 21 Nov 2024

    A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross-Site Scripting (XSS).

    Published: 29 Oct 2021
    5.4
    Medium

    CVE-2021-3662

    Last Modified: 21 Nov 2024

    Certain HP Enterprise LaserJet and PageWide MFPs may be vulnerable to stored cross site scripting (XSS).

    Published: 29 Oct 2021
    7.8
    High

    CVE-2021-22037

    Last Modified: 21 Nov 2024

    Under certain circumstances, when manipulating the Windows registry, InstallBuilder uses the reg.exe system command. The full path to the command is not enforced, which results in a search in the search path until a binary can be identified. This makes the installer/uninstaller vulnerable to Path Interception by Search Order Hijacking, potentially allowing an attacker to plant a malicious reg.exe command so it takes precedence over the system command. The vulnerability only affects Windows installers.

    Published: 29 Oct 2021
    8.8
    High

    CVE-2021-22038

    Last Modified: 21 Nov 2024

    On Windows, the uninstaller binary copies itself to a fixed temporary location, which is then executed (the originally called uninstaller exits, so it does not block the installation directory). This temporary location is not randomized and does not restrict access to Administrators only so a potential attacker could plant a binary to replace the copied binary right before it gets called, thus gaining Administrator privileges (if the original uninstaller was executed as Administrator). The vulnerability only affects Windows installers.

    Published: 29 Oct 2021
    6.1
    Medium

    CVE-2021-31862

    Last Modified: 21 Nov 2024

    SysAid 20.4.74 allows XSS via the KeepAlive.jsp stamp parameter without any authentication.

    Published: 29 Oct 2021
    8.8
    High

    CVE-2021-31627

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in Tenda AC9 V1.0 through V15.03.05.19(6318), and AC9 V3.0 V15.03.06.42_multi, allows attackers to execute arbitrary code via the index parameter.

    Published: 29 Oct 2021
    8.8
    High

    CVE-2021-31624

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in Tenda AC9 V1.0 through V15.03.05.19(6318), and AC9 V3.0 V15.03.06.42_multi, allows attackers to execute arbitrary code via the urls parameter.

    Published: 29 Oct 2021
    9.8
    Critical

    CVE-2020-22079

    Last Modified: 21 Nov 2024

    Stack-based buffer overflow in Tenda AC-10U AC1200 Router US_AC10UV1.0RTL_V15.03.06.48_multi_TDE01 allows remote attackers to execute arbitrary code via the timeZone parameter to goform/SetSysTimeCfg.

    Published: 29 Oct 2021
    7.8
    High

    CVE-2021-3928

    Last Modified: 21 Nov 2024

    vim is vulnerable to Use of Uninitialized Variable

    Published: 29 Oct 2021
    —
    Unknown

    CVE-2021-41874

    Last Modified: 27 Aug 2025

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 29 Oct 2021
    5.9
    Medium

    CVE-2021-41186

    Last Modified: 21 Nov 2024

    Fluentd collects events from various data sources and writes them to files to help unify logging infrastructure. The parser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain pattern of string can spend too much time in a regular expression, resulting in the potential for a DoS attack. This issue is patched in version 1.14.2 There are two workarounds available. Either don't use parser_apache2 for parsing logs (which cannot guarantee generated by Apache), or put patched version of parser_apache2.rb into /etc/fluent/plugin directory (or any other directories specified by the environment variable `FLUENT_PLUGIN` or `--plugin` option of fluentd).

    Published: 29 Oct 2021
    7.8
    High

    CVE-2020-23549

    Last Modified: 21 Nov 2024

    IrfanView 4.54 allows attackers to cause a denial of service or possibly other unspecified impacts via a crafted .cr2 file, related to a "Data from Faulting Address controls Branch Selection starting at FORMATS!GetPlugInInfo+0x00000000000047f6".

    Published: 28 Oct 2021
    7.8
    High

    CVE-2020-23546

    Last Modified: 21 Nov 2024

    IrfanView 4.54 allows attackers to cause a denial of service or possibly other unspecified impacts via a crafted XBM file, related to a "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at FORMATS!ReadMosaic+0x0000000000000981.

    Published: 28 Oct 2021
    —
    Unknown

    CVE-2021-43078

    Last Modified: 17 Mar 2025

    Not used

    Published: 28 Oct 2021
    —
    Unknown

    CVE-2021-43079

    Last Modified: 17 Mar 2025

    Not used

    Published: 28 Oct 2021
    —
    Unknown

    CVE-2021-43069

    Last Modified: 6 May 2025

    Not used

    Published: 28 Oct 2021
    9.1
    Critical

    CVE-2021-41194

    Last Modified: 21 Nov 2024

    FirstUseAuthenticator is a JupyterHub authenticator that helps new users set their password on their first login to JupyterHub. When JupyterHub is used with FirstUseAuthenticator, a vulnerability in versions prior to 1.0.0 allows unauthorized access to any user's account if `create_users=True` and the username is known or guessed. One may upgrade to version 1.0.0 or apply a patch manually to mitigate the vulnerability. For those who cannot upgrade, there is no complete workaround, but a partial mitigation exists. One can disable user creation with `c.FirstUseAuthenticator.create_users = False`, which will only allow login with fully normalized usernames for already existing users prior to jupyterhub-firstuserauthenticator 1.0.0. If any users have never logged in with their normalized username (i.e. lowercase), they will still be vulnerable until a patch or upgrade occurs.

    Published: 28 Oct 2021
    5.4
    Medium

    CVE-2021-36551

    Last Modified: 21 Nov 2024

    TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-calendar.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload under the Add Event module.

    Published: 28 Oct 2021
    5.4
    Medium

    CVE-2021-36550

    Last Modified: 21 Nov 2024

    TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-browse_categories.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload under the Create category module.

    Published: 28 Oct 2021
    9.8
    Critical

    CVE-2021-36547

    Last Modified: 21 Nov 2024

    A remote code execution (RCE) vulnerability in the component /codebase/dir.php?type=filenew of Mara v7.5 allows attackers to execute arbitrary commands via a crafted PHP file.

    Published: 28 Oct 2021
    9.8
    Critical

    CVE-2021-36548

    Last Modified: 21 Nov 2024

    A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4 allows attackers to execute arbitrary commands via a crafted PHP file.

    Published: 28 Oct 2021
    5.4
    Medium

    CVE-2020-25422

    Last Modified: 21 Nov 2024

    A cross site scripting (XSS) vulnerability in menuedit.php of Mara CMS 7.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Published: 28 Oct 2021
    7.8
    High

    CVE-2021-30834

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, iOS 15 and iPadOS 15, watchOS 8, Security Update 2021-007 Catalina. Processing a malicious audio file may result in unexpected application termination or arbitrary code execution.

    Published: 28 Oct 2021
    5.5
    Medium

    CVE-2021-30836

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted audio file may disclose restricted memory.

    Published: 28 Oct 2021
    5.5
    Medium

    CVE-2021-30833

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.0.1. Unpacking a maliciously crafted archive may allow an attacker to write arbitrary files.

    Published: 28 Oct 2021
    7.8
    High

    CVE-2021-30840

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted dfont file may lead to arbitrary code execution.

    Published: 28 Oct 2021
    7.8
    High

    CVE-2021-30821

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. A malicious application may be able to execute arbitrary code with kernel privileges.

    Published: 28 Oct 2021
    7.8
    High

    CVE-2021-30824

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. A malicious application may be able to execute arbitrary code with kernel privileges.

    Published: 28 Oct 2021