CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2021-34764

    Last Modified: 11 Aug 2026

    Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 27 Oct 2021
    4.8
    Medium

    CVE-2021-34763

    Last Modified: 11 Aug 2026

    Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 27 Oct 2021
    8.1
    High

    CVE-2021-34762

    Last Modified: 11 Aug 2026

    A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to perform a directory traversal attack on an affected device. The attacker would require valid device credentials. The vulnerability is due to insufficient input validation of the HTTPS URL by the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTPS request that contains directory traversal character sequences to an affected device. A successful exploit could allow the attacker to read or write arbitrary files on the device.

    Published: 27 Oct 2021
    4.4
    Medium

    CVE-2021-34761

    Last Modified: 11 Aug 2026

    A vulnerability in Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite or append arbitrary data to system files using root-level privileges. The attacker must have administrative credentials on the device. This vulnerability is due to incomplete validation of user input for a specific CLI command. An attacker could exploit this vulnerability by authenticating to the device with administrative privileges and issuing a CLI command with crafted user parameters. A successful exploit could allow the attacker to overwrite or append arbitrary data to system files using root-level privileges.

    Published: 27 Oct 2021
    6.7
    Medium

    CVE-2021-34756

    Last Modified: 11 Aug 2026

    Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 27 Oct 2021
    6.7
    Medium

    CVE-2021-34755

    Last Modified: 11 Aug 2026

    Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 27 Oct 2021
    5.8
    Medium

    CVE-2021-34754

    Last Modified: 11 Aug 2026

    Multiple vulnerabilities in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured rules for ENIP traffic. These vulnerabilities are due to incomplete processing during deep packet inspection for ENIP packets. An attacker could exploit these vulnerabilities by sending a crafted ENIP packet to the targeted interface. A successful exploit could allow the attacker to bypass configured access control and intrusion policies that should be activated for the ENIP packet.

    Published: 27 Oct 2021
    5.3
    Medium

    CVE-2021-40125

    Last Modified: 11 Aug 2026

    A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device. This vulnerability is due to improper control of a resource. An attacker with the ability to spoof a trusted IKEv2 site-to-site VPN peer and in possession of valid IKEv2 credentials for that peer could exploit this vulnerability by sending malformed, authenticated IKEv2 messages to an affected device. A successful exploit could allow the attacker to trigger a reload of the device.

    Published: 27 Oct 2021
    6.5
    Medium

    CVE-2021-3900

    Last Modified: 21 Nov 2024

    firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

    Published: 27 Oct 2021
    5.9
    Medium

    CVE-2021-37808

    Last Modified: 21 Nov 2024

    SQL Injection vulnerabilities exist in https://phpgurukul.com News Portal Project 3.1 via the (1) category, (2) subcategory, (3) sucatdescription, and (4) username parameters, the server response is about (N) seconds delay respectively which mean it is vulnerable to MySQL Blind (Time Based). An attacker can use sqlmap to further the exploitation for extracting sensitive information from the database.

    Published: 27 Oct 2021
    7.5
    High

    CVE-2021-37807

    Last Modified: 21 Nov 2024

    An SQL Injection vulneraility exists in https://phpgurukul.com Online Shopping Portal 3.1 via the email parameter on the /check_availability.php endpoint that serves as a checker whether a new user's email is already exist within the database.

    Published: 27 Oct 2021
    5.5
    Medium

    CVE-2021-29868

    Last Modified: 21 Nov 2024

    IBM i2 iBase 8.9.13 and 9.0.0 could allow a local attacker to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 206213.

    Published: 27 Oct 2021
    5.9
    Medium

    CVE-2021-37806

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability exists in https://phpgurukul.com Vehicle Parking Management System affected version 1.0. The system is vulnerable to time-based SQL injection on multiple endpoints. Based on the SLEEP(N) function payload that will sleep for a number of seconds used on the (1) editid , (2) viewid, and (3) catename parameters, the server response is about (N) seconds delay respectively which mean it is vulnerable to MySQL Blind (Time Based). An attacker can use sqlmap to further the exploitation for extracting sensitive information from the database.

    Published: 27 Oct 2021
    8.8
    High

    CVE-2021-29844

    Last Modified: 21 Nov 2024

    IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

    Published: 27 Oct 2021
    6.5
    Medium

    CVE-2021-29786

    Last Modified: 21 Nov 2024

    IBM Jazz Team Server products stores user credentials in clear text which can be read by an authenticated user. IBM X-Force ID: 203172.

    Published: 27 Oct 2021
    7.5
    High

    CVE-2021-29774

    Last Modified: 21 Nov 2024

    IBM Jazz Team Server products could allow an authenticated user to obtain elevated privileges under certain configurations. IBM X-Force ID: 203025.

    Published: 27 Oct 2021
    5.4
    Medium

    CVE-2021-29713

    Last Modified: 21 Nov 2024

    IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 27 Oct 2021
    5.4
    Medium

    CVE-2021-29673

    Last Modified: 21 Nov 2024

    IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199482.

    Published: 27 Oct 2021
    5.3
    Medium

    CVE-2021-20526

    Last Modified: 21 Nov 2024

    IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 198755.

    Published: 27 Oct 2021
    5.4
    Medium

    CVE-2021-37805

    Last Modified: 21 Nov 2024

    A Stored Cross Site Scripting (XSS) vunerability exists in Sourcecodeste Vehicle Parking Management System affected version 1.0 is via the add-vehicle.php endpoint.

    Published: 27 Oct 2021
    8.1
    High

    CVE-2021-37803

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability exists in Sourcecodester Online Covid Vaccination Scheduler System 1.0 via the username in lognin.php .

    Published: 27 Oct 2021
    6.5
    Medium

    CVE-2021-36756

    Last Modified: 21 Nov 2024

    CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation.

    Published: 27 Oct 2021
    5.5
    Medium

    CVE-2021-38379

    Last Modified: 21 Nov 2024

    The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure.

    Published: 27 Oct 2021
    8.8
    High

    CVE-2021-37221

    Last Modified: 21 Nov 2024

    A file upload vulnerability exists in Sourcecodester Customer Relationship Management System 1.0 via the account update option & customer create option, which could let a remote malicious user upload an arbitrary php file. .

    Published: 27 Oct 2021
    7.5
    High

    CVE-2021-22101

    Last Modified: 21 Nov 2024

    Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerability allowing unauthenticated attackers to cause denial of service by using REST HTTP requests with label_selectors on multiple V3 endpoints by generating an enormous SQL query.

    Published: 27 Oct 2021
    9.8
    Critical

    CVE-2020-24932

    Last Modified: 6 Mar 2026

    An SQL Injection vulnerability exists in Sourcecodester Complaint Management System 1.0 via the cid parameter in complaint-details.php.

    Published: 27 Oct 2021
    9.8
    Critical

    CVE-2021-41589

    Last Modified: 21 Nov 2024

    In Gradle Enterprise before 2021.3 (and Enterprise Build Cache Node before 10.0), there is potential cache poisoning and remote code execution when running the build cache node with its default configuration. This configuration allows anonymous access to the configuration user interface and anonymous write access to the build cache. If access control to the build cache is not changed from the default open configuration, a malicious actor with network access can populate the cache with manipulated entries that may execute malicious code as part of a build process. This applies to the build cache provided with Gradle Enterprise and the separate build cache node service if used. If access control to the user interface is not changed from the default open configuration, a malicious actor can undo build cache access control in order to populate the cache with manipulated entries that may execute malicious code as part of a build process. This does not apply to the build cache provided with Gradle Enterprise, but does apply to the separate build cache node service if used.

    Published: 27 Oct 2021
    7.2
    High

    CVE-2021-41619

    Last Modified: 21 Nov 2024

    An issue was discovered in Gradle Enterprise before 2021.1.2. There is potential remote code execution via the application startup configuration. The installation configuration user interface (available to administrators) allows specifying arbitrary Java Virtual Machine startup options. Some of these options, such as -XX:OnOutOfMemoryError, allow specifying a command to be run on the host. This can be abused to run arbitrary commands on the host, should an attacker gain administrative access to the application.

    Published: 27 Oct 2021
    5.3
    Medium

    CVE-2021-41590

    Last Modified: 21 Nov 2024

    In Gradle Enterprise through 2021.3, probing of the server-side network environment can occur via an SMTP configuration test. The installation configuration user interface available to administrators allows testing the configured SMTP server settings. This test function can be used to identify the listening TCP ports available to the server, revealing information about the internal network environment.

    Published: 27 Oct 2021
    7.5
    High

    CVE-2021-41872

    Last Modified: 21 Nov 2024

    Skyworth Digital Technology Penguin Aurora Box 41502 has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service.

    Published: 27 Oct 2021
    7.5
    High

    CVE-2021-34580

    Last Modified: 21 Nov 2024

    In mymbCONNECT24, mbCONNECT24 <= 2.9.0 an unauthenticated user can enumerate valid backend users by checking what kind of response the server sends for crafted invalid login attempts.

    Published: 27 Oct 2021
    3.1
    Low

    CVE-2021-35236

    Last Modified: 21 Nov 2024

    The Secure flag is not set in the SSL Cookie of Kiwi Syslog Server 9.7.2 and previous versions. The Secure attribute tells the browser to only send the cookie if the request is being sent over a secure channel such as HTTPS. This will help protect the cookie from being passed over unencrypted requests. If the application can be accessed over both HTTP, there is a potential for the cookie can be sent in clear text.

    Published: 27 Oct 2021
    5.3
    Medium

    CVE-2021-35235

    Last Modified: 21 Nov 2024

    The ASP.NET debug feature is enabled by default in Kiwi Syslog Server 9.7.2 and previous versions. ASP.NET allows remote debugging of web applications, if configured to do so. Debug mode causes ASP.NET to compile applications with extra information. The information enables a debugger to closely monitor and control the execution of an application. If an attacker could successfully start a remote debugging session, this is likely to disclose sensitive information about the web application and supporting infrastructure that may be valuable in targeting SWI with malicious intent.

    Published: 27 Oct 2021
    5.3
    Medium

    CVE-2021-32951

    Last Modified: 21 Nov 2024

    WebAccess/NMS (Versions prior to v3.0.3_Build6299) has an improper authentication vulnerability, which may allow unauthorized users to view resources monitored and controlled by the WebAccess/NMS, as well as IP addresses and names of all the devices managed via WebAccess/NMS.

    Published: 27 Oct 2021
    9.8
    Critical

    CVE-2011-4574

    Last Modified: 21 Nov 2024

    PolarSSL versions prior to v1.1 use the HAVEGE random number generation algorithm. At its heart, this uses timing information based on the processor's high resolution timer (the RDTSC instruction). This instruction can be virtualized, and some virtual machine hosts have chosen to disable this instruction, returning 0s or predictable results.

    Published: 27 Oct 2021
    5.3
    Medium

    CVE-2021-35233

    Last Modified: 21 Nov 2024

    The HTTP TRACK & TRACE methods were enabled in Kiwi Syslog Server 9.7.1 and earlier. These methods are intended for diagnostic purposes only. If enabled, the web server will respond to requests that use these methods by returning exact HTTP request that was received in the response to the client. This may lead to the disclosure of sensitive information such as internal authentication headers appended by reverse proxies.

    Published: 27 Oct 2021
    8.1
    High

    CVE-2011-4126

    Last Modified: 21 Nov 2024

    Race condition issues were found in Calibre at devices/linux_mount_helper.c allowing unprivileged users the ability to mount any device to anywhere.

    Published: 27 Oct 2021
    9.8
    Critical

    CVE-2011-4125

    Last Modified: 21 Nov 2024

    A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any program as root.

    Published: 27 Oct 2021
    9.8
    Critical

    CVE-2011-4124

    Last Modified: 21 Nov 2024

    Input validation issues were found in Calibre at devices/linux_mount_helper.c which can lead to argument injection and elevation of privileges.

    Published: 27 Oct 2021
    9.9
    Critical

    CVE-2021-38450

    Last Modified: 21 Nov 2024

    The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software.

    Published: 27 Oct 2021
    7.2
    High

    CVE-2021-26610

    Last Modified: 21 Nov 2024

    The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary code.

    Published: 27 Oct 2021
    8
    High

    CVE-2020-7867

    Last Modified: 21 Nov 2024

    An improper input validation vulnerability in Helpu solution could allow a local attacker to arbitrary file creation and execution without click file transfer menu. It is possible to file in arbitrary directory for user because the viewer program receive the file from agent with privilege of administrator.

    Published: 27 Oct 2021
    7.5
    High

    CVE-2021-37129

    Last Modified: 21 Nov 2024

    There is an out of bounds write vulnerability in some Huawei products. The vulnerability is caused by a function of a module that does not properly verify input parameter. Successful exploit could cause out of bounds write leading to a denial of service condition.Affected product versions include:IPS Module V500R005C00,V500R005C20;NGFW Module V500R005C00;NIP6600 V500R005C00,V500R005C20;S12700 V200R010C00SPC600,V200R011C10SPC500,V200R011C10SPC600,V200R013C00SPC500,V200R019C00SPC200,V200R019C00SPC500,V200R019C10SPC200,V200R020C00,V200R020C10;S1700 V200R010C00SPC600,V200R011C10SPC500,V200R011C10SPC600;S2700 V200R010C00SPC600,V200R011C10SPC500,V200R011C10SPC600;S5700 V200R010C00SPC600,V200R010C00SPC700,V200R011C10SPC500,V200R011C10SPC600,V200R019C00SPC500;S6700 V200R010C00SPC600,V200R011C10SPC500,V200R011C10SPC600;S7700 V200R010C00SPC600,V200R010C00SPC700,V200R011C10SPC500,V200R011C10SPC600;S9700 V200R010C00SPC600,V200R011C10SPC500,V200R011C10SPC600;USG9500 V500R005C00,V500R005C20.

    Published: 27 Oct 2021
    6.5
    Medium

    CVE-2021-37122

    Last Modified: 21 Nov 2024

    There is a use-after-free (UAF) vulnerability in Huawei products. An attacker may craft specific packets to exploit this vulnerability. Successful exploitation may cause the service abnormal. Affected product versions include:CloudEngine 12800 V200R005C10SPC800,V200R019C00SPC800;CloudEngine 5800 V200R005C10SPC800,V200R019C00SPC800;CloudEngine 6800 V200R005C10SPC800,V200R005C20SPC800,V200R019C00SPC800;CloudEngine 7800 V200R005C10SPC800,V200R019C00SPC800.

    Published: 27 Oct 2021
    7.5
    High

    CVE-2021-37130

    Last Modified: 21 Nov 2024

    There is a path traversal vulnerability in Huawei FusionCube 6.0.2.The vulnerability is due to that the software uses external input to construct a pathname that is intended to identify a directory that is located underneath a restricted parent directory, but the software does not properly validate the pathname. Successful exploit could allow the attacker to access a location that is outside of the restricted directory by a crafted filename.

    Published: 27 Oct 2021
    7.2
    High

    CVE-2021-37127

    Last Modified: 21 Nov 2024

    There is a signature management vulnerability in some huawei products. An attacker can forge signature and bypass the signature check. During firmware update process, successful exploit this vulnerability can cause the forged system file overwrite the correct system file. Affected product versions include:iManager NetEco V600R010C00CP2001,V600R010C00CP2002,V600R010C00SPC100,V600R010C00SPC110,V600R010C00SPC120,V600R010C00SPC200,V600R010C00SPC210,V600R010C00SPC300;iManager NetEco 6000 V600R009C00SPC100,V600R009C00SPC110,V600R009C00SPC120,V600R009C00SPC190,V600R009C00SPC200,V600R009C00SPC201,V600R009C00SPC202,V600R009C00SPC210.

    Published: 27 Oct 2021
    6.5
    Medium

    CVE-2021-37124

    Last Modified: 21 Nov 2024

    There is a path traversal vulnerability in Huawei PC product. Because the product does not filter path with special characters,attackers can construct a file path with special characters to exploit this vulnerability. Successful exploitation could allow the attacker to transport a file to certain path.Affected product versions include:PC Smart Full Scene 11.1 versions PCManager 11.1.1.97.

    Published: 27 Oct 2021
    6.8
    Medium

    CVE-2021-37131

    Last Modified: 21 Nov 2024

    There is a CSV injection vulnerability in ManageOne, iManager NetEco and iManager NetEco 6000. An attacker with high privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject CSV files to the target device.

    Published: 27 Oct 2021
    5.3
    Medium

    CVE-2021-25219

    Last Modified: 21 Nov 2024

    In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development branch, exploitation of broken authoritative servers using a flaw in response processing can cause degradation in BIND resolver performance. The way the lame cache is currently designed makes it possible for its internal data structures to grow almost infinitely, which may cause significant delays in client query processing.

    Published: 27 Oct 2021
    6.1
    Medium

    CVE-2021-3914

    Last Modified: 21 Nov 2024

    It was found that the smallrye health metrics UI component did not properly sanitize some user inputs. An attacker could use this flaw to conduct cross-site scripting attacks.

    Published: 27 Oct 2021