CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-41745

    Last Modified: 21 Nov 2024

    ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions.

    Published: 22 Oct 2021
    6.1
    Medium

    CVE-2021-41747

    Last Modified: 21 Nov 2024

    Cross-Site Scripting (XSS) vulnerability exists in Csdn APP 4.10.0, which can be exploited by attackers to obtain sensitive information such as user cookies.

    Published: 22 Oct 2021
    9.8
    Critical

    CVE-2021-41744

    Last Modified: 21 Nov 2024

    All versions of yongyou PLM are affected by a command injection issue. UFIDA PLM (Product Life Cycle Management) is a strategic management method. It applies a series of enterprise application systems to support the entire process from conceptual design to the end of product life, and the collaborative creation, distribution, application and management of product information across organizations. Yonyou PLM uses jboss by default, and you can access the management control background without authorization An attacker can use this vulnerability to gain server permissions.

    Published: 22 Oct 2021
    6.1
    Medium

    CVE-2021-31682

    Last Modified: 21 Nov 2024

    The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for reflected XSS attacks due to the operatorlocale GET parameter not being sanitized. This issue impacts versions 6.5 and below. This issue works by passing in a basic XSS payload to a vulnerable GET parameter that is reflected in the output without sanitization.

    Published: 22 Oct 2021
    9.8
    Critical

    CVE-2021-38449

    Last Modified: 21 Nov 2024

    Some API functions permit by-design writing or copying data into a given buffer. Since the client controls these parameters, an attacker could rewrite the memory in any location of the affected product.

    Published: 22 Oct 2021
    9.8
    Critical

    CVE-2021-38457

    Last Modified: 21 Nov 2024

    The server permits communication without any authentication procedure, allowing the attacker to initiate a session with the server without providing any form of authentication.

    Published: 22 Oct 2021
    7.3
    High

    CVE-2021-38455

    Last Modified: 21 Nov 2024

    The affected product’s OS Service does not verify any given parameter. A user can supply any type of parameter that will be passed to inner calls without checking the type of the parameter or the value.

    Published: 22 Oct 2021
    4.8
    Medium

    CVE-2021-38451

    Last Modified: 21 Nov 2024

    The affected product’s proprietary protocol CSC allows for calling numerous function codes. In order to call those function codes, the user must supply parameters. There is no sanitation on the value of the offset, which allows the client to specify any offset and read out-of-bounds data.

    Published: 22 Oct 2021
    8.1
    High

    CVE-2021-38459

    Last Modified: 21 Nov 2024

    The data of a network capture of the initial handshake phase can be used to authenticate at a SYSDBA level. If a specific .exe is not restarted often, it is possible to access the needed handshake packets between admin/client connections. Using the SYSDBA permission, an attacker can change user passwords or delete the database.

    Published: 22 Oct 2021
    9.1
    Critical

    CVE-2021-38453

    Last Modified: 21 Nov 2024

    Some API functions allow interaction with the registry, which includes reading values as well as data modification.

    Published: 22 Oct 2021
    8.2
    High

    CVE-2021-38461

    Last Modified: 21 Nov 2024

    The affected product uses a hard-coded blowfish key for encryption/decryption processes. The key can be easily extracted from binaries.

    Published: 22 Oct 2021
    8
    High

    CVE-2021-38465

    Last Modified: 21 Nov 2024

    The webinstaller is a Golang web server executable that enables the generation of an Auvesy image agent. Resource consumption can be achieved by generating large amounts of installations, which are then saved without limitation in the temp folder of the webinstaller executable.

    Published: 22 Oct 2021
    7.3
    High

    CVE-2021-38463

    Last Modified: 21 Nov 2024

    The affected product does not properly control the allocation of resources. A user may be able to allocate unlimited memory buffers using API functions.

    Published: 22 Oct 2021
    7.3
    High

    CVE-2021-38467

    Last Modified: 21 Nov 2024

    A specific function code receives a raw pointer supplied by the user and deallocates this pointer. The user can then control what memory regions will be freed and cause use-after-free condition.

    Published: 22 Oct 2021
    9.1
    Critical

    CVE-2021-38471

    Last Modified: 21 Nov 2024

    There are multiple API function codes that permit data writing to any file, which may allow an attacker to modify existing files or create new files.

    Published: 22 Oct 2021
    6.5
    Medium

    CVE-2021-38479

    Last Modified: 21 Nov 2024

    Many API function codes receive raw pointers remotely from the user and trust these pointers as valid in-bound memory regions. An attacker can manipulate API functions by writing arbitrary data into the resolved address of a raw pointer.

    Published: 22 Oct 2021
    9.1
    Critical

    CVE-2021-38469

    Last Modified: 21 Nov 2024

    Many of the services used by the affected product do not specify full paths for the DLLs they are loading. An attacker can exploit the uncontrolled search path by implanting their own DLL near the affected product’s binaries, thus hijacking the loaded DLL.

    Published: 22 Oct 2021
    9.8
    Critical

    CVE-2021-38477

    Last Modified: 21 Nov 2024

    There are multiple API function codes that permit reading and writing data to or from files and directories, which could lead to the manipulation and/or the deletion of files.

    Published: 22 Oct 2021
    8.1
    High

    CVE-2021-38481

    Last Modified: 21 Nov 2024

    The scheduler service running on a specific TCP port enables the user to start and stop jobs. There is no sanitation of the supplied JOB ID provided to the function. An attacker may send a malicious payload that can enable the user to execute another SQL expression by sending a specific string.

    Published: 22 Oct 2021
    8
    High

    CVE-2021-38473

    Last Modified: 21 Nov 2024

    The affected product’s code base doesn’t properly control arguments for specific functions, which could lead to a stack overflow.

    Published: 22 Oct 2021
    7.3
    High

    CVE-2021-38475

    Last Modified: 21 Nov 2024

    The database connection to the server is performed by calling a specific API, which could allow an unprivileged user to gain SYSDBA permissions.

    Published: 22 Oct 2021
    6.7
    Medium

    CVE-2021-35230

    Last Modified: 21 Nov 2024

    As a result of an unquoted service path vulnerability present in the Kiwi CatTools Installation Wizard, a local attacker could gain escalated privileges by inserting an executable into the path of the affected service or uninstall entry.

    Published: 22 Oct 2021
    9.8
    Critical

    CVE-2021-36357

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenPOWER 2.6 firmware. unpack_timestamp() calls le32_to_cpu() for endian conversion of a uint16_t "year" value, resulting in a type mismatch that can truncate a higher integer value to a smaller one, and bypass a timestamp check. The fix is to use the right endian conversion function.

    Published: 22 Oct 2021
    5.4
    Medium

    CVE-2021-31834

    Last Modified: 21 Nov 2024

    Stored Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 11 allows ePO administrators to inject arbitrary web script or HTML via multiple parameters where the administrator's entries were not correctly sanitized.

    Published: 22 Oct 2021
    4.8
    Medium

    CVE-2021-31835

    Last Modified: 21 Nov 2024

    Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 11 allows ePO administrators to inject arbitrary web script or HTML via a specific parameter where the administrator's entries were not correctly sanitized.

    Published: 22 Oct 2021
    8.7
    High

    CVE-2021-34362

    Last Modified: 21 Nov 2024

    A command injection vulnerability has been reported to affect QNAP device running Media Streaming add-on. If exploited, this vulnerability allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of Media Streaming add-on: QTS 5.0.0: Media Streaming add-on 500.0.0.3 ( 2021/08/20 ) and later QTS 4.5.4: Media Streaming add-on 500.0.0.3 ( 2021/08/20 ) and later QTS 4.3.6: Media Streaming add-on 430.1.8.12 ( 2021/08/20 ) and later QTS 4.3.3: Media Streaming add-on 430.1.8.12 ( 2021/09/29 ) and later QuTS-Hero 5.0.0: Media Streaming add-on 500.0.0.3 ( 2021/08/20 ) and later

    Published: 22 Oct 2021
    8.1
    High

    CVE-2021-23463

    Last Modified: 21 Nov 2024

    The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from org.h2.jdbc.JdbcResultSet.getSQLXML() method. If it executes the getSource() method when the parameter is DOMSource.class it will trigger the vulnerability.

    Published: 22 Oct 2021
    5.4
    Medium

    CVE-2021-27746

    Last Modified: 21 Nov 2024

    "HCL Connections Security Update for Reflected Cross-Site Scripting (XSS) Vulnerability"

    Published: 21 Oct 2021
    6.2
    Medium

    CVE-2021-41169

    Last Modified: 21 Nov 2024

    Sulu is an open-source PHP content management system based on the Symfony framework. In versions before 1.6.43 are subject to stored cross site scripting attacks. HTML input into Tag names is not properly sanitized. Only admin users are allowed to create tags. Users are advised to upgrade.

    Published: 21 Oct 2021
    4.8
    Medium

    CVE-2021-36869

    Last Modified: 28 Mar 2025

    Reflected Cross-Site Scripting (XSS) vulnerability in WordPress Ivory Search plugin (versions <= 4.6.6). Vulnerable parameter: &post.

    Published: 21 Oct 2021
    7.3
    High

    CVE-2021-41127

    Last Modified: 21 Nov 2024

    Rasa is an open source machine learning framework to automate text-and voice-based conversations. In affected versions a vulnerability exists in the functionality that loads a trained model `tar.gz` file which allows a malicious actor to craft a `model.tar.gz` file which can overwrite or replace bot files in the bot directory. The vulnerability is fixed in Rasa 2.8.10. For users unable to update ensure that users do not upload untrusted model files, and restrict CLI or API endpoint access where a malicious actor could target a deployed Rasa instance.

    Published: 21 Oct 2021
    6.5
    Medium

    CVE-2021-41168

    Last Modified: 21 Nov 2024

    Snudown is a reddit-specific fork of the Sundown Markdown parser used by GitHub, with Python integration added. In affected versions snudown was found to be vulnerable to denial of service attacks to its reference table implementation. References written in markdown ` [reference_name]: https://www.example.com` are inserted into a hash table which was found to have a weak hash function, meaning that an attacker can reliably generate a large number of collisions for it. This makes the hash table vulnerable to a hash-collision DoS attack, a type of algorithmic complexity attack. Further the hash table allowed for duplicate entries resulting in long retrieval times. Proofs of concept and further discussion of the hash collision issue are discussed on the snudown GHSA(https://github.com/reddit/snudown/security/advisories/GHSA-6gvv-9q92-w5f6). Users are advised to update to version 1.7.0.

    Published: 21 Oct 2021
    4.8
    Medium

    CVE-2021-39354

    Last Modified: 31 Mar 2025

    The Easy Digital Downloads WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $start_date and $end_date parameters found in the ~/includes/admin/payments/class-payments-table.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.11.2.

    Published: 21 Oct 2021
    8.8
    High

    CVE-2021-39321

    Last Modified: 31 Mar 2025

    Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_sss_import_config AJAX action due to deserialization of unvalidated user supplied inputs via the import_config function found in the ~/admin/class-sassy-social-share-admin.php file. This can be exploited by underprivileged authenticated users due to a missing capability check on the import_config function.

    Published: 21 Oct 2021
    5.5
    Medium

    CVE-2021-39328

    Last Modified: 14 Feb 2025

    The Simple Job Board WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $job_board_privacy_policy_label variable echo'd out via the ~/admin/settings/class-simple-job-board-settings-privacy.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 2.9.4. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

    Published: 21 Oct 2021
    7.2
    High

    CVE-2021-39352

    Last Modified: 14 Feb 2025

    The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found in the ~/inc/CatchThemesDemoImport.php file, in versions up to and including 1.7, due to insufficient file type validation. This makes it possible for an attacker with administrative privileges to upload malicious files that can be used to achieve remote code execution.

    Published: 21 Oct 2021
    5.5
    Medium

    CVE-2021-39356

    Last Modified: 14 Feb 2025

    The Content Staging WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and escaping via several parameters that are echo'd out via the ~/templates/settings.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 2.0.1. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

    Published: 21 Oct 2021
    5.5
    Medium

    CVE-2021-39357

    Last Modified: 14 Feb 2025

    The Leaky Paywall WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via the ~/class.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 4.16.5. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

    Published: 21 Oct 2021
    5.5
    Medium

    CVE-2021-39348

    Last Modified: 14 Feb 2025

    The LearnPress WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $custom_profile parameter found in the ~/inc/admin/views/backend-user-profile.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 4.1.3.1. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled. Please note that this is seperate from CVE-2021-24702.

    Published: 21 Oct 2021
    7.5
    High

    CVE-2021-22034

    Last Modified: 21 Nov 2024

    Releases prior to VMware vRealize Operations Tenant App 8.6 contain an Information Disclosure Vulnerability.

    Published: 21 Oct 2021
    9.8
    Critical

    CVE-2021-40719

    Last Modified: 23 Apr 2025

    Adobe Connect version 11.2.3 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve arbitrary method invocation when AMF messages are deserialized on an Adobe Connect server. An attacker can leverage this to execute remote code execution on the server.

    Published: 21 Oct 2021
    5.5
    Medium

    CVE-2021-35228

    Last Modified: 21 Nov 2024

    This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would need to perform a Man in the Middle attack in order to change header for a remote victim.

    Published: 21 Oct 2021
    4.7
    Medium

    CVE-2021-35227

    Last Modified: 21 Nov 2024

    The HTTP interface was enabled for RabbitMQ Plugin in ARM 2020.2.6 and the ability to configure HTTPS was not available.

    Published: 21 Oct 2021
    5
    Medium

    CVE-2021-35225

    Last Modified: 21 Nov 2024

    Each authenticated Orion Platform user in a MSP (Managed Service Provider) environment can view and browse all NetPath Services from all that MSP's customers. This can lead to any user having a limited insight into other customer's infrastructure and potential data cross-contamination.

    Published: 21 Oct 2021
    8.8
    High

    CVE-2021-41146

    Last Modified: 21 Nov 2024

    qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser v1.7.0, the Windows installer for qutebrowser registers a `qutebrowserurl:` URL handler. With certain applications, opening a specially crafted `qutebrowserurl:...` URL can lead to execution of qutebrowser commands, which in turn allows arbitrary code execution via commands such as `:spawn` or `:debug-pyeval`. Only Windows installs where qutebrowser is registered as URL handler are affected. The issue has been fixed in qutebrowser v2.4.0. The fix also adds additional hardening for potential similar issues on Linux (by adding the new --untrusted-args flag to the .desktop file), though no such vulnerabilities are known.

    Published: 21 Oct 2021
    5.7
    Medium

    CVE-2021-28496

    Last Modified: 21 Nov 2024

    On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by BiDirectional Forwarding Detection (BFD) will be leaked when displaying output over eAPI or other JSON outputs to other authenticated users on the device. The affected EOS Versions are: all releases in 4.22.x train, 4.23.9 and below releases in the 4.23.x train, 4.24.7 and below releases in the 4.24.x train, 4.25.4 and below releases in the 4.25.x train, 4.26.1 and below releases in the 4.26.x train

    Published: 21 Oct 2021
    4.3
    Medium

    CVE-2021-29883

    Last Modified: 21 Nov 2024

    IBM Standards Processing Engine (IBM Transformation Extender Advanced 9.0 and 10.0) does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 207090.

    Published: 21 Oct 2021
    8.1
    High

    CVE-2021-29873

    Last Modified: 21 Nov 2024

    IBM Flash System 900 could allow an authenticated attacker to obtain sensitive information and cause a denial of service due to a restricted shell escape vulnerability. IBM X-Force ID: 206229.

    Published: 21 Oct 2021
    3.9
    Low

    CVE-2020-14263

    Last Modified: 21 Nov 2024

    "HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the included MobileIron AppConnect SDK"

    Published: 21 Oct 2021
    8.8
    High

    CVE-2021-20120

    Last Modified: 21 Nov 2024

    The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery attacks. This means that an attacker could make configuration changes (such as changing the administrative password) without the consent of the user.

    Published: 21 Oct 2021