CVE Feed

    Dashboard / CVE

    4.9
    Medium

    CVE-2021-38911

    Last Modified: 21 Nov 2024

    IBM Security Risk Manager on CP4S 1.7.0.0 stores user credentials in plain clear text which can be read by a an authenticatedl privileged user. IBM X-Force ID: 209940.

    Published: 19 Oct 2021
    5.4
    Medium

    CVE-2021-29912

    Last Modified: 21 Nov 2024

    IBM Security Risk Manager on CP4S 1.7.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 207828.

    Published: 19 Oct 2021
    5.5
    Medium

    CVE-2021-39355

    Last Modified: 14 Feb 2025

    The Indeed Job Importer WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/indeed-job-importer/trunk/indeed-job-importer.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.0.5. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

    Published: 19 Oct 2021
    5.5
    Medium

    CVE-2021-39343

    Last Modified: 25 Apr 2025

    The MPL-Publisher WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/libs/PublisherController.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.30.2. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

    Published: 19 Oct 2021
    5.5
    Medium

    CVE-2021-39329

    Last Modified: 14 Feb 2025

    The JobBoardWP WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/includes/admin/class-metabox.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.0.7. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

    Published: 19 Oct 2021
    4.8
    Medium

    CVE-2021-36832

    Last Modified: 21 Nov 2024

    WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at "Headline" (&message_data[16][headline]) input.

    Published: 19 Oct 2021
    5.5
    Medium

    CVE-2021-27001

    Last Modified: 21 Nov 2024

    Clustered Data ONTAP versions 9.x prior to 9.5P18, 9.6P16, 9.7P16, 9.8P7 and 9.9.1P2 are susceptible to a vulnerability which could allow an authenticated privileged local attacker to arbitrarily modify Compliance-mode WORM data prior to the end of the retention period.

    Published: 19 Oct 2021
    6.1
    Medium

    CVE-2021-26589

    Last Modified: 21 Nov 2024

    A potential security vulnerability has been identified in HPE Superdome Flex Servers. The vulnerability could be remotely exploited to allow Cross Site Scripting (XSS) because the Session Cookie is missing an HttpOnly Attribute. HPE has provided a firmware update to resolve the vulnerability in HPE Superdome Flex Servers.

    Published: 19 Oct 2021
    3.7
    Low

    CVE-2011-1075

    Last Modified: 21 Nov 2024

    FreeBSD's crontab calculates the MD5 sum of the previous and new cronjob to determine if any changes have been made before copying the new version in. In particular, it uses the MD5File() function, which takes a pathname as an argument, and is called with euid 0. A race condition in this process may lead to an arbitrary MD5 comparison regardless of the read permissions.

    Published: 19 Oct 2021
    7.2
    High

    CVE-2021-30358

    Last Modified: 21 Nov 2024

    Mobile Access Portal Native Applications who's path is defined by the administrator with environment variables may run applications from other locations by the Mobile Access Portal Agent.

    Published: 19 Oct 2021
    7.5
    High

    CVE-2020-29622

    Last Modified: 21 Nov 2024

    A race condition was addressed with additional validation. This issue is fixed in Security Update 2021-005 Catalina. Mounting a maliciously crafted NFS network share may lead to arbitrary code execution with system privileges.

    Published: 19 Oct 2021
    5.5
    Medium

    CVE-2021-30811

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in iOS 15 and iPadOS 15, watchOS 8. A local attacker may be able to read sensitive information.

    Published: 19 Oct 2021
    2.4
    Low

    CVE-2021-30815

    Last Modified: 21 Nov 2024

    A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15. A local attacker may be able to view contacts from the lock screen.

    Published: 19 Oct 2021
    9.8
    Critical

    CVE-2021-30820

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in iOS 14.8 and iPadOS 14.8. A remote attacker may be able to cause arbitrary code execution.

    Published: 19 Oct 2021
    4.3
    Medium

    CVE-2021-30810

    Last Modified: 21 Nov 2024

    An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15, watchOS 8, tvOS 15. An attacker in physical proximity may be able to force a user onto a malicious Wi-Fi network during device setup.

    Published: 19 Oct 2021
    7.8
    High

    CVE-2021-30825

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in iOS 15 and iPadOS 15. A local attacker may be able to cause unexpected application termination or arbitrary code execution.

    Published: 19 Oct 2021
    5.5
    Medium

    CVE-2021-30819

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 15 and iPadOS 15. Processing a maliciously crafted USD file may disclose memory contents.

    Published: 19 Oct 2021
    7.8
    High

    CVE-2021-30807

    Last Modified: 23 Oct 2025

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS 14.7.1, watchOS 7.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.

    Published: 19 Oct 2021
    7.5
    High

    CVE-2021-30826

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15. In certain situations, the baseband would fail to enable integrity and ciphering protection.

    Published: 19 Oct 2021
    7.8
    High

    CVE-2021-30827

    Last Modified: 21 Nov 2024

    A permissions issue existed. This issue was addressed with improved permission validation. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A local attacker may be able to elevate their privileges.

    Published: 19 Oct 2021
    7.8
    High

    CVE-2021-30829

    Last Modified: 21 Nov 2024

    A URI parsing issue was addressed with improved parsing. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A local user may be able to execute arbitrary files.

    Published: 19 Oct 2021
    5.5
    Medium

    CVE-2021-30828

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A local user may be able to read arbitrary files as root.

    Published: 19 Oct 2021
    7.8
    High

    CVE-2021-30830

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A malicious application may be able to execute arbitrary code with kernel privileges.

    Published: 19 Oct 2021
    7.8
    High

    CVE-2021-30832

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved state management. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A local attacker may be able to elevate their privileges.

    Published: 19 Oct 2021
    7.8
    High

    CVE-2021-30837

    Last Modified: 21 Nov 2024

    A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 15 and iPadOS 15, watchOS 8, tvOS 15. An application may be able to execute arbitrary code with kernel privileges.

    Published: 19 Oct 2021
    7.8
    High

    CVE-2021-30835

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in Security Update 2021-005 Catalina, iTunes 12.12 for Windows, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted image may lead to arbitrary code execution.

    Published: 19 Oct 2021
    7.8
    High

    CVE-2021-30842

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted dfont file may lead to arbitrary code execution.

    Published: 19 Oct 2021
    7.8
    High

    CVE-2021-30838

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15 and iPadOS 15. A malicious application may be able to execute arbitrary code with system privileges on devices with an Apple Neural Engine.

    Published: 19 Oct 2021
    7.8
    High

    CVE-2021-30841

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted dfont file may lead to arbitrary code execution.

    Published: 19 Oct 2021
    7.5
    High

    CVE-2021-30844

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A remote attacker may be able to leak memory.

    Published: 19 Oct 2021
    5.5
    Medium

    CVE-2021-30845

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.6. A local user may be able to read kernel memory.

    Published: 19 Oct 2021
    7.8
    High

    CVE-2021-30843

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted dfont file may lead to arbitrary code execution.

    Published: 19 Oct 2021
    7.8
    High

    CVE-2021-30847

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in watchOS 8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, iTunes 12.12 for Windows. Processing a maliciously crafted image may lead to arbitrary code execution.

    Published: 19 Oct 2021
    7.8
    High

    CVE-2021-30846

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 19 Oct 2021
    7.8
    High

    CVE-2021-30848

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, iOS 15 and iPadOS 15. Processing maliciously crafted web content may lead to code execution.

    Published: 19 Oct 2021
    5.5
    Medium

    CVE-2021-30850

    Last Modified: 21 Nov 2024

    An access issue was addressed with improved access restrictions. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6, tvOS 15. A user may gain access to protected parts of the file system.

    Published: 19 Oct 2021
    7.8
    High

    CVE-2021-30849

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, watchOS 8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, iTunes 12.12 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 19 Oct 2021
    8.1
    High

    CVE-2021-3889

    Last Modified: 21 Nov 2024

    libmobi is vulnerable to Use of Out-of-range Pointer Offset

    Published: 19 Oct 2021
    8.1
    High

    CVE-2021-3888

    Last Modified: 21 Nov 2024

    libmobi is vulnerable to Use of Out-of-range Pointer Offset

    Published: 19 Oct 2021
    5.4
    Medium

    CVE-2021-3879

    Last Modified: 21 Nov 2024

    snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 19 Oct 2021
    7.5
    High

    CVE-2021-3869

    Last Modified: 21 Nov 2024

    corenlp is vulnerable to Improper Restriction of XML External Entity Reference

    Published: 19 Oct 2021
    6.1
    Medium

    CVE-2021-3863

    Last Modified: 21 Nov 2024

    snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 19 Oct 2021
    8.8
    High

    CVE-2021-3858

    Last Modified: 21 Nov 2024

    snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)

    Published: 19 Oct 2021
    5.4
    Medium

    CVE-2021-3851

    Last Modified: 21 Nov 2024

    firefly-iii is vulnerable to URL Redirection to Untrusted Site

    Published: 19 Oct 2021
    8.8
    High

    CVE-2021-3846

    Last Modified: 21 Nov 2024

    firefly-iii is vulnerable to Unrestricted Upload of File with Dangerous Type

    Published: 19 Oct 2021
    8
    High

    CVE-2021-38486

    Last Modified: 21 Nov 2024

    InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 cloud portal allows for self-registration of the affected product without any requirements to create an account, which may allow an attacker to have full control over the product and execute code within the internal network to which the product is connected.

    Published: 19 Oct 2021
    9.1
    Critical

    CVE-2021-38478

    Last Modified: 21 Nov 2024

    InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to an attacker using a traceroute tool to inject commands into the device. This may allow the attacker to remotely run commands on behalf of the device.

    Published: 19 Oct 2021
    9.6
    Critical

    CVE-2021-38480

    Last Modified: 21 Nov 2024

    InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when unauthorized commands are submitted from a user the web application trusts. This may allow an attacker to remotely perform actions on the router’s management portal, such as making configuration changes, changing administrator credentials, and running system commands on the router.

    Published: 19 Oct 2021
    9.1
    Critical

    CVE-2021-38484

    Last Modified: 21 Nov 2024

    InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 do not have a filter or signature check to detect or prevent an upload of malicious files to the server, which may allow an attacker, acting as an administrator, to upload malicious files. This could result in cross-site scripting, deletion of system files, and remote code execution.

    Published: 19 Oct 2021
    8.7
    High

    CVE-2021-38482

    Last Modified: 21 Nov 2024

    InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 website used to control the router is vulnerable to stored cross-site scripting, which may allow an attacker to hijack sessions of users connected to the system.

    Published: 19 Oct 2021