CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2021-38346

    Last Modified: 14 Feb 2025

    The Brizy Page Builder plugin <= 2.3.11 for WordPress allowed authenticated users to upload executable files to a location of their choice using the brizy_create_block_screenshot AJAX action. The file would be named using the id parameter, which could be prepended with "../" to perform directory traversal, and the file contents were populated via the ibsf parameter, which would be base64-decoded and written to the file. While the plugin added a .jpg extension to all uploaded filenames, a double extension attack was still possible, e.g. a file named shell.php would be saved as shell.php.jpg, and would be executable on a number of common configurations.

    Published: 14 Oct 2021
    7.1
    High

    CVE-2021-38345

    Last Modified: 14 Feb 2025

    The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in user accessing any endpoint in the wp-admin directory to modify the content of any existing post or page created with the Brizy editor. An identical issue was found by another researcher in Brizy <= 1.0.125 and fixed in version 1.0.126, but the vulnerability was reintroduced in version 1.0.127.

    Published: 14 Oct 2021
    6.4
    Medium

    CVE-2021-38344

    Last Modified: 14 Feb 2025

    The Brizy Page Builder plugin <= 2.3.11 for WordPress was vulnerable to stored XSS by lower-privileged users such as a subscribers. It was possible to add malicious JavaScript to a page by modifying the request sent to update the page via the brizy_update_item AJAX action and adding JavaScript to the data parameter, which would be executed in the session of any visitor viewing or previewing the post or page.

    Published: 14 Oct 2021
    9.8
    Critical

    CVE-2021-41132

    Last Modified: 21 Nov 2024

    OMERO.web provides a web based client and plugin infrastructure. In versions prior to 5.11.0, a variety of templates do not perform proper sanitization through HTML escaping. Due to the lack of sanitization and use of ``jQuery.html()``, there are a whole host of cross-site scripting possibilities with specially crafted input to a variety of fields. This issue is patched in version 5.11.0. There are no known workarounds aside from upgrading.

    Published: 14 Oct 2021
    7.5
    High

    CVE-2021-37933

    Last Modified: 21 Nov 2024

    An LDAP injection vulnerability in /account/login in Huntflow Enterprise before 3.10.6 could allow an unauthenticated, remote user to modify the logic of an LDAP query and bypass authentication. The vulnerability is due to insufficient server-side validation of the email parameter before using it to construct LDAP queries. An attacker could bypass authentication exploiting this vulnerability by sending login attempts in which there is a valid password but a wildcard character in email parameter.

    Published: 14 Oct 2021
    6.1
    Medium

    CVE-2021-33179

    Last Modified: 21 Nov 2024

    The general user interface in Nagios XI versions prior to 5.8.4 is vulnerable to authenticated reflected cross-site scripting. An authenticated victim, who accesses a specially crafted malicious URL, would unknowingly execute the attached payload.

    Published: 14 Oct 2021
    6.5
    Medium

    CVE-2021-33178

    Last Modified: 3 Nov 2025

    The Manage Backgrounds functionality within NagVis versions prior to 1.9.29 is vulnerable to an authenticated path traversal vulnerability. Exploitation of this results in a malicious actor having the ability to arbitrarily delete files on the local system.

    Published: 14 Oct 2021
    8.8
    High

    CVE-2021-33177

    Last Modified: 21 Nov 2024

    The Bulk Modifications functionality in Nagios XI versions prior to 5.8.5 is vulnerable to SQL injection. Exploitation requires the malicious actor to be authenticated to the vulnerable system, but once authenticated they would be able to execute arbitrary sql queries.

    Published: 14 Oct 2021
    7.5
    High

    CVE-2020-19954

    Last Modified: 21 Nov 2024

    An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbitrary files.

    Published: 14 Oct 2021
    7.5
    High

    CVE-2020-19957

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the id parameter on the /dl/dl_print.php page.

    Published: 14 Oct 2021
    7.5
    High

    CVE-2020-19959

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the dlid parameter in the /dl/dl_sendmail.php page cookie.

    Published: 14 Oct 2021
    7.5
    High

    CVE-2020-19961

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the component subzs.php.

    Published: 14 Oct 2021
    7.5
    High

    CVE-2020-19960

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the dlid parameter in the /dl/dl_sendsms.php page cookie.

    Published: 14 Oct 2021
    5.4
    Medium

    CVE-2020-19962

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in the getClientIp function in /lib/tinwin.class.php of Chaoji CMS 2.39, allows attackers to execute arbitrary web scripts.

    Published: 14 Oct 2021
    6.5
    Medium

    CVE-2020-19964

    Last Modified: 21 Nov 2024

    A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account without authentication.

    Published: 14 Oct 2021
    9.8
    Critical

    CVE-2020-22724

    Last Modified: 21 Nov 2024

    A remote command execution vulnerability exists in add_server_service of PPTP_SERVER in Mercury Router MER1200 v1.0.1 and Mercury Router MER1200G v1.0.1.

    Published: 14 Oct 2021
    6.8
    Medium

    CVE-2021-3882

    Last Modified: 21 Nov 2024

    LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client uses HTTPS and the LedgerSMB server is behind a reverse proxy. By tricking a user to use an unencrypted connection (HTTP), an attacker may be able to obtain the authentication data by capturing network traffic. LedgerSMB 1.8 and newer switched from Basic authentication to using cookie authentication with encrypted cookies. Although an attacker can't access the information inside the cookie, nor the password of the user, possession of the cookie is enough to access the application as the user from which the cookie has been obtained. In order for the attacker to obtain the cookie, first of all the server must be configured to respond to unencrypted requests, the attacker must be suitably positioned to eavesdrop on the network traffic between the client and the server *and* the user must be tricked into using unencrypted HTTP traffic. Proper audit control and separation of duties limit Integrity impact of the attack vector. Users of LedgerSMB 1.8 are urged to upgrade to known-fixed versions. Users of LedgerSMB 1.7 or 1.9 are unaffected by this vulnerability and don't need to take action. As a workaround, users may configure their Apache or Nginx reverse proxy to add the Secure attribute at the network boundary instead of relying on LedgerSMB. For Apache, please refer to the 'Header always edit' configuration command in the mod_headers module. For Nginx, please refer to the 'proxy_cookie_flags' configuration command.

    Published: 14 Oct 2021
    9.8
    Critical

    CVE-2021-42342

    Last Modified: 21 Nov 2024

    An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed with the CGI prefix. This permits tunneling untrusted environment variables into vulnerable CGI scripts.

    Published: 14 Oct 2021
    7.5
    High

    CVE-2021-42341

    Last Modified: 21 Nov 2024

    checkpath in OpenRC before 0.44.7 uses the direct output of strlen() to allocate strings, which does not account for the '\0' byte at the end of the string. This results in memory corruption. CVE-2021-42341 was introduced in git commit 63db2d99e730547339d1bdd28e8437999c380cae, which was introduced as part of OpenRC 0.44.0 development.

    Published: 14 Oct 2021
    7.8
    High

    CVE-2021-40854

    Last Modified: 21 Nov 2024

    AnyDesk before 6.2.6 and 6.3.x before 6.3.3 allows a local user to obtain administrator privileges by using the Open Chat Log feature to launch a privileged Notepad process that can launch other applications.

    Published: 14 Oct 2021
    9.1
    Critical

    CVE-2021-20599

    Last Modified: 21 Nov 2024

    Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information vulnerability in MELSEC iQ-R series Safety CPU R08/16/32/120SFCPU firmware versions "26" and prior and MELSEC iQ-R series SIL2 Process CPU R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to login to a target CPU module by obtaining credentials other than password.

    Published: 14 Oct 2021
    —
    Unknown

    CVE-2022-20424

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 14 Oct 2021
    6.1
    Medium

    CVE-2021-20323

    Last Modified: 21 Nov 2024

    A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.

    Published: 14 Oct 2021
    7.5
    High

    CVE-2021-42340

    Last Modified: 21 Nov 2024

    The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.

    Published: 14 Oct 2021
    9.9
    Critical

    CVE-2021-42369

    Last Modified: 21 Nov 2024

    Imagicle Application Suite (for Cisco UC) before 2021.Summer.2 allows SQL injection. A low-privileged user could inject a SQL statement through the "Export to CSV" feature of the Contact Manager web GUI.

    Published: 14 Oct 2021
    5.5
    Medium

    CVE-2022-0322

    Last Modified: 21 Nov 2024

    A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is allocated triggers a BUG_ON issue, leading to a denial of service (DOS).

    Published: 14 Oct 2021
    7.5
    High

    CVE-2021-41771

    Last Modified: 21 Nov 2024

    ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation.

    Published: 14 Oct 2021
    —
    Unknown

    CVE-2021-3885

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 13 Oct 2021
    9.8
    Critical

    CVE-2021-41075

    Last Modified: 21 Nov 2024

    The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module API.

    Published: 13 Oct 2021
    9.8
    Critical

    CVE-2021-40493

    Last Modified: 21 Nov 2024

    Zoho ManageEngine OpManager before 125437 is vulnerable to SQL Injection in the support diagnostics module. This occurs via the pollingObject parameter of the getDataCollectionFailureReason API.

    Published: 13 Oct 2021
    4.7
    Medium

    CVE-2021-26318

    Last Modified: 21 Nov 2024

    A timing and power-based side channel attack leveraging the x86 PREFETCH instructions on some AMD CPUs could potentially result in leaked kernel address space information.

    Published: 13 Oct 2021
    9.8
    Critical

    CVE-2021-42224

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability exists in IFSC Code Finder Project 1.0 via the searchifsccode POST parameter in /search.php.

    Published: 13 Oct 2021
    6.1
    Medium

    CVE-2021-42223

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS).vulnerability exists in Online DJ Booking Management System 1.0 in view-booking-detail.php.

    Published: 13 Oct 2021
    8.8
    High

    CVE-2021-20131

    Last Modified: 21 Nov 2024

    ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the Personalization interface.

    Published: 13 Oct 2021
    8.8
    High

    CVE-2021-20130

    Last Modified: 21 Nov 2024

    ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the PasswordExpiry interface.

    Published: 13 Oct 2021
    9.8
    Critical

    CVE-2021-40842

    Last Modified: 21 Nov 2024

    Proofpoint Insider Threat Management Server contains a SQL injection vulnerability in the Web Console. The vulnerability exists due to improper input validation on the database name parameter required in certain unauthenticated APIs. A malicious URL visited by anyone with network access to the server could be used to blindly execute arbitrary SQL statements on the backend database. Version 7.12.0 and all versions prior to 7.11.2 are affected.

    Published: 13 Oct 2021
    7.3
    High

    CVE-2021-40843

    Last Modified: 21 Nov 2024

    Proofpoint Insider Threat Management Server contains an unsafe deserialization vulnerability in the Web Console. An attacker with write access to the local database could cause arbitrary code to execute with SYSTEM privileges on the underlying server when a Web Console user triggers retrieval of that data. When chained with a SQL injection vulnerability, the vulnerability could be exploited remotely if Web Console users click a series of maliciously crafted URLs. All versions prior to 7.11.2 are affected.

    Published: 13 Oct 2021
    8.1
    High

    CVE-2021-41139

    Last Modified: 21 Nov 2024

    Anuko Time Tracker is an open source, web-based time tracking application written in PHP. When a logged on user selects a date in Time Tracker, it is being passed on via the date parameter in URI. Because of not checking this parameter for sanity in versions prior to 1.19.30.5600, it was possible to craft the URI with malicious JavaScript, use social engineering to convince logged on user to click on such link, and have the attacker-supplied JavaScript to be executed in user's browser. This issue is patched in version 1.19.30.5600. As a workaround, one may introduce `ttValidDbDateFormatDate` function as in the latest version and add a call to it within the access checks block in time.php.

    Published: 13 Oct 2021
    9.8
    Critical

    CVE-2021-35498

    Last Modified: 21 Nov 2024

    The TIBCO EBX Web Server component of TIBCO Software Inc.'s TIBCO EBX, TIBCO EBX, TIBCO EBX, and TIBCO Product and Service Catalog powered by TIBCO EBX contains a vulnerability that under certain specific conditions allows an attacker to enter a password other than the legitimate password and it will be accepted as valid. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.8.123 and below, TIBCO EBX: versions 5.9.3, 5.9.4, 5.9.5, 5.9.6, 5.9.7, 5.9.8, 5.9.9, 5.9.10, 5.9.11, 5.9.12, 5.9.13, and 5.9.14, TIBCO EBX: versions 6.0.0 and 6.0.1, and TIBCO Product and Service Catalog powered by TIBCO EBX: version 1.0.0.

    Published: 13 Oct 2021
    8.1
    High

    CVE-2021-3057

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect app that enables a man-in-the-middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This issue impacts: GlobalProtect app 5.1 versions earlier than GlobalProtect app 5.1.9 on Windows; GlobalProtect app 5.2 versions earlier than GlobalProtect app 5.2.8 on Windows; GlobalProtect app 5.2 versions earlier than GlobalProtect app 5.2.8 on the Universal Windows Platform; GlobalProtect app 5.3 versions earlier than GlobalProtect app 5.3.1 on Linux.

    Published: 13 Oct 2021
    6.1
    Medium

    CVE-2021-40732

    Last Modified: 3 Nov 2025

    XMP Toolkit version 2020.1 (and earlier) is affected by a null pointer dereference vulnerability that could result in leaking data from certain memory locations and causing a local denial of service in the context of the current user. User interaction is required to exploit this vulnerability in that the victim will need to open a specially crafted MXF file.

    Published: 13 Oct 2021
    6.5
    Medium

    CVE-2021-22036

    Last Modified: 21 Nov 2024

    VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling. A malicious actor may be able to redirect victim to an attacker controlled domain due to improper path handling in vRealize Orchestrator leading to sensitive information disclosure.

    Published: 13 Oct 2021
    4.3
    Medium

    CVE-2021-22035

    Last Modified: 21 Nov 2024

    VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulnerability in interactive analytics export function. An authenticated malicious actor with non-administrative privileges may be able to embed untrusted data prior to exporting a CSV sheet through Log Insight which could be executed in user's environment.

    Published: 13 Oct 2021
    7.5
    High

    CVE-2021-20129

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in Draytek VigorConnect 1.6.0-B3, allowing an unauthenticated attacker to export system logs.

    Published: 13 Oct 2021
    5.4
    Medium

    CVE-2021-20128

    Last Modified: 21 Nov 2024

    The Profile Name field in the floor plan (Network Menu) page in Draytek VigorConnect 1.6.0-B3 was found to be vulnerable to stored XSS, as user input is not properly sanitized.

    Published: 13 Oct 2021
    8.1
    High

    CVE-2021-20127

    Last Modified: 21 Nov 2024

    An arbitrary file deletion vulnerability exists in the file delete functionality of the Html5Servlet endpoint of Draytek VigorConnect 1.6.0-B3. This allows an authenticated user to arbitrarily delete files in any location on the target operating system with root privileges.

    Published: 13 Oct 2021
    8.8
    High

    CVE-2021-20126

    Last Modified: 21 Nov 2024

    Draytek VigorConnect 1.6.0-B3 lacks cross-site request forgery protections and does not sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

    Published: 13 Oct 2021
    9.8
    Critical

    CVE-2021-20125

    Last Modified: 21 Nov 2024

    An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek VigorConnect 1.6.0-B3. An unauthenticated attacker could leverage this vulnerability to upload files to any location on the target operating system with root privileges.

    Published: 13 Oct 2021
    7.5
    High

    CVE-2021-20124

    Last Modified: 3 Nov 2025

    A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

    Published: 13 Oct 2021
    7.5
    High

    CVE-2021-20123

    Last Modified: 3 Nov 2025

    A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

    Published: 13 Oct 2021