CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-25634

    Last Modified: 21 Nov 2024

    LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to modify a digitally signed ODF document to insert an additional signing time timestamp which LibreOffice would incorrectly present as a valid signature signed at the bogus signing time. This issue affects: The Document Foundation LibreOffice 7-0 versions prior to 7.0.6; 7-1 versions prior to 7.1.2.

    Published: 11 Oct 2021
    —
    Unknown

    CVE-2021-42248

    Last Modified: 2 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-42836. Reason: This candidate is a duplicate of CVE-2021-42836. Notes: All CVE users should reference CVE-2021-42836 instead of this candidate.

    Published: 11 Oct 2021
    7.8
    High

    CVE-2021-42252

    Last Modified: 21 Nov 2024

    An issue was discovered in aspeed_lpc_ctrl_mmap in drivers/soc/aspeed/aspeed-lpc-ctrl.c in the Linux kernel before 5.14.6. Local attackers able to access the Aspeed LPC control interface could overwrite memory in the kernel and potentially execute privileges, aka CID-b49a0e69a7b1. This occurs because a certain comparison uses values that are not memory sizes.

    Published: 11 Oct 2021
    5.2
    Medium

    CVE-2021-25635

    Last Modified: 10 Dec 2025

    An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to self sign an ODF document, with a signature untrusted by the target, then modify it to change the signature algorithm to an invalid (or unknown to LibreOffice) algorithm and LibreOffice would incorrectly present such a signature with an unknown algorithm as a valid signature issued by a trusted person This issue affects LibreOffice: from 7.0 before 7.0.5, from 7.1 before 7.1.1.

    Published: 11 Oct 2021
    7.5
    High

    CVE-2021-42260

    Last Modified: 4 Nov 2025

    TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case. It can be triggered by a crafted XML message and leads to a denial of service.

    Published: 11 Oct 2021
    8.8
    High

    CVE-2021-25966

    Last Modified: 30 Apr 2025

    In “Orchard core CMS” application, versions 1.0.0-beta1-3383 to 1.0.0 are vulnerable to an improper session termination after password change. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was changed.

    Published: 10 Oct 2021
    6.5
    Medium

    CVE-2021-37976

    Last Modified: 24 Oct 2025

    Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

    Published: 8 Oct 2021
    8.8
    High

    CVE-2021-37974

    Last Modified: 21 Nov 2024

    Use after free in Safebrowsing in Google Chrome prior to 94.0.4606.71 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

    Published: 8 Oct 2021
    9.6
    Critical

    CVE-2021-37973

    Last Modified: 24 Oct 2025

    Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

    Published: 8 Oct 2021
    4.3
    Medium

    CVE-2021-37971

    Last Modified: 21 Nov 2024

    Incorrect security UI in Web Browser UI in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 8 Oct 2021
    8.8
    High

    CVE-2021-37970

    Last Modified: 21 Nov 2024

    Use after free in File System API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 8 Oct 2021
    7.8
    High

    CVE-2021-37969

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Google Updater in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to perform local privilege escalation via a crafted file.

    Published: 8 Oct 2021
    4.3
    Medium

    CVE-2021-37968

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 8 Oct 2021
    4.3
    Medium

    CVE-2021-37967

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.

    Published: 8 Oct 2021
    4.3
    Medium

    CVE-2021-37966

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Compositing in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 8 Oct 2021
    4.3
    Medium

    CVE-2021-37965

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 8 Oct 2021
    3.3
    Low

    CVE-2021-37964

    Last Modified: 21 Nov 2024

    Inappropriate implementation in ChromeOS Networking in Google Chrome on ChromeOS prior to 94.0.4606.54 allowed an attacker with a rogue wireless access point to to potentially carryout a wifi impersonation attack via a crafted ONC file.

    Published: 8 Oct 2021
    4.3
    Medium

    CVE-2021-37963

    Last Modified: 21 Nov 2024

    Side-channel information leakage in DevTools in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to bypass site isolation via a crafted HTML page.

    Published: 8 Oct 2021
    8.8
    High

    CVE-2021-37962

    Last Modified: 21 Nov 2024

    Use after free in Performance Manager in Google Chrome prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

    Published: 8 Oct 2021
    8.8
    High

    CVE-2021-37961

    Last Modified: 21 Nov 2024

    Use after free in Tab Strip in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 8 Oct 2021
    8.8
    High

    CVE-2021-37959

    Last Modified: 21 Nov 2024

    Use after free in Task Manager in Google Chrome prior to 94.0.4606.54 allowed an attacker who convinced a user to enage in a series of user gestures to potentially exploit heap corruption via a crafted HTML page.

    Published: 8 Oct 2021
    5.4
    Medium

    CVE-2021-37958

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Navigation in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to inject scripts or HTML into a privileged page via a crafted HTML page.

    Published: 8 Oct 2021
    8.8
    High

    CVE-2021-37957

    Last Modified: 21 Nov 2024

    Use after free in WebGPU in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 8 Oct 2021
    8.8
    High

    CVE-2021-37956

    Last Modified: 21 Nov 2024

    Use after free in Offline use in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

    Published: 8 Oct 2021
    9.6
    Critical

    CVE-2021-30633

    Last Modified: 24 Oct 2025

    Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

    Published: 8 Oct 2021
    4.3
    Medium

    CVE-2021-30630

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.

    Published: 8 Oct 2021
    8.8
    High

    CVE-2021-30629

    Last Modified: 21 Nov 2024

    Use after free in Permissions in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

    Published: 8 Oct 2021
    8.8
    High

    CVE-2021-30628

    Last Modified: 21 Nov 2024

    Stack buffer overflow in ANGLE in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page.

    Published: 8 Oct 2021
    8.8
    High

    CVE-2021-30627

    Last Modified: 21 Nov 2024

    Type confusion in Blink layout in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 8 Oct 2021
    8.8
    High

    CVE-2021-30626

    Last Modified: 21 Nov 2024

    Out of bounds memory access in ANGLE in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 8 Oct 2021
    8.8
    High

    CVE-2021-30625

    Last Modified: 21 Nov 2024

    Use after free in Selection API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who convinced the user the visit a malicious website to potentially exploit heap corruption via a crafted HTML page.

    Published: 8 Oct 2021
    6.1
    Medium

    CVE-2021-42112

    Last Modified: 21 Nov 2024

    The "File upload question" functionality in LimeSurvey 3.x-LTS through 3.27.18 allows XSS in assets/scripts/modaldialog.js and assets/scripts/uploader.js.

    Published: 8 Oct 2021
    9.8
    Critical

    CVE-2020-22617

    Last Modified: 21 Nov 2024

    Ardour v5.12 contains a use-after-free vulnerability in the component ardour/libs/pbd/xml++.cc when using xmlFreeDoc and xmlXPathFreeContext.

    Published: 8 Oct 2021
    9.8
    Critical

    CVE-2021-42109

    Last Modified: 21 Nov 2024

    VITEC Exterity IPTV products through 2021-04-30 allow privilege escalation to root.

    Published: 8 Oct 2021
    5.5
    Medium

    CVE-2021-29906

    Last Modified: 21 Nov 2024

    IBM App Connect Enterprise Certified Container 1.0, 1.1, 1.2, 1.3, 1.4 and 1.5 could disclose sensitive information to a local user when it is configured to use an IBM Cloud API key to connect to cloud-based connectors. IBM X-Force ID: 207630.

    Published: 8 Oct 2021
    6.5
    Medium

    CVE-2020-4654

    Last Modified: 21 Nov 2024

    IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensitive information due to improper permission control. IBM X-Force ID: 186090.

    Published: 8 Oct 2021
    5.9
    Medium

    CVE-2021-20600

    Last Modified: 21 Nov 2024

    Uncontrolled resource consumption in Mitsubishi Electric MELSEC iQ-R series C Controller Module R12CCPU-V Firmware Versions "16" and prior allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by sending a large number of packets in a short time while the module starting up. System reset is required for recovery.

    Published: 8 Oct 2021
    7.5
    High

    CVE-2021-41920

    Last Modified: 21 Nov 2024

    webTareas version 2.4 and earlier allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endpoint /includes/library.php, via the sor_cible, sor_champs, and sor_ordre HTTP POST parameters. This allows an attacker to access all the data in the database and obtain access to the webTareas application.

    Published: 8 Oct 2021
    8.8
    High

    CVE-2021-41919

    Last Modified: 21 Nov 2024

    webTareas version 2.4 and earlier allows an authenticated user to arbitrarily upload potentially dangerous files without restrictions. This is working by adding or replacing a personal profile picture. The affected endpoint is /includes/upload.php on the HTTP POST data. This allows an attacker to exploit the platform by injecting code or malware and, under certain conditions, to execute code on remote user browsers.

    Published: 8 Oct 2021
    5.4
    Medium

    CVE-2021-41918

    Last Modified: 21 Nov 2024

    webTareas version 2.4 and earlier allows an authenticated user to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a Reflected Cross-Site Scripting attack against the platform users and administrators. The issue affects every endpoint on the application because it is related on how each URL is echoed back on every response page.

    Published: 8 Oct 2021
    5.4
    Medium

    CVE-2021-41917

    Last Modified: 21 Nov 2024

    webTareas version 2.4 and earlier allows an authenticated user to store arbitrary web script or HTML by creating or editing a client name in the clients section, due to incorrect sanitization of user-supplied data and achieve a Stored Cross-Site Scripting attack against the platform users and administrators. The affected endpoint is /clients/editclient.php, on the HTTP POST cn parameter.

    Published: 8 Oct 2021
    8.8
    High

    CVE-2021-41916

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) vulnerability in webTareas version 2.4 and earlier allows a remote attacker to create a new administrative profile and add a new user to the new profile. without the victim's knowledge, by enticing an authenticated admin user to visit an attacker's web page.

    Published: 8 Oct 2021
    5.3
    Medium

    CVE-2021-41976

    Last Modified: 21 Nov 2024

    Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function to amend the folder names in the book list without logging in.

    Published: 8 Oct 2021
    7.5
    High

    CVE-2021-41975

    Last Modified: 21 Nov 2024

    TadTools special page is vulnerable to authorization bypass, thus remote attackers can use the specific parameter to delete arbitrary files in the system without logging in.

    Published: 8 Oct 2021
    9.1
    Critical

    CVE-2021-41974

    Last Modified: 21 Nov 2024

    Tad Book3 editing book page does not perform identity verification. Remote attackers can use the vulnerability to view and modify arbitrary content of books without permission.

    Published: 8 Oct 2021
    5.3
    Medium

    CVE-2021-41568

    Last Modified: 21 Nov 2024

    Tad Web is vulnerable to authorization bypass, thus remote attackers can exploit the vulnerability to use the original function of viewing bulletin boards and uploading files in the system.

    Published: 8 Oct 2021
    6.1
    Medium

    CVE-2021-41567

    Last Modified: 21 Nov 2024

    The new add subject parameter of Tad Uploader view book list function fails to filter special characters. Unauthenticated attackers can remotely inject JavaScript syntax and execute stored XSS attacks.

    Published: 8 Oct 2021
    9.8
    Critical

    CVE-2021-41566

    Last Modified: 21 Nov 2024

    The file extension of the TadTools file upload function fails to filter, thus remote attackers can upload any types of files and execute arbitrary code without logging in.

    Published: 8 Oct 2021
    6.1
    Medium

    CVE-2021-41565

    Last Modified: 21 Nov 2024

    TadTools special page parameter does not properly restrict the input of specific characters, thus remote attackers can inject JavaScript syntax without logging in, and further perform reflective XSS attacks.

    Published: 8 Oct 2021
    5.3
    Medium

    CVE-2021-41564

    Last Modified: 21 Nov 2024

    Tad Honor viewing book list function is vulnerable to authorization bypass, thus remote attackers can use special parameters to delete articles arbitrarily without logging in.

    Published: 8 Oct 2021