CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2021-41563

    Last Modified: 21 Nov 2024

    Tad Book3 editing book function does not filter special characters. Unauthenticated attackers can remotely inject JavaScript syntax and execute stored XSS attacks.

    Published: 8 Oct 2021
    5.3
    Medium

    CVE-2021-41825

    Last Modified: 21 Nov 2024

    Verint Workforce Optimization (WFO) 15.2.5.1033 allows HTML injection via the /wfo/control/signin username parameter.

    Published: 8 Oct 2021
    6.5
    Medium

    CVE-2021-3312

    Last Modified: 21 Nov 2024

    An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfiltrate files from the server's file system by uploading a crafted SVG document.

    Published: 8 Oct 2021
    9.8
    Critical

    CVE-2021-36767

    Last Modified: 21 Nov 2024

    In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making the protection ineffective. An attacker may send an unauthenticated request to the server. The server will reply with a weakly-hashed version of the server's access password. The attacker may then crack this hash offline in order to successfully login to the server.

    Published: 8 Oct 2021
    8.1
    High

    CVE-2021-35979

    Last Modified: 21 Nov 2024

    An issue was discovered in Digi RealPort through 4.8.488.0. The 'encrypted' mode is vulnerable to man-in-the-middle attacks and does not perform authentication.

    Published: 8 Oct 2021
    9.8
    Critical

    CVE-2021-35977

    Last Modified: 21 Nov 2024

    An issue was discovered in Digi RealPort for Windows through 4.8.488.0. A buffer overflow exists in the handling of ADDP discovery response messages. This could result in arbitrary code execution.

    Published: 8 Oct 2021
    7.2
    High

    CVE-2021-41947

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists in Subrion CMS v4.2.1 in the visual-mode.

    Published: 8 Oct 2021
    5.5
    Medium

    CVE-2021-40832

    Last Modified: 21 Nov 2024

    A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVRDL unpacking module component used in certain F-Secure products can crash while scanning a fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine.

    Published: 8 Oct 2021
    5.5
    Medium

    CVE-2021-33603

    Last Modified: 21 Nov 2024

    A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVPACK module component used in certain F-Secure products can crash while scanning a fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine.

    Published: 8 Oct 2021
    8.8
    High

    CVE-2021-41133

    Last Modified: 21 Nov 2024

    Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.4 and 1.12.0, Flatpak apps with direct access to AF_UNIX sockets such as those used by Wayland, Pipewire or pipewire-pulse can trick portals and other host-OS services into treating the Flatpak app as though it was an ordinary, non-sandboxed host-OS process. They can do this by manipulating the VFS using recent mount-related syscalls that are not blocked by Flatpak's denylist seccomp filter, in order to substitute a crafted `/.flatpak-info` or make that file disappear entirely. Flatpak apps that act as clients for AF_UNIX sockets such as those used by Wayland, Pipewire or pipewire-pulse can escalate the privileges that the corresponding services will believe the Flatpak app has. Note that protocols that operate entirely over the D-Bus session bus (user bus), system bus or accessibility bus are not affected by this. This is due to the use of a proxy process `xdg-dbus-proxy`, whose VFS cannot be manipulated by the Flatpak app, when interacting with these buses. Patches exist for versions 1.10.4 and 1.12.0, and as of time of publication, a patch for version 1.8.2 is being planned. There are no workarounds aside from upgrading to a patched version.

    Published: 8 Oct 2021
    8.8
    High

    CVE-2021-30632

    Last Modified: 24 Oct 2025

    Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 8 Oct 2021
    2.9
    Low

    CVE-2021-41802

    Last Modified: 21 Nov 2024

    HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault Enterprise 1.7.5 and 1.8.4.

    Published: 8 Oct 2021
    8.8
    High

    CVE-2021-37975

    Last Modified: 24 Oct 2025

    Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 8 Oct 2021
    6
    Medium

    CVE-2021-25271

    Last Modified: 21 Nov 2024

    A local attacker could read or write arbitrary files with administrator privileges in HitmanPro before version Build 318.

    Published: 7 Oct 2021
    6.7
    Medium

    CVE-2021-25270

    Last Modified: 21 Nov 2024

    A local attacker could execute arbitrary code with administrator privileges in HitmanPro.Alert before version Build 901.

    Published: 7 Oct 2021
    4.3
    Medium

    CVE-2021-41115

    Last Modified: 21 Nov 2024

    Zulip is an open source team chat server. In affected versions Zulip allows organization administrators on a server to configure "linkifiers" that automatically create links from messages that users send, detected via arbitrary regular expressions. Malicious organization administrators could subject the server to a denial-of-service via regular expression complexity attacks; most simply, by configuring a quadratic-time regular expression in a linkifier, and sending messages that exploited it. A regular expression attempted to parse the user-provided regexes to verify that they were safe from ReDoS -- this was both insufficient, as well as _itself_ subject to ReDoS if the organization administrator entered a sufficiently complex invalid regex. Affected users should [upgrade to the just-released Zulip 4.7](https://zulip.readthedocs.io/en/latest/production/upgrade-or-modify.html#upgrading-to-a-release), or [`main`](https://zulip.readthedocs.io/en/latest/production/upgrade-or-modify.html#upgrading-from-a-git-repository).

    Published: 7 Oct 2021
    9.8
    Critical

    CVE-2021-38298

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.

    Published: 7 Oct 2021
    5.4
    Medium

    CVE-2020-21729

    Last Modified: 21 Nov 2024

    JEECMS x1.1 contains a stored cross-site scripting (XSS) vulnerability in the component of /member-vipcenter.htm, which allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Published: 7 Oct 2021
    9.8
    Critical

    CVE-2020-21726

    Last Modified: 21 Nov 2024

    OpenSNS v6.1.0 contains a blind SQL injection vulnerability in /Controller/ChinaCityController.class.php via the cid parameter.

    Published: 7 Oct 2021
    9.8
    Critical

    CVE-2020-21725

    Last Modified: 21 Nov 2024

    OpenSNS v6.1.0 contains a blind SQL injection vulnerability in /Controller/ChinaCityController.class.php via the pid parameter.

    Published: 7 Oct 2021
    7.5
    High

    CVE-2021-42095

    Last Modified: 21 Nov 2024

    Xshell before 7.0.0.76 allows attackers to cause a crash by triggering rapid changes to the title bar.

    Published: 7 Oct 2021
    9.8
    Critical

    CVE-2020-21865

    Last Modified: 21 Nov 2024

    ThinkPHP50-CMS v1.0 contains a remote code execution (RCE) vulnerability in the component /public/?s=captcha.

    Published: 7 Oct 2021
    6.5
    Medium

    CVE-2021-42084

    Last Modified: 21 Nov 2024

    An issue was discovered in Zammad before 4.1.1. An attacker with valid agent credentials may send a series of crafted requests that cause an endless loop and thus cause denial of service.

    Published: 7 Oct 2021
    5.4
    Medium

    CVE-2021-42085

    Last Modified: 21 Nov 2024

    An issue was discovered in Zammad before 4.1.1. There is stored XSS via a custom Avatar.

    Published: 7 Oct 2021
    8.8
    High

    CVE-2021-42086

    Last Modified: 21 Nov 2024

    An issue was discovered in Zammad before 4.1.1. An Agent account can modify account data, and gain admin access, via a crafted request.

    Published: 7 Oct 2021
    4.9
    Medium

    CVE-2021-42087

    Last Modified: 21 Nov 2024

    An issue was discovered in Zammad before 4.1.1. An admin can discover the application secret via the API.

    Published: 7 Oct 2021
    6.1
    Medium

    CVE-2021-42088

    Last Modified: 21 Nov 2024

    An issue was discovered in Zammad before 4.1.1. The Chat functionality allows XSS because clipboard data is mishandled.

    Published: 7 Oct 2021
    7.5
    High

    CVE-2021-42089

    Last Modified: 21 Nov 2024

    An issue was discovered in Zammad before 4.1.1. The REST API discloses sensitive information.

    Published: 7 Oct 2021
    9.8
    Critical

    CVE-2021-42090

    Last Modified: 21 Nov 2024

    An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.

    Published: 7 Oct 2021
    9.1
    Critical

    CVE-2021-42091

    Last Modified: 21 Nov 2024

    An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration.

    Published: 7 Oct 2021
    5.4
    Medium

    CVE-2021-42092

    Last Modified: 21 Nov 2024

    An issue was discovered in Zammad before 4.1.1. Stored XSS may occur via an Article during addition of an attachment to a Ticket.

    Published: 7 Oct 2021
    7.2
    High

    CVE-2021-42093

    Last Modified: 21 Nov 2024

    An issue was discovered in Zammad before 4.1.1. An admin can execute code on the server via a crafted request that manipulates triggers.

    Published: 7 Oct 2021
    9.8
    Critical

    CVE-2021-42094

    Last Modified: 21 Nov 2024

    An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.

    Published: 7 Oct 2021
    6.4
    Medium

    CVE-2021-41130

    Last Modified: 21 Nov 2024

    Extensible Service Proxy, a.k.a. ESP is a proxy which enables API management capabilities for JSON/REST or gRPC API services. ESPv1 can be configured to authenticate a JWT token. Its verified JWT claim is passed to the application by HTTP header "X-Endpoint-API-UserInfo", the application can use it to do authorization. But if there are two "X-Endpoint-API-UserInfo" headers from the client, ESPv1 only replaces the first one, the 2nd one will be passed to the application. An attacker can send two "X-Endpoint-API-UserInfo" headers, the second one with a fake JWT claim. Application may use the fake JWT claim to do the authorization. This impacts following ESPv1 usages: 1) Users have configured ESPv1 to do JWT authentication with Google ID Token as described in the referenced google endpoint document. 2) Users backend application is using the info in the "X-Endpoint-API-UserInfo" header to do the authorization. It has been fixed by v1.58.0. You need to patch it in the following ways: * If your docker image is using tag ":1", needs to re-start the container to pick up the new version. The tag ":1" will automatically point to the latest version. * If your docker image tag pings to a specific minor version, e.g. ":1.57". You need to update it to ":1.58" and re-start the container. There are no workaround for this issue.

    Published: 7 Oct 2021
    4.3
    Medium

    CVE-2021-29700

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authneticated attacker to obtain sensitive information from configuration files that could aid in further attacks against the system. IBM X-Force ID: 200656.

    Published: 7 Oct 2021
    7.5
    High

    CVE-2021-20584

    Last Modified: 21 Nov 2024

    IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote attacker to upload arbitrary files, caused by improper access controls. IBM X-Force ID: 199397.

    Published: 7 Oct 2021
    5.4
    Medium

    CVE-2021-20571

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator 5.2.0.0 through 6.1.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199246.

    Published: 7 Oct 2021
    6.1
    Medium

    CVE-2021-20561

    Last Modified: 21 Nov 2024

    IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199230.

    Published: 7 Oct 2021
    4.3
    Medium

    CVE-2021-20552

    Last Modified: 21 Nov 2024

    IBM Sterling File Gateway 6.0.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 199170.

    Published: 7 Oct 2021
    8.8
    High

    CVE-2021-20489

    Last Modified: 21 Nov 2024

    IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 197790.

    Published: 7 Oct 2021
    6.1
    Medium

    CVE-2021-20481

    Last Modified: 21 Nov 2024

    IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 197503.

    Published: 7 Oct 2021
    6.5
    Medium

    CVE-2021-20473

    Last Modified: 21 Nov 2024

    IBM Sterling File Gateway User Interface 2.2.0.0 through 6.1.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 196944.

    Published: 7 Oct 2021
    4.3
    Medium

    CVE-2021-20376

    Last Modified: 21 Nov 2024

    IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated attacker to enumerate usernames due to there being an observable discrepancy in returned messages. IBM X-Force ID: 195568.

    Published: 7 Oct 2021
    6.5
    Medium

    CVE-2021-20375

    Last Modified: 21 Nov 2024

    IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to intercept and replace a message sent by another user due to improper access controls. IBM X-Force ID: 195567.

    Published: 7 Oct 2021
    4.3
    Medium

    CVE-2021-20372

    Last Modified: 21 Nov 2024

    IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote authenticated user to cause a denial of another user's service due to insufficient permission checking. IBM X-Force ID: 195518.

    Published: 7 Oct 2021
    5.4
    Medium

    CVE-2021-23447

    Last Modified: 21 Nov 2024

    This affects the package teddy before 0.5.9. A type confusion vulnerability can be used to bypass input sanitization when the model content is an array (instead of a string).

    Published: 7 Oct 2021
    9.8
    Critical

    CVE-2021-42071

    Last Modified: 21 Nov 2024

    In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/login.py User-Agent HTTP header.

    Published: 7 Oct 2021
    6.5
    Medium

    CVE-2021-40439

    Last Modified: 21 Nov 2024

    Apache OpenOffice has a dependency on expat software. Versions prior to 2.1.0 were subject to CVE-2013-0340 a "Billion Laughs" entity expansion denial of service attack and exploit via crafted XML files. ODF files consist of a set of XML files. All versions of Apache OpenOffice up to 4.1.10 are subject to this issue. expat in version 4.1.11 is patched.

    Published: 7 Oct 2021
    7.8
    High

    CVE-2021-28129

    Last Modified: 21 Nov 2024

    While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but instead used a userid and groupid of 500. This both caused issues with desktop integration and could allow a crafted attack on files owned by that user or group if they exist. Users who installed the Apache OpenOffice 4.1.8 DEB packaging should upgrade to the latest version of Apache OpenOffice.

    Published: 7 Oct 2021
    9.8
    Critical

    CVE-2021-37762

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution.

    Published: 7 Oct 2021