CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-37919

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

    Published: 7 Oct 2021
    9.8
    Critical

    CVE-2021-37920

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

    Published: 7 Oct 2021
    9.8
    Critical

    CVE-2021-37921

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

    Published: 7 Oct 2021
    9.8
    Critical

    CVE-2021-37923

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

    Published: 7 Oct 2021
    9.8
    Critical

    CVE-2021-37924

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

    Published: 7 Oct 2021
    5.3
    Medium

    CVE-2021-37922

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to path traversal which allows copying of files from one directory to another.

    Published: 7 Oct 2021
    9.8
    Critical

    CVE-2021-37918

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

    Published: 7 Oct 2021
    9.8
    Critical

    CVE-2021-37931

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

    Published: 7 Oct 2021
    9.8
    Critical

    CVE-2021-37930

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

    Published: 7 Oct 2021
    9.8
    Critical

    CVE-2021-37929

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

    Published: 7 Oct 2021
    9.8
    Critical

    CVE-2021-37928

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

    Published: 7 Oct 2021
    9.8
    Critical

    CVE-2021-37926

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

    Published: 7 Oct 2021
    5.4
    Medium

    CVE-2021-3834

    Last Modified: 21 Nov 2024

    Integria IMS in its 5.0.92 version does not filter correctly some fields related to the login.php file. An attacker could exploit this vulnerability in order to perform a cross-site scripting attack (XSS).

    Published: 7 Oct 2021
    9.8
    Critical

    CVE-2021-3833

    Last Modified: 21 Nov 2024

    Integria IMS login check uses a loose comparator ("==") to compare the MD5 hash of the password provided by the user and the MD5 hash stored in the database. An attacker with a specific formatted password could exploit this vulnerability in order to login in the system with different passwords.

    Published: 7 Oct 2021
    7.8
    High

    CVE-2021-40725

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability when processing AcroForm listbox that could result in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

    Published: 7 Oct 2021
    7.8
    High

    CVE-2021-40726

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability when processing AcroForm field that could result in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

    Published: 7 Oct 2021
    7.5
    High

    CVE-2021-41794

    Last Modified: 21 Nov 2024

    ogs_fqdn_parse in Open5GS 1.0.0 through 2.3.3 inappropriately trusts a client-supplied length value, leading to a buffer overflow. The attacker can send a PFCP Session Establishment Request with "internet" as the PDI Network Instance. The first character is interpreted as a length value to be used in a memcpy call. The destination buffer is only 100 bytes long on the stack. Then, 'i' gets interpreted as 105 bytes to copy from the source buffer to the destination buffer.

    Published: 7 Oct 2021
    8.8
    High

    CVE-2021-33903

    Last Modified: 21 Nov 2024

    In LCOS 10.40 to 10.42.0473-RU3 with SNMPv3 enabled on LANCOM devices, changing the password of the root user via the CLI does not change the password of the root user for SNMPv3 access. (However, changing the password of the root user via LANconfig does change the password of the root user for SNMPv3 access.)

    Published: 7 Oct 2021
    8.1
    High

    CVE-2021-35067

    Last Modified: 21 Nov 2024

    Meross MSG100 devices before 3.2.3 allow an attacker to replay the same data or similar data (e.g., an attacker who sniffs a Close message can transmit an acceptable Open message).

    Published: 7 Oct 2021
    4.3
    Medium

    CVE-2021-28661

    Last Modified: 21 Nov 2024

    Default SilverStripe GraphQL Server (aka silverstripe/graphql) 3.x through 3.4.1 permission checker not inherited by query subclass.

    Published: 7 Oct 2021
    6.1
    Medium

    CVE-2021-36150

    Last Modified: 21 Nov 2024

    SilverStripe Framework through 4.8.1 allows XSS.

    Published: 7 Oct 2021
    9.8
    Critical

    CVE-2021-22958

    Last Modified: 21 Nov 2024

    A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP address to bypass the limitations in place for localhost allowing interaction with local services. Impact can vary depending on services exposed.CVSSv2.0 AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N

    Published: 7 Oct 2021
    9.8
    Critical

    CVE-2021-3832

    Last Modified: 21 Nov 2024

    Integria IMS in its 5.0.92 version is vulnerable to a Remote Code Execution attack through file uploading. An unauthenticated attacker could abuse the AsyncUpload() function in order to exploit the vulnerability.

    Published: 7 Oct 2021
    —
    Unknown

    CVE-2021-20602

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 7 Oct 2021
    —
    Unknown

    CVE-2021-20605

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 7 Oct 2021
    —
    Unknown

    CVE-2021-20604

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 7 Oct 2021
    7.5
    High

    CVE-2021-40978

    Last Modified: 21 Nov 2024

    The mkdocs 1.2.2 built-in dev-server allows directory traversal using the port 8000, enabling remote exploitation to obtain :sensitive information. NOTE: the vendor has disputed this as described in https://github.com/mkdocs/mkdocs/issues/2601.] and https://github.com/nisdn/CVE-2021-40978/issues/1

    Published: 7 Oct 2021
    —
    Unknown

    CVE-2021-20603

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 7 Oct 2021
    9.8
    Critical

    CVE-2021-32172

    Last Modified: 21 Nov 2024

    Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin.

    Published: 7 Oct 2021
    7.5
    High

    CVE-2021-41770

    Last Modified: 21 Nov 2024

    Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.

    Published: 7 Oct 2021
    7.5
    High

    CVE-2021-42054

    Last Modified: 21 Nov 2024

    ACCEL-PPP 1.12.0 has an out-of-bounds read in triton_context_schedule if the client exits after authentication.

    Published: 7 Oct 2021
    5.4
    Medium

    CVE-2021-42053

    Last Modified: 21 Nov 2024

    The Unicorn framework through 0.35.3 for Django allows XSS via component.name.

    Published: 7 Oct 2021
    7.8
    High

    CVE-2021-26557

    Last Modified: 21 Nov 2024

    When Octopus Tentacle is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileged access.

    Published: 7 Oct 2021
    7.8
    High

    CVE-2021-26556

    Last Modified: 21 Nov 2024

    When Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileged access.

    Published: 7 Oct 2021
    7.8
    High

    CVE-2021-3872

    Last Modified: 3 Nov 2025

    vim is vulnerable to Heap-based Buffer Overflow

    Published: 7 Oct 2021
    7.8
    High

    CVE-2021-20319

    Last Modified: 21 Nov 2024

    An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image signature verification and as a consequence can lead to the installation of unsigned content. An attacker able to modify the original installation image can write arbitrary data, and achieve full access to the node being installed.

    Published: 7 Oct 2021
    5.5
    Medium

    CVE-2021-42715

    Last Modified: 21 Nov 2024

    An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines as an infinite sequence of zero-length runs. An attacker could potentially have caused denial of service in applications using stb_image by submitting crafted HDR files.

    Published: 7 Oct 2021
    9.8
    Critical

    CVE-2021-38297

    Last Modified: 21 Nov 2024

    Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM module, when GOARCH=wasm GOOS=js is used.

    Published: 7 Oct 2021
    6.5
    Medium

    CVE-2021-41865

    Last Modified: 21 Nov 2024

    HashiCorp Nomad and Nomad Enterprise 1.1.1 through 1.1.5 allowed authenticated users with job submission capabilities to cause denial of service by submitting incomplete job specifications with a Consul mesh gateway and host networking mode. Fixed in 1.1.6.

    Published: 7 Oct 2021
    9.8
    Critical

    CVE-2021-42013

    Last Modified: 27 Oct 2025

    It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue only affects Apache 2.4.49 and Apache 2.4.50 and not earlier versions.

    Published: 7 Oct 2021
    7.8
    High

    CVE-2021-0707

    Last Modified: 21 Nov 2024

    In dma_buf_release of dma-buf.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-155756045References: Upstream kernel

    Published: 7 Oct 2021
    6.5
    Medium

    CVE-2021-21683

    Last Modified: 21 Nov 2024

    The file browser in Jenkins 2.314 and earlier, LTS 2.303.1 and earlier may interpret some paths to files as absolute on Windows, resulting in a path traversal vulnerability allowing attackers with Overall/Read permission (Windows controller) or Job/Workspace permission (Windows agents) to obtain the contents of arbitrary files.

    Published: 6 Oct 2021
    4.3
    Medium

    CVE-2021-21682

    Last Modified: 21 Nov 2024

    Jenkins 2.314 and earlier, LTS 2.303.1 and earlier accepts names of jobs and other entities with a trailing dot character, potentially replacing the configuration and data of other entities on Windows.

    Published: 6 Oct 2021
    6.5
    Medium

    CVE-2020-21658

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) in WDJA CMS v1.5.2 allows attackers to arbitrarily add administrator accounts via a crafted URL.

    Published: 6 Oct 2021
    5.4
    Medium

    CVE-2020-21656

    Last Modified: 21 Nov 2024

    XYHCMS v3.6 contains a stored cross-site scripting (XSS) vulnerability in the component xyhai.php?s=/Link/index.

    Published: 6 Oct 2021
    7.2
    High

    CVE-2020-21654

    Last Modified: 21 Nov 2024

    emlog v6.0 contains a vulnerability in the component admin\template.php, which allows attackers to getshell via a crafted Zip file.

    Published: 6 Oct 2021
    9.1
    Critical

    CVE-2020-21653

    Last Modified: 21 Nov 2024

    Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploited via the sj() method.

    Published: 6 Oct 2021
    9.8
    Critical

    CVE-2020-21652

    Last Modified: 21 Nov 2024

    Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the addqq() method.

    Published: 6 Oct 2021
    9.8
    Critical

    CVE-2020-21651

    Last Modified: 21 Nov 2024

    Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\point.php, which can be exploited via the add() method.

    Published: 6 Oct 2021
    8.8
    High

    CVE-2020-21650

    Last Modified: 21 Nov 2024

    Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the add() method.

    Published: 6 Oct 2021