CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2020-21013

    Last Modified: 21 Nov 2024

    emlog v6.0.0 contains a SQL injection via /admin/comment.php.

    Published: 1 Oct 2021
    9.8
    Critical

    CVE-2020-21012

    Last Modified: 21 Nov 2024

    Sourcecodester Hotel and Lodge Management System 2.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the email parameter to the edit page for Customer, Room, Currency, Room Booking Details, or Tax Details.

    Published: 1 Oct 2021
    6.5
    Medium

    CVE-2021-41845

    Last Modified: 21 Nov 2024

    A SQL injection issue was discovered in ThycoticCentrify Secret Server before 11.0.000007. The only affected versions are 10.9.000032 through 11.0.000006.

    Published: 1 Oct 2021
    7.8
    High

    CVE-2021-38103

    Last Modified: 21 Nov 2024

    IBJPG2.FLT in Corel Presentations 2020 20.0.0.200 is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious PPT file.

    Published: 1 Oct 2021
    5.5
    Medium

    CVE-2021-38104

    Last Modified: 21 Nov 2024

    IPPP72.FLT in Corel Presentations 2020 20.0.0.200 is affected by an Out-of-bounds Read vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to access unauthorized system memory in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious PPT file.

    Published: 1 Oct 2021
    7.8
    High

    CVE-2021-38099

    Last Modified: 21 Nov 2024

    CDRRip.dll in Corel PhotoPaint Standard 2020 22.0.0.474 is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious CPT file. This is different from CVE-2021-38101.

    Published: 1 Oct 2021
    7.8
    High

    CVE-2021-38096

    Last Modified: 21 Nov 2024

    Coreip.dll in Corel PDF Fusion 2.6.2.0 is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious PDF file.

    Published: 1 Oct 2021
    7.8
    High

    CVE-2021-38097

    Last Modified: 21 Nov 2024

    Corel PDF Fusion 2.6.2.0 is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious PDF file.

    Published: 1 Oct 2021
    6.1
    Medium

    CVE-2021-41467

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in application/controllers/dropbox.php in JustWriting 1.0.0 and below allow remote attackers to inject arbitrary web script or HTML via the challenge parameter.

    Published: 1 Oct 2021
    6.1
    Medium

    CVE-2021-41464

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the rel parameter.

    Published: 1 Oct 2021
    6.1
    Medium

    CVE-2021-41465

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in concrete/elements/collection_theme.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the rel parameter.

    Published: 1 Oct 2021
    6.1
    Medium

    CVE-2021-41462

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the ctID parameter.

    Published: 1 Oct 2021
    6.1
    Medium

    CVE-2021-41463

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in toos/permissions/dialogs/access/entity/types/group_combination.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the cID parameter.

    Published: 1 Oct 2021
    6.1
    Medium

    CVE-2021-41461

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the mode parameter.

    Published: 1 Oct 2021
    6.1
    Medium

    CVE-2021-40973

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the lastname parameter.

    Published: 1 Oct 2021
    6.1
    Medium

    CVE-2021-40975

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in application/modules/admin/views/ecommerce/products.php in Ecommerce-CodeIgniter-Bootstrap (Codeigniter 3.1.11, Bootstrap 3.3.7) allows remote attackers to inject arbitrary web script or HTML via the search_title parameter.

    Published: 1 Oct 2021
    6.1
    Medium

    CVE-2021-40972

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the mail parameter.

    Published: 1 Oct 2021
    6.1
    Medium

    CVE-2021-40971

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the newpassword1 parameter.

    Published: 1 Oct 2021
    6.1
    Medium

    CVE-2021-40969

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the firstname parameter.

    Published: 1 Oct 2021
    6.1
    Medium

    CVE-2021-40970

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the username parameter.

    Published: 1 Oct 2021
    6.1
    Medium

    CVE-2021-40928

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in index.php in FlexTV beta development version allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF parameter.

    Published: 1 Oct 2021
    6.1
    Medium

    CVE-2021-40968

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the newpassword2 parameter.

    Published: 1 Oct 2021
    6.1
    Medium

    CVE-2021-40926

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in demos/demo.mysqli.php in getID3 1.X and v2.0.0-beta allows remote attackers to inject arbitrary web script or HTML via the showtagfiles parameter.

    Published: 1 Oct 2021
    6.1
    Medium

    CVE-2021-40927

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in callback.php in Spotify-for-Alfred 0.13.9 and below allows remote attackers to inject arbitrary web script or HTML via the error parameter.

    Published: 1 Oct 2021
    6.1
    Medium

    CVE-2021-40924

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in install/index.php in bugs 1.8 and below version allows remote attackers to inject arbitrary web script or HTML via the first_name parameter.

    Published: 1 Oct 2021
    6.1
    Medium

    CVE-2021-40925

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in dompdf/dompdf/www/demo.php infaveo-helpdesk v1.11.0 and below allow remote attackers to inject arbitrary web script or HTML via the $_SERVER["PHP_SELF"] parameter.

    Published: 1 Oct 2021
    6.1
    Medium

    CVE-2021-40923

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in install/index.php in bugs 1.8 and below version allows remote attackers to inject arbitrary web script or HTML via the email parameter.

    Published: 1 Oct 2021
    6.1
    Medium

    CVE-2021-40922

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in install/index.php in bugs 1.8 and below version allows remote attackers to inject arbitrary web script or HTML via the last_name parameter.

    Published: 1 Oct 2021
    6.1
    Medium

    CVE-2021-40921

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in _contactform.inc.php in Detector 0.8.5 and below version allows remote attackers to inject arbitrary web script or HTML via the cid parameter.

    Published: 1 Oct 2021
    5.4
    Medium

    CVE-2021-29110

    Last Modified: 10 Apr 2025

    Stored cross-site scripting (XSS) issue in Esri Portal for ArcGIS may allow a remote unauthenticated attacker to pass and store malicious strings in the home application.

    Published: 1 Oct 2021
    6.1
    Medium

    CVE-2021-29109

    Last Modified: 10 Apr 2025

    A reflected XSS vulnerability in Esri Portal for ArcGIS version 10.9 and below may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the user’s browser.

    Published: 1 Oct 2021
    8.8
    High

    CVE-2021-29108

    Last Modified: 10 Apr 2025

    There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker who is able to intercept and modify a SAML assertion to impersonate another account (XML Signature Wrapping Attack). In addition patching, Esri also strongly recommends as best practice for SAML assertions to be signed and encrypted.

    Published: 1 Oct 2021
    9.6
    Critical

    CVE-2021-3825

    Last Modified: 18 May 2026

    On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to the configurations API could get valid LDAP credentials.

    Published: 1 Oct 2021
    9.1
    Critical

    CVE-2021-41647

    Last Modified: 21 Nov 2024

    An un-authenticated error-based and time-based blind SQL injection vulnerability exists in Kaushik Jadhav Online Food Ordering Web App 1.0. An attacker can exploit the vulnerable "username" parameter in login.php and retrieve sensitive database information, as well as add an administrative user.

    Published: 1 Oct 2021
    7.5
    High

    CVE-2021-41648

    Last Modified: 21 Nov 2024

    An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter. Using a post request does not sanitize the user input.

    Published: 1 Oct 2021
    9.8
    Critical

    CVE-2021-41649

    Last Modified: 21 Nov 2024

    An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.

    Published: 1 Oct 2021
    9.8
    Critical

    CVE-2021-40960

    Last Modified: 21 Nov 2024

    Galera WebTemplate 1.0 is affected by a directory traversal vulnerability that could reveal information from /etc/passwd and /etc/shadow.

    Published: 1 Oct 2021
    7.8
    High

    CVE-2021-35297

    Last Modified: 21 Nov 2024

    Scalabium dBase Viewer version 2.6 (Build 5.751) is vulnerable to remote code execution via a crafted DBF file that triggers a buffer overflow. An attacker can use the Structured Exception Handler (SEH) records and redirect execution to attacker-controlled code.

    Published: 1 Oct 2021
    9.1
    Critical

    CVE-2021-41110

    Last Modified: 21 Nov 2024

    cwlviewer is a web application to view and share Common Workflow Language workflows. Versions prior to 1.3.1 contain a Deserialization of Untrusted Data vulnerability. Commit number f6066f09edb70033a2ce80200e9fa9e70a5c29de (dated 2021-09-30) contains a patch. There are no available workarounds aside from installing the patch. The SnakeYaml constructor, by default, allows any data to be parsed. To fix the issue the object needs to be created with a `SafeConstructor` object, as seen in the patch.

    Published: 1 Oct 2021
    8.8
    High

    CVE-2021-23893

    Last Modified: 21 Nov 2024

    Privilege Escalation vulnerability in a Windows system driver of McAfee Drive Encryption (DE) prior to 7.3.0 could allow a local non-admin user to gain elevated system privileges via exploiting an unutilized memory buffer.

    Published: 1 Oct 2021
    5.4
    Medium

    CVE-2021-38675

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Image2PDF. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Image2PDF: Image2PDF 2.1.5 ( 2021/08/17 ) and later

    Published: 1 Oct 2021
    7.6
    High

    CVE-2021-34356

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.18 ( 2021/09/01 ) and later

    Published: 1 Oct 2021
    7.6
    High

    CVE-2021-34355

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 5.4.10 ( 2021/08/19 ) and later Photo Station 5.7.13 ( 2021/08/19 ) and later Photo Station 6.0.18 ( 2021/09/01 ) and later

    Published: 1 Oct 2021
    7.6
    High

    CVE-2021-34354

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.18 ( 2021/09/01 ) and later

    Published: 1 Oct 2021
    7.2
    High

    CVE-2021-34352

    Last Modified: 21 Nov 2024

    A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.5 build 20210902 and later

    Published: 1 Oct 2021
    8.8
    High

    CVE-2021-3747

    Last Modified: 21 Nov 2024

    The MacOS version of Multipass, version 1.7.0, fixed in 1.7.2, accidentally installed the application directory with incorrect owner.

    Published: 1 Oct 2021
    6.5
    Medium

    CVE-2021-3710

    Last Modified: 21 Nov 2024

    An information disclosure via path traversal was discovered in apport/hookutils.py function read_file(). This issue affects: apport 2.14.1 versions prior to 2.14.1-0ubuntu3.29+esm8; 2.20.1 versions prior to 2.20.1-0ubuntu2.30+esm2; 2.20.9 versions prior to 2.20.9-0ubuntu7.26; 2.20.11 versions prior to 2.20.11-0ubuntu27.20; 2.20.11 versions prior to 2.20.11-0ubuntu65.3;

    Published: 1 Oct 2021
    6.5
    Medium

    CVE-2021-3709

    Last Modified: 21 Nov 2024

    Function check_attachment_for_errors() in file data/general-hooks/ubuntu.py could be tricked into exposing private data via a constructed crash file. This issue affects: apport 2.14.1 versions prior to 2.14.1-0ubuntu3.29+esm8; 2.20.1 versions prior to 2.20.1-0ubuntu2.30+esm2; 2.20.9 versions prior to 2.20.9-0ubuntu7.26; 2.20.11 versions prior to 2.20.11-0ubuntu27.20; 2.20.11 versions prior to 2.20.11-0ubuntu65.3;

    Published: 1 Oct 2021
    8.8
    High

    CVE-2021-3626

    Last Modified: 21 Nov 2024

    The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket to perform mounts from the operating system to a guest, allowing for privilege escalation.

    Published: 1 Oct 2021
    7.8
    High

    CVE-2021-33626

    Last Modified: 11 Aug 2026

    A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer(QWORD values for CommBuffer). This can be used by an attacker to corrupt data in SMRAM memory and even lead to arbitrary code execution.

    Published: 1 Oct 2021