CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-41828

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials associated with resetPWD.xml.

    Published: 30 Sept 2021
    7.5
    High

    CVE-2021-41829

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Remote Access Plus before 10.1.2121.1 relies on the application's build number to calculate a certain encryption key.

    Published: 30 Sept 2021
    9.8
    Critical

    CVE-2020-18683

    Last Modified: 21 Nov 2024

    Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of undefined fields mishandling.

    Published: 30 Sept 2021
    9.8
    Critical

    CVE-2020-18685

    Last Modified: 21 Nov 2024

    Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of unchecked prerequisites related to TCP or UDP ports, or group or table IDs.

    Published: 30 Sept 2021
    9.8
    Critical

    CVE-2020-18684

    Last Modified: 21 Nov 2024

    Floodlight through 1.2 has an integer overflow in checkFlow in StaticFlowEntryPusherResource.java via priority or port number.

    Published: 30 Sept 2021
    9.1
    Critical

    CVE-2021-4048

    Last Modified: 21 Nov 2024

    An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application using lapack to crash or possibly disclose portions of its memory.

    Published: 30 Sept 2021
    7.5
    High

    CVE-2021-41799

    Last Modified: 21 Nov 2024

    MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). ApiQueryBacklinks (action=query&list=backlinks) can cause a full table scan.

    Published: 30 Sept 2021
    7.8
    High

    CVE-2021-41864

    Last Modified: 21 Nov 2024

    prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write.

    Published: 30 Sept 2021
    6.1
    Medium

    CVE-2021-41798

    Last Modified: 21 Nov 2024

    MediaWiki before 1.36.2 allows XSS. Month related MediaWiki messages are not escaped before being used on the Special:Search results page.

    Published: 30 Sept 2021
    5.3
    Medium

    CVE-2021-41800

    Last Modified: 21 Nov 2024

    MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). Visiting Special:Contributions can sometimes result in a long running SQL query because PoolCounter protection is mishandled.

    Published: 30 Sept 2021
    6.1
    Medium

    CVE-2021-41826

    Last Modified: 21 Nov 2024

    PlaceOS Authentication Service before 1.29.10.0 allows app/controllers/auth/sessions_controller.rb open redirect.

    Published: 29 Sept 2021
    8.8
    High

    CVE-2021-41824

    Last Modified: 21 Nov 2024

    Craft CMS before 3.7.14 allows CSV injection.

    Published: 29 Sept 2021
    6.5
    Medium

    CVE-2021-41821

    Last Modified: 21 Nov 2024

    Wazuh Manager in Wazuh through 4.1.5 is affected by a remote Integer Underflow vulnerability that might lead to denial of service. A crafted message must be sent from an authenticated agent to the manager.

    Published: 29 Sept 2021
    5.4
    Medium

    CVE-2020-20781

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in /ucms/index.php?do=list_edit of UCMS 1.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the title, key words, description or content text fields.

    Published: 29 Sept 2021
    8.1
    High

    CVE-2021-41034

    Last Modified: 21 Nov 2024

    The build of some language stacks of Eclipse Che version 6 includes pulling some binaries from an unsecured HTTP endpoint. As a consequence the builds of such stacks are vulnerable to MITM attacks that allow the replacement of the original binaries with arbitrary ones. The stacks involved are Java 8 (alpine and centos), Android and PHP. The vulnerability is not exploitable at runtime but only when building Che.

    Published: 29 Sept 2021
    5.4
    Medium

    CVE-2020-20131

    Last Modified: 21 Nov 2024

    LaraCMS v1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows atackers to execute arbitrary web scripts or HTML via a crafted payload in the page management module.

    Published: 29 Sept 2021
    5.4
    Medium

    CVE-2020-20129

    Last Modified: 21 Nov 2024

    LaraCMS v1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the content editor.

    Published: 29 Sept 2021
    7.5
    High

    CVE-2020-20128

    Last Modified: 21 Nov 2024

    LaraCMS v1.0.1 transmits sensitive information in cleartext which can be intercepted by attackers.

    Published: 29 Sept 2021
    6.5
    Medium

    CVE-2021-41795

    Last Modified: 21 Nov 2024

    The Safari app extension bundled with 1Password for Mac 7.7.0 through 7.8.x before 7.8.7 is vulnerable to authorization bypass. By targeting a vulnerable component of this extension, a malicious web page could read a subset of 1Password vault items that would normally be fillable by the user on that web page. These items are usernames and passwords for vault items associated with its domain, usernames and passwords without a domain association, credit cards, and contact items. (1Password must be unlocked for these items to be accessible, but no further user interaction is required.)

    Published: 29 Sept 2021
    5.3
    Medium

    CVE-2021-39342

    Last Modified: 31 Mar 2025

    The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaintext via an AJAX action whenever a site user goes to checkout on a page that has the Credova Financing option enabled. This affects versions up to, and including, 1.4.8.

    Published: 29 Sept 2021
    10
    Critical

    CVE-2020-12030

    Last Modified: 21 Nov 2024

    There is a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled. If a user enables the VLAN setting, the internal gateway firewall becomes disabled resulting in exposure of all ports used by the gateway.

    Published: 29 Sept 2021
    7.5
    High

    CVE-2021-35944

    Last Modified: 21 Nov 2024

    Couchbase Server 6.5.x, 6.6.x through 6.6.2, and 7.0.0 has a Buffer Overflow. A specially crafted network packet sent from an attacker can crash memcached.

    Published: 29 Sept 2021
    9.8
    Critical

    CVE-2021-35943

    Last Modified: 21 Nov 2024

    Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password, per RFC4513.

    Published: 29 Sept 2021
    7.5
    High

    CVE-2021-35945

    Last Modified: 21 Nov 2024

    Couchbase Server 6.5.x, 6.6.0 through 6.6.2, and 7.0.0, has a Buffer Overflow. A specially crafted network packet sent from an attacker can crash memcached.

    Published: 29 Sept 2021
    8.8
    High

    CVE-2021-41764

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability exists in Streama up to and including v1.10.3. The application does not have CSRF checks in place when performing actions such as uploading local files. As a result, attackers could make a logged-in administrator upload arbitrary local files via a CSRF attack and send them to the attacker.

    Published: 29 Sept 2021
    7.5
    High

    CVE-2021-41732

    Last Modified: 21 Nov 2024

    An issue was discovered in zeek version 4.1.0. There is a HTTP request splitting vulnerability that will invalidate any ZEEK HTTP based security analysis. NOTE: the vendor's position is that the observed behavior is intended

    Published: 29 Sept 2021
    7.5
    High

    CVE-2021-41573

    Last Modified: 21 Nov 2024

    Hitachi Content Platform Anywhere (HCP-AW) 4.4.5 and later allows information disclosure. If authenticated user creates a link to a file or folder while the system was running version 4.3.x or earlier and then shares the link and then later deletes the file or folder without deleting the link and before the link expires. If the system has been upgraded to version 4.4.5 or 4.5.0 a malicious user with the link could browse and download all files of the authenticated user that created the link .

    Published: 29 Sept 2021
    7.5
    High

    CVE-2021-23446

    Last Modified: 21 Nov 2024

    The package handsontable before 10.0.0; the package handsontable from 0 and before 10.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) in Handsontable.helper.isNumeric function.

    Published: 29 Sept 2021
    5.4
    Medium

    CVE-2021-29834

    Last Modified: 21 Nov 2024

    IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3,20.0.0.1, 20.0.0.2, and 21.0.2 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204832.

    Published: 29 Sept 2021
    7.8
    High

    CVE-2021-28547

    Last Modified: 23 Apr 2025

    Adobe Creative Cloud Desktop Application for macOS version 5.3 (and earlier) is affected by a privilege escalation vulnerability that could allow a normal user to delete the OOBE directory and get permissions of any directory under the administrator authority.

    Published: 29 Sept 2021
    5.5
    Medium

    CVE-2021-40716

    Last Modified: 3 Nov 2025

    XMP Toolkit SDK versions 2021.07 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 29 Sept 2021
    7.8
    High

    CVE-2021-40710

    Last Modified: 21 Nov 2024

    Adobe Premiere Pro version 15.4 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .svg file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must open a specially crafted file to exploit this vulnerability.

    Published: 29 Sept 2021
    3.3
    Low

    CVE-2021-40697

    Last Modified: 23 Apr 2025

    Adobe Framemaker versions 2019 Update 8 (and earlier) and 2020 Release Update 2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 29 Sept 2021
    7.8
    High

    CVE-2021-39863

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Buffer Overflow vulnerability when parsing a specially crafted PDF file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 29 Sept 2021
    7.8
    High

    CVE-2021-40715

    Last Modified: 21 Nov 2024

    Adobe Premiere Pro version 15.4 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .exr file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must open a specially crafted file to exploit this vulnerability.

    Published: 29 Sept 2021
    3.3
    Low

    CVE-2021-39862

    Last Modified: 21 Nov 2024

    Adobe Framemaker versions 2019 Update 8 (and earlier) and 2020 Release Update 2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 29 Sept 2021
    7.3
    High

    CVE-2021-40708

    Last Modified: 21 Nov 2024

    Adobe Genuine Service versions 7.3 (and earlier) are affected by a privilege escalation vulnerability in the AGSService installer. An authenticated attacker could leverage this vulnerability to achieve read / write privileges to execute arbitrary code. User interaction is required to abuse this vulnerability.

    Published: 29 Sept 2021
    3.3
    Low

    CVE-2021-39865

    Last Modified: 21 Nov 2024

    Adobe Framemaker versions 2019 Update 8 (and earlier) and 2020 Release Update 2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 29 Sept 2021
    3.3
    Low

    CVE-2021-39858

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 29 Sept 2021
    5.5
    Medium

    CVE-2021-39861

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 29 Sept 2021
    6.5
    Medium

    CVE-2021-39856

    Last Modified: 21 Nov 2024

    Acrobat Reader DC ActiveX Control versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to obtain NTLMv2 credentials. Exploitation of this issue requires user interaction in that a victim must visit an attacker controlled web page.

    Published: 29 Sept 2021
    5.5
    Medium

    CVE-2021-39860

    Last Modified: 21 Nov 2024

    Acrobat Pro DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive user memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 29 Sept 2021
    5.5
    Medium

    CVE-2021-39854

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 29 Sept 2021
    6.5
    Medium

    CVE-2021-39855

    Last Modified: 21 Nov 2024

    Acrobat Reader DC ActiveX Control versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to obtain NTLMv2 credentials. Exploitation of this issue requires user interaction in that a victim must open a maliciously crafted Microsoft Office file, or visit an attacker controlled web page.

    Published: 29 Sept 2021
    5.5
    Medium

    CVE-2021-39849

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 29 Sept 2021
    4.3
    Medium

    CVE-2021-39857

    Last Modified: 23 Apr 2025

    Adobe Acrobat Reader DC add-on for Internet Explorer versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to check for existence of local files. Exploitation of this issue requires user interaction in that a victim must visit an attacker controlled web page.

    Published: 29 Sept 2021
    5.5
    Medium

    CVE-2021-39850

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 29 Sept 2021
    5.5
    Medium

    CVE-2021-39852

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 29 Sept 2021
    6.1
    Medium

    CVE-2021-39846

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a stack overflow vulnerability due to insecure handling of a crafted PDF file, potentially resulting in memory corruption in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted PDF file in Acrobat Reader.

    Published: 29 Sept 2021
    5.5
    Medium

    CVE-2021-39851

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 29 Sept 2021