CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2021-39853

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 29 Sept 2021
    6.1
    Medium

    CVE-2021-39845

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a stack overflow vulnerability due to insecure handling of a crafted PDF file, potentially resulting in memory corruption in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted PDF file in Acrobat Reader.

    Published: 29 Sept 2021
    3.3
    Low

    CVE-2021-39844

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 29 Sept 2021
    7.8
    High

    CVE-2021-39843

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 29 Sept 2021
    7.8
    High

    CVE-2021-39842

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 29 Sept 2021
    7.8
    High

    CVE-2021-39841

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Type Confusion vulnerability. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 29 Sept 2021
    7.8
    High

    CVE-2021-39840

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability when processing AcroForms that could result in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

    Published: 29 Sept 2021
    7.8
    High

    CVE-2021-39838

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm buttonGetCaption action that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 29 Sept 2021
    7.8
    High

    CVE-2021-39839

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm getItem action that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 29 Sept 2021
    7.8
    High

    CVE-2021-39837

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm deleteItemAt action that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 29 Sept 2021
    4.3
    Medium

    CVE-2021-39835

    Last Modified: 23 Apr 2025

    Adobe Framemaker versions 2019 Update 8 (and earlier) and 2020 Release Update 2 (and earlier) are affected by a use-after-free vulnerability in the processing of a malformed PDF file that could result in disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious PDF file.

    Published: 29 Sept 2021
    7.8
    High

    CVE-2021-39836

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm buttonGetIcon action that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 29 Sept 2021
    7.8
    High

    CVE-2021-39829

    Last Modified: 23 Apr 2025

    Adobe Framemaker versions 2019 Update 8 (and earlier) and 2020 Release Update 2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious PDF file.

    Published: 29 Sept 2021
    7.8
    High

    CVE-2021-39832

    Last Modified: 23 Apr 2025

    Adobe Framemaker versions 2019 Update 8 (and earlier) and 2020 Release Update 2 (and earlier) are affected by a memory corruption vulnerability due to insecure handling of a malicious PDF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 29 Sept 2021
    3.3
    Low

    CVE-2021-39834

    Last Modified: 23 Apr 2025

    Adobe Framemaker versions 2019 Update 8 (and earlier) and 2020 Release Update 2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious TIF file.

    Published: 29 Sept 2021
    7.8
    High

    CVE-2021-39830

    Last Modified: 23 Apr 2025

    Adobe Framemaker versions 2019 Update 8 (and earlier) and 2020 Release Update 2 (and earlier) are affected by a memory corruption vulnerability due to insecure handling of a malicious PDF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 29 Sept 2021
    3.3
    Low

    CVE-2021-39833

    Last Modified: 23 Apr 2025

    Adobe Framemaker versions 2019 Update 8 (and earlier) and 2020 Release Update 2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious TIF file.

    Published: 29 Sept 2021
    7.8
    High

    CVE-2021-39831

    Last Modified: 23 Apr 2025

    Adobe Framemaker versions 2019 Update 8 (and earlier) and 2020 Release Update 2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious PDF file.

    Published: 29 Sept 2021
    7.8
    High

    CVE-2021-39821

    Last Modified: 23 Apr 2025

    Adobe InDesign versions 16.3 (and earlier), and 16.3.1 (and earlier) are affected by an out-of-bounds read vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious TIF file.

    Published: 29 Sept 2021
    7.3
    High

    CVE-2021-35982

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Uncontrolled Search Path Element vulnerability. A local attacker with non-administrative privileges can plant a malicious DLL to achieve arbitrary code execution in the context of the current user via DLL hijacking. Exploitation of this issue requires user interaction.

    Published: 29 Sept 2021
    8
    High

    CVE-2021-25960

    Last Modified: 21 Nov 2024

    In “SuiteCRM” application, v7.11.18 through v7.11.19 and v7.10.29 through v7.10.31 are affected by “CSV Injection” vulnerability (Formula Injection). A low privileged attacker can use accounts module to inject payloads in the input fields. When an administrator access accounts module to export the data as a CSV file and opens it, the payload gets executed. This was not fixed properly as part of CVE-2020-15301, allowing the attacker to bypass the security measure.

    Published: 29 Sept 2021
    8
    High

    CVE-2021-25962

    Last Modified: 21 Nov 2024

    “Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed.

    Published: 29 Sept 2021
    6.1
    Medium

    CVE-2021-25959

    Last Modified: 21 Nov 2024

    In OpenCRX, versions v4.0.0 through v5.1.0 are vulnerable to reflected Cross-site Scripting (XSS), due to unsanitized parameters in the password reset functionality. This allows execution of external javascript files on any user of the openCRX instance.

    Published: 29 Sept 2021
    8
    High

    CVE-2021-25961

    Last Modified: 21 Nov 2024

    In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset links that is associated with a deleted user id, which makes it possible for account takeover of any newly created user with the same user id.

    Published: 29 Sept 2021
    6.5
    Medium

    CVE-2021-40651

    Last Modified: 21 Nov 2024

    OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary file from the server's filesystem as long as the application has access to the file.

    Published: 29 Sept 2021
    7.3
    High

    CVE-2021-35028

    Last Modified: 21 Nov 2024

    A command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12 could allow an authenticated, local user to execute arbitrary OS commands.

    Published: 29 Sept 2021
    7.5
    High

    CVE-2021-35027

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability in the web server of the Zyxel VPN2S firmware version 1.12 could allow a remote attacker to gain access to sensitive information.

    Published: 29 Sept 2021
    9.8
    Critical

    CVE-2021-36745

    Last Modified: 21 Nov 2024

    A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Network Appliance Filers 5.8, and ServerProtect for Microsoft Windows / Novell Netware 5.8 could allow a remote attacker to bypass authentication on affected installations.

    Published: 29 Sept 2021
    7
    High

    CVE-2021-32466

    Last Modified: 21 Nov 2024

    An uncontrolled search path element privilege escalation vulnerability in Trend Micro HouseCall for Home Networks version 5.3.1225 and below could allow an attacker to escalate privileges by placing a custom crafted file in a specific directory to load a malicious library. Please note that an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.

    Published: 29 Sept 2021
    9.8
    Critical

    CVE-2021-33924

    Last Modified: 21 Nov 2024

    Confluent Ansible (cp-ansible) version 5.5.0, 5.5.1, 5.5.2 and 6.0.0 is vulnerable to Incorrect Access Control via its auxiliary component that allows remote attackers to access sensitive information.

    Published: 29 Sept 2021
    5.5
    Medium

    CVE-2021-33923

    Last Modified: 21 Nov 2024

    Insecure permissions in Confluent Ansible (cp-ansible) 5.5.0, 5.5.1, 5.5.2 and 6.0.0 allows local attackers to access some sensitive information (private keys, state database).

    Published: 29 Sept 2021
    9.8
    Critical

    CVE-2021-41773

    Last Modified: 17 Feb 2026

    A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013.

    Published: 29 Sept 2021
    6.1
    Medium

    CVE-2021-22963

    Last Modified: 21 Nov 2024

    A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbitrary websites via a double slash // followed by a domain: http://localhost:3000//google.com/%2e%2e.The issue shows up on all the fastify-static applications that set redirect: true option. By default, it is false.

    Published: 29 Sept 2021
    7.5
    High

    CVE-2021-3905

    Last Modified: 21 Nov 2024

    A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust available memory by keeping sending packet fragments.

    Published: 29 Sept 2021
    6.8
    Medium

    CVE-2021-4203

    Last Modified: 21 Nov 2024

    A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect()) in the Linux kernel. In this flaw, an attacker with a user privileges may crash the system or leak internal kernel information.

    Published: 29 Sept 2021
    6.1
    Medium

    CVE-2020-20125

    Last Modified: 21 Nov 2024

    EARCLINK ESPCMS-P8 contains a cross-site scripting (XSS) vulnerability in espcms_web\espcms_load.php.

    Published: 28 Sept 2021
    8.8
    High

    CVE-2020-20124

    Last Modified: 5 May 2025

    Wuzhi CMS v4.1.0 contains a remote code execution (RCE) vulnerability in \attachment\admin\index.php.

    Published: 28 Sept 2021
    9.8
    Critical

    CVE-2020-20122

    Last Modified: 5 May 2025

    Wuzhi CMS v4.1 contains a SQL injection vulnerability in the checktitle() function in /coreframe/app/content/admin/content.php.

    Published: 28 Sept 2021
    9.8
    Critical

    CVE-2020-20120

    Last Modified: 21 Nov 2024

    ThinkPHP v3.2.3 and below contains a SQL injection vulnerability which is triggered when the array is not passed to the "where" and "query" methods.

    Published: 28 Sept 2021
    4.4
    Medium

    CVE-2021-41106

    Last Modified: 18 Nov 2025

    JWT is a library to work with JSON Web Token and JSON Web Signature. Prior to versions 3.4.6, 4.0.4, and 4.1.5, users of HMAC-based algorithms (HS256, HS384, and HS512) combined with `Lcobucci\JWT\Signer\Key\LocalFileReference` as key are having their tokens issued/validated using the file path as hashing key - instead of the contents. The HMAC hashing functions take any string as input and, since users can issue and validate tokens, users are lead to believe that everything works properly. Versions 3.4.6, 4.0.4, and 4.1.5 have been patched to always load the file contents, deprecated the `Lcobucci\JWT\Signer\Key\LocalFileReference`, and suggest `Lcobucci\JWT\Signer\Key\InMemory` as the alternative. As a workaround, use `Lcobucci\JWT\Signer\Key\InMemory` instead of `Lcobucci\JWT\Signer\Key\LocalFileReference` to create the instances of one's keys.

    Published: 28 Sept 2021
    7.8
    High

    CVE-2021-36297

    Last Modified: 21 Nov 2024

    SupportAssist Client version 3.8 and 3.9 contains an Untrusted search path vulnerability that allows attackers to load an arbitrary .dll file via .dll planting/hijacking, only by a separate administrative action that is not a default part of the SOSInstallerTool.exe installation for executing arbitrary dll's,

    Published: 28 Sept 2021
    7.1
    High

    CVE-2021-36286

    Last Modified: 21 Nov 2024

    Dell SupportAssist Client Consumer versions 3.9.13.0 and any versions prior to 3.9.13.0 contain an arbitrary file deletion vulnerability that can be exploited by using the Windows feature of NTFS called Symbolic links. Symbolic links can be created by any(non-privileged) user under some object directories, but by themselves are not sufficient to successfully escalate privileges. However, combining them with a different object, such as the NTFS junction point allows for the exploitation. Support assist clean files functionality do not distinguish junction points from the physical folder and proceeds to clean the target of the junction that allows nonprivileged users to create junction points and delete arbitrary files on the system which can be accessed only by the admin.

    Published: 28 Sept 2021
    5.7
    Medium

    CVE-2021-36285

    Last Modified: 21 Nov 2024

    Dell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated malicious administrator could exploit this vulnerability to bypass excessive NVMe password attempt mitigations in order to carry out a brute force attack.

    Published: 28 Sept 2021
    5.7
    Medium

    CVE-2021-36284

    Last Modified: 21 Nov 2024

    Dell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated malicious administrator could exploit this vulnerability to bypass excessive admin password attempt mitigations in order to carry out a brute force attack.

    Published: 28 Sept 2021
    7.5
    High

    CVE-2021-36283

    Last Modified: 21 Nov 2024

    Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

    Published: 28 Sept 2021
    6.8
    Medium

    CVE-2021-21570

    Last Modified: 21 Nov 2024

    Dell NetWorker, versions 18.x and 19.x contain an Information disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and gain access to unauthorized information.

    Published: 28 Sept 2021
    6.8
    Medium

    CVE-2021-21569

    Last Modified: 21 Nov 2024

    Dell NetWorker, versions 18.x and 19.x contain a Path traversal vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and gain access to unauthorized information.

    Published: 28 Sept 2021
    8.2
    High

    CVE-2021-21522

    Last Modified: 21 Nov 2024

    Dell BIOS contains a Credentials Management issue. A local authenticated malicious user may potentially exploit this vulnerability to gain access to sensitive information on an NVMe storage by resetting the BIOS password on the system via the Manageability Interface.

    Published: 28 Sept 2021
    9.8
    Critical

    CVE-2021-38303

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists in Sureline SUREedge Migrator 7.0.7.29360.

    Published: 28 Sept 2021
    6.1
    Medium

    CVE-2021-30086

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability exists in KindEditor (Chinese versions) 4.1.12, which can be exploited by an attacker to obtain user cookie information.

    Published: 28 Sept 2021