CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2021-37267

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability exists in all versions of KindEditor, which can be exploited by an attacker to obtain user cookie information.

    Published: 28 Sept 2021
    5.4
    Medium

    CVE-2021-37271

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability exists in UEditor v1.4.3.3, which can be exploited by an attacker to obtain user cookie information.

    Published: 28 Sept 2021
    7.5
    High

    CVE-2021-37273

    Last Modified: 21 Nov 2024

    A Denial of Service issue exists in China Telecom Corporation EPON Tianyi Gateway ZXHN F450(EPON ONU) 3.0. Tianyi Gateway is a hardware terminal of "Optical Modem Smart Router." Attackers can use this vulnerability to restart the device multiple times.

    Published: 28 Sept 2021
    6.1
    Medium

    CVE-2021-41318

    Last Modified: 25 Sept 2026

    In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input. which could allow an unauthenticated attacker to execute arbitrary code in a victim's browser.

    Published: 28 Sept 2021
    9.8
    Critical

    CVE-2021-36366

    Last Modified: 21 Nov 2024

    Nagios XI before 5.8.5 incorrectly allows manage_services.sh wildcards.

    Published: 28 Sept 2021
    9.8
    Critical

    CVE-2021-36365

    Last Modified: 21 Nov 2024

    Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.

    Published: 28 Sept 2021
    9.8
    Critical

    CVE-2021-36364

    Last Modified: 21 Nov 2024

    Nagios XI before 5.8.5 incorrectly allows backup_xi.sh wildcards.

    Published: 28 Sept 2021
    9.8
    Critical

    CVE-2021-36363

    Last Modified: 21 Nov 2024

    Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.

    Published: 28 Sept 2021
    7.8
    High

    CVE-2021-29367

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in WPG+0x1dda of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted WPG file.

    Published: 28 Sept 2021
    5.5
    Medium

    CVE-2021-29365

    Last Modified: 21 Nov 2024

    Irfanview 4.57 is affected by an infinite loop when processing a crafted BMP file in the EFFECTS!AutoCrop_W component. This can cause a denial of service (DOS).

    Published: 28 Sept 2021
    7.8
    High

    CVE-2021-29366

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in FORMATS!GetPlugInInfo+0x2de9 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.

    Published: 28 Sept 2021
    7.8
    High

    CVE-2021-29364

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in Formats!ReadRAS_W+0x1001 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.

    Published: 28 Sept 2021
    7.8
    High

    CVE-2021-29363

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in FORMATS!ReadRAS_W+0xa74 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.0xa74

    Published: 28 Sept 2021
    7.8
    High

    CVE-2021-29362

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in FORMATS!ReadRAS_W+0xa30 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.

    Published: 28 Sept 2021
    7.8
    High

    CVE-2021-29361

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in FORMATS!Read_Utah_RLE+0x340 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.

    Published: 28 Sept 2021
    7.8
    High

    CVE-2021-29360

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in FORMATS!Read_Utah_RLE+0x37a of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.

    Published: 28 Sept 2021
    5.5
    Medium

    CVE-2021-29358

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in FORMATS!ReadPVR_W+0xfa of Irfanview 4.57 allows attackers to cause a denial of service (DOS) via a crafted PVR file.

    Published: 28 Sept 2021
    7.5
    High

    CVE-2021-41104

    Last Modified: 21 Nov 2024

    ESPHome is a system to control the ESP8266/ESP32. Anyone with web_server enabled and HTTP basic auth configured on version 2021.9.1 or older is vulnerable to an issue in which `web_server` allows over-the-air (OTA) updates without checking user defined basic auth username & password. This issue is patched in version 2021.9.2. As a workaround, one may disable or remove `web_server`.

    Published: 28 Sept 2021
    7.5
    High

    CVE-2021-37105

    Last Modified: 21 Nov 2024

    There is an improper file upload control vulnerability in FusionCompute 6.5.0, 6.5.1 and 8.0.0. Due to the improper verification of file to be uploaded and does not strictly restrict the file access path, attackers may upload malicious files to the device, resulting in the service abnormal.

    Published: 28 Sept 2021
    7.2
    High

    CVE-2021-37106

    Last Modified: 21 Nov 2024

    There is a command injection vulnerability in CMA service module of FusionCompute 6.3.0, 6.3.1, 6.5.0 and 8.0.0 when processing the default certificate file. The software constructs part of a command using external special input from users, but the software does not sufficiently validate the user input. Successful exploit could allow the attacker to inject certain commands to the system.

    Published: 28 Sept 2021
    7.5
    High

    CVE-2021-37104

    Last Modified: 21 Nov 2024

    There is a server-side request forgery vulnerability in HUAWEI P40 versions 10.1.0.118(C00E116R3P3). This vulnerability is due to insufficient validation of parameters while dealing with some messages. A successful exploit could allow the attacker to gain access to certain resource which the attacker are supposed not to do.

    Published: 28 Sept 2021
    9.8
    Critical

    CVE-2021-38124

    Last Modified: 21 Nov 2024

    Remote Code Execution vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, affecting versions 7.0.2 through 7.5. The vulnerability could be exploited resulting in remote code execution.

    Published: 28 Sept 2021
    4.9
    Medium

    CVE-2021-22535

    Last Modified: 21 Nov 2024

    Unauthorized information security disclosure vulnerability on Micro Focus Directory and Resource Administrator (DRA) product, affecting all DRA versions prior to 10.1 Patch 1. The vulnerability could lead to unauthorized information disclosure.

    Published: 28 Sept 2021
    8.8
    High

    CVE-2021-34636

    Last Modified: 31 Mar 2025

    The Countdown and CountUp, WooCommerce Sales Timers WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_theme function found in the ~/includes/admin/coundown_theme_page.php file due to a missing nonce check which allows attackers to inject arbitrary web scripts, in versions up to and including 1.5.7.

    Published: 28 Sept 2021
    7.5
    High

    CVE-2021-37146

    Last Modified: 21 Nov 2024

    An infinite loop in Open Robotics ros_comm XMLRPC server in ROS Melodic through 1.4.11 and ROS Noetic through1.15.11 allows remote attackers to cause a Denial of Service in ros_comm via a crafted XMLRPC call.

    Published: 28 Sept 2021
    9.8
    Critical

    CVE-2021-3762

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentially allowing for remote code execution.

    Published: 28 Sept 2021
    7.8
    High

    CVE-2021-41539

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Solid Edge SE2021 (All versions < SE2021MP8). The affected application contains a use-after-free vulnerability while parsing OBJ files. An attacker could leverage this vulnerability to execute code in the context of the current process (ZDI-CAN-13773).

    Published: 28 Sept 2021
    7.8
    High

    CVE-2021-41540

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Solid Edge SE2021 (All versions < SE2021MP8). The affected application contains a use-after-free vulnerability while parsing OBJ files. An attacker could leverage this vulnerability to execute code in the context of the current process (ZDI-CAN-13776).

    Published: 28 Sept 2021
    3.3
    Low

    CVE-2021-41538

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in NX 1953 Series (All versions < V1973.3700), NX 1980 Series (All versions < V1988), Solid Edge SE2021 (All versions < SE2021MP8). The affected application is vulnerable to information disclosure by unexpected access to an uninitialized pointer while parsing user-supplied OBJ files. An attacker could leverage this vulnerability to leak information from unexpected memory locations (ZDI-CAN-13770).

    Published: 28 Sept 2021
    7.8
    High

    CVE-2021-41537

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Solid Edge SE2021 (All versions < SE2021MP8). The affected application contains a use-after-free vulnerability while parsing OBJ files. An attacker could leverage this vulnerability to execute code in the context of the current process (ZDI-CAN-13789).

    Published: 28 Sept 2021
    7.8
    High

    CVE-2021-41536

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Solid Edge SE2021 (All versions < SE2021MP8). The affected application contains a use-after-free vulnerability while parsing OBJ files. An attacker could leverage this vulnerability to execute code in the context of the current process (ZDI-CAN-13778).

    Published: 28 Sept 2021
    7.8
    High

    CVE-2021-41535

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in NX 1953 Series (All versions < V1973.3700), NX 1980 Series (All versions < V1988), Solid Edge SE2021 (All versions < SE2021MP8). The affected application contains a use-after-free vulnerability while parsing OBJ files. An attacker could leverage this vulnerability to execute code in the context of the current process (ZDI-CAN-13771).

    Published: 28 Sept 2021
    3.3
    Low

    CVE-2021-41534

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in NX 1980 Series (All versions < V1984), Solid Edge SE2021 (All versions < SE2021MP8). The affected application is vulnerable to an out of bounds read past the end of an allocated buffer when parsing JT files. An attacker could leverage this vulnerability to leak information in the context of the current process (ZDI-CAN-13703).

    Published: 28 Sept 2021
    3.3
    Low

    CVE-2021-41533

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in NX 1980 Series (All versions < V1984), Solid Edge SE2021 (All versions < SE2021MP8). The affected application is vulnerable to an out of bounds read past the end of an allocated buffer when parsing JT files. An attacker could leverage this vulnerability to leak information in the context of the current process (ZDI-CAN-13565).

    Published: 28 Sept 2021
    5.3
    Medium

    CVE-2021-36165

    Last Modified: 21 Nov 2024

    RICON Industrial Cellular Router S9922L 16.10.3(3794) is affected by cleartext storage of sensitive information and sends username and password as base64.

    Published: 28 Sept 2021
    7.6
    High

    CVE-2021-33601

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper. An authenticated user can modify settings through the web user interface in a way that could lead to an arbitrary code execution on the F-Secure Internet Gatekeeper server.

    Published: 28 Sept 2021
    5.4
    Medium

    CVE-2021-33600

    Last Modified: 21 Nov 2024

    A denial-of-service (DoS) vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper. The vulnerability occurs because of an attacker can trigger assertion via malformed HTTP packet to web interface. An unauthenticated attacker could exploit this vulnerability by sending a large username parameter. A successful exploitation could lead to a denial-of-service of the product.

    Published: 28 Sept 2021
    4.7
    Medium

    CVE-2021-3521

    Last Modified: 21 Nov 2024

    There is a flaw in RPM's signature functionality. OpenPGP subkeys are associated with a primary key via a "binding signature." RPM does not check the binding signature of subkeys prior to importing them. If an attacker is able to add or socially engineer another party to add a malicious subkey to a legitimate public key, RPM could wrongly trust a malicious signature. The greatest impact of this flaw is to data integrity. To exploit this flaw, an attacker must either compromise an RPM repository or convince an administrator to install an untrusted RPM or public key. It is strongly recommended to only use RPMs and public keys from trusted sources.

    Published: 28 Sept 2021
    8.8
    High

    CVE-2020-20693

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) in GilaCMS v1.11.4 allows authenticated attackers to arbitrarily add administrator accounts.

    Published: 27 Sept 2021
    5.4
    Medium

    CVE-2020-20696

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in /admin/content/post of GilaCMS v1.11.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Tags field.

    Published: 27 Sept 2021
    5.4
    Medium

    CVE-2020-20695

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in GilaCMS v1.11.4 allows attackers to execute arbitrary web scripts or HTML via a crafted SVG file.

    Published: 27 Sept 2021
    6.5
    Medium

    CVE-2020-20691

    Last Modified: 21 Nov 2024

    An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extension filter and uploading crafted HTML files.

    Published: 27 Sept 2021
    7.2
    High

    CVE-2020-20692

    Last Modified: 21 Nov 2024

    GilaCMS v1.11.4 was discovered to contain a SQL injection vulnerability via the $_GET parameter in /src/core/controllers/cm.php.

    Published: 27 Sept 2021
    8.8
    High

    CVE-2021-37274

    Last Modified: 21 Nov 2024

    Kingdee KIS Professional Edition has a privilege escalation vulnerability. Attackers can use the vulnerability to gain computer administrator rights via unspecified loopholes.

    Published: 27 Sept 2021
    8.1
    High

    CVE-2020-24930

    Last Modified: 21 Nov 2024

    Beijing Wuzhi Internet Technology Co., Ltd. Wuzhi CMS 4.0.1 is an open source content management system. The five fingers CMS backend in***.php file has arbitrary file deletion vulnerability. Attackers can use vulnerabilities to delete arbitrary files.

    Published: 27 Sept 2021
    9.8
    Critical

    CVE-2021-37270

    Last Modified: 21 Nov 2024

    There is an unauthorized access vulnerability in the CMS Enterprise Website Construction System 5.0. Attackers can use this vulnerability to directly access the specified background path without logging in to the background to obtain the background administrator authority.

    Published: 27 Sept 2021
    4.2
    Medium

    CVE-2021-41095

    Last Modified: 21 Nov 2024

    Discourse is an open source discussion platform. There is a cross-site scripting (XSS) vulnerability in versions 2.7.7 and earlier of the `stable` branch, versions 2.8.0.beta6 and earlier of the `beta` branch, and versions 2.8.0.beta6 and earlier of the `tests-passed` branch. Rendering of some error messages that contain user input can be susceptible to XSS attacks. This vulnerability only affects sites which have blocked watched words that contain HTML tags, modified or disabled Discourse's default Content Security Policy. This issue is patched in the latest `stable`, `beta` and `tests-passed` versions of Discourse. As a workaround, avoid modifying or disabling Discourse’s default Content Security Policy, and blocking watched words containing HTML tags.

    Published: 27 Sept 2021
    7.5
    High

    CVE-2021-41096

    Last Modified: 21 Nov 2024

    Rucky is a USB HID Rubber Ducky Launch Pad for Android. Versions 2.2 and earlier for release builds and versions 425 and earlier for nightly builds suffer from use of a weak cryptographic algorithm (RSA/ECB/PKCS1Padding). The issue will be patched in v2.3 for release builds and 426 onwards for nightly builds. As a workaround, one may disable an advance security feature if not required.

    Published: 27 Sept 2021
    9.1
    Critical

    CVE-2021-41097

    Last Modified: 21 Nov 2024

    aurelia-path is part of the Aurelia platform and contains utilities for path manipulation. There is a prototype pollution vulnerability in aurelia-path before version 1.1.7. The vulnerability exposes Aurelia application that uses `aurelia-path` package to parse a string. The majority of this will be Aurelia applications that employ the `aurelia-router` package. An example is this could allow an attacker to change the prototype of base object class `Object` by tricking an application to parse the following URL: `https://aurelia.io/blog/?__proto__[asdf]=asdf`. The problem is patched in version `1.1.7`.

    Published: 27 Sept 2021
    6.5
    Medium

    CVE-2021-20035

    Last Modified: 31 Oct 2025

    Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS.

    Published: 27 Sept 2021