CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-34415

    Last Modified: 21 Nov 2024

    The Zone Controller service in the Zoom On-Premise Meeting Connector Controller before version 4.6.358.20210205 does not verify the cnt field sent in incoming network packets, which leads to exhaustion of resources and system crash.

    Published: 27 Sept 2021
    7.2
    High

    CVE-2021-34414

    Last Modified: 21 Nov 2024

    The network proxy page on the web portal for the Zoom on-premise Meeting Connector Controller before version 4.6.348.20201217, Zoom on-premise Meeting Connector MMR before version 4.6.348.20201217, Zoom on-premise Recording Connector before version 3.8.42.20200905, Zoom on-premise Virtual Room Connector before version 4.4.6620.20201110, and Zoom on-premise Virtual Room Connector Load Balancer before version 2.5.5495.20210326 fails to validate input sent in requests to update the network proxy configuration, which could lead to remote command injection on the on-premise image by a web portal administrator.

    Published: 27 Sept 2021
    7.8
    High

    CVE-2021-34412

    Last Modified: 21 Nov 2024

    During the installation process for all versions of the Zoom Client for Meetings for Windows before 5.4.0, it is possible to launch Internet Explorer. If the installer was launched with elevated privileges such as by SCCM this can result in a local privilege escalation.

    Published: 27 Sept 2021
    7.8
    High

    CVE-2021-34411

    Last Modified: 21 Nov 2024

    During the installation process forZoom Rooms for Conference Room for Windows before version 5.3.0 it is possible to launch Internet Explorer with elevated privileges. If the installer was launched with elevated privileges such as by SCCM this can result in a local privilege escalation.

    Published: 27 Sept 2021
    7.8
    High

    CVE-2021-34410

    Last Modified: 21 Nov 2024

    A user-writable application bundle unpacked during the install for all versions of the Zoom Plugin for Microsoft Outlook for Mac before 5.0.25611.0521 allows for privilege escalation to root.

    Published: 27 Sept 2021
    7.8
    High

    CVE-2021-34409

    Last Modified: 21 Nov 2024

    It was discovered that the installation packages of the Zoom Client for Meetings for MacOS (Standard and for IT Admin) installation before version 5.2.0, Zoom Client Plugin for Sharing iPhone/iPad before version 5.2.0, and Zoom Rooms for Conference before version 5.1.0, copy pre- and post- installation shell scripts to a user-writable directory. In the affected products listed below, a malicious actor with local access to a user's machine could use this flaw to potentially run arbitrary system commands in a higher privileged context during the installation process.

    Published: 27 Sept 2021
    7.8
    High

    CVE-2021-34408

    Last Modified: 21 Nov 2024

    The Zoom Client for Meetings for Windows in all versions before version 5.3.2 writes log files to a user writable directory as a privileged user during the installation or update of the client. This could allow for potential privilege escalation if a link was created between the user writable directory used and a non-user writable directory.

    Published: 27 Sept 2021
    9.8
    Critical

    CVE-2021-33907

    Last Modified: 21 Nov 2024

    The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files when performing an update of the client. This could lead to remote code execution in an elevated privileged context.

    Published: 27 Sept 2021
    4.6
    Medium

    CVE-2021-37786

    Last Modified: 21 Nov 2024

    Certain Federal Office of Information Technology Systems and Telecommunication FOITT products are affected by improper handling of exceptional conditions. This affects COVID Certificate App IOS 2.2.0 and below affected, patch in progress and COVID Certificate Check App IOS 2.2.0 and below affected, patch in progress. A denial of service (physically proximate) could be caused by scanning a crafted QR code.

    Published: 27 Sept 2021
    6.5
    Medium

    CVE-2021-22272

    Last Modified: 21 Nov 2024

    The vulnerability origins in the commissioning process where an attacker of the ControlTouch can enter a serial number in a specific way to transfer the device virtually into her/his my.busch-jaeger.de or mybuildings.abb.com profile. A successful attacker can observe and control a ControlTouch remotely under very specific circumstances. The issue is fixed in the cloud side of the system. No firmware update is needed for customer products. If a user wants to understand if (s)he is affected, please read the advisory. This issue affects: ABB and Busch-Jaeger, ControlTouch

    Published: 27 Sept 2021
    7.5
    High

    CVE-2021-36218

    Last Modified: 21 Nov 2024

    An issue was discovered in SKALE sgxwallet 1.58.3. sgx_disp_ippsAES_GCMEncrypt allows an out-of-bounds write, resulting in a segfault and compromised enclave. This issue describes a buffer overflow, which was resolved prior to v1.77.0 and not reproducible in latest sgxwallet v1.77.0

    Published: 27 Sept 2021
    9.8
    Critical

    CVE-2021-36219

    Last Modified: 21 Nov 2024

    An issue was discovered in SKALE sgxwallet 1.58.3. The provided input for ECALL 14 triggers a branch in trustedEcdsaSign that frees a non-initialized pointer from the stack. An attacker can chain multiple enclave calls to prepare a stack that contains a valid address. This address is then freed, resulting in compromised integrity of the enclave. This was resolved after v1.58.3 and not reproducible in sgxwallet v1.77.0.

    Published: 27 Sept 2021
    7.5
    High

    CVE-2021-3828

    Last Modified: 21 Nov 2024

    nltk is vulnerable to Inefficient Regular Expression Complexity

    Published: 27 Sept 2021
    7.5
    High

    CVE-2021-3822

    Last Modified: 21 Nov 2024

    jsoneditor is vulnerable to Inefficient Regular Expression Complexity

    Published: 27 Sept 2021
    7.5
    High

    CVE-2021-3820

    Last Modified: 21 Nov 2024

    inflect is vulnerable to Inefficient Regular Expression Complexity

    Published: 27 Sept 2021
    8.8
    High

    CVE-2021-3819

    Last Modified: 21 Nov 2024

    firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

    Published: 27 Sept 2021
    5.3
    Medium

    CVE-2021-3818

    Last Modified: 21 Nov 2024

    grav is vulnerable to Reliance on Cookies without Validation and Integrity Checking

    Published: 27 Sept 2021
    5.4
    Medium

    CVE-2021-3799

    Last Modified: 21 Nov 2024

    grav-plugin-admin is vulnerable to Improper Restriction of Rendered UI Layers or Frames

    Published: 27 Sept 2021
    7.8
    High

    CVE-2021-23243

    Last Modified: 21 Nov 2024

    In Oppo's battery application, the third-party SDK provides the function of loading a third-party Provider, which can be used.

    Published: 27 Sept 2021
    6.4
    Medium

    CVE-2021-40109

    Last Modified: 21 Nov 2024

    A SSRF issue was discovered in Concrete CMS through 8.5.5. Users can access forbidden files on their local network. A user with permissions to upload files from external sites can upload a URL that redirects to an internal resource of any file type. The redirect is followed and loads the contents of the file from the redirected-to server. Files of disallowed types can be uploaded.

    Published: 27 Sept 2021
    8.8
    High

    CVE-2021-40108

    Last Modified: 21 Nov 2024

    An issue was discovered in Concrete CMS through 8.5.5. The Calendar is vulnerable to CSRF. ccm_token is not verified on the ccm/calendar/dialogs/event/add/save endpoint.

    Published: 27 Sept 2021
    6.1
    Medium

    CVE-2021-40106

    Last Modified: 21 Nov 2024

    An issue was discovered in Concrete CMS through 8.5.5. There is unauthenticated stored XSS in blog comments via the website field.

    Published: 27 Sept 2021
    6.1
    Medium

    CVE-2021-40105

    Last Modified: 21 Nov 2024

    An issue was discovered in Concrete CMS through 8.5.5. There is XSS via Markdown Comments.

    Published: 27 Sept 2021
    7.5
    High

    CVE-2021-40104

    Last Modified: 21 Nov 2024

    An issue was discovered in Concrete CMS through 8.5.5. There is an SVG sanitizer bypass.

    Published: 27 Sept 2021
    4.9
    Medium

    CVE-2021-0660

    Last Modified: 21 Nov 2024

    In ccu, there is a possible out of bounds read due to incorrect error handling. This could lead to information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05827145; Issue ID: ALPS05827145.

    Published: 27 Sept 2021
    7.8
    High

    CVE-2021-0612

    Last Modified: 21 Nov 2024

    In m4u, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05425834.

    Published: 27 Sept 2021
    7.8
    High

    CVE-2021-0611

    Last Modified: 21 Nov 2024

    In m4u, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05425810.

    Published: 27 Sept 2021
    7.8
    High

    CVE-2021-0610

    Last Modified: 21 Nov 2024

    In memory management driver, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05411456.

    Published: 27 Sept 2021
    5.5
    Medium

    CVE-2021-0425

    Last Modified: 21 Nov 2024

    In memory management driver, there is a possible side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05400059.

    Published: 27 Sept 2021
    5.5
    Medium

    CVE-2021-0424

    Last Modified: 21 Nov 2024

    In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05393787.

    Published: 27 Sept 2021
    5.5
    Medium

    CVE-2021-0423

    Last Modified: 21 Nov 2024

    In memory management driver, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05385714.

    Published: 27 Sept 2021
    5.5
    Medium

    CVE-2021-0422

    Last Modified: 21 Nov 2024

    In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05381071.

    Published: 27 Sept 2021
    5.5
    Medium

    CVE-2021-0421

    Last Modified: 21 Nov 2024

    In memory management driver, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05381235.

    Published: 27 Sept 2021
    7.5
    High

    CVE-2021-40103

    Last Modified: 21 Nov 2024

    An issue was discovered in Concrete CMS through 8.5.5. Path Traversal can lead to Arbitrary File Reading and SSRF.

    Published: 27 Sept 2021
    9.8
    Critical

    CVE-2021-40098

    Last Modified: 21 Nov 2024

    An issue was discovered in Concrete CMS through 8.5.5. Path Traversal leading to RCE via external form by adding a regular expression.

    Published: 27 Sept 2021
    8.8
    High

    CVE-2021-40097

    Last Modified: 21 Nov 2024

    An issue was discovered in Concrete CMS through 8.5.5. Authenticated path traversal leads to to remote code execution via uploaded PHP code, related to the bFilename parameter.

    Published: 27 Sept 2021
    6.1
    Medium

    CVE-2021-23054

    Last Modified: 21 Nov 2024

    On version 16.x before 16.1.0, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, a reflected cross-site scripting (XSS) vulnerability exists in the resource information page for authenticated users when a full webtop is configured on the BIG-IP APM system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 27 Sept 2021
    4.7
    Medium

    CVE-2021-27854

    Last Modified: 4 Nov 2025

    Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using combinations of VLAN 0 headers, LLC/SNAP headers, and converting frames from Ethernet to Wifi and its reverse.

    Published: 27 Sept 2021
    4.7
    Medium

    CVE-2021-27853

    Last Modified: 4 Nov 2025

    Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers.

    Published: 27 Sept 2021
    7.5
    High

    CVE-2021-34570

    Last Modified: 21 Nov 2024

    Multiple Phoenix Contact PLCnext control devices in versions prior to 2021.0.5 LTS are prone to a DoS attack through special crafted JSON requests.

    Published: 27 Sept 2021
    5.3
    Medium

    CVE-2021-41580

    Last Modified: 21 Nov 2024

    The passport-oauth2 package before 1.6.1 for Node.js mishandles the error condition of failure to obtain an access token. This is exploitable in certain use cases where an OAuth identity provider uses an HTTP 200 status code for authentication-failure error reports, and an application grants authorization upon simply receiving the access token (i.e., does not try to use the token). NOTE: the passport-oauth2 vendor does not consider this a passport-oauth2 vulnerability

    Published: 27 Sept 2021
    9.8
    Critical

    CVE-2021-38299

    Last Modified: 21 Nov 2024

    Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to login to a vulnerable service using an attached FIDO2 authenticator without passing a check of the user presence.

    Published: 27 Sept 2021
    6.5
    Medium

    CVE-2021-41385

    Last Modified: 21 Nov 2024

    The third party intelligence connector in Securonix SNYPR 6.3.1 Build 184295_0302 allows an authenticated user to obtain access to server configuration details via SSRF.

    Published: 27 Sept 2021
    6.5
    Medium

    CVE-2021-41329

    Last Modified: 21 Nov 2024

    Datalust Seq before 2021.2.6259 allows users (with view filters applied to their accounts) to see query results not constrained by their view filter. This information exposure, caused by an internal cache key collision, occurs when the user's view filter includes an array or IN clause, and when another user has recently executed an identical query differing only by the array elements.

    Published: 27 Sept 2021
    7.3
    High

    CVE-2021-40981

    Last Modified: 21 Nov 2024

    ASUS ROG Armoury Crate Lite before 4.2.10 allows local users to gain privileges by placing a Trojan horse file in the publicly writable %PROGRAMDATA%\ASUS\GamingCenterLib directory.

    Published: 27 Sept 2021
    5.3
    Medium

    CVE-2021-40349

    Last Modified: 21 Nov 2024

    e7d Speed Test (aka speedtest) 0.5.3 allows a path-traversal attack that results in information disclosure via the "GET /.." substring.

    Published: 27 Sept 2021
    7.5
    High

    CVE-2021-31605

    Last Modified: 21 Nov 2024

    furlongm openvpn-monitor through 1.1.3 allows %0a command injection via the OpenVPN management interface socket. This can shut down the server via signal%20SIGTERM.

    Published: 27 Sept 2021
    6.5
    Medium

    CVE-2021-31604

    Last Modified: 21 Nov 2024

    furlongm openvpn-monitor through 1.1.3 allows CSRF to disconnect an arbitrary client.

    Published: 27 Sept 2021
    9.8
    Critical

    CVE-2021-34351

    Last Modified: 21 Nov 2024

    A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.5 build 20210803 and later

    Published: 27 Sept 2021
    7.2
    High

    CVE-2021-34349

    Last Modified: 21 Nov 2024

    A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.5 build 20210803 and later

    Published: 27 Sept 2021