CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2021-29813

    Last Modified: 21 Nov 2024

    IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204331.

    Published: 23 Sept 2021
    5.4
    Medium

    CVE-2021-29812

    Last Modified: 21 Nov 2024

    IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204330.

    Published: 23 Sept 2021
    5.4
    Medium

    CVE-2021-29810

    Last Modified: 21 Nov 2024

    IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204279.

    Published: 23 Sept 2021
    5.3
    Medium

    CVE-2020-24327

    Last Modified: 21 Nov 2024

    Server Side Request Forgery (SSRF) vulnerability exists in Discourse 2.3.2 and 2.6 via the email function. When writing an email in an editor, you can upload pictures of remote websites.

    Published: 23 Sept 2021
    5.4
    Medium

    CVE-2021-38870

    Last Modified: 21 Nov 2024

    IBM Aspera Cloud is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 208343.

    Published: 23 Sept 2021
    7.5
    High

    CVE-2021-38864

    Last Modified: 21 Nov 2024

    IBM Security Verify Bridge 1.0.5.0 could allow a user to obtain sensitive information due to improper certificate validation. IBM X-Force ID: 208155.

    Published: 23 Sept 2021
    4.3
    Medium

    CVE-2021-20563

    Last Modified: 21 Nov 2024

    IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 could allow a remote authenciated user to obtain sensitive information. By sending a specially crafted request, the user could disclose a valid filepath on the server which could be used in further attacks against the system. IBM X-Force ID: 199234.

    Published: 23 Sept 2021
    4.3
    Medium

    CVE-2021-20485

    Last Modified: 21 Nov 2024

    IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 197667.

    Published: 23 Sept 2021
    5.4
    Medium

    CVE-2021-20484

    Last Modified: 21 Nov 2024

    IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 197666.

    Published: 23 Sept 2021
    5.5
    Medium

    CVE-2021-20435

    Last Modified: 21 Nov 2024

    IBM Security Verify Bridge 1.0.5.0 does not properly validate a certificate which could allow a local attacker to obtain sensitive information that could aid in further attacks against the system. IBM X-Force ID: 196355.

    Published: 23 Sept 2021
    4.4
    Medium

    CVE-2021-20434

    Last Modified: 21 Nov 2024

    IBM Security Verify Bridge 1.0.5.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 196346.

    Published: 23 Sept 2021
    4.3
    Medium

    CVE-2020-4941

    Last Modified: 21 Nov 2024

    IBM Edge 4.2 could reveal sensitive version information about the server from error pages that could aid an attacker in further attacks against the system. IBM X-Force ID: 191941.

    Published: 23 Sept 2021
    4.4
    Medium

    CVE-2021-20317

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel. A corrupted timer tree caused the task wakeup to be missing in the timerqueue_add function in lib/timerqueue.c. This flaw allows a local attacker with special user privileges to cause a denial of service, slowing and eventually stopping the system while running OSP.

    Published: 23 Sept 2021
    5.5
    Medium

    CVE-2021-38863

    Last Modified: 21 Nov 2024

    IBM Security Verify Bridge 1.0.5.0 stores user credentials in plain clear text which can be read by a locally authenticated user. IBM X-Force ID: 208154.

    Published: 23 Sept 2021
    5.4
    Medium

    CVE-2021-29800

    Last Modified: 21 Nov 2024

    IBM Tivoli Netcool/OMNIbus_GUI and IBM Jazz for Service Management 1.1.3.10 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 23 Sept 2021
    2.7
    Low

    CVE-2021-20377

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195569.

    Published: 23 Sept 2021
    3.3
    Low

    CVE-2020-4809

    Last Modified: 21 Nov 2024

    IBM Edge 4.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 189633.

    Published: 23 Sept 2021
    3.3
    Low

    CVE-2020-4805

    Last Modified: 21 Nov 2024

    IBM Edge 4.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 189539.

    Published: 23 Sept 2021
    3.3
    Low

    CVE-2020-4803

    Last Modified: 21 Nov 2024

    IBM Edge 4.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 189535.

    Published: 23 Sept 2021
    9.8
    Critical

    CVE-2020-4690

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.3 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 186697.

    Published: 23 Sept 2021
    6.1
    Medium

    CVE-2021-22276

    Last Modified: 21 Nov 2024

    The vulnerability allows a successful attacker to bypass the integrity check of FW uploaded to the free@home System Access Point.

    Published: 23 Sept 2021
    9.8
    Critical

    CVE-2021-26794

    Last Modified: 21 Nov 2024

    Privilege escalation in 'upload.php' in FrogCMS SentCMS v0.9.5 allows attacker to execute arbitrary code via crafted php file.

    Published: 23 Sept 2021
    6.6
    Medium

    CVE-2021-36823

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cusmin AGCA - Absolutely Glamorous Custom Admin (WordPress plugin) allows Stored XSS.This issue affects AGCA - Absolutely Glamorous Custom Admin (WordPress plugin): from n/a through 6.8.

    Published: 23 Sept 2021
    5.5
    Medium

    CVE-2021-36873

    Last Modified: 28 Mar 2025

    Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress iQ Block Country plugin (versions <= 1.2.11). Vulnerable parameter: &blockcountry_blockmessage.

    Published: 23 Sept 2021
    5.5
    Medium

    CVE-2021-36872

    Last Modified: 28 Mar 2025

    Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress Popular Posts plugin (versions <= 5.3.3). Vulnerable at &widget-wpp[2][post_type].

    Published: 23 Sept 2021
    6.1
    Medium

    CVE-2021-3824

    Last Modified: 21 Nov 2024

    OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbitrary web script or HTML via the web login page URL.

    Published: 23 Sept 2021
    9.8
    Critical

    CVE-2021-21913

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the WiFi Smart Mesh functionality of D-LINK DIR-3040 1.13B03. A specially-crafted network request can lead to command execution. An attacker can connect to the MQTT service to trigger this vulnerability.

    Published: 23 Sept 2021
    7.8
    High

    CVE-2021-26750

    Last Modified: 21 Nov 2024

    DLL hijacking in Panda Agent <=1.16.11 in Panda Security, S.L.U. Panda Adaptive Defense 360 <= 8.0.17 allows attacker to escalate privileges via maliciously crafted DLL file.

    Published: 23 Sept 2021
    —
    Unknown

    CVE-2021-41428

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 23 Sept 2021
    7.5
    High

    CVE-2021-32987

    Last Modified: 21 Nov 2024

    Null pointer dereference in SuiteLink server while processing command 0x0b

    Published: 23 Sept 2021
    7.5
    High

    CVE-2021-32999

    Last Modified: 21 Nov 2024

    Improper handling of exceptional conditions in SuiteLink server while processing command 0x01

    Published: 23 Sept 2021
    7.5
    High

    CVE-2021-32979

    Last Modified: 21 Nov 2024

    Null pointer dereference in SuiteLink server while processing commands 0x04/0x0a

    Published: 23 Sept 2021
    7.5
    High

    CVE-2021-32971

    Last Modified: 21 Nov 2024

    Null pointer dereference in SuiteLink server while processing command 0x07

    Published: 23 Sept 2021
    8.1
    High

    CVE-2021-32959

    Last Modified: 21 Nov 2024

    Heap-based buffer overflow in SuiteLink server while processing commands 0x05/0x06

    Published: 23 Sept 2021
    7.5
    High

    CVE-2021-32963

    Last Modified: 21 Nov 2024

    Null pointer dereference in SuiteLink server while processing commands 0x03/0x10

    Published: 23 Sept 2021
    9.8
    Critical

    CVE-2021-22941

    Last Modified: 3 Nov 2025

    Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.

    Published: 23 Sept 2021
    7.1
    High

    CVE-2021-22948

    Last Modified: 21 Nov 2024

    Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqid() PHP function. Under some circumstances, an attacker could theoretically be able to brute force session IDs in order to take over a specific account.

    Published: 23 Sept 2021
    5.4
    Medium

    CVE-2021-22953

    Last Modified: 21 Nov 2024

    A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to clone topics which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security Research Team"

    Published: 23 Sept 2021
    8.8
    High

    CVE-2021-22952

    Last Modified: 21 Nov 2024

    A vulnerability found in UniFi Talk application V1.12.3 and earlier permits a malicious actor who has already gained access to a network to subsequently control Talk device(s) assigned to said network if they are not yet adopted. This vulnerability is fixed in UniFi Talk application V1.12.5 and later.

    Published: 23 Sept 2021
    6.5
    Medium

    CVE-2021-22950

    Last Modified: 21 Nov 2024

    Concrete CMS prior to 8.5.6 had a CSFR vulnerability allowing attachments to comments in the conversation section to be deleted.Credit for discovery: "Solar Security Research Team"

    Published: 23 Sept 2021
    5.4
    Medium

    CVE-2021-22949

    Last Modified: 21 Nov 2024

    A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security CMS Research Team"

    Published: 23 Sept 2021
    5.5
    Medium

    CVE-2021-22020

    Last Modified: 21 Nov 2024

    The vCenter Server contains a denial-of-service vulnerability in the Analytics service. Successful exploitation of this issue may allow an attacker to create a denial-of-service condition on vCenter Server.

    Published: 23 Sept 2021
    7.5
    High

    CVE-2021-22019

    Last Modified: 21 Nov 2024

    The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 5480 on vCenter Server may exploit this issue by sending a specially crafted jsonrpc message to create a denial of service condition.

    Published: 23 Sept 2021
    6.5
    Medium

    CVE-2021-22018

    Last Modified: 21 Nov 2024

    The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious actor with network access to port 9087 on vCenter Server may exploit this issue to delete non critical files.

    Published: 23 Sept 2021
    5.3
    Medium

    CVE-2021-22017

    Last Modified: 30 Oct 2025

    Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being accessed.

    Published: 23 Sept 2021
    6.1
    Medium

    CVE-2021-22016

    Last Modified: 21 Nov 2024

    The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sanitization. An attacker may exploit this issue to execute malicious scripts by tricking a victim into clicking a malicious link.

    Published: 23 Sept 2021
    7.2
    High

    CVE-2021-22014

    Last Modified: 21 Nov 2024

    The vCenter Server contains an authenticated code execution vulnerability in VAMI (Virtual Appliance Management Infrastructure). An authenticated VAMI user with network access to port 5480 on vCenter Server may exploit this issue to execute code on the underlying operating system that hosts vCenter Server.

    Published: 23 Sept 2021
    7.5
    High

    CVE-2021-22013

    Last Modified: 21 Nov 2024

    The vCenter Server contains a file path traversal vulnerability leading to information disclosure in the appliance management API. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.

    Published: 23 Sept 2021
    7.5
    High

    CVE-2021-22012

    Last Modified: 21 Nov 2024

    The vCenter Server contains an information disclosure vulnerability due to an unauthenticated appliance management API. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.

    Published: 23 Sept 2021
    5.3
    Medium

    CVE-2021-22011

    Last Modified: 21 Nov 2024

    vCenter Server contains an unauthenticated API endpoint vulnerability in vCenter Server Content Library. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to perform unauthenticated VM network setting manipulation.

    Published: 23 Sept 2021