CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2021-20037

    Last Modified: 21 Nov 2024

    SonicWall Global VPN Client 4.10.5 installer (32-bit and 64-bit) incorrect default file permission vulnerability leads to privilege escalation which potentially allows command execution in the host operating system. This vulnerability impacts GVC 4.10.5 installer and earlier.

    Published: 21 Sept 2021
    8.8
    High

    CVE-2021-37972

    Last Modified: 21 Nov 2024

    Out of bounds read in libjpeg-turbo in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 21 Sept 2021
    5.9
    Medium

    CVE-2021-38153

    Last Modified: 21 Nov 2024

    Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0.

    Published: 21 Sept 2021
    6.5
    Medium

    CVE-2021-3941

    Last Modified: 21 Nov 2024

    In ImfChromaticities.cpp routine RGBtoXYZ(), there are some division operations such as `float Z = (1 - chroma.white.x - chroma.white.y) * Y / chroma.white.y;` and `chroma.green.y * (X + Z))) / d;` but the divisor is not checked for a 0 value. A specially crafted file could trigger a divide-by-zero condition which could affect the availability of programs linked with OpenEXR.

    Published: 21 Sept 2021
    8
    High

    CVE-2021-41083

    Last Modified: 21 Nov 2024

    Dada Mail is a web-based e-mail list management system. In affected versions a bad actor could give someone a carefully crafted web page via email, SMS, etc, that - when visited, allows them control of the list control panel as if the bad actor was logged in themselves. This includes changing any mailing list password, as well as the Dada Mail Root Password - which could effectively shut out actual list owners of the mailing list and allow the bad actor complete and unfettered control of your mailing list. This vulnerability also affects profile logins. For this vulnerability to work, the target of the bad actor would need to be logged into the list control panel themselves. This CSRF vulnerability in Dada Mail affects all versions of Dada Mail v11.15.1 and below. Although we know of no known CSRF exploits that have happened in the wild, this vulnerability has been confirmed by our testing, and by a third party. Users are advised to update to version 11.16.0.

    Published: 20 Sept 2021
    7.5
    High

    CVE-2021-39229

    Last Modified: 21 Nov 2024

    Apprise is an open source library which allows you to send a notification to almost all of the most popular notification services available. In affected versions users who use Apprise granting them access to the IFTTT plugin (which just comes out of the box) are subject to a denial of service attack on an inefficient regular expression. The vulnerable regular expression is [here](https://github.com/caronc/apprise/blob/0007eade20934ddef0aba38b8f1aad980cfff253/apprise/plugins/NotifyIFTTT.py#L356-L359). The problem has been patched in release version 0.9.5.1. Users who are unable to upgrade are advised to remove `apprise/plugins/NotifyIFTTT.py` to eliminate the service.

    Published: 20 Sept 2021
    7.5
    High

    CVE-2021-41082

    Last Modified: 21 Nov 2024

    Discourse is a platform for community discussion. In affected versions any private message that includes a group had its title and participating user exposed to users that do not have access to the private messages. However, access control for the private messages was not compromised as users were not able to view the posts in the leaked private message despite seeing it in their inbox. The problematic commit was reverted around 32 minutes after it was made. Users are encouraged to upgrade to the latest commit if they are running Discourse against the `tests-passed` branch.

    Published: 20 Sept 2021
    5.4
    Medium

    CVE-2021-34650

    Last Modified: 31 Mar 2025

    The eID Easy WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the error parameter found in the ~/admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.6.

    Published: 20 Sept 2021
    6.1
    Medium

    CVE-2021-39325

    Last Modified: 31 Mar 2025

    The OptinMonster WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient input validation in the load_previews function found in the ~/OMAPI/Output.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.6.0.

    Published: 20 Sept 2021
    6.8
    Medium

    CVE-2020-16630

    Last Modified: 21 Nov 2024

    TI’s BLE stack caches and reuses the LTK’s property for a bonded mobile. A LTK can be an unauthenticated-and-no-MITM-protection key created by Just Works or an authenticated-and-MITM-protection key created by Passkey Entry, Numeric Comparison or OOB. Assume that a victim mobile uses secure pairing to pair with a victim BLE device based on TI chips and generate an authenticated-and-MITM-protection LTK. If a fake mobile with the victim mobile’s MAC address uses Just Works and pairs with the victim device, the generated LTK still has the property of authenticated-and-MITM-protection. Therefore, the fake mobile can access attributes with the authenticated read/write permission.

    Published: 20 Sept 2021
    6.1
    Medium

    CVE-2020-19915

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS vulnerability exists in WUZHI CMS 4.1.0 via the mailbox username in index.php.

    Published: 20 Sept 2021
    7.5
    High

    CVE-2021-32838

    Last Modified: 21 Nov 2024

    Flask-RESTX (pypi package flask-restx) is a community driven fork of Flask-RESTPlus. Flask-RESTX before version 0.5.1 is vulnerable to ReDoS (Regular Expression Denial of Service) in email_regex. This is fixed in version 0.5.1.

    Published: 20 Sept 2021
    4.4
    Medium

    CVE-2021-38899

    Last Modified: 21 Nov 2024

    IBM Cloud Pak for Data 2.5 could allow a local user with special privileges to obtain highly sensitive information. IBM X-Force ID: 209575.

    Published: 20 Sept 2021
    6.5
    Medium

    CVE-2021-29856

    Last Modified: 21 Nov 2024

    IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 could allow an authenticated usre to cause a denial of service through the WebGUI Map Creation page. IBM X-Force ID: 205685.

    Published: 20 Sept 2021
    5.4
    Medium

    CVE-2021-29821

    Last Modified: 21 Nov 2024

    IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204348.

    Published: 20 Sept 2021
    5.4
    Medium

    CVE-2021-29820

    Last Modified: 21 Nov 2024

    IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204347.

    Published: 20 Sept 2021
    5.4
    Medium

    CVE-2021-29819

    Last Modified: 21 Nov 2024

    IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204346.

    Published: 20 Sept 2021
    5.4
    Medium

    CVE-2021-29818

    Last Modified: 21 Nov 2024

    IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204345.

    Published: 20 Sept 2021
    5.4
    Medium

    CVE-2021-29817

    Last Modified: 21 Nov 2024

    IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204343.

    Published: 20 Sept 2021
    4.9
    Medium

    CVE-2021-29811

    Last Modified: 21 Nov 2024

    IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 stores user credentials in plain clear text which can be read by an authenticated admin user. IBM X-Force ID: 204329.

    Published: 20 Sept 2021
    5.4
    Medium

    CVE-2021-29809

    Last Modified: 21 Nov 2024

    IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204270.

    Published: 20 Sept 2021
    5.4
    Medium

    CVE-2021-29808

    Last Modified: 21 Nov 2024

    IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204269.

    Published: 20 Sept 2021
    5.4
    Medium

    CVE-2021-29807

    Last Modified: 21 Nov 2024

    IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204265.

    Published: 20 Sept 2021
    5.4
    Medium

    CVE-2021-29806

    Last Modified: 21 Nov 2024

    IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204264.

    Published: 20 Sept 2021
    7.8
    High

    CVE-2021-39551

    Last Modified: 21 Nov 2024

    An issue was discovered in sela through 20200412. file::SelaFile::readFromFile() in sela_file.c has a heap-based buffer overflow.

    Published: 20 Sept 2021
    8.8
    High

    CVE-2021-39525

    Last Modified: 21 Nov 2024

    An issue was discovered in libredwg through v0.10.1.3751. bit_read_fixed() in bits.c has a heap-based buffer overflow.

    Published: 20 Sept 2021
    8.8
    High

    CVE-2021-32298

    Last Modified: 21 Nov 2024

    An issue was discovered in libiff through 20190123. A global-buffer-overflow exists in the function IFF_errorId located in error.c. It allows an attacker to cause code Execution.

    Published: 20 Sept 2021
    5.5
    Medium

    CVE-2021-39585

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function traits_dump() located in abc.c. It allows an attacker to cause Denial of Service.

    Published: 20 Sept 2021
    5.5
    Medium

    CVE-2021-39591

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_GetShapeBoundingBox() located in swfshape.c. It allows an attacker to cause Denial of Service.

    Published: 20 Sept 2021
    5.5
    Medium

    CVE-2021-39588

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_ReadABC() located in abc.c. It allows an attacker to cause Denial of Service.

    Published: 20 Sept 2021
    7.8
    High

    CVE-2021-39582

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the function swf_GetPlaceObject() located in swfobject.c. It allows an attacker to cause code Execution.

    Published: 20 Sept 2021
    5.5
    Medium

    CVE-2021-39593

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_FontExtract_DefineFontInfo() located in swftext.c. It allows an attacker to cause Denial of Service.

    Published: 20 Sept 2021
    7.8
    High

    CVE-2021-39564

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the function swf_DumpActions() located in swfaction.c. It allows an attacker to cause code Execution.

    Published: 20 Sept 2021
    7.8
    High

    CVE-2021-39558

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20200710. A stack-buffer-overflow exists in the function VectorGraphicOutputDev::drawGeneralImage() located in VectorGraphicOutputDev.cc. It allows an attacker to cause code Execution.

    Published: 20 Sept 2021
    5.5
    Medium

    CVE-2021-39594

    Last Modified: 21 Nov 2024

    Other An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function updateusage() located in swftext.c. It allows an attacker to cause Denial of Service.

    Published: 20 Sept 2021
    5.5
    Medium

    CVE-2021-39563

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_DumpActions() located in swfaction.c. It allows an attacker to cause Denial of Service.

    Published: 20 Sept 2021
    7.8
    High

    CVE-2021-39579

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the function string_hash() located in q.c. It allows an attacker to cause code Execution.

    Published: 20 Sept 2021
    5.5
    Medium

    CVE-2021-39587

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_DumpABC() located in abc.c. It allows an attacker to cause Denial of Service.

    Published: 20 Sept 2021
    7.8
    High

    CVE-2021-39574

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the function pool_read() located in pool.c. It allows an attacker to cause code Execution.

    Published: 20 Sept 2021
    5.5
    Medium

    CVE-2021-39589

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function parse_metadata() located in abc.c. It allows an attacker to cause Denial of Service.

    Published: 20 Sept 2021
    5.5
    Medium

    CVE-2021-39592

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function pool_lookup_uint() located in pool.c. It allows an attacker to cause Denial of Service.

    Published: 20 Sept 2021
    7.8
    High

    CVE-2021-39595

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20200710. A stack-buffer-overflow exists in the function rfx_alloc() located in mem.c. It allows an attacker to cause code Execution.

    Published: 20 Sept 2021
    5.5
    Medium

    CVE-2021-39583

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function pool_lookup_string2() located in pool.c. It allows an attacker to cause Denial of Service.

    Published: 20 Sept 2021
    7.8
    High

    CVE-2021-39569

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the function OpAdvance() located in swfaction.c. It allows an attacker to cause code Execution.

    Published: 20 Sept 2021
    5.5
    Medium

    CVE-2021-39590

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function params_dump() located in abc.c. It allows an attacker to cause Denial of Service.

    Published: 20 Sept 2021
    7.8
    High

    CVE-2021-39577

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the function main() located in swfdump.c. It allows an attacker to cause code Execution.

    Published: 20 Sept 2021
    5.5
    Medium

    CVE-2021-39553

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function grealloc() located in gmem.cc. It allows an attacker to cause Denial of Service.

    Published: 20 Sept 2021
    5.5
    Medium

    CVE-2021-39554

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function Lexer::Lexer() located in Lexer.cc. It allows an attacker to cause Denial of Service.

    Published: 20 Sept 2021
    5.5
    Medium

    CVE-2021-39555

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function InfoOutputDev::type3D0() located in InfoOutputDev.cc. It allows an attacker to cause Denial of Service.

    Published: 20 Sept 2021
    5.5
    Medium

    CVE-2021-39556

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function InfoOutputDev::type3D1() located in InfoOutputDev.cc. It allows an attacker to cause Denial of Service.

    Published: 20 Sept 2021