CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2018-20686

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 17 Sept 2021
    9.9
    Critical

    CVE-2020-12083

    Last Modified: 21 Nov 2024

    An elevated privileges issue related to Spring MVC calls impacts Code Insight v7.x releases up to and including 2020 R1 (7.11.0-64).

    Published: 17 Sept 2021
    5.4
    Medium

    CVE-2020-12082

    Last Modified: 21 Nov 2024

    A stored cross-site scripting issue impacts certain areas of the Web UI for Code Insight v7.x releases up to and including 2020 R1 (7.11.0-64).

    Published: 17 Sept 2021
    7.5
    High

    CVE-2020-12080

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability has been identified in FlexNet Publisher's lmadmin.exe version 11.16.6. A certain message protocol can be exploited to cause lmadmin to crash.

    Published: 17 Sept 2021
    8.6
    High

    CVE-2021-40825

    Last Modified: 21 Nov 2024

    nLight ECLYPSE (nECY) system Controllers running software prior to 1.17.21245.754 contain a default key vulnerability. The nECY does not force a change to the key upon the initial configuration of an affected device. nECY system controllers utilize an encrypted channel to secure SensorViewTM configuration and monitoring software and nECY to nECY communications. Impacted devices are at risk of exploitation. A remote attacker with IP access to an impacted device could submit lighting control commands to the nECY by leveraging the default key. A successful attack may result in the attacker gaining the ability to modify lighting conditions or gain the ability to update the software on lighting devices. The impacted key is referred to as the SensorView Password in the nECY nLight Explorer Interface and the Gateway Password in the SensorView application. An attacker cannot authenticate to or modify the configuration or software of the nECY system controller.

    Published: 17 Sept 2021
    7.8
    High

    CVE-2021-38304

    Last Modified: 21 Nov 2024

    Improper input validation in the National Instruments NI-PAL driver in versions 20.0.0 and prior may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 17 Sept 2021
    7.5
    High

    CVE-2019-9060

    Last Modified: 21 Nov 2024

    An issue was discovered in CMS Made Simple 2.2.8. It is possible to achieve unauthenticated path traversal in the CGExtensions module (in the file action.setdefaulttemplate.php) with the m1_filename parameter; and through the action.showmessage.php file, it is possible to read arbitrary file content (by using that path traversal with m1_prefname set to cg_errormsg and m1_resettodefault=1).

    Published: 17 Sept 2021
    9.8
    Critical

    CVE-2021-41317

    Last Modified: 21 Nov 2024

    XSS Hunter Express before 2021-09-17 does not properly enforce authentication requirements for paths.

    Published: 17 Sept 2021
    8.8
    High

    CVE-2021-41315

    Last Modified: 21 Nov 2024

    The Device42 Remote Collector before 17.05.01 does not sanitize user input in its SNMP Connectivity utility. This allows an authenticated attacker (with access to the console application) to execute arbitrary OS commands and escalate privileges.

    Published: 17 Sept 2021
    8.1
    High

    CVE-2021-41316

    Last Modified: 21 Nov 2024

    The Device42 Main Appliance before 17.05.01 does not sanitize user input in its Nmap Discovery utility. An attacker (with permissions to add or edit jobs run by this utility) can inject an extra argument to overwrite arbitrary files as the root user on the Remote Collector.

    Published: 17 Sept 2021
    6.2
    Medium

    CVE-2021-39227

    Last Modified: 21 Nov 2024

    ZRender is a lightweight graphic library providing 2d draw for Apache ECharts. In versions prior to 5.2.1, using `merge` and `clone` helper methods in the `src/core/util.ts` module results in prototype pollution. It affects the popular data visualization library Apache ECharts, which uses and exports these two methods directly. The GitHub Security Advisory page for this vulnerability contains a proof of concept. This issue is patched in ZRender version 5.2.1. One workaround is available: Check if there is `__proto__` in the object keys. Omit it before using it as an parameter in these affected methods. Or in `echarts.util.merge` and `setOption` if project is using ECharts.

    Published: 17 Sept 2021
    6.5
    Medium

    CVE-2021-39228

    Last Modified: 21 Nov 2024

    Tremor is an event processing system for unstructured data. A vulnerability exists between versions 0.7.2 and 0.11.6. This vulnerability is a memory safety Issue when using `patch` or `merge` on `state` and assign the result back to `state`. In this case, affected versions of Tremor and the tremor-script crate maintains references to memory that might have been freed already. And these memory regions can be accessed by retrieving the `state`, e.g. send it over TCP or HTTP. This requires the Tremor server (or any other program using tremor-script) to execute a tremor-script script that uses the mentioned language construct. The issue has been patched in version 0.11.6 by removing the optimization and always cloning the target expression of a Merge or Patch. If an upgrade is not possible, a possible workaround is to avoid the optimization by introducing a temporary variable and not immediately reassigning to `state`.

    Published: 17 Sept 2021
    8.2
    High

    CVE-2021-31844

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.200 allows a local attacker to execute arbitrary code with elevated privileges through placing carefully constructed Ami Pro (.sam) files onto the local system and triggering a DLP Endpoint scan through accessing a file. This is caused by the destination buffer being of fixed size and incorrect checks being made on the source size.

    Published: 17 Sept 2021
    8.4
    High

    CVE-2021-31845

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in McAfee Data Loss Prevention (DLP) Discover prior to 11.6.100 allows an attacker in the same network as the DLP Discover to execute arbitrary code through placing carefully constructed Ami Pro (.sam) files onto a machine and having DLP Discover scan it, leading to remote code execution with elevated privileges. This is caused by the destination buffer being of fixed size and incorrect checks being made on the source size.

    Published: 17 Sept 2021
    7.3
    High

    CVE-2021-31843

    Last Modified: 24 Feb 2026

    Improper privileges management vulnerability in McAfee Endpoint Security (ENS) Windows prior to 10.7.0 September 2021 Update allows local users to access files which they would otherwise not have access to via manipulating junction links to redirect McAfee folder operations to an unintended location.

    Published: 17 Sept 2021
    5
    Medium

    CVE-2021-31842

    Last Modified: 21 Nov 2024

    XML Entity Expansion injection vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2021 Update allows a local user to initiate high CPU and memory consumption resulting in a Denial of Service attack through carefully editing the EPDeploy.xml file and then executing the setup process.

    Published: 17 Sept 2021
    5.3
    Medium

    CVE-2021-39327

    Last Modified: 31 Mar 2025

    The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible ~/db_backup_log.txt file which grants attackers the full path of the site, in addition to the path of database backup files. This affects versions up to, and including, 5.1.

    Published: 17 Sept 2021
    8.6
    High

    CVE-2021-23442

    Last Modified: 21 Nov 2024

    This affects all versions of package @cookiex/deep. The global proto object can be polluted using the __proto__ object.

    Published: 17 Sept 2021
    8.4
    High

    CVE-2021-30261

    Last Modified: 21 Nov 2024

    Possible integer and heap overflow due to lack of input command size validation while handling beacon template update command from HLOS in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 17 Sept 2021
    8.4
    High

    CVE-2021-30260

    Last Modified: 21 Nov 2024

    Possible Integer overflow to buffer overflow issue can occur due to improper validation of input parameters when extscan hostlist configuration command is received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 17 Sept 2021
    9.8
    Critical

    CVE-2021-1976

    Last Modified: 21 Nov 2024

    A use after free can occur due to improper validation of P2P device address in PD Request frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 17 Sept 2021
    8.4
    High

    CVE-2021-1947

    Last Modified: 21 Nov 2024

    Use-after-free vulnerability in kernel graphics driver because of storing an invalid pointer in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 17 Sept 2021
    8.4
    High

    CVE-2021-1939

    Last Modified: 21 Nov 2024

    Null pointer dereference occurs due to improper validation when the preemption feature enablement is toggled in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables

    Published: 17 Sept 2021
    6.1
    Medium

    CVE-2021-3812

    Last Modified: 21 Nov 2024

    adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 17 Sept 2021
    6.1
    Medium

    CVE-2021-3811

    Last Modified: 21 Nov 2024

    adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 17 Sept 2021
    7.5
    High

    CVE-2021-3810

    Last Modified: 21 Nov 2024

    code-server is vulnerable to Inefficient Regular Expression Complexity

    Published: 17 Sept 2021
    7.5
    High

    CVE-2021-3804

    Last Modified: 21 Nov 2024

    taro is vulnerable to Inefficient Regular Expression Complexity

    Published: 17 Sept 2021
    6.1
    Medium

    CVE-2021-20828

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Order Status Batch Change Plug-in (for EC-CUBE 3.0 series) all versions allows a remote attacker to inject an arbitrary script via unspecified vectors.

    Published: 17 Sept 2021
    6.1
    Medium

    CVE-2021-20825

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in List (order management) item change plug-in (for EC-CUBE 3.0 series) Ver.1.1 and earlier allows a remote attacker to inject an arbitrary script via unspecified vectors.

    Published: 17 Sept 2021
    9.3
    Critical

    CVE-2021-20791

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in RevoWorks Browser 2.1.230 and earlier allows an attacker to bypass access restriction and to exchange unauthorized files between the local environment and the isolated environment or settings of the web browser via unspecified vectors.

    Published: 17 Sept 2021
    9.6
    Critical

    CVE-2021-20790

    Last Modified: 21 Nov 2024

    Improper control of program execution vulnerability in RevoWorks Browser 2.1.230 and earlier allows an attacker to execute an arbitrary command or code via unspecified vectors.

    Published: 17 Sept 2021
    7.5
    High

    CVE-2021-40690

    Last Modified: 25 Aug 2026

    All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.

    Published: 17 Sept 2021
    7.5
    High

    CVE-2021-3807

    Last Modified: 21 Nov 2024

    ansi-regex is vulnerable to Inefficient Regular Expression Complexity

    Published: 17 Sept 2021
    9.8
    Critical

    CVE-2021-41326

    Last Modified: 21 Nov 2024

    In MISP before 2.4.148, app/Lib/Export/OpendataExport.php mishandles parameter data that is used in a shell_exec call.

    Published: 17 Sept 2021
    8.8
    High

    CVE-2021-41314

    Last Modified: 21 Nov 2024

    Certain NETGEAR smart switches are affected by a \n injection in the web UI's password field, which - due to several faulty aspects of the authentication scheme - allows the attacker to create (or overwrite) a file with specific content (e.g., the "2" string). This leads to admin session crafting and therefore gaining full web UI admin privileges by an unauthenticated attacker. This affects GC108P before 1.0.8.2, GC108PP before 1.0.8.2, GS108Tv3 before 7.0.7.2, GS110TPP before 7.0.7.2, GS110TPv3 before 7.0.7.2, GS110TUP before 1.0.5.3, GS308T before 1.0.3.2, GS310TP before 1.0.3.2, GS710TUP before 1.0.5.3, GS716TP before 1.0.4.2, GS716TPP before 1.0.4.2, GS724TPP before 2.0.6.3, GS724TPv2 before 2.0.6.3, GS728TPPv2 before 6.0.8.2, GS728TPv2 before 6.0.8.2, GS750E before 1.0.1.10, GS752TPP before 6.0.8.2, GS752TPv2 before 6.0.8.2, MS510TXM before 1.0.4.2, and MS510TXUP before 1.0.4.2.

    Published: 16 Sept 2021
    9.8
    Critical

    CVE-2021-40670

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords iparameter under the /coreframe/app/order/admin/card.php file.

    Published: 16 Sept 2021
    9.8
    Critical

    CVE-2021-40669

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords parameter under the coreframe/app/promote/admin/index.php file.

    Published: 16 Sept 2021
    5.3
    Medium

    CVE-2021-29842

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 21.0.0.9 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-Force ID: 205202.

    Published: 16 Sept 2021
    7.5
    High

    CVE-2021-29825

    Last Modified: 21 Nov 2024

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information when using ADMIN_CMD with LOAD or BACKUP. IBM X-Force ID: 204470.

    Published: 16 Sept 2021
    5.1
    Medium

    CVE-2021-29763

    Last Modified: 21 Nov 2024

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 under very specific conditions, could allow a local user to keep running a procedure that could cause the system to run out of memory.and cause a denial of service. IBM X-Force ID: 202267.

    Published: 16 Sept 2021
    4.4
    Medium

    CVE-2021-29752

    Last Modified: 21 Nov 2024

    IBM Db2 11.2 and 11.5 contains an information disclosure vulnerability, exposing remote storage credentials to privileged users under specific conditions. IBM X-Fporce ID: 201780.

    Published: 16 Sept 2021
    8.1
    High

    CVE-2021-39214

    Last Modified: 21 Nov 2024

    mitmproxy is an interactive, SSL/TLS-capable intercepting proxy. In mitmproxy 7.0.2 and below, a malicious client or server is able to perform HTTP request smuggling attacks through mitmproxy. This means that a malicious client/server could smuggle a request/response through mitmproxy as part of another request/response's HTTP message body. While a smuggled request is still captured as part of another request's body, it does not appear in the request list and does not go through the usual mitmproxy event hooks, where users may have implemented custom access control checks or input sanitization. Unless one uses mitmproxy to protect an HTTP/1 service, no action is required. The vulnerability has been fixed in mitmproxy 7.0.3 and above.

    Published: 16 Sept 2021
    7.5
    High

    CVE-2021-39239

    Last Modified: 21 Nov 2024

    A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including exposing the contents of local files to a remote server.

    Published: 16 Sept 2021
    4.3
    Medium

    CVE-2021-39208

    Last Modified: 21 Nov 2024

    SharpCompress is a fully managed C# library to deal with many compression types and formats. Versions prior to 0.29.0 are vulnerable to partial path traversal. SharpCompress recreates a hierarchy of directories under destinationDirectory if ExtractFullPath is set to true in options. In order to prevent extraction outside the destination directory the destinationFileName path is verified to begin with fullDestinationDirectoryPath. However, prior to version 0.29.0, it is not enforced that fullDestinationDirectoryPath ends with slash. If the destinationDirectory is not slash terminated like `/home/user/dir` it is possible to create a file with a name thats begins as the destination directory one level up from the directory, i.e. `/home/user/dir.sh`. Because of the file name and destination directory constraints the arbitrary file creation impact is limited and depends on the use case. This issue is fixed in SharpCompress version 0.29.0.

    Published: 16 Sept 2021
    6.1
    Medium

    CVE-2021-27340

    Last Modified: 21 Nov 2024

    OpenSIS Community Edition version <= 7.6 is affected by a reflected XSS vulnerability in EmailCheck.php via the "opt" parameter.

    Published: 16 Sept 2021
    9.8
    Critical

    CVE-2021-27341

    Last Modified: 21 Nov 2024

    OpenSIS Community Edition version <= 7.6 is affected by a local file inclusion vulnerability in DownloadWindow.php via the "filename" parameter.

    Published: 16 Sept 2021
    4.3
    Medium

    CVE-2021-34576

    Last Modified: 21 Nov 2024

    In Kaden PICOFLUX Air in all known versions an information exposure through observable discrepancy exists. This may give sensitive information (water consumption without distinct values) to third parties.

    Published: 16 Sept 2021
    6.2
    Medium

    CVE-2021-34573

    Last Modified: 21 Nov 2024

    In Enbra EWM in Version 1.7.29 together with several tested wireless M-Bus Sensors the events backflow and "no flow" are not reconized or misinterpreted. This may lead to wrong values and missing events.

    Published: 16 Sept 2021
    6.5
    Medium

    CVE-2021-34572

    Last Modified: 21 Nov 2024

    Enbra EWM 1.7.29 does not check for or detect replay attacks sent by wireless M-Bus Security mode 5 devices. Instead timestamps of the sensor are replaced by the time of the readout even if the data is a replay of earlier data.

    Published: 16 Sept 2021
    6.5
    Medium

    CVE-2021-34571

    Last Modified: 21 Nov 2024

    Multiple Wireless M-Bus devices by Enbra use Hard-coded Credentials in Security mode 5 without an option to change the encryption key. An adversary can learn all information that is available in Enbra EWM.

    Published: 16 Sept 2021