CVE Feed

    Dashboard / CVE

    9.1
    Critical

    CVE-2021-33695

    Last Modified: 21 Nov 2024

    Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted without sufficient validation of the certificate.

    Published: 15 Sept 2021
    7.5
    High

    CVE-2021-33692

    Last Modified: 21 Nov 2024

    SAP Cloud Connector, version - 2.0, allows the upload of zip files as backup. This backup file can be tricked to inject special elements such as '..' and '/' separators, for attackers to escape outside of the restricted location to access files or directories.

    Published: 15 Sept 2021
    5.4
    Medium

    CVE-2021-33696

    Last Modified: 21 Nov 2024

    SAP BusinessObjects Business Intelligence Platform (Crystal Report), versions - 420, 430, does not sufficiently encode user controlled inputs and therefore an authorized attacker can exploit a XSS vulnerability, leading to non-permanently deface or modify displayed content from a Web site.

    Published: 15 Sept 2021
    9.9
    Critical

    CVE-2021-33690

    Last Modified: 21 Nov 2024

    Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50The SAP NetWeaver Development Infrastructure Component Build Service allows a threat actor who has access to the server to perform proxy attacks on server by sending crafted queries. Due to this, the threat actor could completely compromise sensitive data residing on the Server and impact its availability.Note: The impact of this vulnerability depends on whether SAP NetWeaver Development Infrastructure (NWDI) runs on the intranet or internet. The CVSS score reflects the impact considering the worst-case scenario that it runs on the internet.

    Published: 15 Sept 2021
    5.4
    Medium

    CVE-2021-29773

    Last Modified: 21 Nov 2024

    IBM Security Guardium 10.6 and 11.3 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 202865.

    Published: 15 Sept 2021
    7.5
    High

    CVE-2021-29750

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 201778.

    Published: 15 Sept 2021
    6.5
    Medium

    CVE-2021-20433

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.3 could allow a an authenticated user to obtain sensitive information that could be used in further attacks against the system. IBM X-Force ID: 196345.

    Published: 15 Sept 2021
    5.4
    Medium

    CVE-2021-28901

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities exist in SITA Software Azur CMS 1.2.3.1 and earlier, which allows remote attackers to inject arbitrary web script or HTML via the (1) NOM_CLI , (2) ADRESSE , (3) ADRESSE2, (4) LOCALITE parameters to /eshop/products/json/aouCustomerAdresse; and the (5) nom_liste parameter to /eshop/products/json/addCustomerFavorite.

    Published: 15 Sept 2021
    7.5
    High

    CVE-2021-39215

    Last Modified: 21 Nov 2024

    Jitsi Meet is an open source video conferencing application. In versions prior to 2.0.5963, a Prosody module allows the use of symmetrical algorithms to validate JSON web tokens. This means that tokens generated by arbitrary sources can be used to gain authorization to protected rooms. This issue is fixed in Jitsi Meet 2.0.5963. There are no known workarounds aside from updating.

    Published: 15 Sept 2021
    6.8
    Medium

    CVE-2021-39205

    Last Modified: 21 Nov 2024

    Jitsi Meet is an open source video conferencing application. Versions prior to 2.0.6173 are vulnerable to client-side cross-site scripting via injecting properties into JSON objects that were not properly escaped. There are no known incidents related to this vulnerability being exploited in the wild. This issue is fixed in Jitsi Meet version 2.0.6173. There are no known workarounds aside from upgrading.

    Published: 15 Sept 2021
    6.5
    Medium

    CVE-2021-40964

    Last Modified: 31 Dec 2025

    A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload a file (with Admin credentials or with the CSRF vulnerability) with the "fullpath" parameter containing path traversal strings (../ and ..\) in order to escape the server's intended working directory and write malicious files onto any directory on the computer.

    Published: 15 Sept 2021
    8.8
    High

    CVE-2021-40965

    Last Modified: 31 Dec 2025

    A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload files and run OS commands by inducing the Administrator user to browse a URL controlled by an attacker.

    Published: 15 Sept 2021
    5.4
    Medium

    CVE-2021-40966

    Last Modified: 31 Dec 2025

    A Stored XSS exists in TinyFileManager All version up to and including 2.4.6 in /tinyfilemanager.php when the server is given a file that contains HTML and javascript in its name. A malicious user can upload a file with a malicious filename containing javascript code and it will run on any user browser when they access the server.

    Published: 15 Sept 2021
    6.8
    Medium

    CVE-2021-39213

    Last Modified: 21 Nov 2024

    GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with API Rest enabled is vulnerable to API bypass with custom header injection. This issue is fixed in version 9.5.6. One may disable API Rest as a workaround.

    Published: 15 Sept 2021
    5.3
    Medium

    CVE-2021-39211

    Last Modified: 21 Nov 2024

    GLPI is a free Asset and IT management software package. Starting in version 9.2 and prior to version 9.5.6, the telemetry endpoint discloses GLPI and server information. This issue is fixed in version 9.5.6. As a workaround, remove the file `ajax/telemetry.php`, which is not needed for usual functions of GLPI.

    Published: 15 Sept 2021
    6.5
    Medium

    CVE-2021-39210

    Last Modified: 21 Nov 2024

    GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses the "remember me" feature) is accessible by scripts. A malicious plugin that could steal this cookie would be able to use it to autologin. This issue is fixed in version 9.5.6. As a workaround, one may avoid using the "remember me" feature.

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-40156

    Last Modified: 21 Nov 2024

    A maliciously crafted DWG file in Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to write beyond allocated boundaries when parsing the DWG files. This vulnerability can be exploited to execute arbitrary code.

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-40155

    Last Modified: 21 Nov 2024

    A maliciously crafted DWG file in Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to read beyond allocated boundaries when parsing the DWG files. This vulnerability can be exploited to execute arbitrary code.

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-27046

    Last Modified: 21 Nov 2024

    A Memory Corruption vulnerability for PDF files in Autodesk Navisworks 2019, 2020, 2021, 2022 may lead to code execution through maliciously crafted DLL files.

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-27045

    Last Modified: 21 Nov 2024

    A maliciously crafted PDF file in Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to read beyond allocated boundaries when parsing the PDF file. This vulnerability can be exploited to execute arbitrary code.

    Published: 15 Sept 2021
    6.1
    Medium

    CVE-2021-37412

    Last Modified: 21 Nov 2024

    The TechRadar app 1.1 for Confluence Server allows XSS via the Title field of a Radar.

    Published: 15 Sept 2021
    6.1
    Medium

    CVE-2021-40238

    Last Modified: 21 Nov 2024

    A Cross Site Scriptiong (XSS) vulnerability exists in the admin panel in Webuzo < 2.9.0 via an HTTP request to a non-existent page, which is activated by administrators viewing the "Error Log" page. An attacker can leverage this to achieve Unauthenticated Remote Code Execution via the "Cron Jobs" functionality of Webuzo.

    Published: 15 Sept 2021
    9.8
    Critical

    CVE-2020-21127

    Last Modified: 21 Nov 2024

    MetInfo 7.0.0 contains a SQL injection vulnerability via admin/?n=logs&c=index&a=dodel.

    Published: 15 Sept 2021
    8.8
    High

    CVE-2020-21126

    Last Modified: 21 Nov 2024

    MetInfo 7.0.0 contains a Cross-Site Request Forgery (CSRF) via admin/?n=admin&c=index&a=doSaveInfo.

    Published: 15 Sept 2021
    9.8
    Critical

    CVE-2020-21124

    Last Modified: 21 Nov 2024

    UReport 2.2.9 allows attackers to execute arbitrary code due to a lack of access control to the designer page.

    Published: 15 Sept 2021
    9.8
    Critical

    CVE-2020-21125

    Last Modified: 21 Nov 2024

    An arbitrary file creation vulnerability in UReport 2.2.9 allows attackers to execute arbitrary code.

    Published: 15 Sept 2021
    5.3
    Medium

    CVE-2020-21122

    Last Modified: 21 Nov 2024

    UReport v2.2.9 contains a Server-Side Request Forgery (SSRF) in the designer page which allows attackers to detect intranet device ports.

    Published: 15 Sept 2021
    9.8
    Critical

    CVE-2020-21121

    Last Modified: 21 Nov 2024

    Pligg CMS 2.0.2 contains a time-based SQL injection vulnerability via the $recordIDValue parameter in the admin_update_module_widgets.php file.

    Published: 15 Sept 2021
    9.8
    Critical

    CVE-2021-39392

    Last Modified: 21 Nov 2024

    The management tool in MyLittleBackup up to and including 1.7 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the same for all customers' installations) in web.config, and can be used to send serialized ASP code.

    Published: 15 Sept 2021
    8.8
    High

    CVE-2021-25741

    Last Modified: 21 Nov 2024

    A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.

    Published: 15 Sept 2021
    8.8
    High

    CVE-2021-39209

    Last Modified: 21 Nov 2024

    GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, a user who is logged in to GLPI can bypass Cross-Site Request Forgery (CSRF) protection in many places. This could allow a malicious actor to perform many actions on GLPI. This issue is fixed in version 9.5.6. There are no workarounds aside from upgrading.

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-40157

    Last Modified: 21 Nov 2024

    A user may be tricked into opening a malicious FBX file which may exploit an Untrusted Pointer Dereference vulnerability in FBX’s Review version 1.5.0 and prior causing it to run arbitrary code on the system.

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-27044

    Last Modified: 21 Nov 2024

    A Out-Of-Bounds Read/Write Vulnerability in Autodesk FBX Review version 1.4.0 may lead to remote code execution through maliciously crafted DLL files or information disclosure.

    Published: 15 Sept 2021
    8.8
    High

    CVE-2020-19159

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) in LaikeTui v3 allows remote attackers to execute arbitrary code via the component '/index.php?module=member&action=add'.

    Published: 15 Sept 2021
    5.4
    Medium

    CVE-2020-19158

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in S-CMS build 20191014 and earlier allows remote attackers to execute arbitrary code via the 'Site Title' parameter of the component '/data/admin/#/app/config/'.

    Published: 15 Sept 2021
    6.1
    Medium

    CVE-2020-19157

    Last Modified: 21 Nov 2024

    Cross Site Scripting (CSS) in Wenku CMS v3.4 allows remote attackers to execute arbitrary code via the 'Intro' parameter for the component '/index.php?m=ucenter&a=index'.

    Published: 15 Sept 2021
    5.4
    Medium

    CVE-2020-19156

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in Ari Adminer v1 allows remote attackers to execute arbitrary code via the 'Title' parameter of the 'Add New Connections' component when the 'save()' function is called.

    Published: 15 Sept 2021
    8.8
    High

    CVE-2020-19155

    Last Modified: 21 Nov 2024

    Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' function in the component 'modules/filemanager/FileManagerController.java'.

    Published: 15 Sept 2021
    8.8
    High

    CVE-2020-19151

    Last Modified: 21 Nov 2024

    Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via the component 'jfinal_cms/admin/filemanager/list'.

    Published: 15 Sept 2021
    6.5
    Medium

    CVE-2020-19154

    Last Modified: 21 Nov 2024

    Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java'.

    Published: 15 Sept 2021
    8.1
    High

    CVE-2020-19150

    Last Modified: 21 Nov 2024

    Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component 'modules/filemanager/FileManagerController.java'.

    Published: 15 Sept 2021
    5.4
    Medium

    CVE-2020-19148

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code via the 'Nickname' parameter in the component '/jfinal_cms/front/person/profile.html'.

    Published: 15 Sept 2021
    6.5
    Medium

    CVE-2020-19147

    Last Modified: 21 Nov 2024

    Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive infromation via the 'getFolder()' function in the component '/modules/filemanager/FileManager.java'.

    Published: 15 Sept 2021
    6.5
    Medium

    CVE-2020-19146

    Last Modified: 21 Nov 2024

    Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'TemplatePath' parameter in the component 'jfinal_cms/admin/folder/list'.

    Published: 15 Sept 2021
    5.3
    Medium

    CVE-2021-39189

    Last Modified: 21 Nov 2024

    Pimcore is an open source data & experience management platform. In versions prior to 10.1.3, it is possible to enumerate usernames via the forgot password functionality. This issue is fixed in version 10.1.3. As a workaround, one may apply the available patch manually.

    Published: 15 Sept 2021
    5.4
    Medium

    CVE-2021-38156

    Last Modified: 21 Nov 2024

    In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.

    Published: 15 Sept 2021
    7.8
    High

    CVE-2021-21798

    Last Modified: 21 Nov 2024

    An exploitable return of stack variable address vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a stack variable to go out of scope, resulting in the application dereferencing a stale pointer. This can lead to code execution under the context of the application. An attacker can convince a user to open a document to trigger the vulnerability.

    Published: 15 Sept 2021
    9.8
    Critical

    CVE-2021-3797

    Last Modified: 21 Nov 2024

    hestiacp is vulnerable to Use of Wrong Operator in String Comparison

    Published: 15 Sept 2021
    6.1
    Medium

    CVE-2021-39307

    Last Modified: 21 Nov 2024

    PDFTron's WebViewer UI 8.0 or below renders dangerous URLs as hyperlinks in supported documents, including JavaScript URLs, allowing the execution of arbitrary JavaScript code.

    Published: 15 Sept 2021
    —
    Unknown

    CVE-2021-41076

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 15 Sept 2021