CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2021-32132

    Last Modified: 21 Nov 2024

    The abst_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

    Published: 13 Sept 2021
    5.5
    Medium

    CVE-2021-32135

    Last Modified: 21 Nov 2024

    The trak_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

    Published: 13 Sept 2021
    5.5
    Medium

    CVE-2021-32137

    Last Modified: 21 Nov 2024

    Heap buffer overflow in the URL_GetProtocolType function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.

    Published: 13 Sept 2021
    5.5
    Medium

    CVE-2021-32134

    Last Modified: 21 Nov 2024

    The gf_odf_desc_copy function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

    Published: 13 Sept 2021
    7.8
    High

    CVE-2021-32136

    Last Modified: 21 Nov 2024

    Heap buffer overflow in the print_udta function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.

    Published: 13 Sept 2021
    4.9
    Medium

    CVE-2021-22526

    Last Modified: 21 Nov 2024

    Open Redirection vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4

    Published: 13 Sept 2021
    5.4
    Medium

    CVE-2021-22524

    Last Modified: 21 Nov 2024

    Injection attack caused the denial of service vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4

    Published: 13 Sept 2021
    6
    Medium

    CVE-2021-22527

    Last Modified: 21 Nov 2024

    Information leakage vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4

    Published: 13 Sept 2021
    5.3
    Medium

    CVE-2020-27970

    Last Modified: 21 Nov 2024

    Yandex Browser before 20.10.0 allows remote attackers to spoof the address bar

    Published: 13 Sept 2021
    7.3
    High

    CVE-2020-27969

    Last Modified: 21 Nov 2024

    Yandex Browser for Android 20.8.4 allows remote attackers to perform SOP bypass and addresss bar spoofing

    Published: 13 Sept 2021
    8
    High

    CVE-2021-22528

    Last Modified: 21 Nov 2024

    Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4

    Published: 13 Sept 2021
    5.4
    Medium

    CVE-2021-40214

    Last Modified: 21 Nov 2024

    Gibbon v22.0.00 suffers from a stored XSS vulnerability within the wall messages component.

    Published: 13 Sept 2021
    9.8
    Critical

    CVE-2021-40870

    Last Modified: 10 Nov 2025

    An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

    Published: 13 Sept 2021
    7.8
    High

    CVE-2021-40867

    Last Modified: 21 Nov 2024

    Certain NETGEAR smart switches are affected by an authentication hijacking race-condition vulnerability by an unauthenticated attacker who uses the same source IP address as an admin in the process of logging in (e.g., behind the same NAT device, or already in possession of a foothold on an admin's machine). This occurs because the multi-step HTTP authentication process is effectively tied only to the source IP address. This affects GC108P before 1.0.8.2, GC108PP before 1.0.8.2, GS108Tv3 before 7.0.7.2, GS110TPP before 7.0.7.2, GS110TPv3 before 7.0.7.2, GS110TUP before 1.0.5.3, GS308T before 1.0.3.2, GS310TP before 1.0.3.2, GS710TUP before 1.0.5.3, GS716TP before 1.0.4.2, GS716TPP before 1.0.4.2, GS724TPP before 2.0.6.3, GS724TPv2 before 2.0.6.3, GS728TPPv2 before 6.0.8.2, GS728TPv2 before 6.0.8.2, GS750E before 1.0.1.10, GS752TPP before 6.0.8.2, GS752TPv2 before 6.0.8.2, MS510TXM before 1.0.4.2, and MS510TXUP before 1.0.4.2.

    Published: 13 Sept 2021
    9.8
    Critical

    CVE-2021-40866

    Last Modified: 21 Nov 2024

    Certain NETGEAR smart switches are affected by a remote admin password change by an unauthenticated attacker via the (disabled by default) /sqfs/bin/sccd daemon, which fails to check authentication when the authentication TLV is missing from a received NSDP packet. This affects GC108P before 1.0.8.2, GC108PP before 1.0.8.2, GS108Tv3 before 7.0.7.2, GS110TPP before 7.0.7.2, GS110TPv3 before 7.0.7.2, GS110TUP before 1.0.5.3, GS308T before 1.0.3.2, GS310TP before 1.0.3.2, GS710TUP before 1.0.5.3, GS716TP before 1.0.4.2, GS716TPP before 1.0.4.2, GS724TPP before 2.0.6.3, GS724TPv2 before 2.0.6.3, GS728TPPv2 before 6.0.8.2, GS728TPv2 before 6.0.8.2, GS750E before 1.0.1.10, GS752TPP before 6.0.8.2, GS752TPv2 before 6.0.8.2, MS510TXM before 1.0.4.2, and MS510TXUP before 1.0.4.2.

    Published: 13 Sept 2021
    7.5
    High

    CVE-2021-3803

    Last Modified: 21 Nov 2024

    nth-check is vulnerable to Inefficient Regular Expression Complexity

    Published: 13 Sept 2021
    5.5
    Medium

    CVE-2021-33361

    Last Modified: 21 Nov 2024

    Memory leak in the afra_box_read function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.

    Published: 13 Sept 2021
    5.5
    Medium

    CVE-2021-33363

    Last Modified: 21 Nov 2024

    Memory leak in the infe_box_read function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.

    Published: 13 Sept 2021
    5.5
    Medium

    CVE-2021-33364

    Last Modified: 21 Nov 2024

    Memory leak in the def_parent_box_new function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.

    Published: 13 Sept 2021
    5.5
    Medium

    CVE-2021-33366

    Last Modified: 21 Nov 2024

    Memory leak in the gf_isom_oinf_read_entry function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.

    Published: 13 Sept 2021
    7.5
    High

    CVE-2021-3703

    Last Modified: 21 Nov 2024

    It was found that the CVE-2021-27918, CVE-2021-31525 and CVE-2021-33196 have been incorrectly mentioned as fixed in RHSA for Serverless 1.16.0 and Serverless client kn 1.16.0. These have been fixed with Serverless 1.17.0.

    Published: 13 Sept 2021
    7.8
    High

    CVE-2021-3847

    Last Modified: 21 Nov 2024

    An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to escalate their privileges on the system.

    Published: 13 Sept 2021
    4.4
    Medium

    CVE-2021-39212

    Last Modified: 21 Nov 2024

    ImageMagick is free software delivered as a ready-to-run binary distribution or as source code that you may use, copy, modify, and distribute in both open and proprietary applications. In affected versions and in certain cases, Postscript files could be read and written when specifically excluded by a `module` policy in `policy.xml`. ex. <policy domain="module" rights="none" pattern="PS" />. The issue has been resolved in ImageMagick 7.1.0-7 and in 6.9.12-22. Fortunately, in the wild, few users utilize the `module` policy and instead use the `coder` policy that is also our workaround recommendation: <policy domain="coder" rights="none" pattern="{PS,EPI,EPS,EPSF,EPSI}" />.

    Published: 13 Sept 2021
    5.5
    Medium

    CVE-2021-33365

    Last Modified: 21 Nov 2024

    Memory leak in the gf_isom_get_root_od function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.

    Published: 13 Sept 2021
    4.2
    Medium

    CVE-2021-3802

    Last Modified: 21 Nov 2024

    A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highest threat from this vulnerability is to system availability.

    Published: 13 Sept 2021
    7.5
    High

    CVE-2021-3805

    Last Modified: 21 Nov 2024

    object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

    Published: 13 Sept 2021
    5.5
    Medium

    CVE-2021-4148

    Last Modified: 21 Nov 2024

    A vulnerability was found in the Linux kernel's block_invalidatepage in fs/buffer.c in the filesystem. A missing sanity check may allow a local attacker with user privilege to cause a denial of service (DOS) problem.

    Published: 13 Sept 2021
    —
    Unknown

    CVE-2021-41064

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

    Published: 13 Sept 2021
    7.6
    High

    CVE-2021-23435

    Last Modified: 21 Nov 2024

    This affects the package clearance before 2.5.0. The vulnerability can be possible when users are able to set the value of session[:return_to]. If the value used for return_to contains multiple leading slashes (/////example.com) the user ends up being redirected to the external domain that comes after the slashes (http://example.com).

    Published: 12 Sept 2021
    7.8
    High

    CVE-2021-4197

    Last Modified: 21 Nov 2024

    An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have higher privileged parent process. It is actually both for cgroup2 and cgroup1 versions of control groups. A local user could use this flaw to crash the system or escalate their privileges on the system.

    Published: 12 Sept 2021
    7.3
    High

    CVE-2021-23440

    Last Modified: 21 Nov 2024

    This affects the package set-value before <2.0.1, >=3.0.0 <4.0.1. A type confusion vulnerability can lead to a bypass of CVE-2019-10747 when the user-provided keys used in the path parameter are arrays.

    Published: 12 Sept 2021
    9.8
    Critical

    CVE-2021-40146

    Last Modified: 21 Nov 2024

    A Remote Code Execution (RCE) vulnerability was discovered in the Any23 YAMLExtractor.java file and is known to affect Any23 versions < 2.5. RCE vulnerabilities allow a malicious actor to execute any code of their choice on a remote machine over LAN, WAN, or internet. RCE belongs to the broader class of arbitrary code execution (ACE) vulnerabilities.

    Published: 11 Sept 2021
    9.1
    Critical

    CVE-2021-38555

    Last Modified: 21 Nov 2024

    An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application's processing of XML data. It often allows an attacker to view files on the application server filesystem, and to interact with any back-end or external systems that the application itself can access.

    Published: 11 Sept 2021
    6.5
    Medium

    CVE-2021-3801

    Last Modified: 21 Nov 2024

    prism is vulnerable to Inefficient Regular Expression Complexity

    Published: 11 Sept 2021
    7.3
    High

    CVE-2021-3796

    Last Modified: 21 Nov 2024

    vim is vulnerable to Use After Free

    Published: 11 Sept 2021
    8.4
    High

    CVE-2021-39207

    Last Modified: 21 Nov 2024

    parlai is a framework for training and evaluating AI models on a variety of openly available dialogue datasets. In affected versions the package is vulnerable to YAML deserialization attack caused by unsafe loading which leads to Arbitary code execution. This security bug is patched by avoiding unsafe loader users should update to version above v1.1.0. If upgrading is not possible then users can change the Loader used to SafeLoader as a workaround. See commit 507d066ef432ea27d3e201da08009872a2f37725 for details.

    Published: 10 Sept 2021
    9.8
    Critical

    CVE-2021-24040

    Last Modified: 21 Nov 2024

    Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input, resulting in remote code execution or similar risks. This issue affects ParlAI prior to v1.1.0.

    Published: 10 Sept 2021
    5.4
    Medium

    CVE-2021-40347

    Last Modified: 21 Nov 2024

    An issue was discovered in views/list.py in GNU Mailman Postorius before 1.3.5. An attacker (logged into any account) can send a crafted POST request to unsubscribe any user from a mailing list, also revealing whether that address was subscribed in the first place.

    Published: 10 Sept 2021
    6.7
    Medium

    CVE-2021-3145

    Last Modified: 21 Nov 2024

    In Ionic Identity Vault before 5, a local root attacker on an Android device can bypass biometric authentication.

    Published: 10 Sept 2021
    9.8
    Critical

    CVE-2021-40864

    Last Modified: 21 Nov 2024

    The Translate plugin 6.1.x through 6.3.x before 6.3.0.72 for ONLYOFFICE Document Server lacks escape calls for the msg.data and text fields.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-3646

    Last Modified: 21 Nov 2024

    btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 10 Sept 2021
    9.8
    Critical

    CVE-2021-37422

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases.

    Published: 10 Sept 2021
    9.8
    Critical

    CVE-2021-37423

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover.

    Published: 10 Sept 2021
    —
    Unknown

    CVE-2021-37418

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-31874. Reason: This candidate is a reservation duplicate of CVE-2021-31874. Notes: All CVE users should reference CVE-2021-31874 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 10 Sept 2021
    7.5
    High

    CVE-2021-37414

    Last Modified: 21 Nov 2024

    Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication.

    Published: 10 Sept 2021
    8.3
    High

    CVE-2021-38360

    Last Modified: 31 Mar 2025

    The wp-publications WordPress plugin is vulnerable to restrictive local file inclusion via the Q_FILE parameter found in the ~/bibtexbrowser.php file which allows attackers to include local zip files and achieve remote code execution, in versions up to and including 0.0.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-38357

    Last Modified: 2 May 2025

    The SMS OVH WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the position parameter found in the ~/sms-ovh-sent.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.1.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-38358

    Last Modified: 2 May 2025

    The MoolaMojo WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the classes parameter found in the ~/views/button-generator.html.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.7.4.1.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-38359

    Last Modified: 2 May 2025

    The WordPress InviteBox Plugin for viral Refer-a-Friend Promotions WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the message parameter found in the ~/admin/admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.4.1.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-38354

    Last Modified: 2 May 2025

    The GNU-Mailman Integration WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the gm_error parameter found in the ~/includes/admin/mailing-lists-page.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.6.

    Published: 10 Sept 2021