CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2020-19263

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) in MipCMS v5.0.1 allows attackers to arbitrarily escalate user privileges to administrator via index.php?s=/user/ApiAdminUser/itemEdit.

    Published: 9 Sept 2021
    7.5
    High

    CVE-2021-28910

    Last Modified: 21 Nov 2024

    BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 contains basic SSRF vulnerability. It allow unauthenticated attackers to request to any internal and external server.

    Published: 9 Sept 2021
    9.8
    Critical

    CVE-2021-28909

    Last Modified: 21 Nov 2024

    BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers to access uncontrolled the login service at /webif/SecurityModule in a brute force attack. The password could be weak and default username is known as 'admin'. This is usable and part of an attack chain to gain SSH root access.

    Published: 9 Sept 2021
    6.5
    Medium

    CVE-2021-40284

    Last Modified: 21 Nov 2024

    D-Link DSL-3782 EU v1.01:EU v1.03 is affected by a buffer overflow which can cause a denial of service. This vulnerability exists in the web interface "/cgi-bin/New_GUI/Igmp.asp". Authenticated remote attackers can trigger this vulnerability by sending a long string in parameter 'igmpsnoopEnable' via an HTTP request.

    Published: 9 Sept 2021
    9.8
    Critical

    CVE-2021-38727

    Last Modified: 21 Nov 2024

    FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items

    Published: 9 Sept 2021
    7.5
    High

    CVE-2021-32487

    Last Modified: 21 Nov 2024

    In modem 2G RRM, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00500736; Issue ID: ALPS04938456.

    Published: 9 Sept 2021
    7.5
    High

    CVE-2021-32486

    Last Modified: 21 Nov 2024

    In modem 2G RRM, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00500621; Issue ID: ALPS04964928.

    Published: 9 Sept 2021
    7.5
    High

    CVE-2021-32485

    Last Modified: 21 Nov 2024

    In modem 2G RRM, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00500621; Issue ID: ALPS04964926.

    Published: 9 Sept 2021
    7.5
    High

    CVE-2021-32484

    Last Modified: 21 Nov 2024

    In modem 2G RRM, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00500621; Issue ID: ALPS04964917.

    Published: 9 Sept 2021
    9.8
    Critical

    CVE-2021-38540

    Last Modified: 21 Nov 2024

    The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information disclosure or remote code execution. This issue affects Apache Airflow >=2.0.0, <2.1.3.

    Published: 9 Sept 2021
    5
    Medium

    CVE-2021-22239

    Last Modified: 21 Nov 2024

    An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later.

    Published: 9 Sept 2021
    6.1
    Medium

    CVE-2020-19515

    Last Modified: 21 Nov 2024

    qdPM V9.1 is vulnerable to Cross Site Scripting (XSS) via qdPM\install\modules\database_config.php.

    Published: 9 Sept 2021
    6.5
    Medium

    CVE-2021-38721

    Last Modified: 21 Nov 2024

    FUEL CMS 1.5.0 login.php contains a cross-site request forgery (CSRF) vulnerability

    Published: 9 Sept 2021
    8.8
    High

    CVE-2021-38723

    Last Modified: 21 Nov 2024

    FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/pages/items

    Published: 9 Sept 2021
    5.3
    Medium

    CVE-2021-38725

    Last Modified: 21 Nov 2024

    Fuel CMS 1.5.0 has a brute force vulnerability in fuel/modules/fuel/controllers/Login.php

    Published: 9 Sept 2021
    7.5
    High

    CVE-2021-3761

    Last Modified: 21 Nov 2024

    Any CA issuer in the RPKI can trick OctoRPKI prior to 1.3.0 into emitting an invalid VRP "MaxLength" value, causing RTR sessions to terminate. An attacker can use this to disable RPKI Origin Validation in a victim network (for example AS 13335 - Cloudflare) prior to launching a BGP hijack which during normal operations would be rejected as "RPKI invalid". Additionally, in certain deployments RTR session flapping in and of itself also could cause BGP routing churn, causing availability issues.

    Published: 9 Sept 2021
    6.8
    Medium

    CVE-2021-37101

    Last Modified: 21 Nov 2024

    There is an improper authorization vulnerability in AIS-BW50-00 9.0.6.2(H100SP10C00) and 9.0.6.2(H100SP15C00). Due to improper authorization mangement, an attakcer can exploit this vulnerability by physical accessing the device and implant malicious code. Successfully exploit could leads to arbitrary code execution in the target device.

    Published: 9 Sept 2021
    8.8
    High

    CVE-2021-26608

    Last Modified: 21 Nov 2024

    An arbitrary file download and execution vulnerability was found in the HShell.dll of handysoft Co., Ltd groupware ActiveX module. This issue is due to missing support for integrity check of download URL or downloaded file hash.

    Published: 9 Sept 2021
    8.8
    High

    CVE-2020-7874

    Last Modified: 21 Nov 2024

    Download of code without integrity check vulnerability in NEXACRO14 Runtime ActiveX control of tobesoft Co., Ltd allows the attacker to cause an arbitrary file download and execution. This vulnerability is due to incomplete validation of file download URL or file extension.

    Published: 9 Sept 2021
    8.8
    High

    CVE-2020-7873

    Last Modified: 21 Nov 2024

    Download of code without integrity check vulnerability in ActiveX control of Younglimwon Co., Ltd allows the attacker to cause a arbitrary file download and execution.

    Published: 9 Sept 2021
    9.6
    Critical

    CVE-2021-28494

    Last Modified: 21 Nov 2024

    In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication is bypassed by unprivileged users who are accessing the Web UI. This issue affects: Arista Metamako Operating System MOS-0.34.0 and prior releases

    Published: 9 Sept 2021
    8.4
    High

    CVE-2021-28493

    Last Modified: 21 Nov 2024

    In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, a user may be able to execute commands despite not having the privileges to do so. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train MOS-0.32.0 and prior releases

    Published: 9 Sept 2021
    7.2
    High

    CVE-2021-28495

    Last Modified: 21 Nov 2024

    In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can be bypassed when API access is enabled via the JSON-RPC APIs. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train MOS-0.13 and post releases in the MOS-0.1x train MOS-0.26.6 and below releases in the MOS-0.2x train MOS-0.31.1 and below releases in the MOS-0.3x train

    Published: 9 Sept 2021
    4.4
    Medium

    CVE-2021-28497

    Last Modified: 21 Nov 2024

    In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, the bash shell might be accessible to unprivileged users in situations where they should not have access. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train MOS-0.26.6 and below releases in the MOS-0.2x train MOS-0.31.1 and below releases in the MOS-0.3x train

    Published: 9 Sept 2021
    6.3
    Medium

    CVE-2021-28499

    Last Modified: 21 Nov 2024

    In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user account passwords set in clear text could leak to users without any password. This issue affects: Arista Metamako Operating System MOS-0.18 and post releases in the MOS-0.1x train All releases in the MOS-0.2x train MOS-0.31.1 and prior releases in the MOS-0.3x train

    Published: 9 Sept 2021
    8.7
    High

    CVE-2021-28498

    Last Modified: 21 Nov 2024

    In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user enable passwords set in clear text could result in unprivileged users getting complete access to the systems. This issue affects: Arista Metamako Operating System MOS-0.13 and post releases in the MOS-0.1x train MOS-0.26.6 and prior releases in the MOS-0.2x train MOS-0.31.1 and prior releases in the MOS-0.3x train

    Published: 9 Sept 2021
    7.2
    High

    CVE-2021-39459

    Last Modified: 21 Nov 2024

    Remote code execution in the modules component in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user to execute code on the hosting system via a module containing malicious PHP code.

    Published: 9 Sept 2021
    6.5
    Medium

    CVE-2021-39458

    Last Modified: 21 Nov 2024

    Triggering an error page of the import process in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user has to alternate the files of a vaild file backup. This leads of leaking the database credentials in the environment variables.

    Published: 9 Sept 2021
    6.7
    Medium

    CVE-2021-20118

    Last Modified: 21 Nov 2024

    Nessus Agent 8.3.0 and earlier was found to contain a local privilege escalation vulnerability which could allow an authenticated, local administrator to run specific executables on the Nessus Agent host. This is different than CVE-2021-20117.

    Published: 9 Sept 2021
    6.7
    Medium

    CVE-2021-20117

    Last Modified: 21 Nov 2024

    Nessus Agent 8.3.0 and earlier was found to contain a local privilege escalation vulnerability which could allow an authenticated, local administrator to run specific executables on the Nessus Agent host. This is different than CVE-2021-20118.

    Published: 9 Sept 2021
    9.8
    Critical

    CVE-2021-38408

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow vulnerability in Advantech WebAccess Versions 9.02 and prior caused by a lack of proper validation of the length of user-supplied data may allow remote code execution.

    Published: 9 Sept 2021
    5.5
    Medium

    CVE-2021-36871

    Last Modified: 28 Mar 2025

    Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps Pro premium plugin (versions <= 8.1.11). Vulnerable parameters: &wpgmaps_marker_category_name, Value > &attributes[], Name > &attributes[], &icons[], &names[], &description, &link, &title.

    Published: 9 Sept 2021
    5.5
    Medium

    CVE-2021-36870

    Last Modified: 21 Nov 2024

    Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps plugin (versions <= 8.1.12). Vulnerable parameters: &dataset_name, &wpgmza_gdpr_retention_purpose, &wpgmza_gdpr_company_name, &name #2, &name, &polyname #2, &polyname, &address.

    Published: 9 Sept 2021
    8.6
    High

    CVE-2021-26603

    Last Modified: 21 Nov 2024

    A heap overflow issue was found in ARK library of bandisoft Co., Ltd when the Ark_DigPathA function parsed a file path. This vulnerability is due to missing support for string length check.

    Published: 9 Sept 2021
    5.4
    Medium

    CVE-2021-40223

    Last Modified: 21 Nov 2024

    Rittal CMC PU III Web management (version V3.11.00_2) fails to sanitize user input on several parameters of the configuration (User Configuration dialog, Task Configuration dialog and set logging filter dialog). This allows an attacker to backdoor the device with HTML and browser-interpreted content (such as JavaScript or other client-side scripts). The XSS payload will be triggered when the user accesses some specific sections of the application.

    Published: 9 Sept 2021
    7.2
    High

    CVE-2021-40222

    Last Modified: 21 Nov 2024

    Rittal CMC PU III Web management Version affected: V3.11.00_2. Version fixed: V3.17.10 is affected by a remote code execution vulnerablity. It is possible to introduce shell code to create a reverse shell in the PU-Hostname field of the TCP/IP Configuration dialog. Web application fails to sanitize user input on Network TCP/IP configuration page. This allows the attacker to inject commands as root on the device which will be executed once the data is received.

    Published: 9 Sept 2021
    9.8
    Critical

    CVE-2021-37579

    Last Modified: 21 Nov 2024

    The Dubbo Provider will check the incoming request and the corresponding serialization type of this request meet the configuration set by the server. But there's an exception that the attacker can use to skip the security check (when enabled) and reaching a deserialization operation with native java serialization. Apache Dubbo 2.7.13, 3.0.2 fixed this issue by quickly fail when any unrecognized request was found.

    Published: 9 Sept 2021
    9.8
    Critical

    CVE-2021-36161

    Last Modified: 21 Nov 2024

    Some component in Dubbo will try to print the formated string of the input arguments, which will possibly cause RCE for a maliciously customized bean with special toString method. In the latest version, we fix the toString call in timeout, cache and some other places. Fixed in Apache Dubbo 2.7.13

    Published: 9 Sept 2021
    8.4
    High

    CVE-2021-30295

    Last Modified: 21 Nov 2024

    Possible heap overflow due to improper validation of local variable while storing current task information locally in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 9 Sept 2021
    8.4
    High

    CVE-2021-30294

    Last Modified: 21 Nov 2024

    Potential null pointer dereference in KGSL GPU auxiliary command due to improper validation of user input in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 9 Sept 2021
    8.4
    High

    CVE-2021-30290

    Last Modified: 21 Nov 2024

    Possible null pointer dereference due to race condition between timeline fence signal and time line fence destroy in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 9 Sept 2021
    7.5
    High

    CVE-2021-1974

    Last Modified: 21 Nov 2024

    Possible buffer over read due to lack of alignment between map or unmap length of IPA SMMU and WLAN SMMU in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 9 Sept 2021
    7.5
    High

    CVE-2021-1971

    Last Modified: 21 Nov 2024

    Possible assertion due to lack of physical layer state validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

    Published: 9 Sept 2021
    6.7
    Medium

    CVE-2021-1963

    Last Modified: 21 Nov 2024

    Possible use-after-free due to lack of validation for the rule count in filter table in IPA driver in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 9 Sept 2021
    6.7
    Medium

    CVE-2021-1962

    Last Modified: 21 Nov 2024

    Buffer Overflow while processing IOCTL for getting peripheral endpoint information there is no proper validation for input maximum endpoint pair and its size in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 9 Sept 2021
    6.7
    Medium

    CVE-2021-1961

    Last Modified: 21 Nov 2024

    Possible buffer overflow due to lack of offset length check while updating the buffer value in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 9 Sept 2021
    6.5
    Medium

    CVE-2021-1960

    Last Modified: 21 Nov 2024

    Improper handling of ASB-C broadcast packets with crafted opcode in LMP can lead to uncontrolled resource consumption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 9 Sept 2021
    6.7
    Medium

    CVE-2021-1958

    Last Modified: 21 Nov 2024

    A race condition in fastrpc kernel driver for dynamic process creation can lead to use after free scenario in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wearables

    Published: 9 Sept 2021
    6.5
    Medium

    CVE-2021-1957

    Last Modified: 21 Nov 2024

    Improper Access Control when ACL link encryption is failed and ACL link is not disconnected during reconnection with paired device in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

    Published: 9 Sept 2021
    6.5
    Medium

    CVE-2021-1956

    Last Modified: 21 Nov 2024

    Improper handling of ASB-U packet with L2CAP channel ID by slave host can lead to interference with piconet in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

    Published: 9 Sept 2021