CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2020-20349

    Last Modified: 21 Nov 2024

    WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link address field under the background links module.

    Published: 1 Sept 2021
    5.4
    Medium

    CVE-2020-20347

    Last Modified: 21 Nov 2024

    WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the source field under the article management module.

    Published: 1 Sept 2021
    5.4
    Medium

    CVE-2020-20348

    Last Modified: 21 Nov 2024

    WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link field under the background menu management module.

    Published: 1 Sept 2021
    5.4
    Medium

    CVE-2020-20345

    Last Modified: 21 Nov 2024

    WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows attackers to obtain cookies via a crafted payload entered into the search box.

    Published: 1 Sept 2021
    5.4
    Medium

    CVE-2020-20344

    Last Modified: 21 Nov 2024

    WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the keyword search function under the background articles module.

    Published: 1 Sept 2021
    6.5
    Medium

    CVE-2020-20343

    Last Modified: 21 Nov 2024

    WTCMS 1.0 contains a cross-site request forgery (CSRF) vulnerability in the index.php?g=admin&m=nav&a=add_post component that allows attackers to arbitrarily add articles in the administrator background.

    Published: 1 Sept 2021
    8.8
    High

    CVE-2021-40385

    Last Modified: 21 Nov 2024

    An issue was discovered in the server software in Kaseya Unitrends Backup Software before 10.5.5-2. There is a privilege escalation from read-only user to admin.

    Published: 1 Sept 2021
    8.8
    High

    CVE-2021-40387

    Last Modified: 21 Nov 2024

    An issue was discovered in the server software in Kaseya Unitrends Backup Software before 10.5.5-2. There is authenticated remote code execution.

    Published: 1 Sept 2021
    4.3
    Medium

    CVE-2021-39186

    Last Modified: 21 Nov 2024

    GlobalNewFiles is a MediaWiki extension maintained by Miraheze. Prior to commit number cee254e1b158cdb0ddbea716b1d3edc31fa4fb5d, the username column of the GlobalNewFiles special page is vulnerable to a stored XSS. Commit number cee254e1b158cdb0ddbea716b1d3edc31fa4fb5d contains a patch. As a workaround, one may disallow <,> (or other characters required to insert html/js) from being used in account names so an XSS is not possible.

    Published: 1 Sept 2021
    8.8
    High

    CVE-2021-39181

    Last Modified: 21 Nov 2024

    OpenOlat is a web-based learning management system (LMS). Prior to version 15.3.18, 15.5.3, and 16.0.0, using a prepared import XML file (e.g. a course) any class on the Java classpath can be instantiated, including spring AOP bean factories. This can be used to execute code arbitrary code by the attacker. The attack requires an OpenOlat user account with the authoring role. It can not be exploited by unregistered users. The problem is fixed in versions 15.3.18, 15.5.3, and 16.0.0. There are no known workarounds aside from upgrading.

    Published: 1 Sept 2021
    7.5
    High

    CVE-2020-20341

    Last Modified: 21 Nov 2024

    YzmCMS v5.5 contains a server-side request forgery (SSRF) in the grab_image() function.

    Published: 1 Sept 2021
    7.5
    High

    CVE-2020-20340

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in the 4.edu.php\conn\function.php component of S-CMS v1.0 allows attackers to access sensitive database information.

    Published: 1 Sept 2021
    9.1
    Critical

    CVE-2021-39185

    Last Modified: 21 Nov 2024

    Http4s is a minimal, idiomatic Scala interface for HTTP services. In http4s versions 0.21.26 and prior, 0.22.0 through 0.22.2, 0.23.0, 0.23.1, and 1.0.0-M1 through 1.0.0-M24, the default CORS configuration is vulnerable to an origin reflection attack. The middleware is also susceptible to a Null Origin Attack. The problem is fixed in 0.21.27, 0.22.3, 0.23.2, and 1.0.0-M25. The original `CORS` implementation and `CORSConfig` are deprecated. See the GitHub GHSA for more information, including code examples and workarounds.

    Published: 1 Sept 2021
    8.6
    High

    CVE-2021-30355

    Last Modified: 21 Nov 2024

    Amazon Kindle e-reader prior to and including version 5.13.4 improperly manages privileges, allowing the framework user to elevate privileges to root.

    Published: 1 Sept 2021
    8.6
    High

    CVE-2021-30354

    Last Modified: 21 Nov 2024

    Amazon Kindle e-reader prior to and including version 5.13.4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function CJBig2Image::expand() and results in a memory corruption that leads to code execution when parsing a crafted PDF book.

    Published: 1 Sept 2021
    8.8
    High

    CVE-2021-34435

    Last Modified: 21 Nov 2024

    In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE. But with the way it is made it is possible for a previewed HTML file to trigger an RCE. This exploit only happens if a user previews a malicious file..

    Published: 1 Sept 2021
    7.5
    High

    CVE-2021-40379

    Last Modified: 21 Nov 2024

    An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. rstp://.../medias2 does not require authorization.

    Published: 1 Sept 2021
    7.5
    High

    CVE-2021-40380

    Last Modified: 21 Nov 2024

    An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. cameralist.cgi and setcamera.cgi disclose credentials.

    Published: 1 Sept 2021
    7.5
    High

    CVE-2021-40381

    Last Modified: 21 Nov 2024

    An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. index_MJpeg.cgi allows video access.

    Published: 1 Sept 2021
    7.5
    High

    CVE-2021-40382

    Last Modified: 21 Nov 2024

    An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. mjpegStreamer.cgi allows video screenshot access.

    Published: 1 Sept 2021
    8.1
    High

    CVE-2021-40378

    Last Modified: 21 Nov 2024

    An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. /cgi-bin/support/killps.cgi deletes all data from the device.

    Published: 1 Sept 2021
    4.3
    Medium

    CVE-2021-29853

    Last Modified: 21 Nov 2024

    IBM Planning Analytics 2.0 could expose information that could be used to to create attacks by not validating the return values from some methods or functions. IBM X-Force ID: 205529.

    Published: 1 Sept 2021
    5.4
    Medium

    CVE-2021-29852

    Last Modified: 21 Nov 2024

    IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 205528.

    Published: 1 Sept 2021
    4.3
    Medium

    CVE-2021-29851

    Last Modified: 21 Nov 2024

    IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 205527.

    Published: 1 Sept 2021
    7.8
    High

    CVE-2021-39817

    Last Modified: 23 Apr 2025

    Adobe Bridge version 11.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious Bridge file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 1 Sept 2021
    7.8
    High

    CVE-2021-36079

    Last Modified: 23 Apr 2025

    Adobe Bridge version 11.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted .SGI file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 1 Sept 2021
    7.8
    High

    CVE-2021-36075

    Last Modified: 23 Apr 2025

    Adobe Bridge version 11.1 (and earlier) is affected by a Buffer Overflow vulnerability due to insecure handling of a malicious Bridge file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 1 Sept 2021
    5.5
    Medium

    CVE-2021-36077

    Last Modified: 21 Nov 2024

    Adobe Bridge version 11.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious SVG file, potentially resulting in local application denial of service in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 1 Sept 2021
    7.8
    High

    CVE-2021-36073

    Last Modified: 23 Apr 2025

    Adobe Bridge version 11.1 (and earlier) is affected by a heap-based buffer overflow vulnerability when parsing a crafted .SGI file. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 1 Sept 2021
    7.8
    High

    CVE-2021-39847

    Last Modified: 3 Nov 2025

    XMP Toolkit SDK version 2020.1 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.

    Published: 1 Sept 2021
    7.8
    High

    CVE-2021-36078

    Last Modified: 23 Apr 2025

    Adobe Bridge version 11.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious Bridge file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 1 Sept 2021
    7.8
    High

    CVE-2021-39816

    Last Modified: 23 Apr 2025

    Adobe Bridge version 11.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious Bridge file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 1 Sept 2021
    3.3
    Low

    CVE-2021-36071

    Last Modified: 21 Nov 2024

    Adobe Bridge versions 11.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 1 Sept 2021
    7.8
    High

    CVE-2021-36076

    Last Modified: 23 Apr 2025

    Adobe Bridge version 11.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious Bridge file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 1 Sept 2021
    3.3
    Low

    CVE-2021-36074

    Last Modified: 23 Apr 2025

    Adobe Bridge versions 11.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 1 Sept 2021
    7.8
    High

    CVE-2021-36069

    Last Modified: 23 Apr 2025

    Adobe Bridge version 11.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious Bridge file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 1 Sept 2021
    7.8
    High

    CVE-2021-36067

    Last Modified: 23 Apr 2025

    Adobe Bridge version 11.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious Bridge file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 1 Sept 2021
    7.8
    High

    CVE-2021-36065

    Last Modified: 21 Nov 2024

    Adobe Photoshop versions 21.2.10 (and earlier) and 22.4.3 (and earlier) are affected by a heap-based buffer overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 1 Sept 2021
    7.8
    High

    CVE-2021-36072

    Last Modified: 23 Apr 2025

    Adobe Bridge versions 11.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 1 Sept 2021
    7.8
    High

    CVE-2021-36070

    Last Modified: 23 Apr 2025

    Adobe Media Encoder version 15.1 (and earlier) is affected by an improper memory access vulnerability when parsing a crafted .SVG file. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 1 Sept 2021
    5.4
    Medium

    CVE-2021-36063

    Last Modified: 21 Nov 2024

    Adobe Connect version 11.2.2 (and earlier) is affected by a Reflected Cross-site Scripting vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

    Published: 1 Sept 2021
    7.8
    High

    CVE-2021-36066

    Last Modified: 21 Nov 2024

    Adobe Photoshop versions 21.2.10 (and earlier) and 22.4.3 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 1 Sept 2021
    7.8
    High

    CVE-2021-36068

    Last Modified: 23 Apr 2025

    Adobe Bridge version 11.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious Bridge file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 1 Sept 2021
    5.5
    Medium

    CVE-2021-36058

    Last Modified: 3 Nov 2025

    XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Integer Overflow vulnerability potentially resulting in application-level denial of service in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.

    Published: 1 Sept 2021
    5.4
    Medium

    CVE-2021-36061

    Last Modified: 21 Nov 2024

    Adobe Connect version 11.2.2 (and earlier) is affected by a secure design principles violation vulnerability via the 'pbMode' parameter. An unauthenticated attacker could leverage this vulnerability to edit or delete recordings on the Connect environment. Exploitation of this issue requires user interaction in that a victim must publish a link of a Connect recording.

    Published: 1 Sept 2021
    7.8
    High

    CVE-2021-36064

    Last Modified: 3 Nov 2025

    XMP Toolkit version 2020.1 (and earlier) is affected by a Buffer Underflow vulnerability which could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 1 Sept 2021
    5.5
    Medium

    CVE-2021-36056

    Last Modified: 3 Nov 2025

    XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.

    Published: 1 Sept 2021
    5.4
    Medium

    CVE-2021-36062

    Last Modified: 21 Nov 2024

    Adobe Connect version 11.2.2 (and earlier) is affected by a Reflected Cross-site Scripting vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

    Published: 1 Sept 2021
    3.3
    Low

    CVE-2021-36054

    Last Modified: 3 Nov 2025

    XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in local application denial of service in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.

    Published: 1 Sept 2021
    7.8
    High

    CVE-2021-36059

    Last Modified: 23 Apr 2025

    Adobe Bridge version 11.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious Bridge file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 1 Sept 2021