CVE Feed

    Dashboard / CVE

    3.3
    Low

    CVE-2021-36057

    Last Modified: 3 Nov 2025

    XMP Toolkit SDK version 2020.1 (and earlier) is affected by a write-what-where condition vulnerability caused during the application's memory allocation process. This may cause the memory management functions to become mismatched resulting in local application denial of service in the context of the current user.

    Published: 1 Sept 2021
    7.8
    High

    CVE-2021-36055

    Last Modified: 3 Nov 2025

    XMP Toolkit SDK versions 2020.1 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 1 Sept 2021
    7.8
    High

    CVE-2021-36052

    Last Modified: 3 Nov 2025

    XMP Toolkit version 2020.1 (and earlier) is affected by a memory corruption vulnerability, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 1 Sept 2021
    3.3
    Low

    CVE-2021-36053

    Last Modified: 3 Nov 2025

    XMP Toolkit SDK versions 2020.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 1 Sept 2021
    7.8
    High

    CVE-2021-36050

    Last Modified: 3 Nov 2025

    XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.

    Published: 1 Sept 2021
    7.5
    High

    CVE-2021-36044

    Last Modified: 21 Nov 2024

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An unauthenticated attacker could abuse this vulnerability to cause a server-side denial-of-service using a GraphQL field.

    Published: 1 Sept 2021
    7.8
    High

    CVE-2021-36048

    Last Modified: 3 Nov 2025

    XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.

    Published: 1 Sept 2021
    7.8
    High

    CVE-2021-36047

    Last Modified: 3 Nov 2025

    XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.

    Published: 1 Sept 2021
    7.8
    High

    CVE-2021-36049

    Last Modified: 23 Apr 2025

    Adobe Bridge version 11.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious Bridge file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 1 Sept 2021
    3.3
    Low

    CVE-2021-36045

    Last Modified: 3 Nov 2025

    XMP Toolkit SDK versions 2020.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 1 Sept 2021
    6.5
    Medium

    CVE-2021-36027

    Last Modified: 21 Nov 2024

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a stored cross-site scripting vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

    Published: 1 Sept 2021
    8
    High

    CVE-2021-36043

    Last Modified: 21 Nov 2024

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a blind SSRF vulnerability in the bundled dotmailer extension. An attacker with admin privileges could abuse this to achieve remote code execution should Redis be enabled.

    Published: 1 Sept 2021
    7.8
    High

    CVE-2021-36046

    Last Modified: 3 Nov 2025

    XMP Toolkit version 2020.1 (and earlier) is affected by a memory corruption vulnerability, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 1 Sept 2021
    9.1
    Critical

    CVE-2021-36042

    Last Modified: 21 Nov 2024

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability in the API File Option Upload Extension. An attacker with Admin privileges can achieve unrestricted file upload which can result in remote code execution.

    Published: 1 Sept 2021
    7.5
    High

    CVE-2021-36030

    Last Modified: 21 Nov 2024

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability during the checkout process. An unauthenticated attacker can leverage this vulnerability to alter the price of items.

    Published: 1 Sept 2021
    9.1
    Critical

    CVE-2021-36041

    Last Modified: 21 Nov 2024

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An attacker with admin privileges could upload a specially crafted file in the 'pub/media` directory could lead to remote code execution.

    Published: 1 Sept 2021
    9.1
    Critical

    CVE-2021-36040

    Last Modified: 21 Nov 2024

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An attacker with admin privileges can upload a specially crafted file to bypass file extension restrictions and could lead to remote code execution.

    Published: 1 Sept 2021
    9.1
    Critical

    CVE-2021-36025

    Last Modified: 21 Nov 2024

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability while saving a customer's details with a specially crafted file. An authenticated attacker with admin privileges can leverage this vulnerability to achieve remote code execution.

    Published: 1 Sept 2021
    8.2
    High

    CVE-2021-36020

    Last Modified: 21 Nov 2024

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the 'City' field. An unauthenticated attacker can trigger a specially crafted script to achieve remote code execution.

    Published: 1 Sept 2021
    9.1
    Critical

    CVE-2021-36035

    Last Modified: 21 Nov 2024

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An attacker with admin privileges could make a crafted request to the Adobe Stock API to achieve remote code execution.

    Published: 1 Sept 2021
    9.1
    Critical

    CVE-2021-36024

    Last Modified: 21 Nov 2024

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper Neutralization of Special Elements Used In A Command via the Data collection endpoint. An attacker with admin privileges can upload a specially crafted file to achieve remote code execution.

    Published: 1 Sept 2021
    7.2
    High

    CVE-2021-36031

    Last Modified: 21 Nov 2024

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a Path Traversal vulnerability via the `theme[preview_image]` parameter. An attacker with admin privileges could leverage this vulnerability to achieve remote code execution.

    Published: 1 Sept 2021
    8.6
    High

    CVE-2021-23427

    Last Modified: 21 Nov 2024

    This affects all versions of package elFinder.NetCore. The ExtractAsync function within the FileSystem is vulnerable to arbitrary extraction due to insufficient validation.

    Published: 1 Sept 2021
    8.6
    High

    CVE-2021-23428

    Last Modified: 21 Nov 2024

    This affects all versions of package elFinder.NetCore. The Path.Combine(...) method is used to create an absolute file path. Due to missing sanitation of the user input and a missing check of the generated path its possible to escape the Files directory via path traversal

    Published: 1 Sept 2021
    6.5
    Medium

    CVE-2021-36039

    Last Modified: 21 Nov 2024

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability via the `quoteId` parameter. An attacker can abuse this vulnerability to disclose sensitive information.

    Published: 1 Sept 2021
    9.1
    Critical

    CVE-2021-36029

    Last Modified: 21 Nov 2024

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vulnerability. An attacker with admin privileges could leverage this vulnerability to achieve remote code execution.

    Published: 1 Sept 2021
    6.5
    Medium

    CVE-2021-36026

    Last Modified: 21 Nov 2024

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a stored cross-site scripting vulnerability in the customer address upload feature that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

    Published: 1 Sept 2021
    8.3
    High

    CVE-2021-36032

    Last Modified: 21 Nov 2024

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An authenticated attacker can trigger an insecure direct object reference in the `V1/customers/me` endpoint to achieve information exposure and privilege escalation.

    Published: 1 Sept 2021
    6.5
    Medium

    CVE-2021-36038

    Last Modified: 21 Nov 2024

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability in the Multishipping Module. An authenticated attacker could leverage this vulnerability to achieve sensitive information disclosure.

    Published: 1 Sept 2021
    5
    Medium

    CVE-2021-36002

    Last Modified: 21 Nov 2024

    Adobe Captivate version 11.5.5 (and earlier) is affected by an Creation of Temporary File In Directory With Incorrect Permissions vulnerability that could result in privilege escalation in the context of the current user. The attacker must plant a malicious file in a particular location of the victim's machine. Exploitation of this issue requires user interaction in that a victim must launch the Captivate Installer.

    Published: 1 Sept 2021
    9.1
    Critical

    CVE-2021-36028

    Last Modified: 21 Nov 2024

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability when saving a configurable product. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.

    Published: 1 Sept 2021
    9.1
    Critical

    CVE-2021-36034

    Last Modified: 21 Nov 2024

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An attacker with admin privileges can upload a specially crafted file to achieve remote code execution.

    Published: 1 Sept 2021
    9.1
    Critical

    CVE-2021-36022

    Last Modified: 21 Nov 2024

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.

    Published: 1 Sept 2021
    9.1
    Critical

    CVE-2021-36033

    Last Modified: 21 Nov 2024

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.

    Published: 1 Sept 2021
    6.5
    Medium

    CVE-2021-36037

    Last Modified: 21 Nov 2024

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vulnerability. An authenticated attacker could leverage this vulnerability to achieve sensitive information disclosure.

    Published: 1 Sept 2021
    6.5
    Medium

    CVE-2021-36012

    Last Modified: 21 Nov 2024

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a business logic error in the placeOrder graphql mutation. An authenticated attacker can leverage this vulnerability to altar the price of an item.

    Published: 1 Sept 2021
    5.6
    Medium

    CVE-2021-23426

    Last Modified: 21 Nov 2024

    This affects all versions of package Proto. It is possible to inject pollute the object property of an application using Proto by leveraging the merge function.

    Published: 1 Sept 2021
    8.9
    High

    CVE-2021-35218

    Last Modified: 21 Nov 2024

    Deserialization of Untrusted Data in the Web Console Chart Endpoint can lead to remote code execution. An unauthorized attacker who has network access to the Orion Patch Manager Web Console could potentially exploit this and compromise the server

    Published: 1 Sept 2021
    8.9
    High

    CVE-2021-35216

    Last Modified: 21 Nov 2024

    Insecure Deserialization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module. An Authenticated Attacker with network access via HTTP can compromise this vulnerability can result in Remote Code Execution.

    Published: 1 Sept 2021
    9.8
    Critical

    CVE-2021-40350

    Last Modified: 21 Nov 2024

    webctrl.cgi.elf on Christie Digital DWU850-GS V06.46 devices allows attackers to perform any desired action via a crafted query containing an unspecified Cookie header. Authentication bypass can be achieved by including an administrative cookie that the device does not validate.

    Published: 1 Sept 2021
    8.9
    High

    CVE-2021-35215

    Last Modified: 21 Nov 2024

    Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is required to exploit this vulnerability.

    Published: 1 Sept 2021
    6.1
    Medium

    CVE-2021-39320

    Last Modified: 5 May 2025

    The underConstruction plugin <= 1.18 for WordPress echoes out the raw value of `$GLOBALS['PHP_SELF']` in the ucOptions.php file. On certain configurations including Apache+modPHP, this makes it possible to use it to perform a reflected Cross-Site Scripting attack by injecting malicious code in the request path.

    Published: 1 Sept 2021
    8
    High

    CVE-2021-39170

    Last Modified: 21 Nov 2024

    Pimcore is an open source data & experience management platform. Prior to version 10.1.2, an authenticated user could add XSS code as a value of custom metadata on assets. There is a patch for this issue in Pimcore version 10.1.2. As a workaround, users may apply the patch manually.

    Published: 1 Sept 2021
    8
    High

    CVE-2021-39166

    Last Modified: 21 Nov 2024

    Pimcore is an open source data & experience management platform. Prior to version 10.1.2, text-values were not properly escaped before printed in the version preview. This allowed XSS by authenticated users with access to the resources. This issue is patched in Pimcore version 10.1.2.

    Published: 1 Sept 2021
    8.8
    High

    CVE-2021-35508

    Last Modified: 21 Nov 2024

    NMSAccess32.exe in TeraRecon AQNetClient 4.4.13 allows attackers to execute a malicious binary with SYSTEM privileges via a low-privileged user account. To exploit this, a low-privileged user must change the service configuration or overwrite the binary service.

    Published: 1 Sept 2021
    9.8
    Critical

    CVE-2021-39379

    Last Modified: 21 Nov 2024

    A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the ResetUserInfo.php password_stn_id parameter.

    Published: 1 Sept 2021
    5.3
    Medium

    CVE-2021-37151

    Last Modified: 21 Nov 2024

    CyberArk Identity 21.5.131, when handling an invalid authentication attempt, sometimes reveals whether the username is valid. In certain authentication policy configurations with MFA, the API response length can be used to differentiate between a valid user and an invalid one (aka Username Enumeration). Response differentiation enables attackers to enumerate usernames of valid application users. Attackers can use this information to leverage brute-force and dictionary attacks in order to discover valid account information such as passwords.

    Published: 1 Sept 2021
    9.8
    Critical

    CVE-2021-39377

    Last Modified: 21 Nov 2024

    A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the index.php username parameter.

    Published: 1 Sept 2021
    7.8
    High

    CVE-2021-39373

    Last Modified: 21 Nov 2024

    Samsung Drive Manager 2.0.104 on Samsung H3 devices allows attackers to bypass intended access controls on disk management. WideCharToMultiByte, WideCharStr, and MultiByteStr can contribute to password exposure.

    Published: 1 Sept 2021
    9.8
    Critical

    CVE-2021-39378

    Last Modified: 21 Nov 2024

    A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the NamesList.php str parameter.

    Published: 1 Sept 2021