CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2021-40352

    Last Modified: 21 Nov 2024

    OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can read the messages of all users.

    Published: 1 Sept 2021
    4.7
    Medium

    CVE-2021-3753

    Last Modified: 21 Nov 2024

    A race problem was seen in the vt_k_ioctl in drivers/tty/vt/vt_ioctl.c in the Linux kernel, which may cause an out of bounds read in vt as the write access to vc_mode is not protected by lock-in vt_ioctl (KDSETMDE). The highest threat from this vulnerability is to data confidentiality.

    Published: 1 Sept 2021
    8.8
    High

    CVE-2021-38703

    Last Modified: 21 Nov 2024

    Wireless devices running certain Arcadyan-derived firmware (such as KPN Experia WiFi 1.00.15) do not properly sanitise user input to the syslog configuration form. An authenticated remote attacker could leverage this to alter the device configuration and achieve remote code execution. This can be exploited in conjunction with CVE-2021-20090.

    Published: 1 Sept 2021
    4.8
    Medium

    CVE-2021-35238

    Last Modified: 21 Nov 2024

    User with Orion Platform Admin Rights could store XSS through URL POST parameter in CreateExternalWebsite website.

    Published: 1 Sept 2021
    7.5
    High

    CVE-2020-9002

    Last Modified: 21 Nov 2024

    An issue was discovered in iPortalis iCS 7.1.13.0. An attacker can gain privileges by intercepting a request and changing UserRoleKey=COMPANY_ADMIN to UserRoleKey=DOMAIN_ADMIN (to achieve Domain Administrator access).

    Published: 1 Sept 2021
    7.5
    High

    CVE-2020-9000

    Last Modified: 21 Nov 2024

    An issue was discovered in iPortalis iCS 7.1.13.0. Attackers can send a sequence of requests to rapidly cause .NET Input Validation errors. This increases the size of the log file on the remote server until memory is exhausted, therefore consuming the maximum amount of resources (triggering a denial of service condition).

    Published: 1 Sept 2021
    9.8
    Critical

    CVE-2021-37415

    Last Modified: 31 Oct 2025

    Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.

    Published: 1 Sept 2021
    7.5
    High

    CVE-2021-39109

    Last Modified: 21 Nov 2024

    The renderWidgetResource resource in Atlasian Atlasboard before version 1.1.9 allows remote attackers to read arbitrary files via a path traversal vulnerability.

    Published: 1 Sept 2021
    7.8
    High

    CVE-2021-36235

    Last Modified: 21 Nov 2024

    An issue was discovered in Ivanti Workspace Control before 10.6.30.0. A locally authenticated user with low privileges can bypass File and Folder Security by leveraging an unspecified attack vector. As a result, the attacker can start applications with elevated privileges.

    Published: 1 Sept 2021
    9.8
    Critical

    CVE-2021-40353

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the index.php USERNAME parameter. NOTE: this issue may exist because of an incomplete fix for CVE-2020-6637.

    Published: 1 Sept 2021
    5.6
    Medium

    CVE-2021-23436

    Last Modified: 21 Nov 2024

    This affects the package immer before 9.0.6. A type confusion vulnerability can lead to a bypass of CVE-2020-28477 when the user-provided keys used in the path parameter are arrays. In particular, this bypass is possible because the condition (p === "__proto__" || p === "constructor") in applyPatches_ returns false if p is ['__proto__'] (or ['constructor']). The === operator (strict equality operator) returns false if the operands have different type.

    Published: 1 Sept 2021
    5.6
    Medium

    CVE-2021-23438

    Last Modified: 21 Nov 2024

    This affects the package mpath before 0.8.4. A type confusion vulnerability can lead to a bypass of CVE-2018-16490. In particular, the condition ignoreProperties.indexOf(parts[i]) !== -1 returns -1 if parts[i] is ['__proto__']. This is because the method that has been called if the input is an array is Array.prototype.indexOf() and not String.prototype.indexOf(). They behave differently depending on the type of the input.

    Published: 1 Sept 2021
    7.5
    High

    CVE-2021-33582

    Last Modified: 21 Nov 2024

    Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction. Because there are many insertions into a single bucket, strcmp becomes slow. This is fixed in 3.4.2, 3.2.8, and 3.0.16.

    Published: 1 Sept 2021
    8.8
    High

    CVE-2021-37218

    Last Modified: 21 Nov 2024

    HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.0.10 and 1.1.4.

    Published: 1 Sept 2021
    9.1
    Critical

    CVE-2020-20495

    Last Modified: 21 Nov 2024

    bludit v3.13.0 contains an arbitrary file deletion vulnerability in the backup plugin via the `deleteBackup' parameter.

    Published: 31 Aug 2021
    7.5
    High

    CVE-2020-20490

    Last Modified: 21 Nov 2024

    A heap buffer-overflow in the client_example1.c component of libiec_iccp_mod v1.5 leads to a denial of service (DOS).

    Published: 31 Aug 2021
    7.5
    High

    CVE-2020-20486

    Last Modified: 21 Nov 2024

    IEC104 v1.0 contains a stack-buffer overflow in the parameter Iec10x_Sta_Addr.

    Published: 31 Aug 2021
    7.5
    High

    CVE-2021-22003

    Last Modified: 21 Nov 2024

    VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be practical based on lockout policy configuration and password complexity for the target account.

    Published: 31 Aug 2021
    9.8
    Critical

    CVE-2021-22002

    Last Modified: 21 Nov 2024

    VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network access to port 443 could tamper with host headers to facilitate access to the /cfg web app, in addition a malicious actor could access /cfg diagnostic endpoints without authentication.

    Published: 31 Aug 2021
    7.5
    High

    CVE-2021-22029

    Last Modified: 21 Nov 2024

    VMware Workspace ONE UEM REST API contains a denial of service vulnerability. A malicious actor with access to /API/system/admins/session could cause an API denial of service due to improper rate limiting.

    Published: 31 Aug 2021
    7.5
    High

    CVE-2021-39176

    Last Modified: 21 Nov 2024

    detect-character-encoding is a package for detecting character encoding using ICU. In detect-character-encoding v0.3.0 and earlier, allocated memory is not released. The problem has been patched in detect-character-encoding v0.3.1.

    Published: 31 Aug 2021
    8.1
    High

    CVE-2021-39180

    Last Modified: 21 Nov 2024

    OpenOLAT is a web-based learning management system (LMS). A path traversal vulnerability exists in versions prior to 15.3.18, 15.5.3, and 16.0.0. Using a specially prepared ZIP file, it is possible to overwrite any file that is writable by the application server user (e.g. the tomcat user). Depending on the configuration this can be limited to files of the OpenOlat user data directory, however, if not properly set up, the attack could also be used to overwrite application server config files, java code or even operating system files. The attack could be used to corrupt or modify any OpenOlat file such as course structures, config files or temporary test data. Those attack would require in-depth knowledge of the installation and thus more theoretical. If the app server configuration allows the execution of jsp files and the path to the context is known, it is also possible to execute java code. If the app server runs with the same user that is used to deploy the OpenOlat code or has write permissions on the OpenOlat code files and the path to the context is know, code injection is possible. The attack requires an OpenOlat user account to upload a ZIP file and trigger the unzip method. It can not be exploited by unregistered users. The problem is fixed in versions 15.3.18, 15.5.3 and 16.0.0. There are no known workarounds aside from upgrading.

    Published: 31 Aug 2021
    6.5
    Medium

    CVE-2021-36233

    Last Modified: 21 Nov 2024

    The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary files from the filesystem by specifying the file path.

    Published: 31 Aug 2021
    5.5
    Medium

    CVE-2021-36234

    Last Modified: 21 Nov 2024

    Use of a hard-coded cryptographic key in MIK.starlight 7.9.5.24363 allows local users to decrypt credentials via unspecified vectors.

    Published: 31 Aug 2021
    8.8
    High

    CVE-2021-36231

    Last Modified: 21 Nov 2024

    Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attackers to execute operating system commands by crafting serialized objects.

    Published: 31 Aug 2021
    8.8
    High

    CVE-2021-36232

    Last Modified: 21 Nov 2024

    Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate privileges.

    Published: 31 Aug 2021
    5.4
    Medium

    CVE-2021-37794

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in FileBrowser < v2.16.0 that allows an authenticated user authorized to upload a malicious .svg file which acts as a stored XSS payload. If this stored XSS payload is triggered by an administrator it will trigger malicious OS commands on the server running the FileBrowser instance.

    Published: 31 Aug 2021
    8.9
    High

    CVE-2021-35212

    Last Modified: 21 Nov 2024

    An SQL injection Privilege Escalation Vulnerability was discovered in the Orion Platform reported by the ZDI Team. A blind Boolean SQL injection which could lead to full read/write over the Orion database content including the Orion certificate for any authenticated user.

    Published: 31 Aug 2021
    9.8
    Critical

    CVE-2021-21811

    Last Modified: 21 Nov 2024

    A memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs’ Xmill 0.7. A specially crafted XML file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 31 Aug 2021
    6.1
    Medium

    CVE-2021-22929

    Last Modified: 21 Nov 2024

    An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that included timestamps of connections to V2 onion domains in tor.log.

    Published: 31 Aug 2021
    9.6
    Critical

    CVE-2021-22943

    Last Modified: 21 Nov 2024

    A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained access to a network to subsequently control the Protect camera(s) assigned to said network. This vulnerability is fixed in UniFi Protect application V1.19.0 and later.

    Published: 31 Aug 2021
    8
    High

    CVE-2021-22944

    Last Modified: 21 Nov 2024

    A vulnerability found in UniFi Protect application V1.18.1 and earlier allows a malicious actor with a view-only role and network access to gain the same privileges as the owner of the UniFi Protect application. This vulnerability is fixed in UniFi Protect application V1.19.0 and later.

    Published: 31 Aug 2021
    7.5
    High

    CVE-2021-22684

    Last Modified: 21 Nov 2024

    Tizen RT RTOS version 3.0.GBB is vulnerable to integer wrap-around in functions_calloc and mm_zalloc. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash

    Published: 31 Aug 2021
    3.1
    Low

    CVE-2021-39164

    Last Modified: 21 Nov 2024

    Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the membership (list of members, with their display names) of a room if they know the ID of the room. The vulnerability is limited to rooms with `shared` history visibility. Furthermore, the unauthorised user must be using an account on a vulnerable homeserver that is in the room. Server administrators should upgrade to 1.41.1 or later in order to receive the patch. One workaround is available. Administrators of servers that use a reverse proxy could, with potentially unacceptable loss of functionality, block the endpoints: `/_matrix/client/r0/rooms/{room_id}/members` with `at` query parameter, and `/_matrix/client/unstable/rooms/{room_id}/members` with `at` query parameter.

    Published: 31 Aug 2021
    8.8
    High

    CVE-2021-29907

    Last Modified: 21 Nov 2024

    IBM OpenPages with Watson 8.1 and 8.2 could allow an authenticated user to upload a file that could execute arbitrary code on the system. IBM X-Force ID: 207633.

    Published: 31 Aug 2021
    8.5
    High

    CVE-2021-35223

    Last Modified: 21 Nov 2024

    The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command can be supplied with parameters that can take the form of user string variables, allowing remote code execution.

    Published: 31 Aug 2021
    3.1
    Low

    CVE-2021-39163

    Last Modified: 21 Nov 2024

    Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the name, avatar, topic and number of members of a room if they know the ID of the room. This vulnerability is limited to homeservers where the vulnerable homeserver is in the room and untrusted users are permitted to create groups (communities). By default, only homeserver administrators can create groups. However, homeserver administrators can already access this information in the database or using the admin API. As a result, only homeservers where the configuration setting `enable_group_creation` has been set to `true` are impacted. Server administrators should upgrade to 1.41.1 or higher to patch the vulnerability. There are two potential workarounds. Server administrators can set `enable_group_creation` to `false` in their homeserver configuration (this is the default value) to prevent creation of groups by non-administrators. Administrators that are using a reverse proxy could, with partial loss of group functionality, block the endpoints `/_matrix/client/r0/groups/{group_id}/rooms` and `/_matrix/client/unstable/groups/{group_id}/rooms`.

    Published: 31 Aug 2021
    8.9
    High

    CVE-2021-35213

    Last Modified: 21 Nov 2024

    An Improper Access Control Privilege Escalation Vulnerability was discovered in the User Setting of Orion Platform version 2020.2.5. It allows a guest user to elevate privileges to the Administrator using this vulnerability. Authentication is required to exploit the vulnerability.

    Published: 31 Aug 2021
    6.5
    Medium

    CVE-2021-35240

    Last Modified: 21 Nov 2024

    A security researcher stored XSS via a Help Server setting. This affects customers using Internet Explorer, because they do not support 'rel=noopener'.

    Published: 31 Aug 2021
    7.5
    High

    CVE-2021-35239

    Last Modified: 21 Nov 2024

    A security researcher found a user with Orion map manage rights could store XSS through via text box hyperlink.

    Published: 31 Aug 2021
    5.5
    Medium

    CVE-2021-21681

    Last Modified: 21 Nov 2024

    Jenkins Nomad Plugin 0.7.4 and earlier stores Docker passwords unencrypted in the global config.xml file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

    Published: 31 Aug 2021
    7.1
    High

    CVE-2021-21680

    Last Modified: 21 Nov 2024

    Jenkins Nested View Plugin 1.20 and earlier does not configure its XML transformer to prevent XML external entity (XXE) attacks.

    Published: 31 Aug 2021
    8.8
    High

    CVE-2021-21679

    Last Modified: 21 Nov 2024

    Jenkins Azure AD Plugin 179.vf6841393099e and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.

    Published: 31 Aug 2021
    8.8
    High

    CVE-2021-21678

    Last Modified: 21 Nov 2024

    Jenkins SAML Plugin 2.0.7 and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.

    Published: 31 Aug 2021
    8.8
    High

    CVE-2021-21677

    Last Modified: 21 Nov 2024

    Jenkins Code Coverage API Plugin 1.4.0 and earlier does not apply Jenkins JEP-200 deserialization protection to Java objects it deserializes from disk, resulting in a remote code execution vulnerability.

    Published: 31 Aug 2021
    5.4
    Medium

    CVE-2020-19049

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Description" field found in the "Add New Forum" page by doing an authenticated POST HTTP request to '/Upload/admin/index.php?module=forum-management&action=add'.

    Published: 31 Aug 2021
    5.4
    Medium

    CVE-2020-19048

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Title" field found in the "Add New Forum" page by doing an authenticated POST HTTP request to '/Upload/admin/index.php?module=forum-management&action=add'.

    Published: 31 Aug 2021
    8.8
    High

    CVE-2020-19047

    Last Modified: 21 Nov 2024

    Cross Site Request Forgey (CSRF) in iWebShop v5.3 allows remote atatckers to execute arbitrary code via malicious POST request to the component '/index.php?controller=system&action=admin_edit_act'.

    Published: 31 Aug 2021
    5.4
    Medium

    CVE-2020-19046

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in S-CMS v1.0 allows remote attackers to execute arbitrary code via the component '/admin/tpl.php?page='.

    Published: 31 Aug 2021
    8
    High

    CVE-2021-35222

    Last Modified: 21 Nov 2024

    This vulnerability allows attackers to impersonate users and perform arbitrary actions leading to a Remote Code Execution (RCE) from the Alerts Settings page.

    Published: 31 Aug 2021