CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2021-24593

    Last Modified: 21 Nov 2024

    The Business Hours Indicator WordPress plugin before 2.3.5 does not sanitise or escape its 'Now closed message" setting when outputting it in the backend and frontend, leading to an Authenticated Stored Cross-Site Scripting issue

    Published: 30 Aug 2021
    4.8
    Medium

    CVE-2021-24592

    Last Modified: 21 Nov 2024

    The Sitewide Notice WP WordPress plugin before 2.3 does not sanitise some of its settings before outputting them in frontend pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 30 Aug 2021
    8.8
    High

    CVE-2021-24581

    Last Modified: 21 Nov 2024

    The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin does not have CSRF check in place when saving its settings, allowing the issue to be exploited via a CSRF attack.

    Published: 30 Aug 2021
    8.8
    High

    CVE-2021-24580

    Last Modified: 21 Nov 2024

    The Side Menu Lite WordPress plugin before 2.2.6 does not sanitise user input from the List page in the admin dashboard before using it in SQL statement, leading to a SQL Injection issue

    Published: 30 Aug 2021
    8.8
    High

    CVE-2021-24579

    Last Modified: 21 Nov 2024

    The bt_bb_get_grid AJAX action of the Bold Page Builder WordPress plugin before 3.1.6 passes user input into the unserialize() function without any validation or sanitisation, which could lead to a PHP Object Injection. Even though the plugin did not contain a suitable gadget to fully exploit the issue, other installed plugins on the blog could allow such issue to be exploited and lead to RCE in some cases.

    Published: 30 Aug 2021
    5.4
    Medium

    CVE-2021-24528

    Last Modified: 21 Nov 2024

    The FluentSMTP WordPress plugin before 2.0.1 does not sanitize parameters before storing the settings in the database, nor does the plugin escape the values before outputting them when viewing the SMTP settings set by this plugin, leading to a stored cross site scripting (XSS) vulnerability. Only users with roles capable of managing plugins can modify the plugin's settings.

    Published: 30 Aug 2021
    6.1
    Medium

    CVE-2021-24438

    Last Modified: 21 Nov 2024

    The ShareThis Dashboard for Google Analytics WordPress plugin before 2.5.2 does not sanitise or escape the 'ga_action' parameter in the stats view before outputting it back in an attribute when the plugin is connected to a Google Analytics account, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator

    Published: 30 Aug 2021
    6.1
    Medium

    CVE-2021-24437

    Last Modified: 21 Nov 2024

    The Favicon by RealFaviconGenerator WordPress plugin through 1.3.20 does not sanitise or escape one of its parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting (XSS) which is executed in the context of a logged administrator.

    Published: 30 Aug 2021
    6.5
    Medium

    CVE-2021-25958

    Last Modified: 21 Nov 2024

    In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle errors at multiple locations but leaks out sensitive table info which may aid the attacker for further recon. A user can register with a very long password, but when he tries to login with it an exception occurs.

    Published: 30 Aug 2021
    9.6
    Critical

    CVE-2020-15744

    Last Modified: 21 Nov 2024

    Stack-based Buffer Overflow vulnerability in the ONVIF server component of Victure PC420 smart camera allows an attacker to execute remote code on the target device. This issue affects: Victure PC420 firmware version 1.2.2 and prior versions.

    Published: 30 Aug 2021
    4.8
    Medium

    CVE-2021-39117

    Last Modified: 21 Nov 2024

    The AssociateFieldToScreens page in Atlassian Jira Server and Data Center before version 8.18.0 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability via the name of a custom field.

    Published: 30 Aug 2021
    7.5
    High

    CVE-2021-39113

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to continue to view cached content even after losing permissions, via a Broken Access Control vulnerability in the allowlist feature. The affected versions are before version 8.13.9, and from version 8.14.0 before 8.18.0.

    Published: 30 Aug 2021
    6.1
    Medium

    CVE-2021-39111

    Last Modified: 21 Nov 2024

    The Editor plugin in Atlassian Jira Server and Data Center before version 8.5.18, from 8.6.0 before 8.13.10, and from version 8.14.0 before 8.18.2 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the handling of supplied content such as from a PDF when pasted into a field such as the description field.

    Published: 30 Aug 2021
    9.8
    Critical

    CVE-2021-26084

    Last Modified: 16 Dec 2025

    In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.

    Published: 30 Aug 2021
    8.8
    High

    CVE-2021-39271

    Last Modified: 21 Nov 2024

    OrbiTeam BSCW Classic before 7.4.3 allows authenticated remote code execution (RCE) during archive extraction via attacker-supplied Python code in the class attribute of a .bscw file. This is fixed in 5.0.12, 5.1.10, 5.2.4, 7.3.3, and 7.4.3.

    Published: 30 Aug 2021
    8.8
    High

    CVE-2021-36359

    Last Modified: 21 Nov 2024

    OrbiTeam BSCW Classic before 7.4.3 allows exportpdf authenticated remote code execution (RCE) via XML tag injection because reportlab\platypus\paraparser.py (reached via bscw.cgi op=_editfolder.EditFolder) calls eval on attacker-supplied Python code. This is fixed in 5.0.12, 5.1.10, 5.2.4, 7.3.3, and 7.4.3.

    Published: 30 Aug 2021
    9.8
    Critical

    CVE-2021-37749

    Last Modified: 21 Nov 2024

    MapService.svc in Hexagon GeoMedia WebMap 2020 before Update 2 (aka 16.6.2.66) allows blind SQL Injection via the Id (within sourceItems) parameter to the GetMap method.

    Published: 30 Aug 2021
    7.8
    High

    CVE-2021-35268

    Last Modified: 5 Jul 2026

    In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode is loaded in the function ntfs_inode_real_open, a heap buffer overflow can occur allowing for code execution and escalation of privileges.

    Published: 30 Aug 2021
    7.8
    High

    CVE-2021-35267

    Last Modified: 5 Jul 2026

    NTFS-3G versions < 2021.8.22, a stack buffer overflow can occur when correcting differences in the MFT and MFTMirror allowing for code execution or escalation of privileges when setuid-root.

    Published: 30 Aug 2021
    7.8
    High

    CVE-2021-33289

    Last Modified: 5 Jul 2026

    In NTFS-3G versions < 2021.8.22, when a specially crafted MFT section is supplied in an NTFS image a heap buffer overflow can occur and allow for code execution.

    Published: 30 Aug 2021
    7.8
    High

    CVE-2021-33285

    Last Modified: 3 Dec 2025

    In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute is supplied to the function ntfs_get_attribute_value, a heap buffer overflow can occur allowing for memory disclosure or denial of service. The vulnerability is caused by an out-of-bound buffer access which can be triggered by mounting a crafted ntfs partition. The root cause is a missing consistency check after reading an MFT record : the "bytes_in_use" field should be less than the "bytes_allocated" field. When it is not, the parsing of the records proceeds into the wild.

    Published: 30 Aug 2021
    7.8
    High

    CVE-2021-39262

    Last Modified: 2 Dec 2025

    A crafted NTFS image can cause an out-of-bounds access in ntfs_decompress in NTFS-3G < 2021.8.22.

    Published: 30 Aug 2021
    7.8
    High

    CVE-2021-39260

    Last Modified: 2 Dec 2025

    A crafted NTFS image can cause an out-of-bounds access in ntfs_inode_sync_standard_information in NTFS-3G < 2021.8.22.

    Published: 30 Aug 2021
    7.8
    High

    CVE-2021-39259

    Last Modified: 2 Dec 2025

    A crafted NTFS image can trigger an out-of-bounds access, caused by an unsanitized attribute length in ntfs_inode_lookup_by_name, in NTFS-3G < 2021.8.22.

    Published: 30 Aug 2021
    7.8
    High

    CVE-2021-39258

    Last Modified: 2 Dec 2025

    A crafted NTFS image can cause out-of-bounds reads in ntfs_attr_find and ntfs_external_attr_find in NTFS-3G < 2021.8.22.

    Published: 30 Aug 2021
    7.8
    High

    CVE-2021-39256

    Last Modified: 2 Dec 2025

    A crafted NTFS image can cause a heap-based buffer overflow in ntfs_inode_lookup_by_name in NTFS-3G < 2021.8.22.

    Published: 30 Aug 2021
    7.8
    High

    CVE-2021-39255

    Last Modified: 2 Dec 2025

    A crafted NTFS image can trigger an out-of-bounds read, caused by an invalid attribute in ntfs_attr_find_in_attrdef, in NTFS-3G < 2021.8.22.

    Published: 30 Aug 2021
    7.8
    High

    CVE-2021-39253

    Last Modified: 2 Dec 2025

    A crafted NTFS image can cause an out-of-bounds read in ntfs_runlists_merge_i in NTFS-3G < 2021.8.22.

    Published: 30 Aug 2021
    7.8
    High

    CVE-2021-39251

    Last Modified: 2 Dec 2025

    A crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_open in NTFS-3G < 2021.8.22.

    Published: 30 Aug 2021
    7.8
    High

    CVE-2021-33287

    Last Modified: 5 Jul 2026

    In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntfs_attr_pread_i, a heap buffer overflow can occur and allow for writing to arbitrary memory or denial of service of the application.

    Published: 30 Aug 2021
    7.5
    High

    CVE-2021-41772

    Last Modified: 21 Nov 2024

    Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field.

    Published: 30 Aug 2021
    9.8
    Critical

    CVE-2021-41411

    Last Modified: 21 Nov 2024

    drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.

    Published: 30 Aug 2021
    7.8
    High

    CVE-2021-39263

    Last Modified: 2 Dec 2025

    A crafted NTFS image can trigger a heap-based buffer overflow, caused by an unsanitized attribute in ntfs_get_attribute_value, in NTFS-3G < 2021.8.22.

    Published: 30 Aug 2021
    5.5
    Medium

    CVE-2021-39257

    Last Modified: 21 Nov 2024

    A crafted NTFS image with an unallocated bitmap can lead to a endless recursive function call chain (starting from ntfs_attr_pwrite), causing stack consumption in NTFS-3G < 2021.8.22.

    Published: 30 Aug 2021
    7.5
    High

    CVE-2021-38385

    Last Modified: 21 Nov 2024

    Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-signature verification, leading to a remote assertion failure, aka TROVE-2021-007.

    Published: 30 Aug 2021
    8.8
    High

    CVE-2020-35633

    Last Modified: 23 Apr 2025

    A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser<EW>::read_sface() store_sm_boundary_item() Edge_of.A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger this vulnerability.

    Published: 30 Aug 2021
    9.8
    Critical

    CVE-2021-21741

    Last Modified: 21 Nov 2024

    There is a command execution vulnerability in a ZTE conference management system. As some services are enabled by default, the attacker could exploit this vulnerability to execute arbitrary commands by sending specific serialization command.

    Published: 30 Aug 2021
    5.3
    Medium

    CVE-2021-34434

    Last Modified: 21 Nov 2024

    In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked when a durable client is offline, then existing subscriptions for that client are not revoked.

    Published: 30 Aug 2021
    7.8
    High

    CVE-2021-35269

    Last Modified: 5 Jul 2026

    NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute from the MFT is setup in the function ntfs_attr_setup_flag, a heap buffer overflow can occur allowing for code execution and escalation of privileges.

    Published: 30 Aug 2021
    9.8
    Critical

    CVE-2021-3757

    Last Modified: 21 Nov 2024

    immer is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

    Published: 30 Aug 2021
    7.8
    High

    CVE-2021-39252

    Last Modified: 2 Dec 2025

    A crafted NTFS image can cause an out-of-bounds read in ntfs_ie_lookup in NTFS-3G < 2021.8.22.

    Published: 30 Aug 2021
    7.8
    High

    CVE-2021-39254

    Last Modified: 2 Dec 2025

    A crafted NTFS image can cause an integer overflow in memmove, leading to a heap-based buffer overflow in the function ntfs_attr_record_resize, in NTFS-3G < 2021.8.22.

    Published: 30 Aug 2021
    7.8
    High

    CVE-2021-39261

    Last Modified: 5 Dec 2025

    A crafted NTFS image can cause a heap-based buffer overflow in ntfs_compressed_pwrite in NTFS-3G < 2021.8.22.

    Published: 30 Aug 2021
    8.8
    High

    CVE-2020-35634

    Last Modified: 23 Apr 2025

    A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser<EW>::read_sface() sfh->boundary_entry_objects Sloop_of. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger this vulnerability.

    Published: 30 Aug 2021
    8.8
    High

    CVE-2020-35635

    Last Modified: 23 Apr 2025

    A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sface() store_sm_boundary_item() Sloop_of OOB read. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger this vulnerability.

    Published: 30 Aug 2021
    7.8
    High

    CVE-2021-33286

    Last Modified: 21 Nov 2024

    In NTFS-3G versions < 2021.8.22, when a specially crafted unicode string is supplied in an NTFS image a heap buffer overflow can occur and allow for code execution.

    Published: 30 Aug 2021
    7.8
    High

    CVE-2021-35266

    Last Modified: 5 Jul 2026

    In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode pathname is supplied in an NTFS image a heap buffer overflow can occur resulting in memory disclosure, denial of service and even code execution.

    Published: 30 Aug 2021
    8.8
    High

    CVE-2021-40172

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Log360 before Build 5219 allows a CSRF attack on proxy settings.

    Published: 29 Aug 2021
    8.8
    High

    CVE-2021-40173

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Cloud Security Plus before Build 4117 allows a CSRF attack on the server proxy settings.

    Published: 29 Aug 2021
    8.8
    High

    CVE-2021-40174

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings.

    Published: 29 Aug 2021