CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2020-18469

    Last Modified: 21 Nov 2024

    Stored cross-site scripting (XSS) vulnerability in the Copyright Text field found in the Application page under the Configuration menu in Rukovoditel 2.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to /rukovoditel_2.4.1/index.php?module=configuration/save&redirect_to=configuration/application.

    Published: 26 Aug 2021
    5.4
    Medium

    CVE-2020-18468

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page page under the General menu via a crafted website name by doing an authenticated POST HTTP request to /qdPM_9.1/index.php/configuration.

    Published: 26 Aug 2021
    5.4
    Medium

    CVE-2020-18467

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerabilty exists in BigTree-CMS 4.4.3 in the tag name field found in the Tags page under the General menu via a crafted website name by doing an authenticated POST HTTP request to admin/tags/create.

    Published: 26 Aug 2021
    4.4
    Medium

    CVE-2021-36931

    Last Modified: 10 Aug 2026

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Published: 26 Aug 2021
    6.3
    Medium

    CVE-2021-36929

    Last Modified: 10 Aug 2026

    Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

    Published: 26 Aug 2021
    6
    Medium

    CVE-2021-36928

    Last Modified: 10 Aug 2026

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Published: 26 Aug 2021
    6.8
    Medium

    CVE-2021-30597

    Last Modified: 21 Nov 2024

    Use after free in Browser UI in Google Chrome on Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via physical access to the device.

    Published: 26 Aug 2021
    4.3
    Medium

    CVE-2021-30596

    Last Modified: 21 Nov 2024

    Incorrect security UI in Navigation in Google Chrome on Android prior to 92.0.4515.131 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 26 Aug 2021
    6.8
    Medium

    CVE-2021-30594

    Last Modified: 21 Nov 2024

    Use after free in Page Info UI in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via physical access to the device.

    Published: 26 Aug 2021
    8.1
    High

    CVE-2021-30593

    Last Modified: 21 Nov 2024

    Out of bounds read in Tab Strip in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted HTML page.

    Published: 26 Aug 2021
    8.8
    High

    CVE-2021-30592

    Last Modified: 21 Nov 2024

    Out of bounds write in Tab Groups in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.

    Published: 26 Aug 2021
    8.8
    High

    CVE-2021-30591

    Last Modified: 21 Nov 2024

    Use after free in File System API in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Aug 2021
    8.8
    High

    CVE-2021-30590

    Last Modified: 21 Nov 2024

    Heap buffer overflow in Bookmarks in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Aug 2021
    9.8
    Critical

    CVE-2021-40147

    Last Modified: 21 Nov 2024

    EmTec ZOC before 8.02.2 allows \e[201~ pastes, a different vulnerability than CVE-2021-32198.

    Published: 26 Aug 2021
    5.3
    Medium

    CVE-2021-32076

    Last Modified: 21 Nov 2024

    Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Started Wizard', especially the admin account creation page, from a non-privileged IP address network range or loopback address by intercepting the HTTP request and changing the referrer from the public IP address to the loopback.

    Published: 26 Aug 2021
    5.4
    Medium

    CVE-2021-36352

    Last Modified: 21 Nov 2024

    Stored cross-site scripting (XSS) vulnerability in Care2x Hospital Information Management 2.7 Alpha. The vulnerability has found POST requests in /modules/registration_admission/patient_register.php page with "name_middle", "addr_str", "station", "name_maiden", "name_2", "name_3" parameters.

    Published: 26 Aug 2021
    6.5
    Medium

    CVE-2021-3634

    Last Modified: 21 Nov 2024

    A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shared secrets during the lifetime of the session. One of them is called secret_hash and the other session_id. Initially, both of them are the same, but after key re-exchange, previous session_id is kept and used as an input to new secret_hash. Historically, both of these buffers had shared length variable, which worked as long as these buffers were same. But the key re-exchange operation can also change the key exchange method, which can be based on hash of different size, eventually creating "secret_hash" of different size than the session_id has. This becomes an issue when the session_id memory is zeroed or when it is used again during second key re-exchange.

    Published: 26 Aug 2021
    8.8
    High

    CVE-2021-3734

    Last Modified: 21 Nov 2024

    yourls is vulnerable to Improper Restriction of Rendered UI Layers or Frames

    Published: 26 Aug 2021
    6.1
    Medium

    CVE-2021-38559

    Last Modified: 21 Nov 2024

    DigitalDruid HotelDruid 3.0.2 has an XSS vulnerability in prenota.php affecting the fineperiodo1 parameter.

    Published: 26 Aug 2021
    9.8
    Critical

    CVE-2021-27944

    Last Modified: 21 Nov 2024

    Several high privileged APIs on the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs do not enforce access controls, allowing an unauthenticated threat actor to access privileged functionality, leading to OS command execution. The specific attack methodology is a file upload.

    Published: 26 Aug 2021
    7.5
    High

    CVE-2020-14160

    Last Modified: 21 Nov 2024

    An SSRF vulnerability in Gotenberg through 6.2.1 exists in the remote URL to PDF conversion, which results in a remote attacker being able to read local files or fetch intranet resources.

    Published: 26 Aug 2021
    6.1
    Medium

    CVE-2020-14161

    Last Modified: 21 Nov 2024

    It is possible to inject HTML and/or JavaScript in the HTML to PDF conversion in Gotenberg through 6.2.1 via the /convert/html endpoint.

    Published: 26 Aug 2021
    7.4
    High

    CVE-2021-20322

    Last Modified: 21 Nov 2024

    A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the source port UDP randomization. The highest threat from this vulnerability is to confidentiality and possibly integrity, because software that relies on UDP source port randomization are indirectly affected as well.

    Published: 26 Aug 2021
    7.2
    High

    CVE-2020-19822

    Last Modified: 21 Nov 2024

    A remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018 allows attackers to execute arbitrary PHP code via the "ml" and "title" parameters.

    Published: 26 Aug 2021
    8.8
    High

    CVE-2020-19821

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in admin.php of DOYOCMS 2.3 allows attackers to execute arbitrary SQL commands via the orders[] parameter.

    Published: 26 Aug 2021
    9.8
    Critical

    CVE-2020-19705

    Last Modified: 21 Nov 2024

    thinkphp-zcms as of 20190715 allows SQL injection via index.php?m=home&c=message&a=add.

    Published: 26 Aug 2021
    6.1
    Medium

    CVE-2020-19709

    Last Modified: 21 Nov 2024

    Insufficient filtering of the tag parameters in feehicms 0.1.3 allows attackers to execute arbitrary web or HTML via a crafted payload.

    Published: 26 Aug 2021
    5.4
    Medium

    CVE-2020-19704

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability via ResourceController.java in spring-boot-admin as of 20190710 allows attackers to execute arbitrary web scripts or HTML.

    Published: 26 Aug 2021
    6.1
    Medium

    CVE-2020-19703

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the referer parameter of Dzzoffice 2.02 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Published: 26 Aug 2021
    6.1
    Medium

    CVE-2021-20815

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Edit Boilerplate screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type 6.8.0 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.44 and earlier, and Movable Type Premium Advanced 1.44 and earlier) allows remote attackers to inject arbitrary script or HTML via unspecified vectors.

    Published: 26 Aug 2021
    6.1
    Medium

    CVE-2021-20814

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Setting screen of ContentType Information Widget Plugin of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series), and Movable Type Premium 1.44 and earlier) allows remote attackers to inject arbitrary script or HTML via unspecified vectors.

    Published: 26 Aug 2021
    6.1
    Medium

    CVE-2021-20813

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Edit screen of Content Data of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series) and Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series)) allows remote attackers to inject arbitrary script or HTML via unspecified vectors.

    Published: 26 Aug 2021
    6.1
    Medium

    CVE-2021-20812

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Setting screen of Server Sync of Movable Type (Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series) and Movable Type Premium Advanced 1.44 and earlier) allows remote attackers to inject arbitrary script or HTML via unspecified vectors.

    Published: 26 Aug 2021
    6.1
    Medium

    CVE-2021-20811

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in List of Assets screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type 6.8.0 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.44 and earlier, and Movable Type Premium Advanced 1.44 and earlier) allows remote attackers to inject arbitrary script or HTML via unspecified vectors.

    Published: 26 Aug 2021
    6.1
    Medium

    CVE-2021-20810

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Website Management screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type 6.8.0 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.44 and earlier, and Movable Type Premium Advanced 1.44 and earlier) allows remote attackers to inject arbitrary script or HTML via unspecified vectors.

    Published: 26 Aug 2021
    6.1
    Medium

    CVE-2021-20809

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Create screens of Entry, Page, and Content Type of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type 6.8.0 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.44 and earlier, and Movable Type Premium Advanced 1.44 and earlier) allows remote attackers to inject arbitrary script or HTML via unspecified vectors.

    Published: 26 Aug 2021
    6.1
    Medium

    CVE-2021-20808

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Search screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type 6.8.0 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.44 and earlier, and Movable Type Premium Advanced 1.44 and earlier) allows remote attackers to inject arbitrary script or HTML via unspecified vectors.

    Published: 26 Aug 2021
    7.8
    High

    CVE-2021-20793

    Last Modified: 21 Nov 2024

    Untrusted search path vulnerability in the installer of Sony Audio USB Driver V1.10 and prior and the installer of HAP Music Transfer Ver.1.3.0 and prior allows an attacker to gain privileges and execute arbitrary code via a Trojan horse DLL in an unspecified directory.

    Published: 26 Aug 2021
    7.5
    High

    CVE-2021-40145

    Last Modified: 21 Nov 2024

    gdImageGd2Ptr in gd_gd2.c in the GD Graphics Library (aka LibGD) through 2.3.2 has a double free. NOTE: the vendor's position is "The GD2 image format is a proprietary image format of libgd. It has to be regarded as being obsolete, and should only be used for development and testing purposes.

    Published: 26 Aug 2021
    8.8
    High

    CVE-2021-37219

    Last Modified: 21 Nov 2024

    HashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.8.15, 1.9.9 and 1.10.2.

    Published: 26 Aug 2021
    9.8
    Critical

    CVE-2021-37334

    Last Modified: 21 Nov 2024

    Umbraco Forms version 4.0.0 up to and including 8.7.5 and below are vulnerable to a security flaw that could lead to a remote code execution attack and/or arbitrary file deletion. A vulnerability occurs because validation of the file extension is performed after the file has been stored in a temporary directory. By default, files are stored within the application directory structure at %BASEDIR%/APP_DATA/TEMP/FileUploads/. Whilst access to this directory is restricted by the root web.config file, it is possible to override this restriction by uploading another specially crafted web.config file to the temporary directory. It is possible to exploit this flaw to upload a malicious script file to execute arbitrary code and system commands on the server.

    Published: 25 Aug 2021
    9.8
    Critical

    CVE-2021-37153

    Last Modified: 21 Nov 2024

    ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issue.

    Published: 25 Aug 2021
    9.8
    Critical

    CVE-2021-37154

    Last Modified: 21 Nov 2024

    In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.

    Published: 25 Aug 2021
    4.3
    Medium

    CVE-2021-28070

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) vulnerability exist in PopojiCMS 2.0.1 in po-admin/route.php?mod=user&act=multidelete.

    Published: 25 Aug 2021
    6.5
    Medium

    CVE-2020-19547

    Last Modified: 21 Nov 2024

    Directory Traversal vulnerability exists in PopojiCMS 2.0.1 via the id parameter in admin.php.

    Published: 25 Aug 2021
    5.4
    Medium

    CVE-2020-18065

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability exists in PopojiCMS 2.0.1 in admin.php?mod=menumanager--------- edit menu.

    Published: 25 Aug 2021
    4.3
    Medium

    CVE-2021-1592

    Last Modified: 21 Nov 2024

    A vulnerability in the way Cisco UCS Manager software handles SSH sessions could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management for established SSH sessions. An attacker could exploit this vulnerability by opening a significant number of SSH sessions on an affected device. A successful exploit could allow the attacker to cause a crash and restart of internal Cisco UCS Manager software processes and a temporary loss of access to the Cisco UCS Manager CLI and web UI. Note: The attacker must have valid user credentials to authenticate to the affected device.

    Published: 25 Aug 2021
    5.8
    Medium

    CVE-2021-1591

    Last Modified: 21 Nov 2024

    A vulnerability in the EtherChannel port subscription logic of Cisco Nexus 9500 Series Switches could allow an unauthenticated, remote attacker to bypass access control list (ACL) rules that are configured on an affected device. This vulnerability is due to oversubscription of resources that occurs when applying ACLs to port channel interfaces. An attacker could exploit this vulnerability by attempting to access network resources that are protected by the ACL. A successful exploit could allow the attacker to access network resources that would be protected by the ACL that was applied on the port channel interface.

    Published: 25 Aug 2021
    5.3
    Medium

    CVE-2021-1590

    Last Modified: 21 Nov 2024

    A vulnerability in the implementation of the system login block-for command for Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a login process to unexpectedly restart, causing a denial of service (DoS) condition. This vulnerability is due to a logic error in the implementation of the system login block-for command when an attack is detected and acted upon. An attacker could exploit this vulnerability by performing a brute-force login attack on an affected device. A successful exploit could allow the attacker to cause a login process to reload, which could result in a delay during authentication to the affected device.

    Published: 25 Aug 2021
    8.6
    High

    CVE-2021-1588

    Last Modified: 21 Nov 2024

    A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation when an affected device is processing an MPLS echo-request or echo-reply packet. An attacker could exploit this vulnerability by sending malicious MPLS echo-request or echo-reply packets to an interface that is enabled for MPLS forwarding on the affected device. A successful exploit could allow the attacker to cause the MPLS OAM process to crash and restart multiple times, causing the affected device to reload and resulting in a DoS condition.

    Published: 25 Aug 2021