CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2021-35981

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Use-after-free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 20 Aug 2021
    5.5
    Medium

    CVE-2021-35985

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 20 Aug 2021
    7.8
    High

    CVE-2021-35983

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Use-after-free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 20 Aug 2021
    3.3
    Low

    CVE-2021-28643

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by a Type Confusion vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 20 Aug 2021
    7.3
    High

    CVE-2021-28640

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Use-after-free vulnerability. An authenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 20 Aug 2021
    8.8
    High

    CVE-2021-28642

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Out-of-bounds write vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 20 Aug 2021
    7.8
    High

    CVE-2021-28641

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Use-after-free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 20 Aug 2021
    7.8
    High

    CVE-2021-28638

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by a Heap-based Buffer overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 20 Aug 2021
    7.8
    High

    CVE-2021-28639

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Use-after-free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 20 Aug 2021
    7.3
    High

    CVE-2021-28636

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Uncontrolled Search Path Element vulnerability. An attacker with access to the victim's C:/ folder could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 20 Aug 2021
    7.8
    High

    CVE-2021-28635

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by a use-after-free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 20 Aug 2021
    7.8
    High

    CVE-2021-28637

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an out-of-bounds read vulnerability. An unauthenticated attacker could leverage this vulnerability achieve arbitrary read / write system information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 20 Aug 2021
    8.2
    High

    CVE-2021-28634

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Improper Neutralization of Special Elements used in an OS Command. An authenticated attacker could leverage this vulnerability to achieve arbitrary code execution on the host machine in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 20 Aug 2021
    7.8
    High

    CVE-2021-28595

    Last Modified: 23 Apr 2025

    Adobe Dimension version 3.4 (and earlier) is affected by an Uncontrolled Search Path Element element. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 20 Aug 2021
    7.8
    High

    CVE-2021-28591

    Last Modified: 23 Apr 2025

    Adobe Illustrator version 25.2.3 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 20 Aug 2021
    7.8
    High

    CVE-2021-28624

    Last Modified: 23 Apr 2025

    Adobe Bridge version 11.0.2 (and earlier) are affected by a Heap-based Buffer overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 20 Aug 2021
    3.3
    Low

    CVE-2021-28589

    Last Modified: 23 Apr 2025

    Adobe Media Encoder version 15.2 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 20 Aug 2021
    7.8
    High

    CVE-2021-28592

    Last Modified: 23 Apr 2025

    Adobe Illustrator version 25.2.3 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 20 Aug 2021
    3.3
    Low

    CVE-2021-28593

    Last Modified: 23 Apr 2025

    Adobe Illustrator version 25.2.3 (and earlier) is affected by a Use After Free vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose potential sensitive information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 20 Aug 2021
    3.3
    Low

    CVE-2021-28590

    Last Modified: 23 Apr 2025

    Adobe Media Encoder version 15.2 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 20 Aug 2021
    7.7
    High

    CVE-2021-22255

    Last Modified: 21 Nov 2024

    SSRF in URL file upload in Baserow <1.1.0 allows remote authenticated users to retrieve files from the internal server network exposed over HTTP by inserting an internal address.

    Published: 20 Aug 2021
    6.8
    Medium

    CVE-2021-22238

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature in issues.

    Published: 20 Aug 2021
    7.7
    High

    CVE-2021-22246

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions before 14.0.2, 13.12.6, 13.11.6. GitLab Webhook feature could be abused to perform denial of service attacks.

    Published: 20 Aug 2021
    3.1
    Low

    CVE-2021-22254

    Last Modified: 21 Nov 2024

    Under very specific conditions a user could be impersonated using Gitlab shell. This vulnerability affects GitLab CE/EE 13.1 and later through 14.1.2, 14.0.7 and 13.12.9.

    Published: 20 Aug 2021
    7.7
    High

    CVE-2021-35529

    Last Modified: 21 Nov 2024

    Insufficiently Protected Credentials vulnerability in client environment of Hitachi ABB Power Grids Retail Operations and Counterparty Settlement Billing (CSB) allows an attacker or unauthorized user to access database credentials, shut down the product and access or alter. This issue affects: Hitachi ABB Power Grids Retail Operations version 5.7.2 and prior versions. Hitachi ABB Power Grids Counterparty Settlement Billing (CSB) version 5.7.2 and prior versions.

    Published: 20 Aug 2021
    7.5
    High

    CVE-2021-36748

    Last Modified: 21 Nov 2024

    A SQL Injection issue in the list controller of the Prestahome Blog (aka ph_simpleblog) module before 1.7.8 for Prestashop allows a remote attacker to extract data from the database via the sb_category parameter.

    Published: 20 Aug 2021
    7.5
    High

    CVE-2021-21823

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the Friend finder functionality of GmbH Komoot version 10.26.9 up to 11.1.11. A specially crafted series of network requests can lead to the disclosure of sensitive information.

    Published: 20 Aug 2021
    7.5
    High

    CVE-2021-34433

    Last Modified: 21 Nov 2024

    In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally succeeds without verifying the server side's signature on the client side, if that signature is not included in the server's ServerKeyExchange.

    Published: 20 Aug 2021
    6.1
    Medium

    CVE-2021-34228

    Last Modified: 21 Nov 2024

    Cross-site scripting in parent_control.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Description" field and "Service Name" field.

    Published: 20 Aug 2021
    6.1
    Medium

    CVE-2021-34223

    Last Modified: 21 Nov 2024

    Cross-site scripting in urlfilter.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "URL Address" field.

    Published: 20 Aug 2021
    6.1
    Medium

    CVE-2021-34220

    Last Modified: 21 Nov 2024

    Cross-site scripting in tr069config.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "User Name" field or "Password" field.

    Published: 20 Aug 2021
    5.3
    Medium

    CVE-2021-34218

    Last Modified: 21 Nov 2024

    Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /add/ , /img/, /js/, and /mobile directories via GET Parameter.

    Published: 20 Aug 2021
    6.1
    Medium

    CVE-2021-34215

    Last Modified: 21 Nov 2024

    Cross-site scripting in tcpipwan.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Service Name" field.

    Published: 20 Aug 2021
    6.1
    Medium

    CVE-2021-34207

    Last Modified: 21 Nov 2024

    Cross-site scripting in ddns.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Domain Name" field, "Server Address" field, "User Name/Email", or "Password/Key" field.

    Published: 20 Aug 2021
    9.8
    Critical

    CVE-2020-36474

    Last Modified: 21 Nov 2024

    SafeCurl before 0.9.2 has a DNS rebinding vulnerability.

    Published: 20 Aug 2021
    7.2
    High

    CVE-2020-18886

    Last Modified: 21 Nov 2024

    Unrestricted File Upload in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the component 'admin/upload_file_do.php'.

    Published: 20 Aug 2021
    7.2
    High

    CVE-2020-18885

    Last Modified: 21 Nov 2024

    Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the component '/admin/web_config.php'.

    Published: 20 Aug 2021
    9.8
    Critical

    CVE-2020-18879

    Last Modified: 21 Nov 2024

    Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component 'bl-kereln/ajax/upload-logo.php'.

    Published: 20 Aug 2021
    5.3
    Medium

    CVE-2020-18878

    Last Modified: 21 Nov 2024

    Directory Traversal in Skycaiji v1.3 allows remote attackers to obtain sensitive information via the component 'index.php?m=admin&c=Tool&a=log&file=D%3A%5CphpStudy%5CWWW%5Cindex.php'.

    Published: 20 Aug 2021
    7.5
    High

    CVE-2020-18877

    Last Modified: 21 Nov 2024

    SQL Injection in Wuzhi CMS v4.1.0 allows remote attackers to obtain sensitive information via the 'flag' parameter in the component '/coreframe/app/order/admin/index.php'.

    Published: 20 Aug 2021
    5.5
    Medium

    CVE-2021-3764

    Last Modified: 21 Nov 2024

    A memory leak flaw was found in the Linux kernel's ccp_run_aes_gcm_cmd() function that allows an attacker to cause a denial of service. The vulnerability is similar to the older CVE-2019-18808. The highest threat from this vulnerability is to system availability.

    Published: 20 Aug 2021
    6.1
    Medium

    CVE-2021-22942

    Last Modified: 21 Nov 2024

    A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow attackers to redirect users to a malicious website.

    Published: 20 Aug 2021
    7.1
    High

    CVE-2021-3743

    Last Modified: 21 Nov 2024

    An out-of-bounds (OOB) memory read flaw was found in the Qualcomm IPC router protocol in the Linux kernel. A missing sanity check allows a local attacker to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability.

    Published: 20 Aug 2021
    5.5
    Medium

    CVE-2021-3744

    Last Modified: 21 Nov 2024

    A memory leak flaw was found in the Linux kernel in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ccp/ccp-ops.c, which allows attackers to cause a denial of service (memory consumption). This vulnerability is similar with the older CVE-2019-18808.

    Published: 20 Aug 2021
    3.3
    Low

    CVE-2020-18900

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow in the libexe_io_handle_read_coff_optional_header function of libyal libexe before 20181128. NOTE: the vendor has disputed this as described in libyal/libexe issue 1 on GitHub

    Published: 19 Aug 2021
    7.8
    High

    CVE-2020-18897

    Last Modified: 21 Nov 2024

    An use-after-free vulnerability in the libpff_item_tree_create_node function of libyal Libpff before 20180623 allows attackers to cause a denial of service (DOS) or execute arbitrary code via a crafted pff file.

    Published: 19 Aug 2021
    9.8
    Critical

    CVE-2021-37597

    Last Modified: 21 Nov 2024

    WP Cerber before 8.9.3 allows MFA bypass via wordpress_logged_in_[hash] manipulation.

    Published: 19 Aug 2021
    5.3
    Medium

    CVE-2021-37598

    Last Modified: 21 Nov 2024

    WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character.

    Published: 19 Aug 2021
    8.8
    High

    CVE-2021-28490

    Last Modified: 21 Nov 2024

    In OWASP CSRFGuard through 3.1.0, CSRF can occur because the CSRF cookie may be retrieved by using only a session token.

    Published: 19 Aug 2021
    5.4
    Medium

    CVE-2020-20645

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability exists in EyouCMS1.3.6 in the basic_information area.

    Published: 19 Aug 2021