CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-34730

    Last Modified: 21 Nov 2024

    A vulnerability in the Universal Plug-and-Play (UPnP) service of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validation of incoming UPnP traffic. An attacker could exploit this vulnerability by sending a crafted UPnP request to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a DoS condition. Cisco has not released software updates that address this vulnerability.

    Published: 18 Aug 2021
    6.7
    Medium

    CVE-2021-34716

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as the root user. This vulnerability is due to incorrect handling of certain crafted software images that are uploaded to the affected device. An attacker could exploit this vulnerability by authenticating to the system as an administrative user and then uploading specific crafted software images to the affected device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system as the root user.

    Published: 18 Aug 2021
    4.7
    Medium

    CVE-2021-34715

    Last Modified: 21 Nov 2024

    A vulnerability in the image verification function of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with internal user privileges on the underlying operating system. The vulnerability is due to insufficient validation of the content of upgrade packages. An attacker could exploit this vulnerability by uploading a malicious archive to the Upgrade page of the administrative web interface. A successful exploit could allow the attacker to execute code with user-level privileges (the _nobody account) on the underlying operating system.

    Published: 18 Aug 2021
    5.4
    Medium

    CVE-2021-1561

    Last Modified: 21 Nov 2024

    A vulnerability in the spam quarantine feature of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), could allow an authenticated, remote attacker to gain unauthorized access and modify the spam quarantine settings of another user. This vulnerability exists because access to the spam quarantine feature is not properly restricted. An attacker could exploit this vulnerability by sending malicious requests to an affected system. A successful exploit could allow the attacker to modify another user's spam quarantine settings, possibly disabling security controls or viewing email messages stored on the spam quarantine interfaces.

    Published: 18 Aug 2021
    7.5
    High

    CVE-2021-39270

    Last Modified: 21 Nov 2024

    In Ping Identity RSA SecurID Integration Kit before 3.2, user impersonation can occur.

    Published: 18 Aug 2021
    9.8
    Critical

    CVE-2020-25928

    Last Modified: 21 Nov 2024

    The DNS feature in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: DNS response processing functions: dns_upcall(), getoffset(), dnc_set_answer(). The attack vector is: a specific DNS response packet. The code does not check the "response data length" field of individual DNS answers, which may cause out-of-bounds read/write operations, leading to Information leak, Denial-or-Service, or Remote Code Execution, depending on the context.

    Published: 18 Aug 2021
    7.5
    High

    CVE-2020-25767

    Last Modified: 21 Nov 2024

    An issue was discovered in HCC Embedded NicheStack IPv4 4.1. The dnc_copy_in routine for parsing DNS domain names does not check whether a domain name compression pointer is pointing within the bounds of the packet (e.g., forward compression pointer jumps are allowed), which leads to an Out-of-bounds Read, and a Denial-of-Service as a consequence.

    Published: 18 Aug 2021
    7.5
    High

    CVE-2020-25927

    Last Modified: 21 Nov 2024

    The DNS feature in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Out-of-bounds Read. The impact is: a denial of service (remote). The component is: DNS response processing in function: dns_upcall(). The attack vector is: a specific DNS response packet. The code does not check whether the number of queries/responses specified in the DNS packet header corresponds to the query/response data available in the DNS packet.

    Published: 18 Aug 2021
    7.5
    High

    CVE-2020-25926

    Last Modified: 21 Nov 2024

    The DNS client in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Insufficient entropy in the DNS transaction id. The impact is: DNS cache poisoning (remote). The component is: dns_query_type(). The attack vector is: a specific DNS response packet.

    Published: 18 Aug 2021
    8.8
    High

    CVE-2020-19669

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=admin&c=Admin&a=admin_add&lang=cn.

    Published: 18 Aug 2021
    8.8
    High

    CVE-2020-22120

    Last Modified: 21 Nov 2024

    A remote code execution (RCE) vulnerability in /root/run/adm.php?admin-ediy&part=exdiy of imcat v5.1 allows authenticated attackers to execute arbitrary code.

    Published: 18 Aug 2021
    7.5
    High

    CVE-2020-22122

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in /oa.php?c=Staff&a=read of Find a Place LJCMS v 1.3 allows attackers to access sensitive database information via a crafted POST request.

    Published: 18 Aug 2021
    7.5
    High

    CVE-2020-22124

    Last Modified: 21 Nov 2024

    A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access sensitive information.

    Published: 18 Aug 2021
    6.1
    Medium

    CVE-2021-39286

    Last Modified: 21 Nov 2024

    Webrecorder pywb before 2.6.0 allows XSS because it does not ensure that Jinja2 templates are autoescaped.

    Published: 18 Aug 2021
    7.3
    High

    CVE-2021-37617

    Last Modified: 21 Nov 2024

    The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. The Nextcloud Desktop Client invokes its uninstaller script when being installed to make sure there are no remnants of previous installations. In versions 3.0.3 through 3.2.4, the Client searches the `Uninstall.exe` file in a folder that can be written by regular users. This could lead to a case where a malicious user creates a malicious `Uninstall.exe`, which would be executed with administrative privileges on the Nextcloud Desktop Client installation. This issue is fixed in Nextcloud Desktop Client version 3.3.0. As a workaround, do not allow untrusted users to create content in the `C:\` system folder and verify that there is no malicious `C:\Uninstall.exe` file on the system.

    Published: 18 Aug 2021
    7.5
    High

    CVE-2021-39282

    Last Modified: 21 Nov 2024

    Live555 through 1.08 has a memory leak in AC3AudioStreamParser for AC3 files.

    Published: 18 Aug 2021
    5.5
    Medium

    CVE-2021-39283

    Last Modified: 21 Nov 2024

    liveMedia/FramedSource.cpp in Live555 through 1.08 allows an assertion failure and application exit via multiple SETUP and PLAY commands.

    Published: 18 Aug 2021
    8.8
    High

    CVE-2020-18875

    Last Modified: 21 Nov 2024

    Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl (velocity) files.

    Published: 18 Aug 2021
    6.1
    Medium

    CVE-2020-28146

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter.

    Published: 18 Aug 2021
    6.5
    Medium

    CVE-2020-23069

    Last Modified: 21 Nov 2024

    Path Traversal vulneraility exists in webTareas 2.0 via the extpath parameter in general_serv.php, which could let a malicious user read arbitrary files.

    Published: 18 Aug 2021
    6.5
    Medium

    CVE-2021-32728

    Last Modified: 21 Nov 2024

    The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. Clients using the Nextcloud end-to-end encryption feature download the public and private key via an API endpoint. In versions prior to 3.3.0, the Nextcloud Desktop client fails to check if a private key belongs to previously downloaded public certificate. If the Nextcloud instance serves a malicious public key, the data would be encrypted for this key and thus could be accessible to a malicious actor. This issue is fixed in Nextcloud Desktop Client version 3.3.0. There are no known workarounds aside from upgrading.

    Published: 18 Aug 2021
    8
    High

    CVE-2021-37702

    Last Modified: 21 Nov 2024

    Pimcore is an open source data & experience management platform. Prior to version 10.1.1, Data Object CSV import allows formular injection. The problem is patched in 10.1.1. Aside from upgrading, one may apply the patch manually as a workaround.

    Published: 18 Aug 2021
    6.7
    Medium

    CVE-2021-0628

    Last Modified: 21 Nov 2024

    In OMA DRM, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05722454; Issue ID: ALPS05722454.

    Published: 18 Aug 2021
    6.7
    Medium

    CVE-2021-0627

    Last Modified: 21 Nov 2024

    In OMA DRM, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05722434; Issue ID: ALPS05722434.

    Published: 18 Aug 2021
    6.7
    Medium

    CVE-2021-0626

    Last Modified: 21 Nov 2024

    In ged, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05687510; Issue ID: ALPS05687510.

    Published: 18 Aug 2021
    5.5
    Medium

    CVE-2021-0420

    Last Modified: 21 Nov 2024

    In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05381065.

    Published: 18 Aug 2021
    5.5
    Medium

    CVE-2021-0419

    Last Modified: 21 Nov 2024

    In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05336713.

    Published: 18 Aug 2021
    5.5
    Medium

    CVE-2021-0418

    Last Modified: 21 Nov 2024

    In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05336706.

    Published: 18 Aug 2021
    5.5
    Medium

    CVE-2021-0417

    Last Modified: 21 Nov 2024

    In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05336702.

    Published: 18 Aug 2021
    5.5
    Medium

    CVE-2021-0416

    Last Modified: 21 Nov 2024

    In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05336700.

    Published: 18 Aug 2021
    5.5
    Medium

    CVE-2021-0415

    Last Modified: 21 Nov 2024

    In memory management driver, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05336692.

    Published: 18 Aug 2021
    5.5
    Medium

    CVE-2021-0408

    Last Modified: 21 Nov 2024

    In asf extractor, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489195; Issue ID: ALPS05489220.

    Published: 18 Aug 2021
    6.7
    Medium

    CVE-2021-0407

    Last Modified: 21 Nov 2024

    In clk driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05479659; Issue ID: ALPS05479659.

    Published: 18 Aug 2021
    6.1
    Medium

    CVE-2021-38710

    Last Modified: 21 Nov 2024

    Static (Persistent) XSS Vulnerability exists in version 4.3.0 of Yclas when using the install/view/form.php script. An attacker can store XSS in the database through the vulnerable SITE_NAME parameter.

    Published: 18 Aug 2021
    7.8
    High

    CVE-2021-21868

    Last Modified: 21 Nov 2024

    An unsafe deserialization vulnerability exists in the ObjectManager.plugin Project.get_MissingTypes() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 18 Aug 2021
    7.8
    High

    CVE-2021-21867

    Last Modified: 21 Nov 2024

    An unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 18 Aug 2021
    9.8
    Critical

    CVE-2021-37358

    Last Modified: 21 Nov 2024

    SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=checkrepeat&v_name=".

    Published: 18 Aug 2021
    7.2
    High

    CVE-2020-18746

    Last Modified: 21 Nov 2024

    SQL Injection in AiteCMS v1.0 allows remote attackers to execute arbitrary code via the component "aitecms/login/diy_list.php".

    Published: 18 Aug 2021
    8.8
    High

    CVE-2021-21862

    Last Modified: 21 Nov 2024

    Multiple exploitable integer truncation vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an improper memory allocation resulting in a heap-based buffer overflow that causes memory corruption The implementation of the parser used for the “Xtra” FOURCC code is handled. An attacker can convince a user to open a video to trigger this vulnerability.

    Published: 18 Aug 2021
    9.8
    Critical

    CVE-2021-21825

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow vulnerability exists in the XML Decompression PlainTextUncompressor::UncompressItem functionality of AT&T Labs’ Xmill 0.7. A specially crafted XMI file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 18 Aug 2021
    8.8
    High

    CVE-2021-21858

    Last Modified: 21 Nov 2024

    Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

    Published: 18 Aug 2021
    8.8
    High

    CVE-2021-21857

    Last Modified: 21 Nov 2024

    Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

    Published: 18 Aug 2021
    8.8
    High

    CVE-2021-21856

    Last Modified: 21 Nov 2024

    Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

    Published: 18 Aug 2021
    8.8
    High

    CVE-2021-21855

    Last Modified: 21 Nov 2024

    Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

    Published: 18 Aug 2021
    8.8
    High

    CVE-2021-21854

    Last Modified: 21 Nov 2024

    Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

    Published: 18 Aug 2021
    8.8
    High

    CVE-2021-21853

    Last Modified: 21 Nov 2024

    Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

    Published: 18 Aug 2021
    8.8
    High

    CVE-2021-21839

    Last Modified: 21 Nov 2024

    Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

    Published: 18 Aug 2021
    8.8
    High

    CVE-2021-21838

    Last Modified: 21 Nov 2024

    Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

    Published: 18 Aug 2021
    8.8
    High

    CVE-2021-21837

    Last Modified: 21 Nov 2024

    Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

    Published: 18 Aug 2021
    8.8
    High

    CVE-2021-21844

    Last Modified: 21 Nov 2024

    Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input when encountering an atom using the “stco” FOURCC code, can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

    Published: 18 Aug 2021