CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-29295

    Last Modified: 21 Nov 2024

    Null Pointer Dereference vulnerability exists in D-Link DSP-W215 1.10, which could let a remote malicious user cause a denial of servie via usr/bin/lighttpd. It could be triggered by sending an HTTP request without URL in the start line directly to the device. NOTE: The DSP-W215 and all hardware revisions is considered End of Life and as such this issue will not be patched

    Published: 10 Aug 2021
    7.5
    High

    CVE-2021-29294

    Last Modified: 21 Nov 2024

    Null Pointer Dereference vulnerability exists in D-Link DSL-2740R UK_1.01, which could let a remove malicious user cause a denial of service via the send_hnap_unauthorized function. It could be triggered by sending crafted POST request to /HNAP1/. NOTE: The DSL-2740R and all hardware revisions are considered End of Life and as such this issue will not be patched

    Published: 10 Aug 2021
    8.8
    High

    CVE-2021-33708

    Last Modified: 21 Nov 2024

    Due to insufficient input validation in Kyma, authenticated users can pass a Header of their choice and escalate privileges.

    Published: 10 Aug 2021
    6.5
    Medium

    CVE-2021-28846

    Last Modified: 21 Nov 2024

    A Format String vulnerablity exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial of service due to a logic bug at address 0x40dcd0 when calling fprintf with "%s: key len = %d, too long\n" format. The two variables seem to be put in the wrong order. The vulnerability could be triggered by sending the POST request to apply_cgi with a long and unknown key in the request body.

    Published: 10 Aug 2021
    7.5
    High

    CVE-2021-28845

    Last Modified: 21 Nov 2024

    Null Pointer Dereference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial of service by sending the POST request to apply_cgi via the lang action without a language key.

    Published: 10 Aug 2021
    8.8
    High

    CVE-2021-21601

    Last Modified: 21 Nov 2024

    Dell EMC Data Protection Search, 19.4 and prior, and IDPA, 2.6.1 and prior, contain an Information Exposure in Log File Vulnerability in CIS. A local low privileged attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with the privileges of the compromised account.

    Published: 10 Aug 2021
    6.5
    Medium

    CVE-2021-21600

    Last Modified: 21 Nov 2024

    Dell EMC NetWorker, 19.4 or older, contain an uncontrolled resource consumption flaw in its API service. An authorized API user could potentially exploit this vulnerability via the web and desktop user interfaces, leading to denial of service in the manageability path.

    Published: 10 Aug 2021
    3.9
    Low

    CVE-2021-21598

    Last Modified: 21 Nov 2024

    Dell Wyse ThinOS, versions 9.0, 9.1, and 9.1 MR1, contain a Sensitive Information Disclosure Vulnerability. An authenticated attacker with physical access to the system could exploit this vulnerability to read sensitive Smartcard data in log files.

    Published: 10 Aug 2021
    7.2
    High

    CVE-2021-21597

    Last Modified: 21 Nov 2024

    Dell Wyse ThinOS, version 9.0, contains a Sensitive Information Disclosure Vulnerability. An authenticated malicious user with physical access to the system could exploit this vulnerability to read sensitive information written to the log files.

    Published: 10 Aug 2021
    7.8
    High

    CVE-2021-21567

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS 9.1.0.x contains an improper privilege management vulnerability. It may allow an authenticated user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE to elevate privilege.

    Published: 10 Aug 2021
    6.1
    Medium

    CVE-2021-37389

    Last Modified: 21 Nov 2024

    Chamilo 1.11.14 allows stored XSS via main/install/index.php and main/install/ajax.php through the port parameter.

    Published: 10 Aug 2021
    6.1
    Medium

    CVE-2021-37390

    Last Modified: 21 Nov 2024

    A Chamilo LMS 1.11.14 reflected XSS vulnerability exists in main/social/search.php=q URI (social network search feature).

    Published: 10 Aug 2021
    5.4
    Medium

    CVE-2021-37391

    Last Modified: 21 Nov 2024

    A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator, through main/social/search.php, main/inc/lib/social.lib.php and steal cookies or execute arbitrary code on the administration side via a stored XSS vulnerability via social network the send invitation feature.

    Published: 10 Aug 2021
    5
    Medium

    CVE-2021-34485

    Last Modified: 10 Aug 2026

    .NET Core and Visual Studio Information Disclosure Vulnerability

    Published: 10 Aug 2021
    7.5
    High

    CVE-2021-38386

    Last Modified: 21 Nov 2024

    In Contiki 3.0, a buffer overflow in the Telnet service allows remote attackers to cause a denial of service because the ls command is mishandled when a directory has many files with long names.

    Published: 10 Aug 2021
    7.5
    High

    CVE-2021-38387

    Last Modified: 21 Nov 2024

    In Contiki 3.0, a Telnet server that silently quits (before disconnection with clients) leads to connected clients entering an infinite loop and waiting forever, which may cause excessive CPU consumption.

    Published: 10 Aug 2021
    7.5
    High

    CVE-2021-28844

    Last Modified: 21 Nov 2024

    Null Pointer Dereference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03 by sending the POST request to apply_cgi via a do_graph_auth action without a session_id key.

    Published: 10 Aug 2021
    7.5
    High

    CVE-2021-28843

    Last Modified: 21 Nov 2024

    Null Pointer Dereference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03 by sending the POST request to apply_cgi with an unknown action name.

    Published: 10 Aug 2021
    7.5
    High

    CVE-2021-28842

    Last Modified: 21 Nov 2024

    Null Pointer Deference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial os service by sending the POST request to apply_cgi via action do_graph_auth without login_name key.

    Published: 10 Aug 2021
    7.5
    High

    CVE-2021-28841

    Last Modified: 21 Nov 2024

    Null Pointer Dereference vulnerability in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial of service by sending a POST request to apply_cgi via an action ping_test without a ping_ipaddr key.

    Published: 10 Aug 2021
    9.8
    Critical

    CVE-2021-38140

    Last Modified: 21 Nov 2024

    The set_user extension module before 2.0.1 for PostgreSQL allows a potential privilege escalation using RESET SESSION AUTHORIZATION after set_user().

    Published: 10 Aug 2021
    9.8
    Critical

    CVE-2021-38384

    Last Modified: 21 Nov 2024

    Serverless Offline 8.0.0 returns a 403 HTTP status code for a route that has a trailing / character, which might cause a developer to implement incorrect access control, because the actual behavior within the Amazon AWS environment is a 200 HTTP status code (i.e., possibly greater than expected permissions).

    Published: 10 Aug 2021
    7.5
    High

    CVE-2021-28840

    Last Modified: 21 Nov 2024

    Null Pointer Dereference vulnerability exists in D-Link DAP-2310 2.07.RC031, DAP-2330 1.07.RC028, DAP-2360 2.07.RC043, DAP-2553 3.06.RC027, DAP-2660 1.13.RC074, DAP-2690 3.16.RC100, DAP-2695 1.17.RC063, DAP-3320 1.01.RC014 and DAP-3662 1.01.RC022 in the upload_config function of sbin/httpd binary. When the binary handle the specific HTTP GET request, the content in upload_file variable is NULL in the upload_config function then the strncasecmp would take NULL as first argument, and incur the NULL pointer dereference vulnerability.

    Published: 10 Aug 2021
    7.5
    High

    CVE-2021-28839

    Last Modified: 21 Nov 2024

    Null Pointer Dereference vulnerability exists in D-Link DAP-2310 2.07.RC031, DAP-2330 1.07.RC028, DAP-2360 2.07.RC043, DAP-2553 3.06.RC027, DAP-2660 1.13.RC074, DAP-2690 3.16.RC100, DAP-2695 1.17.RC063, DAP-3320 1.01.RC014 and DAP-3662 1.01.RC022 in the upload_certificate function of sbin/httpd binary. When the binary handle the specific HTTP GET request, the strrchr in the upload_certificate function would take NULL as first argument, and incur the NULL pointer dereference vulnerability.

    Published: 10 Aug 2021
    7.5
    High

    CVE-2021-28838

    Last Modified: 21 Nov 2024

    Null pointer dereference vulnerability in D-Link DAP-2310 2,10RC039, DAP-2330 1.10RC036 BETA, DAP-2360 2.10RC055, DAP-2553 3.10rc039 BETA, DAP-2660 1.15rc131b, DAP-2690 3.20RC115 BETA, DAP-2695 1.20RC093, DAP-3320 1.05RC027 BETA and DAP-3662 1.05rc069 in the sbin/httpd binary. The crash happens at the `atoi' operation when a specific network package are sent to the httpd binary.

    Published: 10 Aug 2021
    7.5
    High

    CVE-2021-38380

    Last Modified: 21 Nov 2024

    Live555 through 1.08 mishandles huge requests for the same MP3 stream, leading to recursion and s stack-based buffer over-read. An attacker can leverage this to launch a DoS attack.

    Published: 10 Aug 2021
    6.5
    Medium

    CVE-2021-38381

    Last Modified: 21 Nov 2024

    Live555 through 1.08 does not handle MPEG-1 or 2 files properly. Sending two successive RTSP SETUP commands for the same track causes a Use-After-Free and daemon crash.

    Published: 10 Aug 2021
    6.5
    Medium

    CVE-2021-38382

    Last Modified: 21 Nov 2024

    Live555 through 1.08 does not handle Matroska and Ogg files properly. Sending two successive RTSP SETUP commands for the same track causes a Use-After-Free and daemon crash.

    Published: 10 Aug 2021
    9.8
    Critical

    CVE-2021-38383

    Last Modified: 13 Feb 2026

    OwnTone (aka owntone-server) through 28.1 has a use-after-free in net_bind() in misc.c.

    Published: 10 Aug 2021
    7.5
    High

    CVE-2021-26423

    Last Modified: 10 Aug 2026

    .NET Core and Visual Studio Denial of Service Vulnerability

    Published: 10 Aug 2021
    5.5
    Medium

    CVE-2021-34532

    Last Modified: 10 Aug 2026

    ASP.NET Core and Visual Studio Information Disclosure Vulnerability

    Published: 10 Aug 2021
    6.1
    Medium

    CVE-2021-32768

    Last Modified: 21 Nov 2024

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions failing to properly parse, sanitize and encode malicious rich-text content, the content rendering process in the website frontend is vulnerable to cross-site scripting. Corresponding rendering instructions via TypoScript functionality HTMLparser does not consider all potentially malicious HTML tag & attribute combinations per default. In default scenarios, a valid backend user account is needed to exploit this vulnerability. In case custom plugins used in the website frontend accept and reflect rich-text content submitted by users, no authentication is required. Update to TYPO3 versions 7.6.53 ELTS, 8.7.42 ELTS, 9.5.29, 10.4.19, 11.3.2 that fix the problem described.

    Published: 10 Aug 2021
    5.3
    Medium

    CVE-2021-3692

    Last Modified: 21 Nov 2024

    yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator

    Published: 10 Aug 2021
    3.8
    Low

    CVE-2020-25082

    Last Modified: 21 Nov 2024

    An attacker with physical access to Nuvoton Trusted Platform Module (NPCT75x 7.2.x before 7.2.2.0) could extract an Elliptic Curve Cryptography (ECC) private key via a side-channel attack against ECDSA, because of an Observable Timing Discrepancy.

    Published: 10 Aug 2021
    6.1
    Medium

    CVE-2021-37365

    Last Modified: 21 Nov 2024

    CTparental before 4.45.03 is vulnerable to cross-site scripting (XSS) in the CTparental admin panel. In bl_categires_help.php, the 'categories' variable is assigned with the content of the query string param 'cat' without sanitization or encoding, enabling an attacker to inject malicious code into the output webpage.

    Published: 10 Aug 2021
    8.8
    High

    CVE-2021-37366

    Last Modified: 21 Nov 2024

    CTparental before 4.45.03 is vulnerable to cross-site request forgery (CSRF) in the CTparental admin panel. By combining CSRF with XSS, an attacker can trick the administrator into clicking a link that cancels the filtering for all standard users.

    Published: 10 Aug 2021
    7.8
    High

    CVE-2021-37367

    Last Modified: 21 Nov 2024

    CTparental before 4.45.07 is affected by a code execution vulnerability in the CTparental admin panel. Because The file "bl_categories_help.php" is vulnerable to directory traversal, an attacker can create a file that contains scripts and run arbitrary commands.

    Published: 10 Aug 2021
    5.5
    Medium

    CVE-2020-23172

    Last Modified: 21 Nov 2024

    A vulnerability in all versions of Kuba allows attackers to overwrite arbitrary files in arbitrary directories with crafted Zip files due to improper validation of file paths in .zip archives.

    Published: 10 Aug 2021
    5.5
    Medium

    CVE-2020-23171

    Last Modified: 21 Nov 2024

    A vulnerability in all versions of Nim-lang allows unauthenticated attackers to write files to arbitrary directories via a crafted zip file with dot-slash characters included in the name of the crafted file.

    Published: 10 Aug 2021
    3.7
    Low

    CVE-2021-38372

    Last Modified: 21 Nov 2024

    In KDE Trojita 0.7, man-in-the-middle attackers can create new folders because untagged responses from an IMAP server are accepted before STARTTLS.

    Published: 10 Aug 2021
    4.3
    Medium

    CVE-2021-33706

    Last Modified: 21 Nov 2024

    Due to improper input validation in InfraBox, logs can be modified by an authenticated user.

    Published: 10 Aug 2021
    6.1
    Medium

    CVE-2021-33702

    Last Modified: 21 Nov 2024

    Under certain conditions, NetWeaver Enterprise Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode report data. An attacker can craft malicious data and print it to the report. In a successful attack, a victim opens the report, and the malicious script gets executed in the victim's browser, resulting in a Stored Cross-Site Scripting (XSS) vulnerability.

    Published: 10 Aug 2021
    6.1
    Medium

    CVE-2021-33703

    Last Modified: 21 Nov 2024

    Under certain conditions, NetWeaver Enterprise Portal, versions - 7.30, 7.31, 7.40, 7.50, does not sufficiently encode URL parameters. An attacker can craft a malicious link and send it to a victim. A successful attack results in Reflected Cross-Site Scripting (XSS) vulnerability.

    Published: 10 Aug 2021
    6.1
    Medium

    CVE-2021-33707

    Last Modified: 21 Nov 2024

    SAP NetWeaver Knowledge Management allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via a URL stored in a component. This could enable the attacker to compromise the user's confidentiality and integrity.

    Published: 10 Aug 2021
    6.5
    Medium

    CVE-2021-33699

    Last Modified: 21 Nov 2024

    Task Hijacking is a vulnerability that affects the applications running on Android devices due to a misconfiguration in their AndroidManifest.xml with their Task Control features. This allows an unauthorized attacker or malware to takeover legitimate apps and to steal user's sensitive information.

    Published: 10 Aug 2021
    7.5
    High

    CVE-2021-38371

    Last Modified: 3 Nov 2025

    The STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending.

    Published: 10 Aug 2021
    6.1
    Medium

    CVE-2021-36601

    Last Modified: 21 Nov 2024

    GetSimpleCMS 3.3.16 contains a cross-site Scripting (XSS) vulnerability, where Function TSL does not filter check settings.php Website URL: "siteURL" parameter.

    Published: 10 Aug 2021
    9.8
    Critical

    CVE-2021-32943

    Last Modified: 21 Nov 2024

    The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1).

    Published: 10 Aug 2021
    6.1
    Medium

    CVE-2021-22676

    Last Modified: 21 Nov 2024

    UserExcelOut.asp within WebAccess/SCADA is vulnerable to cross-site scripting (XSS), which could allow an attacker to send malicious JavaScript code. This could result in hijacking of cookie/session tokens, redirection to a malicious webpage, and unintended browser action on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1).

    Published: 10 Aug 2021
    6.5
    Medium

    CVE-2021-22674

    Last Modified: 21 Nov 2024

    The affected product is vulnerable to a relative path traversal condition, which may allow an attacker access to unauthorized files and directories on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1).

    Published: 10 Aug 2021