CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2021-32798

    Last Modified: 21 Nov 2024

    The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code on load. Jupyter Notebook uses a deprecated version of Google Caja to sanitize user inputs. A public Caja bypass can be used to trigger an XSS when a victim opens a malicious ipynb document in Jupyter Notebook. The XSS allows an attacker to execute arbitrary code on the victim computer using Jupyter APIs.

    Published: 9 Aug 2021
    7.8
    High

    CVE-2021-38305

    Last Modified: 21 Nov 2024

    23andMe Yamale before 3.0.8 allows remote attackers to execute arbitrary code via a crafted schema file. The schema parser uses eval as part of its processing, and tries to protect from malicious expressions by limiting the builtins that are passed to the eval. When processing the schema, each line is run through Python's eval function to make the validator available. A well-constructed string within the schema rules can execute system commands; thus, by exploiting the vulnerability, an attacker can run arbitrary code on the image that invokes Yamale.

    Published: 9 Aug 2021
    7.4
    High

    CVE-2021-32797

    Last Modified: 21 Nov 2024

    JupyterLab is a user interface for Project Jupyter which will eventually replace the classic Jupyter Notebook. In affected versions untrusted notebook can execute code on load. In particular JupyterLab doesn’t sanitize the action attribute of html `<form>`. Using this it is possible to trigger the form validation outside of the form itself. This is a remote code execution, but requires user action to open a notebook.

    Published: 9 Aug 2021
    7.4
    High

    CVE-2021-37634

    Last Modified: 21 Nov 2024

    Leafkit is a templating language with Swift-inspired syntax. Versions prior to 1.3.0 are susceptible to Cross-site Scripting (XSS) attacks. This affects anyone passing unsanitised data to Leaf's variable tags. Before this fix, Leaf would not escape any strings passed to tags as variables. If an attacker managed to find a variable that was rendered with their unsanitised data, they could inject scripts into a generated Leaf page, which could enable XSS attacks if other mitigations such as a Content Security Policy were not enabled. This has been patched in 1.3.0. As a workaround sanitize any untrusted input before passing it to Leaf and enable a CSP to block inline script and CSS data.

    Published: 9 Aug 2021
    7.4
    High

    CVE-2021-37633

    Last Modified: 21 Nov 2024

    Discourse is an open source discussion platform. In versions prior to 2.7.8 rendering of d-popover tooltips can be susceptible to XSS attacks. This vulnerability only affects sites which have modified or disabled Discourse's default Content Security Policy. This issue is patched in the latest `stable` 2.7.8 version of Discourse. As a workaround users may ensure that the Content Security Policy is enabled, and has not been modified in a way which would make it more vulnerable to XSS attacks.

    Published: 9 Aug 2021
    6.1
    Medium

    CVE-2018-17861

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in SAP J2EE Engine/7.01/Portal/EPP allows remote attackers to inject arbitrary web script via the wsdlLib parameter to /ctcprotocol/Protocol. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 9 Aug 2021
    6.1
    Medium

    CVE-2018-17865

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in SAP J2EE Engine 7.01 allows remote attackers to inject arbitrary web script via the wsdlPath parameter to /ctcprotocol/Protocol. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 9 Aug 2021
    6.1
    Medium

    CVE-2018-17862

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in SAP J2EE Engine/7.01/Fiori allows remote attackers to inject arbitrary web script via the sys_jdbc parameter to /TestJDBC_Web/test2. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 9 Aug 2021
    9.8
    Critical

    CVE-2014-9320

    Last Modified: 21 Nov 2024

    SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and consequently gain SYSTEM privileges via vectors involving CORBA calls, aka SAP Note 2039905.

    Published: 9 Aug 2021
    5.5
    Medium

    CVE-2015-7731

    Last Modified: 21 Nov 2024

    SAP Mobile Platform 3.0 SP05 ClientHub allows attackers to obtain the keystream and other sensitive information via the DataVault, aka SAP Security Note 2094830.

    Published: 9 Aug 2021
    7.5
    High

    CVE-2015-2074

    Last Modified: 21 Nov 2024

    The File Repository Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attackers to write to arbitrary files via a full pathname, aka SAP Note 2018681.

    Published: 9 Aug 2021
    7.5
    High

    CVE-2015-2073

    Last Modified: 21 Nov 2024

    The File RepositoRy Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attackers to read arbitrary files via a full pathname, aka SAP Note 2018682.

    Published: 9 Aug 2021
    5.4
    Medium

    CVE-2013-4718

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) ITSM 3.0.x before 3.0.9, 3.1.x before 3.1.10, and 3.2.x before 3.2.7 allows remote authenticated users to inject arbitrary web script or HTML via an ITSM ConfigItem search.

    Published: 9 Aug 2021
    8.8
    High

    CVE-2013-4717

    Last Modified: 21 Nov 2024

    Multiple SQL injection vulnerabilities in Open Ticket Request System (OTRS) Help Desk 3.0.x before 3.0.22, 3.1.x before 3.1.18, and 3.2.x before 3.2.9 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to Kernel/Output/HTML/PreferencesCustomQueue.pm, Kernel/System/CustomerCompany.pm, Kernel/System/Ticket/IndexAccelerator/RuntimeDB.pm, Kernel/System/Ticket/IndexAccelerator/StaticDB.pm, and Kernel/System/TicketSearch.pm.

    Published: 9 Aug 2021
    9.8
    Critical

    CVE-2013-6276

    Last Modified: 21 Nov 2024

    QNAP F_VioCard 2312 and F_VioGate 2308 have hardcoded entries in authorized_keys files. NOTE: 1. All active models are not affected. The last affected model was EOL since 2010. 2. The legacy authorization mechanism is no longer adopted in all active models

    Published: 9 Aug 2021
    4.3
    Medium

    CVE-2021-25954

    Last Modified: 21 Nov 2024

    In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthorized actor. A low privileged attacker can modify the Private Note which only an administrator has rights to do, the affected field is at “/adherents/note.php?id=1” endpoint.

    Published: 9 Aug 2021
    6.5
    Medium

    CVE-2021-29714

    Last Modified: 21 Nov 2024

    IBM Content Navigator 3.0.CD could allow a malicious user to cause a denial of service due to improper input validation. IBM X-Force ID: 200968.

    Published: 9 Aug 2021
    5.3
    Medium

    CVE-2021-20349

    Last Modified: 21 Nov 2024

    IBM Tivoli Workload Scheduler 9.4 and 9.5 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and gain lower level privileges. IBM X-Force ID: 194599.

    Published: 9 Aug 2021
    2.4
    Low

    CVE-2021-21740

    Last Modified: 21 Nov 2024

    There is an information leak vulnerability in the digital media player (DMS) of ZTE's residential gateway product. The attacker could insert the USB disk with the symbolic link into the residential gateway, and access unauthorized directory information through the symbolic link, causing information leak.

    Published: 9 Aug 2021
    8.8
    High

    CVE-2021-33256

    Last Modified: 21 Nov 2024

    A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulnerable and a reverse shell could be obtained if a privileged user exports "User Attempts Audit Report" as CSV file. Note: The vendor disputes this vulnerability, claiming "This is not a valid vulnerability in our ADSSP product. We don't see this as a security issue at our side.

    Published: 9 Aug 2021
    6.1
    Medium

    CVE-2021-37573

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability in the web server TTiny Java Web Server and Servlet Container (TJWS) <=1.115 allows an adversary to inject malicious code on the server's "404 Page not Found" error page

    Published: 9 Aug 2021
    7.5
    High

    CVE-2021-36798

    Last Modified: 21 Nov 2024

    A Denial-of-Service (DoS) vulnerability was discovered in Team Server in HelpSystems Cobalt Strike 4.2 and 4.3. It allows remote attackers to crash the C2 server thread and block beacons' communication with it.

    Published: 9 Aug 2021
    5.4
    Medium

    CVE-2021-37788

    Last Modified: 21 Nov 2024

    A vulnerability in the web UI of Gurock TestRail v5.3.0.3603 could allow an unauthenticated, remote attacker to affect the integrity of a device via a clickjacking attack. The vulnerability is due to insufficient input validation of iFrame data in HTTP requests that are sent to an affected device. An attacker could exploit this vulnerability by sending crafted HTTP packets with malicious iFrame data. A successful exploit could allow the attacker to perform a clickjacking attack where the user is tricked into clicking a malicious link.

    Published: 9 Aug 2021
    9.8
    Critical

    CVE-2021-22910

    Last Modified: 21 Nov 2024

    A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which could result in a NoSQL injection, potentially leading to RCE.

    Published: 9 Aug 2021
    6.1
    Medium

    CVE-2021-34660

    Last Modified: 23 May 2025

    The WP Fusion Lite WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the startdate parameter found in the ~/includes/admin/logging/class-log-table-list.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.37.18.

    Published: 9 Aug 2021
    6.1
    Medium

    CVE-2021-34661

    Last Modified: 23 May 2025

    The WP Fusion Lite WordPress plugin is vulnerable to Cross-Site Request Forgery via the `show_logs_section` function found in the ~/includes/admin/logging/class-log-handler.php file which allows attackers to drop all logs for the plugin, in versions up to and including 3.37.18.

    Published: 9 Aug 2021
    8.1
    High

    CVE-2021-38290

    Last Modified: 21 Nov 2024

    A host header attack vulnerability exists in FUEL CMS 1.5.0 through fuel/modules/fuel/config/fuel_constants.php and fuel/modules/fuel/libraries/Asset.php. An attacker can use a man in the middle attack such as phishing.

    Published: 9 Aug 2021
    6.1
    Medium

    CVE-2021-24522

    Last Modified: 21 Nov 2024

    The User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.11's widget for tabbed login/register was not properly escaped and could be used in an XSS attack which could lead to wp-admin access. Further, the plugin in several places assigned $_POST as $_GET which meant that in some cases this could be replicated with just $_GET parameters and no need for $_POST values.

    Published: 9 Aug 2021
    7.2
    High

    CVE-2021-24521

    Last Modified: 21 Nov 2024

    The Side Menu Lite – add sticky fixed buttons WordPress plugin before 2.2.1 does not properly sanitize input values from the browser when building an SQL statement. Users with the administrator role or permission to manage this plugin could perform an SQL Injection attack.

    Published: 9 Aug 2021
    8.8
    High

    CVE-2021-24520

    Last Modified: 21 Nov 2024

    The Stock in & out WordPress plugin through 1.0.4 lacks proper sanitization before passing variables to an SQL request, making it vulnerable to SQL Injection attacks. Users with a role of contributor or higher can exploit this vulnerability.

    Published: 9 Aug 2021
    5.4
    Medium

    CVE-2021-24509

    Last Modified: 21 Nov 2024

    The Page View Count WordPress plugin before 2.4.9 does not escape the postid parameter of pvc_stats shortcode, allowing users with a role as low as Contributor to perform Stored XSS attacks. A post made by a contributor would still have to be approved by an admin to have the XSS triggered in the frontend, however, higher privilege users, such as editor could exploit this without the need of approval, and even when the blog disallows the unfiltered_html capability.

    Published: 9 Aug 2021
    9.8
    Critical

    CVE-2021-24507

    Last Modified: 21 Nov 2024

    The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both unauthenticated and authenticated user) before using them in SQL statement, leading to an SQL Injection issues

    Published: 9 Aug 2021
    5.4
    Medium

    CVE-2021-24505

    Last Modified: 21 Nov 2024

    The Forms WordPress plugin before 1.12.3 did not sanitise its input fields, leading to Stored Cross-Site scripting issues. The plugin was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) vulnerability within the Forms "Add new" field.

    Published: 9 Aug 2021
    4.8
    Medium

    CVE-2021-24502

    Last Modified: 7 May 2025

    The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the page, leading to a Stored Cross-Site Scripting issue by high privilege users, even when the unfiltered_html capability is disallowed

    Published: 9 Aug 2021
    8.1
    High

    CVE-2021-24501

    Last Modified: 21 Nov 2024

    The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user was authorized to perform critical operations such as modifying or deleting objects. This allowed a logged in user to modify or delete objects belonging to other users on the site.

    Published: 9 Aug 2021
    8.1
    High

    CVE-2021-24500

    Last Modified: 21 Nov 2024

    Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object references that were not validated. This allows an attacker to trick a logged in user to submit a POST request to the vulnerable site, potentially modifying or deleting arbitrary objects on the target site.

    Published: 9 Aug 2021
    6.1
    Medium

    CVE-2021-24495

    Last Modified: 21 Nov 2024

    The Marmoset Viewer WordPress plugin before 1.9.3 does not property sanitize, validate or escape the 'id' parameter before outputting back in the page, leading to a reflected Cross-Site Scripting issue.

    Published: 9 Aug 2021
    6.5
    Medium

    CVE-2021-24467

    Last Modified: 21 Nov 2024

    The Leaflet Map WordPress plugin before 3.0.0 does not verify the CSRF nonce when saving its settings, which allows attackers to make a logged in admin update the settings via a Cross-Site Request Forgery attack. This could lead to Cross-Site Scripting issues by either changing the URL of the JavaScript library being used, or using malicious attributions which will be executed in all page with an embed map from the plugin

    Published: 9 Aug 2021
    6.1
    Medium

    CVE-2021-24304

    Last Modified: 21 Nov 2024

    The Newsmag WordPress theme before 5.0 does not sanitise the td_block_id parameter in its td_ajax_block AJAX action, leading to an unauthenticated Reflected Cross-site Scripting (XSS) vulnerability.

    Published: 9 Aug 2021
    4.3
    Medium

    CVE-2021-37215

    Last Modified: 21 Nov 2024

    The employee management page of Flygo contains an Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attacker can manipulate the user data and then over-write another employee’s user data by specifying that employee’s ID in the API parameter.

    Published: 9 Aug 2021
    8.8
    High

    CVE-2021-37214

    Last Modified: 21 Nov 2024

    The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID in specific parameters to arbitrary access employee's data, modify it, and then obtain administrator privilege and execute arbitrary command.

    Published: 9 Aug 2021
    4.3
    Medium

    CVE-2021-37213

    Last Modified: 21 Nov 2024

    The check-in record page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID and date in specific parameters to access particular employee’s check-in record.

    Published: 9 Aug 2021
    5.4
    Medium

    CVE-2021-37212

    Last Modified: 21 Nov 2024

    The bulletin function of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the bulletin ID in specific Url parameters and access and modify bulletin particular content.

    Published: 9 Aug 2021
    5.4
    Medium

    CVE-2021-37211

    Last Modified: 21 Nov 2024

    The bulletin function of Flygo does not filter special characters while a new announcement is added. Remoter attackers can use the vulnerability with general user’s credential to inject JavaScript and execute stored XSS attacks.

    Published: 9 Aug 2021
    7.5
    High

    CVE-2021-3737

    Last Modified: 17 Dec 2025

    A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.

    Published: 9 Aug 2021
    7.8
    High

    CVE-2021-36770

    Last Modified: 3 Nov 2025

    Encode.pm, as distributed in Perl through 5.34.0, allows local users to gain privileges via a Trojan horse Encode::ConfigLocal library (in the current working directory) that preempts dynamic module loading. Exploitation requires an unusual configuration, and certain 2021 versions of Encode.pm (3.05 through 3.11). This issue occurs because the || operator evaluates @INC in a scalar context, and thus @INC has only an integer value.

    Published: 9 Aug 2021
    9.8
    Critical

    CVE-2021-24499

    Last Modified: 21 Nov 2024

    The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks, or validate that the request is from a valid user in any other way. The endpoints allowed for uploading arbitrary files to the uploads/workreap-temp directory. Uploaded files were neither sanitized nor validated, allowing an unauthenticated visitor to upload executable code such as php scripts.

    Published: 9 Aug 2021
    5.3
    Medium

    CVE-2021-38373

    Last Modified: 21 Nov 2024

    In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked.

    Published: 9 Aug 2021
    7.5
    High

    CVE-2022-27383

    Last Modified: 21 Nov 2024

    MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially crafted SQL statements.

    Published: 9 Aug 2021
    7.5
    High

    CVE-2021-38604

    Last Modified: 30 May 2025

    In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix.

    Published: 9 Aug 2021