CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2021-38193

    Last Modified: 21 Nov 2024

    An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870.

    Published: 8 Aug 2021
    9.8
    Critical

    CVE-2021-38194

    Last Modified: 21 Nov 2024

    An issue was discovered in the ark-r1cs-std crate before 0.3.1 for Rust. It does not enforce any constraints in the FieldVar::mul_by_inverse method. Thus, a prover can produce a proof that is unsound but is nonetheless verified.

    Published: 8 Aug 2021
    9.8
    Critical

    CVE-2021-38195

    Last Modified: 21 Nov 2024

    An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow.

    Published: 8 Aug 2021
    9.8
    Critical

    CVE-2021-38196

    Last Modified: 21 Nov 2024

    An issue was discovered in the better-macro crate through 2021-07-22 for Rust. It intentionally demonstrates that remote attackers can execute arbitrary code via proc-macros, and otherwise has no legitimate purpose.

    Published: 8 Aug 2021
    5.5
    Medium

    CVE-2021-34334

    Last Modified: 21 Nov 2024

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop is triggered when Exiv2 is used to read the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted image file. The bug is fixed in version v0.27.5.

    Published: 8 Aug 2021
    4.7
    Medium

    CVE-2021-34335

    Last Modified: 21 Nov 2024

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A floating point exception (FPE) due to an integer divide by zero was found in Exiv2 versions v0.27.4 and earlier. The FPE is triggered when Exiv2 is used to print the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when printing the interpreted (translated) data, which is a less frequently used Exiv2 operation that requires an extra command line option (`-p t` or `-P t`). The bug is fixed in version v0.27.5.

    Published: 8 Aug 2021
    6.4
    Medium

    CVE-2021-3700

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c. This issue occurs when serializing large amounts of buffered write data in the case of a slow or blocked destination.

    Published: 8 Aug 2021
    4.7
    Medium

    CVE-2021-37618

    Last Modified: 21 Nov 2024

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to print the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when printing the image ICC profile, which is a less frequently used Exiv2 operation that requires an extra command line option (`-p C`). The bug is fixed in version v0.27.5.

    Published: 8 Aug 2021
    4.7
    Medium

    CVE-2021-37619

    Last Modified: 21 Nov 2024

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as insert. The bug is fixed in version v0.27.5.

    Published: 8 Aug 2021
    5.5
    Medium

    CVE-2021-37621

    Last Modified: 21 Nov 2024

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered when Exiv2 is used to print the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when printing the image ICC profile, which is a less frequently used Exiv2 operation that requires an extra command line option (`-p C`). The bug is fixed in version v0.27.5.

    Published: 8 Aug 2021
    5.5
    Medium

    CVE-2021-37622

    Last Modified: 21 Nov 2024

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered when Exiv2 is used to modify the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when deleting the IPTC data, which is a less frequently used Exiv2 operation that requires an extra command line option (`-d I rm`). The bug is fixed in version v0.27.5.

    Published: 8 Aug 2021
    5.5
    Medium

    CVE-2021-37623

    Last Modified: 21 Nov 2024

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered when Exiv2 is used to modify the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when deleting the IPTC data, which is a less frequently used Exiv2 operation that requires an extra command line option (`-d I rm`). The bug is fixed in version v0.27.5.

    Published: 8 Aug 2021
    5.5
    Medium

    CVE-2021-32815

    Last Modified: 21 Nov 2024

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The assertion failure is triggered when Exiv2 is used to modify the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when modifying the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as `fi`. ### Patches The bug is fixed in version v0.27.5. ### References Regression test and bug fix: #1739 ### For more information Please see our [security policy](https://github.com/Exiv2/exiv2/security/policy) for information about Exiv2 security.

    Published: 8 Aug 2021
    4.7
    Medium

    CVE-2021-37615

    Last Modified: 21 Nov 2024

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A null pointer dereference was found in Exiv2 versions v0.27.4 and earlier. The null pointer dereference is triggered when Exiv2 is used to print the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when printing the interpreted (translated) data, which is a less frequently used Exiv2 operation that requires an extra command line option (`-p t` or `-P t`). The bug is fixed in version v0.27.5.

    Published: 8 Aug 2021
    5.5
    Medium

    CVE-2021-37616

    Last Modified: 21 Nov 2024

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A null pointer dereference was found in Exiv2 versions v0.27.4 and earlier. The null pointer dereference is triggered when Exiv2 is used to print the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when printing the interpreted (translated) data, which is a less frequently used Exiv2 operation that requires an extra command line option (`-p t` or `-P t`). The bug is fixed in version v0.27.5.

    Published: 8 Aug 2021
    4.7
    Medium

    CVE-2021-37620

    Last Modified: 21 Nov 2024

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted image file. The bug is fixed in version v0.27.5.

    Published: 8 Aug 2021
    9.8
    Critical

    CVE-2021-38173

    Last Modified: 21 Nov 2024

    Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using ssh_filter_btrbk.sh in authorized_keys.

    Published: 7 Aug 2021
    8.8
    High

    CVE-2021-38168

    Last Modified: 21 Nov 2024

    Roxy-WI through 5.2.2.0 allows authenticated SQL injection via select_servers.

    Published: 7 Aug 2021
    8.8
    High

    CVE-2021-38169

    Last Modified: 21 Nov 2024

    Roxy-WI through 5.2.2.0 allows command injection via /app/funct.py and /api/api_funct.py.

    Published: 7 Aug 2021
    9.8
    Critical

    CVE-2021-38167

    Last Modified: 21 Nov 2024

    Roxy-WI through 5.2.2.0 allows SQL Injection via check_login. An unauthenticated attacker can extract a valid uuid to bypass authentication.

    Published: 7 Aug 2021
    9.8
    Critical

    CVE-2021-38159

    Last Modified: 21 Nov 2024

    In certain Progress MOVEit Transfer versions before 2021.0.4 (aka 13.0.4), SQL injection in the MOVEit Transfer web application could allow an unauthenticated remote attacker to gain access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, or execute SQL statements that alter or delete database elements, via crafted strings sent to unique MOVEit Transfer transaction types. The fixed versions are 2019.0.8 (11.0.8), 2019.1.7 (11.1.7), 2019.2.4 (11.2.4), 2020.0.7 (12.0.7), 2020.1.6 (12.1.6), and 2021.0.4 (13.0.4).

    Published: 7 Aug 2021
    9.8
    Critical

    CVE-2021-38148

    Last Modified: 21 Nov 2024

    Obsidian before 0.12.12 does not require user confirmation for non-http/https URLs.

    Published: 7 Aug 2021
    5.3
    Medium

    CVE-2021-38165

    Last Modified: 21 Nov 2024

    Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.

    Published: 7 Aug 2021
    7.8
    High

    CVE-2021-38166

    Last Modified: 21 Nov 2024

    In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-bounds write when many elements are placed in a single bucket. NOTE: exploitation might be impractical without the CAP_SYS_ADMIN capability.

    Published: 7 Aug 2021
    9.8
    Critical

    CVE-2020-28088

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in /jeecg-boot/sys/common/upload of jeecg-boot CMS 2.3 allows attackers to execute arbitrary code.

    Published: 6 Aug 2021
    7.5
    High

    CVE-2020-28087

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in /jeecg boot/sys/dict/loadtreedata of jeecg-boot CMS 2.3 allows attackers to access sensitive database information.

    Published: 6 Aug 2021
    6.5
    Medium

    CVE-2020-21358

    Last Modified: 21 Nov 2024

    A cross site request forgery (CSRF) in Wage-CMS 1.5.x-dev allows attackers to arbitrarily add users.

    Published: 6 Aug 2021
    6.1
    Medium

    CVE-2020-21357

    Last Modified: 21 Nov 2024

    A stored cross site scripting (XSS) vulnerability in /admin.php?mod=user&act=addnew of PopojiCMS 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the E-Mail field.

    Published: 6 Aug 2021
    5.3
    Medium

    CVE-2020-21356

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in upload.php of PopojiCMS 1.2 leads to physical path disclosure of the host when 'name = "file" is deleted during file uploads.

    Published: 6 Aug 2021
    5.4
    Medium

    CVE-2020-21353

    Last Modified: 21 Nov 2024

    A stored cross site scripting (XSS) vulnerability in /admin/snippets.php of GetSimple CMS 3.4.0a allows attackers to execute arbitrary web scripts or HTML via crafted payload in the Edit Snippets module.

    Published: 6 Aug 2021
    6.1
    Medium

    CVE-2021-38157

    Last Modified: 21 Nov 2024

    LeoStream Connection Broker 9.x before 9.0.34.3 allows Unauthenticated Reflected XSS via the /index.pl user parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 6 Aug 2021
    7.8
    High

    CVE-2021-35312

    Last Modified: 21 Nov 2024

    A vulnerability was found in CIR 2000 / Gestionale Amica Prodigy v1.7. The Amica Prodigy's executable "RemoteBackup.Service.exe" has incorrect permissions, allowing a local unprivileged user to replace it with a malicious file that will be executed with "LocalSystem" privileges.

    Published: 6 Aug 2021
    8.8
    High

    CVE-2020-18694

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) in IgnitedCMS v1.0 allows remote attackers to obtain sensitive information and gain privilege via the component "/admin/profile/save_profile".

    Published: 6 Aug 2021
    5.4
    Medium

    CVE-2020-18693

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in MineWebCMS v1.7.0 allows remote attackers to execute arbitrary code by injecting malicious code into the 'Title' field of the component '/admin/news'.

    Published: 6 Aug 2021
    7.8
    High

    CVE-2021-36795

    Last Modified: 21 Nov 2024

    A permission issue in the Cohesity Linux agent may allow privilege escalation in version 6.5.1b to 6.5.1d-hotfix10, 6.6.0a to 6.6.0b-hotfix1. An underprivileged linux user, if certain environment criteria are met, can gain additional privileges.

    Published: 6 Aug 2021
    5.3
    Medium

    CVE-2021-20598

    Last Modified: 21 Nov 2024

    Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R08/16/32/120SFCPU all versions, R08/16/32/120PSFCPU all versions) allows a remote unauthenticated attacker to lockout a legitimate user by continuously trying login with incorrect password.

    Published: 6 Aug 2021
    8.8
    High

    CVE-2021-36455

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in Naviwebs Navigate CMS 2.9 via the quicksearch parameter in \lib\packages\comments\comments.php.

    Published: 6 Aug 2021
    5.4
    Medium

    CVE-2021-36454

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Naviwebs Navigate Cms 2.9 via the navigate-quickse parameter to 1) backups\backups.php, 2) blocks\blocks.php, 3) brands\brands.php, 4) comments\comments.php, 5) coupons\coupons.php, 6) feeds\feeds.php, 7) functions\functions.php, 8) items\items.php, 9) menus\menus.php, 10) orders\orders.php, 11) payment_methods\payment_methods.php, 12) products\products.php, 13) profiles\profiles.php, 14) shipping_methods\shipping_methods.php, 15) templates\templates.php, 16) users\users.php, 17) webdictionary\webdictionary.php, 18) websites\websites.php, and 19) webusers\webusers.php because the initial_url function is built in these files.

    Published: 6 Aug 2021
    4.3
    Medium

    CVE-2021-26999

    Last Modified: 21 Nov 2024

    NetApp Cloud Manager versions prior to 3.9.9 log sensitive information when an Active Directory connection fails. The logged information is available only to authenticated users. Customers with auto-upgrade enabled should already be on a fixed version while customers using on-prem connectors with auto-upgrade disabled are advised to upgrade to a fixed version.

    Published: 6 Aug 2021
    4.3
    Medium

    CVE-2021-26998

    Last Modified: 21 Nov 2024

    NetApp Cloud Manager versions prior to 3.9.9 log sensitive information that is available only to authenticated users. Customers with auto-upgrade enabled should already be on a fixed version while customers using on-prem connectors with auto-upgrade disabled are advised to upgrade to a fixed version.

    Published: 6 Aug 2021
    9.8
    Critical

    CVE-2021-26606

    Last Modified: 21 Nov 2024

    A vulnerability in PKI Security Solution of Dream Security could allow arbitrary command execution. This vulnerability is due to insufficient validation of the authorization certificate. An attacker could exploit this vulnerability by sending a crafted HTTP request an affected program. A successful exploit could allow the attacker to remotely execute arbitrary code on a target system.

    Published: 6 Aug 2021
    6.5
    Medium

    CVE-2021-38136

    Last Modified: 21 Nov 2024

    Corero SecureWatch Managed Services 9.7.2.0020 is affected by a Path Traversal vulnerability via the snap_file parameter in the /it-IT/splunkd/__raw/services/get_snapshot HTTP API endpoint. A ‘low privileged’ attacker can read any file on the target host.

    Published: 6 Aug 2021
    8.1
    High

    CVE-2021-38137

    Last Modified: 21 Nov 2024

    Corero SecureWatch Managed Services 9.7.2.0020 does not correctly check swa-monitor and cns-monitor user’s privileges, allowing a user to perform actions not belonging to his role.

    Published: 6 Aug 2021
    4.3
    Medium

    CVE-2021-37554

    Last Modified: 21 Nov 2024

    In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.

    Published: 6 Aug 2021
    7.5
    High

    CVE-2021-37553

    Last Modified: 21 Nov 2024

    In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used.

    Published: 6 Aug 2021
    5.3
    Medium

    CVE-2021-37551

    Last Modified: 21 Nov 2024

    In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.

    Published: 6 Aug 2021
    5.4
    Medium

    CVE-2021-37552

    Last Modified: 21 Nov 2024

    In JetBrains YouTrack before 2021.2.17925, stored XSS was possible.

    Published: 6 Aug 2021
    7.5
    High

    CVE-2021-37550

    Last Modified: 21 Nov 2024

    In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used.

    Published: 6 Aug 2021
    6.1
    Medium

    CVE-2020-22330

    Last Modified: 21 Nov 2024

    Cross-Site Scripting (XSS) vulnerability in Subrion 4.2.1 via the title when adding a page.

    Published: 6 Aug 2021
    9.1
    Critical

    CVE-2021-37549

    Last Modified: 21 Nov 2024

    In JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient.

    Published: 6 Aug 2021