CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-37548

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2021.1, passwords in cleartext sometimes could be stored in VCS.

    Published: 6 Aug 2021
    5.3
    Medium

    CVE-2021-37547

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2020.2.4, insufficient checks during file uploading were made.

    Published: 6 Aug 2021
    5.3
    Medium

    CVE-2021-37546

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used.

    Published: 6 Aug 2021
    7.5
    High

    CVE-2021-37545

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2021.1.1, insufficient authentication checks for agent requests were made.

    Published: 6 Aug 2021
    9.8
    Critical

    CVE-2021-37544

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization.

    Published: 6 Aug 2021
    6.1
    Medium

    CVE-2021-37542

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2020.2.3, XSS was possible.

    Published: 6 Aug 2021
    8.8
    High

    CVE-2021-37543

    Last Modified: 21 Nov 2024

    In JetBrains RubyMine before 2021.1.1, code execution without user confirmation was possible for untrusted projects.

    Published: 6 Aug 2021
    6.1
    Medium

    CVE-2021-37541

    Last Modified: 21 Nov 2024

    In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible.

    Published: 6 Aug 2021
    6.5
    Medium

    CVE-2021-37540

    Last Modified: 21 Nov 2024

    In JetBrains Hub before 2021.1.13262, a potentially insufficient CSP for the Widget deployment feature was used.

    Published: 6 Aug 2021
    7.5
    High

    CVE-2021-36708

    Last Modified: 21 Nov 2024

    In ProLink PRC2402M V1.0.18 and older, the set_sys_init function in the login.cgi binary allows an attacker to reset the password to the administrative interface of the router.

    Published: 6 Aug 2021
    9.8
    Critical

    CVE-2021-36707

    Last Modified: 21 Nov 2024

    In ProLink PRC2402M V1.0.18 and older, the set_ledonoff function in the adm.cgi binary, accessible with a page parameter value of ledonoff contains a trivial command injection where the value of the led_cmd parameter is passed directly to do_system.

    Published: 6 Aug 2021
    9.8
    Critical

    CVE-2021-36209

    Last Modified: 21 Nov 2024

    In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset.

    Published: 6 Aug 2021
    9.8
    Critical

    CVE-2021-36706

    Last Modified: 21 Nov 2024

    In ProLink PRC2402M V1.0.18 and older, the set_sys_cmd function in the adm.cgi binary, accessible with a page parameter value of sysCMD contains a trivial command injection where the value of the command parameter is passed directly to system.

    Published: 6 Aug 2021
    9.8
    Critical

    CVE-2021-36705

    Last Modified: 21 Nov 2024

    In ProLink PRC2402M V1.0.18 and older, the set_TR069 function in the adm.cgi binary, accessible with a page parameter value of TR069 contains a trivial command injection where the value of the TR069_local_port parameter is passed directly to system.

    Published: 6 Aug 2021
    9.8
    Critical

    CVE-2021-36351

    Last Modified: 21 Nov 2024

    SQL Injection Vulnerability in Care2x Open Source Hospital Information Management 2.7 Alpha via the (1) pday, (2) pmonth, and (3) pyear parameters in GET requests sent to /modules/nursing/nursing-station.php.

    Published: 6 Aug 2021
    5.5
    Medium

    CVE-2021-22295

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a permission bypass vulnerability. Local attackers may exploit this vulnerability to cause the device to hang due to the page error OsVmPageFaultHandler.

    Published: 6 Aug 2021
    8.8
    High

    CVE-2021-37381

    Last Modified: 21 Nov 2024

    Southsoft GMIS 5.0 is vulnerable to CSRF attacks. Attackers can access other users' private information such as photos through CSRF. For example: any student's photo information can be accessed through /gmis/(S([1]))/student/grgl/PotoImageShow/?bh=[2]. Among them, the code in [1] is a random string generated according to the user's login related information. It can protect the user's identity, but it can not effectively prevent unauthorized access. The code in [2] is the student number of any student. The attacker can carry out CSRF attack on the system by modifying [2] without modifying [1].

    Published: 6 Aug 2021
    5.4
    Medium

    CVE-2021-38152

    Last Modified: 21 Nov 2024

    index.php/appointment/insert_patient_add_appointment in Chikitsa Patient Management System 2.0.0 allows XSS.

    Published: 6 Aug 2021
    5.4
    Medium

    CVE-2021-38151

    Last Modified: 21 Nov 2024

    index.php/appointment/todos in Chikitsa Patient Management System 2.0.0 allows XSS.

    Published: 6 Aug 2021
    5.4
    Medium

    CVE-2021-38149

    Last Modified: 21 Nov 2024

    index.php/admin/add_user in Chikitsa Patient Management System 2.0.0 allows XSS.

    Published: 6 Aug 2021
    9.8
    Critical

    CVE-2021-37388

    Last Modified: 21 Nov 2024

    A buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an attacker to crash the webserver and might even gain remote code execution.

    Published: 6 Aug 2021
    4.3
    Medium

    CVE-2021-32587

    Last Modified: 21 Nov 2024

    An improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface 7.0.0, 6.4.5 and below, 6.2.8 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker with restricted user profile to retrieve the list of administrative users of other ADOMs and their related configuration.

    Published: 6 Aug 2021
    4.6
    Medium

    CVE-2021-32597

    Last Modified: 21 Nov 2024

    Multiple improper neutralization of input during web page generation (CWE-79) in FortiManager and FortiAnalyzer versions 7.0.0, 6.4.5 and below, 6.2.7 and below user interface, may allow a remote authenticated attacker to perform a Stored Cross Site Scripting attack (XSS) by injecting malicious payload in GET parameters.

    Published: 6 Aug 2021
    4.4
    Medium

    CVE-2021-3635

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel netfilter implementation in versions prior to 5.5-rc7. A user with root (CAP_SYS_ADMIN) access is able to panic the system when issuing netfilter netflow commands.

    Published: 6 Aug 2021
    7.5
    High

    CVE-2021-38155

    Last Modified: 21 Nov 2024

    OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). By guessing the name of an account and failing to authenticate multiple times, any unauthenticated actor could both confirm the account exists and obtain that account's corresponding UUID, which might be leveraged for other unrelated attacks. All deployments enabling security_compliance.lockout_failure_attempts are affected.

    Published: 6 Aug 2021
    9.1
    Critical

    CVE-2021-20597

    Last Modified: 21 Nov 2024

    Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to login to the target unauthorizedly by sniffing network traffic and obtaining credentials when registering user information in the target or changing a password.

    Published: 6 Aug 2021
    7.1
    High

    CVE-2021-3739

    Last Modified: 21 Nov 2024

    A NULL pointer dereference flaw was found in the btrfs_rm_device function in fs/btrfs/volumes.c in the Linux Kernel, where triggering the bug requires ‘CAP_SYS_ADMIN’. This flaw allows a local attacker to crash the system or leak kernel internal information. The highest threat from this vulnerability is to system availability.

    Published: 6 Aug 2021
    7.8
    High

    CVE-2021-38185

    Last Modified: 9 Jun 2025

    GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is unclear whether there are common cases where the pattern file, associated with the -E option, is untrusted data.

    Published: 6 Aug 2021
    7.5
    High

    CVE-2021-20594

    Last Modified: 21 Nov 2024

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to acquire legitimate user names registered in the module via brute-force attack on user names.

    Published: 6 Aug 2021
    5.4
    Medium

    CVE-2020-22392

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.2 when adding a blog and then editing an image file.

    Published: 5 Aug 2021
    7.5
    High

    CVE-2021-20592

    Last Modified: 21 Nov 2024

    Missing synchronization vulnerability in GOT2000 series GT27 model communication driver versions 01.19.000 through 01.39.010, GT25 model communication driver versions 01.19.000 through 01.39.010 and GT23 model communication driver versions 01.19.000 through 01.39.010 and GT SoftGOT2000 versions 1.170C through 1.256S allows a remote unauthenticated attacker to cause DoS condition on the MODBUS/TCP slave communication function of the products by rapidly and repeatedly connecting and disconnecting to and from the MODBUS/TCP communication port on a target. Restart or reset is required to recover.

    Published: 5 Aug 2021
    7.8
    High

    CVE-2021-28216

    Last Modified: 3 Nov 2025

    BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.

    Published: 5 Aug 2021
    8.8
    High

    CVE-2021-22517

    Last Modified: 21 Nov 2024

    A potential unauthorized privilege escalation vulnerability has been identified in Micro Focus Data Protector. The vulnerability affects versions 10.10, 10.20, 10.30, 10.40, 10.50, 10.60, 10.70, 10.80, 10.0 and 10.91. A privileged user may potentially misuse this feature and thus allow unintended and unauthorized access of data.

    Published: 5 Aug 2021
    7.5
    High

    CVE-2021-26586

    Last Modified: 21 Nov 2024

    A potential security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software. The vulnerability could be remotely exploited to disclose sensitive information. HPE has made software updates available to resolve the vulnerability in the HPE Edgeline Infrastructure Manager (EIM).

    Published: 5 Aug 2021
    7.5
    High

    CVE-2021-35325

    Last Modified: 21 Nov 2024

    A stack overflow in the checkLoginUser function of TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to cause a denial of service (DOS).

    Published: 5 Aug 2021
    9.8
    Critical

    CVE-2021-35327

    Last Modified: 21 Nov 2024

    A vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, then login with the default credentials via a crafted POST request.

    Published: 5 Aug 2021
    7.5
    High

    CVE-2021-35326

    Last Modified: 21 Nov 2024

    A vulnerability in TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows attackers to download the configuration file via sending a crafted HTTP request.

    Published: 5 Aug 2021
    9.8
    Critical

    CVE-2021-35324

    Last Modified: 21 Nov 2024

    A vulnerability in the Form_Login function of TOTOLINK A720R A720R_Firmware V4.1.5cu.470_B20200911 allows attackers to bypass authentication.

    Published: 5 Aug 2021
    6.1
    Medium

    CVE-2021-20116

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4. The paths provided in the f, d, and dir parameters in tce_select_mediafile.php were not properly validated and could cause reflected XSS via the unsanitized output of the path supplied. An attacker could craft a malicious link which, if triggered by an administrator, could result in the attacker hijacking the victim's session or performing actions on their behalf.

    Published: 5 Aug 2021
    6.1
    Medium

    CVE-2021-20115

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3. The paths provided in the f, d, and dir parameters in tce_filemanager.php were not properly validated and could cause reflected XSS via the unsanitized output of the path supplied. An attacker could craft a malicious link which, if triggered by an administrator, could result in the attacker hijacking the victim's session or performing actions on their behalf.

    Published: 5 Aug 2021
    7.5
    High

    CVE-2021-37156

    Last Modified: 21 Nov 2024

    Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the intended behavior is for those sessions to be terminated.

    Published: 5 Aug 2021
    —
    Unknown

    CVE-2021-3591

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 5 Aug 2021
    8
    High

    CVE-2021-32003

    Last Modified: 21 Nov 2024

    Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is used after provisioning. This issue affects: Secomea SiteManager All versions prior to 9.5 on Hardware.

    Published: 5 Aug 2021
    4.3
    Medium

    CVE-2021-32002

    Last Modified: 21 Nov 2024

    Improper Access Control vulnerability in web service of Secomea SiteManager allows local attacker without credentials to gather network information and configuration of the SiteManager. This issue affects: Secomea SiteManager All versions prior to 9.5 on Hardware.

    Published: 5 Aug 2021
    9.6
    Critical

    CVE-2021-22234

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12.8, and all versions starting from 14.0 before 14.0.4. A specially crafted design image allowed attackers to read arbitrary files on the server.

    Published: 5 Aug 2021
    7.5
    High

    CVE-2021-1630

    Last Modified: 21 Nov 2024

    XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime Fabric, Pivotal Cloud Foundry, Private Cloud Edition, and on-premise customers.

    Published: 5 Aug 2021
    8.8
    High

    CVE-2020-7863

    Last Modified: 21 Nov 2024

    A vulnerability in File Transfer Solution of Raonwiz could allow arbitrary command execution as the result of viewing a specially-crafted web page. This vulnerability is due to insufficient validation of the parameter of the specific method. An attacker could exploit this vulnerability by setting the parameter to the command they want to execute. A successful exploit could allow the attacker to execute arbitrary commands on a target system as the user. However, the victim must run the Internet Explorer browser with administrator privileges because of the cross-domain policy.

    Published: 5 Aug 2021
    7.5
    High

    CVE-2021-26605

    Last Modified: 21 Nov 2024

    An improper input validation vulnerability in the service of ezPDFReader allows attacker to execute arbitrary command. This issue occurred when the ezPDF launcher received and executed crafted input values through JSON-RPC communication.

    Published: 5 Aug 2021
    5.5
    Medium

    CVE-2021-3566

    Last Modified: 21 Nov 2024

    Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' function assigned to it. By crafting a legitimate "ffconcat" file that references an image, followed by a file the triggers the tty demuxer, the contents of the second file will be copied into the output file verbatim (as long as the `-vcodec copy` option is passed to ffmpeg).

    Published: 5 Aug 2021
    6.5
    Medium

    CVE-2021-34638

    Last Modified: 21 Mar 2025

    Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS attacks, by setting Download template to a file containing configuration information or an uploaded JavaScript with an image extension This issue affects: WordPress Download Manager version 3.1.24 and prior versions.

    Published: 5 Aug 2021