CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-34272

    Last Modified: 21 Nov 2024

    A security flaw in the 'owned' function of a smart contract implementation for RobotCoin (RBTC), a tradeable Ethereum ERC20 token, allows attackers to hijack victim accounts and arbitrarily increase the digital supply of assets.

    Published: 3 Aug 2021
    7.5
    High

    CVE-2021-34270

    Last Modified: 21 Nov 2024

    An integer overflow in the mintToken function of a smart contract implementation for Doftcoin Token, an Ethereum ERC20 token, allows the owner to cause unexpected financial losses.

    Published: 3 Aug 2021
    7.5
    High

    CVE-2021-33403

    Last Modified: 21 Nov 2024

    An integer overflow in the transfer function of a smart contract implementation for Lancer Token, an Ethereum ERC20 token, allows the owner to cause unexpected financial losses between two large accounts during a transaction.

    Published: 3 Aug 2021
    9.8
    Critical

    CVE-2020-19305

    Last Modified: 21 Nov 2024

    An issue in /app/system/column/admin/index.class.php of Metinfo v7.0.0 causes the indeximg parameter to be deleted when the column is deleted, allowing attackers to escalate privileges.

    Published: 3 Aug 2021
    7.5
    High

    CVE-2020-19304

    Last Modified: 21 Nov 2024

    An issue in /admin/index.php?n=system&c=filept&a=doGetFileList of Metinfo v7.0.0 allows attackers to perform a directory traversal and access sensitive information.

    Published: 3 Aug 2021
    7.8
    High

    CVE-2020-19303

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in /fileupload.php of hdcms 5.7 allows attackers to execute arbitrary code via a crafted file.

    Published: 3 Aug 2021
    9.8
    Critical

    CVE-2020-19302

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in the avatar upload function of vaeThink v1.0.1 allows attackers to open a webshell via changing uploaded file suffixes to ".php".

    Published: 3 Aug 2021
    9.8
    Critical

    CVE-2020-19301

    Last Modified: 21 Nov 2024

    A vulnerability in the vae_admin_rule database table of vaeThink v1.0.1 allows attackers to execute arbitrary code via a crafted payload in the condition parameter.

    Published: 3 Aug 2021
    8.1
    High

    CVE-2021-38084

    Last Modified: 21 Nov 2024

    An issue was discovered in the POP3 component of Courier Mail Server before 1.1.5. Meddler-in-the-middle attackers can pipeline commands after the POP3 STLS command, injecting plaintext commands into an encrypted user session.

    Published: 3 Aug 2021
    7.2
    High

    CVE-2021-33335

    Last Modified: 13 May 2025

    Privilege escalation vulnerability in Liferay Portal 7.0.3 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9 allows remote authenticated users with permission to update/edit users to take over a company administrator user account by editing the company administrator user.

    Published: 3 Aug 2021
    6.1
    Medium

    CVE-2021-33332

    Last Modified: 13 May 2025

    Cross-site scripting (XSS) vulnerability in the Portlet Configuration module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 7, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portlet_configuration_css_web_portlet_PortletConfigurationCSSPortlet_portletResource parameter.

    Published: 3 Aug 2021
    4.3
    Medium

    CVE-2021-33334

    Last Modified: 13 May 2025

    The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.2, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 6, does not properly check user permissions, which allows remote attackers with the forms "Access in Site Administration" permission to view all forms and form entries in a site via the forms section in site administration.

    Published: 3 Aug 2021
    6.3
    Medium

    CVE-2021-33333

    Last Modified: 13 May 2025

    The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix pack 19 and 7.2 before fix pack 6, does not properly check user permission, which allows remote authenticated users to view and delete workflow submissions via crafted URLs.

    Published: 3 Aug 2021
    6.1
    Medium

    CVE-2021-33331

    Last Modified: 13 May 2025

    Open redirect vulnerability in the Notifications module in Liferay Portal 7.0.0 through 7.3.1, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19 and 7.2 before fix pack 8, allows remote attackers to redirect users to arbitrary external URLs via the 'redirect' parameter.

    Published: 3 Aug 2021
    4.3
    Medium

    CVE-2021-30589

    Last Modified: 21 Nov 2024

    Insufficient validation of untrusted input in Sharing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to bypass navigation restrictions via a crafted click-to-call link.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2021-30588

    Last Modified: 21 Nov 2024

    Type confusion in V8 in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 3 Aug 2021
    4.3
    Medium

    CVE-2021-30587

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Compositing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2021-30586

    Last Modified: 21 Nov 2024

    Use after free in dialog box handling in Windows in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2021-30585

    Last Modified: 21 Nov 2024

    Use after free in sensor handling in Google Chrome on Windows prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 3 Aug 2021
    6.5
    Medium

    CVE-2021-30584

    Last Modified: 21 Nov 2024

    Incorrect security UI in Downloads in Google Chrome on Android prior to 92.0.4515.107 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

    Published: 3 Aug 2021
    6.5
    Medium

    CVE-2021-30583

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in image handling in iOS in Google Chrome on iOS prior to 92.0.4515.107 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 3 Aug 2021
    6.5
    Medium

    CVE-2021-30582

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Animation in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2021-30581

    Last Modified: 21 Nov 2024

    Use after free in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

    Published: 3 Aug 2021
    6.5
    Medium

    CVE-2021-30580

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Android intents in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious application to obtain potentially sensitive information via a crafted HTML page.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2021-30579

    Last Modified: 21 Nov 2024

    Use after free in UI framework in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2021-30578

    Last Modified: 21 Nov 2024

    Uninitialized use in Media in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.

    Published: 3 Aug 2021
    7.8
    High

    CVE-2021-30577

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Installer in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to perform local privilege escalation via a crafted file.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2021-30576

    Last Modified: 21 Nov 2024

    Use after free in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2021-30575

    Last Modified: 21 Nov 2024

    Out of bounds write in Autofill in Google Chrome prior to 92.0.4515.107 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2021-30574

    Last Modified: 21 Nov 2024

    Use after free in protocol handling in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2021-30573

    Last Modified: 21 Nov 2024

    Use after free in GPU in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2021-30572

    Last Modified: 21 Nov 2024

    Use after free in Autofill in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 3 Aug 2021
    9.6
    Critical

    CVE-2021-30571

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2021-30569

    Last Modified: 21 Nov 2024

    Use after free in sqlite in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2021-30568

    Last Modified: 21 Nov 2024

    Heap buffer overflow in WebGL in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2021-30567

    Last Modified: 21 Nov 2024

    Use after free in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to open DevTools to potentially exploit heap corruption via specific user gesture.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2021-30566

    Last Modified: 21 Nov 2024

    Stack buffer overflow in Printing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker who had compromised the renderer process to potentially exploit stack corruption via a crafted HTML page.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2021-30565

    Last Modified: 21 Nov 2024

    Out of bounds write in Tab Groups in Google Chrome on Linux and ChromeOS prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.

    Published: 3 Aug 2021
    4.3
    Medium

    CVE-2021-33330

    Last Modified: 13 May 2025

    Liferay Portal 7.2.0 through 7.3.2, and Liferay DXP 7.2 before fix pack 9, allows access to Cross-origin resource sharing (CORS) protected resources if the user is only authenticated using the portal session authentication, which allows remote attackers to obtain sensitive information including the targeted user’s email address and current CSRF token.

    Published: 3 Aug 2021
    4.3
    Medium

    CVE-2021-33327

    Last Modified: 13 May 2025

    The Portlet Configuration module in Liferay Portal 7.2.0 through 7.3.3, and Liferay DXP 7.0 fix pack pack 93 and 94, 7.1 fix pack 18, and 7.2 before fix pack 8, does not properly check user permission, which allows remote authenticated users to view the Guest and User role even if "Role Visibility" is enabled.

    Published: 3 Aug 2021
    5.4
    Medium

    CVE-2021-33328

    Last Modified: 13 May 2025

    Cross-site scripting (XSS) vulnerability in the Asset module's edit vocabulary page in Liferay Portal 7.0.0 through 7.3.4, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20, and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the (1) _com_liferay_journal_web_portlet_JournalPortlet_name or (2) _com_liferay_document_library_web_portlet_DLAdminPortlet_name parameter.

    Published: 3 Aug 2021
    6.1
    Medium

    CVE-2021-33326

    Last Modified: 13 May 2025

    Cross-site scripting (XSS) vulnerability in the Frontend JS module in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20 and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the title of a modal window.

    Published: 3 Aug 2021
    4.9
    Medium

    CVE-2021-33325

    Last Modified: 13 May 2025

    The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix pack 19, and 7.2 before fix pack 7, user's clear text passwords are stored in the database if workflow is enabled for user creation, which allows attackers with access to the database to obtain a user's password.

    Published: 3 Aug 2021
    7.5
    High

    CVE-2021-33322

    Last Modified: 13 May 2025

    In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 18, and 7.2 before fix pack 5, password reset tokens are not invalidated after a user changes their password, which allows remote attackers to change the user’s password via the old password reset token.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2021-30564

    Last Modified: 21 Nov 2024

    Heap buffer overflow in WebXR in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2021-30563

    Last Modified: 24 Oct 2025

    Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2021-30562

    Last Modified: 21 Nov 2024

    Use after free in WebSerial in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2021-30561

    Last Modified: 21 Nov 2024

    Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2021-30559

    Last Modified: 21 Nov 2024

    Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2021-30541

    Last Modified: 21 Nov 2024

    Use after free in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 3 Aug 2021