CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2021-33324

    Last Modified: 13 May 2025

    The Layout module in Liferay Portal 7.1.0 through 7.3.1, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 5, does not properly check permission of pages, which allows remote authenticated users without view permission of a page to view the page via a site's page administration.

    Published: 3 Aug 2021
    7.5
    High

    CVE-2021-33323

    Last Modified: 13 May 2025

    The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 7, autosaves form values for unauthenticated users, which allows remote attackers to view the autosaved values by viewing the form as an unauthenticated user.

    Published: 3 Aug 2021
    4.3
    Medium

    CVE-2021-36543

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.UnlockDocument.php in SeedDMS v5.1.x <5.1.23 and v6.0.x <6.0.16 allows a remote attacker to unlock any document without victim's knowledge, by enticing an authenticated user to visit an attacker's web page.

    Published: 3 Aug 2021
    7.5
    High

    CVE-2021-33321

    Last Modified: 21 Nov 2024

    Insecure default configuration in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3, allows remote attackers to enumerate user email address via the forgot password functionality. The portal.property login.secure.forgot.password should be defaulted to true.

    Published: 3 Aug 2021
    4.3
    Medium

    CVE-2021-36542

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.LockDocument.php in SeedDMS v5.1.x<5.1.23 and v6.0.x <6.0.16 allows a remote attacker to lock any document without victim's knowledge, by enticing an authenticated user to visit an attacker's web page.

    Published: 3 Aug 2021
    4.3
    Medium

    CVE-2021-33320

    Last Modified: 13 May 2025

    The Flags module in Liferay Portal 7.3.1 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20, and 7.2 before fix pack 5, does not limit the rate at which content can be flagged as inappropriate, which allows remote authenticated users to spam the site administrator with emails

    Published: 3 Aug 2021
    4.3
    Medium

    CVE-2021-35343

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.Ajax.php in SeedDMS v5.1.x<5.1.23 and v6.0.x<6.0.16 allows a remote attacker to edit document name without victim's knowledge, by enticing an authenticated user to visit an attacker's web page.

    Published: 3 Aug 2021
    6.1
    Medium

    CVE-2021-36703

    Last Modified: 21 Nov 2024

    The "blog title" field in the "Settings" menu "config" page of "dashboard" in htmly 2.8.1 has a storage cross site scripting (XSS) vulnerability. It allows remote attackers to send an authenticated post HTTP request to admin/config and inject arbitrary web script or HTML through a special website name.

    Published: 3 Aug 2021
    6.1
    Medium

    CVE-2021-36702

    Last Modified: 21 Nov 2024

    The "content" field in the "regular post" page of the "add content" menu under "dashboard" in htmly 2.8.1 has a storage cross site scripting (XSS) vulnerability. It allows remote attackers to send authenticated post-http requests to add / content and inject arbitrary web scripts or HTML through special content.

    Published: 3 Aug 2021
    9.1
    Critical

    CVE-2021-36701

    Last Modified: 21 Nov 2024

    In htmly version 2.8.1, is vulnerable to an Arbitrary File Deletion on the local host when delete backup files. The vulnerability may allow a remote attacker to delete arbitrary know files on the host.

    Published: 3 Aug 2021
    8.5
    High

    CVE-2021-32018

    Last Modified: 30 May 2025

    An issue was discovered in JUMP AMS 3.6.0.04.009-2487. The JUMP SOAP API was vulnerable to arbitrary file reading due to an improper limitation of file loading on the server filesystem, aka directory traversal.

    Published: 3 Aug 2021
    9.9
    Critical

    CVE-2021-32016

    Last Modified: 30 May 2025

    An issue was discovered in JUMP AMS 3.6.0.04.009-2487. A JUMP SOAP endpoint permitted the writing of arbitrary files to a user-controlled location on the remote filesystem (with user-controlled content) via directory traversal, potentially leading to remote code and command execution.

    Published: 3 Aug 2021
    9.8
    Critical

    CVE-2021-36623

    Last Modified: 21 Nov 2024

    Arbitrary File Upload in Sourcecodester Phone Shop Sales Management System 1.0 enables RCE.

    Published: 3 Aug 2021
    5.4
    Medium

    CVE-2021-36654

    Last Modified: 21 Nov 2024

    CMSuno 1.7 is vulnerable to an authenticated stored cross site scripting in modifying the filename parameter (tgo) while updating the theme.

    Published: 3 Aug 2021
    9.8
    Critical

    CVE-2021-36622

    Last Modified: 21 Nov 2024

    Sourcecodester Online Covid Vaccination Scheduler System 1.0 is affected vulnerable to Arbitrary File Upload. The admin panel has an upload function of profile photo accessible at http://localhost/scheduler/admin/?page=user. An attacker could upload a malicious file such as shell.php with the Content-Type: image/png. Then, the attacker have to visit the uploaded profile photo to access the shell.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2019-14453

    Last Modified: 21 Nov 2024

    An issue was discovered in Comelit "App lejos de casa (web)" 2.8.0. It allows privilege escalation via modified domus and logged fields, related to js/bridge.min.js and login.json. For example, an attacker can achieve high privileges (installer or administrator) for the graphical interface via a 1C000000000S value for domus, in conjunction with a zero value for logged.

    Published: 3 Aug 2021
    7.8
    High

    CVE-2021-22423

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Out-of-bounds Write Vulnerability. Local attackers may exploit this vulnerability to cause integer overflow.

    Published: 3 Aug 2021
    7.8
    High

    CVE-2021-22420

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause the underlying trust of the application trustlist mechanism is missing..

    Published: 3 Aug 2021
    7.8
    High

    CVE-2021-22418

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting.

    Published: 3 Aug 2021
    5.5
    Medium

    CVE-2021-22419

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Insufficient Verification of Data Authenticity vulnerability. Local attackers may exploit this vulnerability to cause persistent dos.

    Published: 3 Aug 2021
    7.8
    High

    CVE-2021-22425

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Double Free vulnerability. Local attackers may exploit this vulnerability to cause Root Elevating Privileges.

    Published: 3 Aug 2021
    7.8
    High

    CVE-2021-22416

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel Code Execution.

    Published: 3 Aug 2021
    7.8
    High

    CVE-2021-22421

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to cause further Elevation of Privileges.

    Published: 3 Aug 2021
    5.5
    Medium

    CVE-2021-22424

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Kernel Memory Leakage Vulnerability. Local attackers may exploit this vulnerability to cause Kernel Denial of Service.

    Published: 3 Aug 2021
    5.5
    Medium

    CVE-2021-22417

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel Memory Leakage.

    Published: 3 Aug 2021
    7.8
    High

    CVE-2021-22422

    Last Modified: 21 Nov 2024

    A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting.

    Published: 3 Aug 2021
    6.8
    Medium

    CVE-2021-27942

    Last Modified: 21 Nov 2024

    Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs allow a threat actor to execute arbitrary code from a USB drive via the Smart Cast functionality, because files on the USB drive are effectively under the web root and can be executed.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2021-32814

    Last Modified: 21 Nov 2024

    Skytable is a NoSQL database with automated snapshots and TLS. Versions prior to 0.5.1 are vulnerable to a a directory traversal attack enabling remotely connected clients to destroy and/or manipulate critical files on the host's file system. This security bug has been patched in version 0.5.1. There are no known workarounds aside from upgrading.

    Published: 3 Aug 2021
    7.8
    High

    CVE-2021-31504

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop Build 16.6.3.84 (package 16.6.3.134). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of a user-supplied value prior to dereferencing it as a pointer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-12691.

    Published: 3 Aug 2021
    7.8
    High

    CVE-2021-31503

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop Build 16.6.3.84 (package 16.6.3.134). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of IGS files. The issue results from the lack of proper initialization of a pointer prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-12690.

    Published: 3 Aug 2021
    9.9
    Critical

    CVE-2021-32017

    Last Modified: 30 May 2025

    An issue was discovered in JUMP AMS 3.6.0.04.009-2487. A JUMP SOAP endpoint permitted the listing of the content of the remote file system. This can be used to identify the complete server filesystem structure, i.e., identifying all the directories and files.

    Published: 3 Aug 2021
    7.5
    High

    CVE-2021-33486

    Last Modified: 21 Nov 2024

    All versions of the CODESYS V3 Runtime Toolkit for VxWorks from version V3.5.8.0 and before version V3.5.17.10 have Improper Handling of Exceptional Conditions.

    Published: 3 Aug 2021
    7.5
    High

    CVE-2021-36763

    Last Modified: 21 Nov 2024

    In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.

    Published: 3 Aug 2021
    9.8
    Critical

    CVE-2021-33485

    Last Modified: 29 May 2026

    CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.

    Published: 3 Aug 2021
    9.8
    Critical

    CVE-2021-37558

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in a MediaWiki script in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote unauthenticated attackers to execute arbitrary SQL commands via the host_name and service_description parameters. The vulnerability can be exploited only when a valid Knowledge Base URL is configured on the Knowledge Base configuration page and points to a MediaWiki instance. This relates to the proxy feature in class/centreon-knowledge/ProceduresProxy.class.php and include/configuration/configKnowledge/proxy/proxy.php.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2021-37557

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in image generation in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-privileged) attackers to execute arbitrary SQL commands via the include/views/graphs/generateGraphs/generateImage.php index parameter.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2021-37556

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in reporting export in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-privileged) attackers to execute arbitrary SQL commands via the include/reporting/dashboard/csvExport/csv_HostGroupLogs.php start and end parameters.

    Published: 3 Aug 2021
    6.5
    Medium

    CVE-2021-21581

    Last Modified: 21 Nov 2024

    Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link.

    Published: 3 Aug 2021
    4.3
    Medium

    CVE-2021-21580

    Last Modified: 21 Nov 2024

    Dell EMC iDRAC8 versions prior to 2.80.80.80 & Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a Content spoofing / Text injection, where a malicious URL can inject text to present a customized message on the application that can phish users into believing that the message is legitimate.

    Published: 3 Aug 2021
    6.1
    Medium

    CVE-2021-21579

    Last Modified: 21 Nov 2024

    Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links.

    Published: 3 Aug 2021
    6.1
    Medium

    CVE-2021-21578

    Last Modified: 21 Nov 2024

    Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links.

    Published: 3 Aug 2021
    6.1
    Medium

    CVE-2021-21577

    Last Modified: 21 Nov 2024

    Dell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link.

    Published: 3 Aug 2021
    6.1
    Medium

    CVE-2021-21576

    Last Modified: 21 Nov 2024

    Dell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2021-31630

    Last Modified: 21 Nov 2024

    Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/hardware" page of the application.

    Published: 3 Aug 2021
    7.5
    High

    CVE-2021-27953

    Last Modified: 21 Nov 2024

    A NULL pointer dereference vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HomeKit Wireless Access Control setup process. A threat actor can exploit this vulnerability to cause a denial of service, forcing the device to reboot via a crafted HTTP request.

    Published: 3 Aug 2021
    9.8
    Critical

    CVE-2021-27952

    Last Modified: 21 Nov 2024

    Hardcoded default root credentials exist on the ecobee3 lite 4.5.81.200 device. This allows a threat actor to gain access to the password-protected bootloader environment through the serial console.

    Published: 3 Aug 2021
    8.2
    High

    CVE-2021-27954

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HKProcessConfig function of the HomeKit Wireless Access Control setup process. A threat actor can exploit this vulnerability to force the device to connect to a SSID or cause a denial of service.

    Published: 3 Aug 2021
    8.8
    High

    CVE-2021-32772

    Last Modified: 21 Nov 2024

    Poddycast is a podcast app made with Electron. Prior to version 0.8.1, an attacker can create a podcast or episode with malicious characters and execute commands on the client machine. The application does not clean the HTML characters of the podcast information obtained from the Feed, which allows the injection of HTML and JS code (cross-site scripting). Being an application made in electron, cross-site scripting can be scaled to remote code execution, making it possible to execute commands on the machine where the application is running. The vulnerability is patched in Poddycast version 0.8.1.

    Published: 3 Aug 2021
    —
    Unknown

    CVE-2021-36379

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 3 Aug 2021
    5.5
    Medium

    CVE-2021-22400

    Last Modified: 21 Nov 2024

    Some Huawei Smartphones has an insufficient input validation vulnerability due to the lack of parameter validation. An attacker may trick a user into installing a malicious APP. The app can modify specific parameters, causing the system to crash. Affected product include:OxfordS-AN00A 10.0.1.10(C00E10R1P1),10.0.1.105(C00E103R3P3),10.0.1.115(C00E110R3P3),10.0.1.123(C00E121R3P3),10.0.1.135(C00E130R3P3),10.0.1.135(C00E130R4P1),10.0.1.152(C00E140R4P1),10.0.1.160(C00E160R4P1),10.0.1.167(C00E166R4P1),10.0.1.173(C00E172R5P1),10.0.1.178(C00E175R5P1) and 10.1.0.202(C00E79R5P1).

    Published: 3 Aug 2021