CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2021-36092

    Last Modified: 21 Nov 2024

    It's possible to create an email which contains specially crafted link and it can be used to perform XSS attack. This issue affects: OTRS AG ((OTRS)) Community Edition:6.0.x version 6.0.1 and later versions. OTRS AG OTRS: 7.0.x version 7.0.27 and prior versions; 8.0.x version 8.0.14 and prior versions.

    Published: 26 Jul 2021
    3.5
    Low

    CVE-2021-36091

    Last Modified: 21 Nov 2024

    Agents are able to list appointments in the calendars without required permissions. This issue affects: OTRS AG ((OTRS)) Community Edition: 6.0.x version 6.0.1 and later versions. OTRS AG OTRS: 7.0.x versions prior to 7.0.27.

    Published: 26 Jul 2021
    3.5
    Low

    CVE-2021-21443

    Last Modified: 21 Nov 2024

    Agents are able to list customer user emails without required permissions in the bulk action screen. This issue affects: OTRS AG ((OTRS)) Community Edition: 6.0.x version 6.0.1 and later versions. OTRS AG OTRS: 7.0.x versions prior to 7.0.27.

    Published: 26 Jul 2021
    4.5
    Medium

    CVE-2021-21442

    Last Modified: 21 Nov 2024

    In the project create screen it's possible to inject malicious JS code to the certain fields. The code might be executed in the Reporting screen. This issue affects: OTRS AG Time Accounting: 7.0.x versions prior to 7.0.19.

    Published: 26 Jul 2021
    5.2
    Medium

    CVE-2021-21440

    Last Modified: 21 Nov 2024

    Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.27 and prior versions; 8.0.x version 8.0.14 and prior versions.

    Published: 26 Jul 2021
    7.5
    High

    CVE-2021-31292

    Last Modified: 21 Nov 2024

    An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata.

    Published: 26 Jul 2021
    8.1
    High

    CVE-2021-31291

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-29457. Reason: This candidate is a duplicate of CVE-2021-29457. Notes: All CVE users should reference CVE-2021-29457 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 26 Jul 2021
    —
    Unknown

    CVE-2021-37438

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 25 Jul 2021
    6.5
    Medium

    CVE-2021-37439

    Last Modified: 21 Nov 2024

    NCH FlexiServer v6.00 suffers from a syslog?file=/.. path traversal vulnerability.

    Published: 25 Jul 2021
    6.5
    Medium

    CVE-2021-37440

    Last Modified: 21 Nov 2024

    NCH Axon PBX v2.22 and earlier allows path traversal for file disclosure via the logprop?file=/.. substring.

    Published: 25 Jul 2021
    8.8
    High

    CVE-2021-37441

    Last Modified: 21 Nov 2024

    NCH Axon PBX v2.22 and earlier allows path traversal for file deletion via the logdelete?file=/.. substring.

    Published: 25 Jul 2021
    6.5
    Medium

    CVE-2021-37442

    Last Modified: 21 Nov 2024

    NCH IVM Attendant v5.12 and earlier allows path traversal via viewfile?file=/.. to read files.

    Published: 25 Jul 2021
    8.1
    High

    CVE-2021-37443

    Last Modified: 21 Nov 2024

    NCH IVM Attendant v5.12 and earlier allows path traversal via the logdeleteselected check0 parameter for file deletion.

    Published: 25 Jul 2021
    8.8
    High

    CVE-2021-37444

    Last Modified: 21 Nov 2024

    NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive. This can lead to code execution if a ZIP element's pathname is set to a Windows startup folder, a file for the inbuilt Out-Going Message function, or a file for the the inbuilt Autodial function.

    Published: 25 Jul 2021
    6.5
    Medium

    CVE-2021-37445

    Last Modified: 21 Nov 2024

    In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/.. for file reading.

    Published: 25 Jul 2021
    4.3
    Medium

    CVE-2021-37446

    Last Modified: 21 Nov 2024

    In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentprop?file=/.. for file reading.

    Published: 25 Jul 2021
    8.1
    High

    CVE-2021-37447

    Last Modified: 21 Nov 2024

    In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentdelete?file=/.. for file deletion.

    Published: 25 Jul 2021
    5.4
    Medium

    CVE-2021-37448

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via the Mailbox name (stored).

    Published: 25 Jul 2021
    5.4
    Medium

    CVE-2021-37449

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmlist?folder= (reflected).

    Published: 25 Jul 2021
    5.4
    Medium

    CVE-2021-37450

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmprop?id= (reflected).

    Published: 25 Jul 2021
    5.4
    Medium

    CVE-2021-37451

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /msglist?mbx= (reflected).

    Published: 25 Jul 2021
    5.5
    Medium

    CVE-2021-37452

    Last Modified: 21 Nov 2024

    NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configuration files.

    Published: 25 Jul 2021
    5.4
    Medium

    CVE-2021-37453

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the extension name (stored).

    Published: 25 Jul 2021
    5.4
    Medium

    CVE-2021-37454

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the line name (stored).

    Published: 25 Jul 2021
    5.4
    Medium

    CVE-2021-37455

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the outbound dialing plan (stored).

    Published: 25 Jul 2021
    5.4
    Medium

    CVE-2021-37456

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the blacklist IP address (stored).

    Published: 25 Jul 2021
    5.4
    Medium

    CVE-2021-37457

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored).

    Published: 25 Jul 2021
    5.4
    Medium

    CVE-2021-37458

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the primary phone field (stored).

    Published: 25 Jul 2021
    5.4
    Medium

    CVE-2021-37459

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the customer name field (stored).

    Published: 25 Jul 2021
    5.4
    Medium

    CVE-2021-37460

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /planprop?id= (reflected).

    Published: 25 Jul 2021
    5.4
    Medium

    CVE-2021-37461

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /extensionsinstruction?id= (reflected).

    Published: 25 Jul 2021
    5.4
    Medium

    CVE-2021-37462

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /ipblacklist?errorip= (reflected).

    Published: 25 Jul 2021
    5.4
    Medium

    CVE-2021-37463

    Last Modified: 21 Nov 2024

    In NCH Quorum v2.03 and earlier, XSS exists via User Display Name (stored).

    Published: 25 Jul 2021
    5.4
    Medium

    CVE-2021-37464

    Last Modified: 21 Nov 2024

    In NCH Quorum v2.03 and earlier, XSS exists via Conference Description (stored).

    Published: 25 Jul 2021
    5.4
    Medium

    CVE-2021-37465

    Last Modified: 21 Nov 2024

    In NCH Quorum v2.03 and earlier, XSS exists via /uploaddoc?id= (reflected).

    Published: 25 Jul 2021
    5.4
    Medium

    CVE-2021-37466

    Last Modified: 21 Nov 2024

    In NCH Quorum v2.03 and earlier, XSS exists via /conference?id= (reflected).

    Published: 25 Jul 2021
    5.4
    Medium

    CVE-2021-37467

    Last Modified: 21 Nov 2024

    In NCH Quorum v2.03 and earlier, XSS exists via /conferencebrowseuploadfile?confid= (reflected).

    Published: 25 Jul 2021
    3.3
    Low

    CVE-2021-37468

    Last Modified: 21 Nov 2024

    NCH Reflect CRM 3.01 allows local users to discover cleartext user account information by reading the configuration files.

    Published: 25 Jul 2021
    6.5
    Medium

    CVE-2021-37469

    Last Modified: 21 Nov 2024

    In NCH WebDictate v2.13 and earlier, authenticated users can abuse logprop?file=/.. path traversal to read files on the filesystem.

    Published: 25 Jul 2021
    5.4
    Medium

    CVE-2021-37470

    Last Modified: 21 Nov 2024

    In NCH WebDictate v2.13, persistent Cross Site Scripting (XSS) exists in the Recipient Name field. An authenticated user can add or modify the affected field to inject arbitrary JavaScript.

    Published: 25 Jul 2021
    7.5
    High

    CVE-2021-3663

    Last Modified: 21 Nov 2024

    firefly-iii is vulnerable to Improper Restriction of Excessive Authentication Attempts

    Published: 25 Jul 2021
    4.2
    Medium

    CVE-2021-37436

    Last Modified: 21 Nov 2024

    Amazon Echo Dot devices through 2021-07-02 sometimes allow attackers, who have physical access to a device after a factory reset, to obtain sensitive information via a series of complex hardware and software attacks. NOTE: reportedly, there were vendor marketing statements about safely removing personal content via a factory reset. Also, the vendor has reportedly indicated that they are working on mitigations.

    Published: 24 Jul 2021
    5.9
    Medium

    CVE-2021-32791

    Last Modified: 21 Nov 2024

    mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9, the AES GCM encryption in mod_auth_openidc uses a static IV and AAD. It is important to fix because this creates a static nonce and since aes-gcm is a stream cipher, this can lead to known cryptographic issues, since the same key is being reused. From 2.4.9 onwards this has been patched to use dynamic values through usage of cjose AES encryption routines.

    Published: 24 Jul 2021
    3.1
    Low

    CVE-2021-32792

    Last Modified: 21 Nov 2024

    mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9, there is an XSS vulnerability in when using `OIDCPreservePost On`.

    Published: 24 Jul 2021
    8.5
    High

    CVE-2021-32783

    Last Modified: 21 Nov 2024

    Contour is a Kubernetes ingress controller using Envoy proxy. In Contour before version 1.17.1 a specially crafted ExternalName type Service may be used to access Envoy's admin interface, which Contour normally prevents from access outside the Envoy container. This can be used to shut down Envoy remotely (a denial of service), or to expose the existence of any Secret that Envoy is using for its configuration, including most notably TLS Keypairs. However, it *cannot* be used to get the *content* of those secrets. Since this attack allows access to the administration interface, a variety of administration options are available, such as shutting down the Envoy or draining traffic. In general, the Envoy admin interface cannot easily be used for making changes to the cluster, in-flight requests, or backend services, but it could be used to shut down or drain Envoy, change traffic routing, or to retrieve secret metadata, as mentioned above. The issue will be addressed in Contour v1.18.0 and a cherry-picked patch release, v1.17.1, has been released to cover users who cannot upgrade at this time. For more details refer to the linked GitHub Security Advisory.

    Published: 23 Jul 2021
    5.3
    Medium

    CVE-2021-25809

    Last Modified: 21 Nov 2024

    UCMS 1.5.0 was discovered to contain a physical path leakage via an error message returned by the adminchannelscache() function in top.php.

    Published: 23 Jul 2021
    7.8
    High

    CVE-2021-25808

    Last Modified: 21 Nov 2024

    A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a crafted ZIP file.

    Published: 23 Jul 2021
    9.8
    Critical

    CVE-2020-20741

    Last Modified: 21 Nov 2024

    Incorrect Access Control in Beckhoff Automation GmbH & Co. KG CX9020 with firmware version CX9020_CB3011_WEC7_HPS_v602_TC31_B4016.6 allows remote attackers to bypass authentication via the "CE Remote Display Tool" as it does not close the incoming connection on the Windows CE side if the credentials are incorrect.

    Published: 23 Jul 2021
    5.4
    Medium

    CVE-2021-25791

    Last Modified: 21 Nov 2024

    Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in the First Name, Last Name, and Address text fields.

    Published: 23 Jul 2021
    5.4
    Medium

    CVE-2021-25790

    Last Modified: 21 Nov 2024

    Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in all text fields except for Phone Number and Alternate Phone Number.

    Published: 23 Jul 2021