CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2021-23412

    Last Modified: 21 Nov 2024

    All versions of package gitlogplus are vulnerable to Command Injection via the main functionality, as options attributes are appended to the command to be executed without sanitization.

    Published: 23 Jul 2021
    5.4
    Medium

    CVE-2021-3159

    Last Modified: 21 Nov 2024

    A stored cross site scripting (XSS) vulnerability in the /sys/attachment/uploaderServlet component of Landray EKP V12.0.9.R.20160325 allows attackers to execute arbitrary web scripts or HTML via a crafted SVG, SHTML, or MHT file.

    Published: 23 Jul 2021
    7.5
    High

    CVE-2021-25201

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Learning Management System v 1.0 allows remote attackers to execute arbitrary SQL statements through the id parameter to obtain sensitive database information.

    Published: 23 Jul 2021
    5.4
    Medium

    CVE-2021-25204

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in SourceCodester E-Commerce Website v 1.0 allows remote attackers to inject arbitrary web script or HTM via the subject field to feedback_process.php.

    Published: 23 Jul 2021
    9.8
    Critical

    CVE-2021-25203

    Last Modified: 21 Nov 2024

    Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload to \CMSsite-master\admin\includes\admin_add_post.php.

    Published: 23 Jul 2021
    9.8
    Critical

    CVE-2021-25206

    Last Modified: 21 Nov 2024

    Arbitrary file upload vulnerability in SourceCodester Responsive Ordering System v 1.0 allows attackers to execute arbitrary code via the file upload to Product_model.php.

    Published: 23 Jul 2021
    9.8
    Critical

    CVE-2021-25208

    Last Modified: 21 Nov 2024

    Arbitrary file upload vulnerability in SourceCodester Travel Management System v 1.0 allows attackers to execute arbitrary code via the file upload to updatepackage.php.

    Published: 23 Jul 2021
    9.8
    Critical

    CVE-2021-25207

    Last Modified: 21 Nov 2024

    Arbitrary file upload vulnerability in SourceCodester E-Commerce Website v 1.0 allows attackers to execute arbitrary code via the file upload to prodViewUpdate.php.

    Published: 23 Jul 2021
    —
    Unknown

    CVE-2019-9983

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 23 Jul 2021
    6.1
    Medium

    CVE-2021-26799

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in admin/files/edit in Omeka Classic <=2.7 allows remote attackers to inject arbitrary web script or HTML.

    Published: 23 Jul 2021
    9.8
    Critical

    CVE-2020-14032

    Last Modified: 21 Nov 2024

    ASRock 4x4 BOX-R1000 before BIOS P1.40 allows privilege escalation via code execution in the SMM.

    Published: 23 Jul 2021
    9.8
    Critical

    CVE-2021-24036

    Last Modified: 21 Nov 2024

    Passing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds write on the heap with the possibility of remote code execution. This issue affects versions of folly prior to v2021.07.22.00. This issue affects HHVM versions prior to 4.80.5, all versions between 4.81.0 and 4.102.1, all versions between 4.103.0 and 4.113.0, and versions 4.114.0, 4.115.0, 4.116.0, 4.117.0, 4.118.0 and 4.118.1.

    Published: 23 Jul 2021
    5.9
    Medium

    CVE-2021-32686

    Last Modified: 4 Nov 2025

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In PJSIP before version 2.11.1, there are a couple of issues found in the SSL socket. First, a race condition between callback and destroy, due to the accepted socket having no group lock. Second, the SSL socket parent/listener may get destroyed during handshake. Both issues were reported to happen intermittently in heavy load TLS connections. They cause a crash, resulting in a denial of service. These are fixed in version 2.11.1.

    Published: 23 Jul 2021
    9.8
    Critical

    CVE-2021-3169

    Last Modified: 21 Nov 2024

    An issue in Jumpserver before 2.6.2, before 2.5.4, before 2.4.5 allows attackers to create a connection token through an API which does not have access control and use it to access sensitive assets.

    Published: 23 Jul 2021
    7.8
    High

    CVE-2021-37576

    Last Modified: 21 Nov 2024

    arch/powerpc/kvm/book3s_rtas.c in the Linux kernel through 5.13.5 on the powerpc platform allows KVM guest OS users to cause host OS memory corruption via rtas_args.nargs, aka CID-f62f3c20647e.

    Published: 23 Jul 2021
    4.6
    Medium

    CVE-2021-34268

    Last Modified: 21 Nov 2024

    An issue in the USBH_ParseDevDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial of service (DOS) via a malformed USB device packet.

    Published: 22 Jul 2021
    4.6
    Medium

    CVE-2021-34267

    Last Modified: 21 Nov 2024

    An in the USBH_MSC_InterfaceInit() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial of service (DOS) when the system tries to communicate with the connected endpoint.

    Published: 22 Jul 2021
    6.8
    Medium

    CVE-2021-34262

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in the USBH_ParseEPDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code.

    Published: 22 Jul 2021
    4.6
    Medium

    CVE-2021-34261

    Last Modified: 21 Nov 2024

    An issue in USBH_ParseCfgDesc() of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial of service due to the system hanging when trying to set a remote wake-up feature.

    Published: 22 Jul 2021
    6.8
    Medium

    CVE-2021-34260

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in the USBH_ParseInterfaceDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code.

    Published: 22 Jul 2021
    6.8
    Medium

    CVE-2021-34259

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in the USBH_ParseCfgDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code.

    Published: 22 Jul 2021
    7.5
    High

    CVE-2020-22284

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in the zepif_linkoutput() function of Free Software Foundation lwIP git head version and version 2.1.2 allows attackers to access sensitive information via a crafted 6LoWPAN packet.

    Published: 22 Jul 2021
    9.8
    Critical

    CVE-2021-25205

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in SourceCodester E-Commerce Website V 1.0 allows remote attackers to execute arbitrary SQL statements, via the update parameter to empViewUpdate.php .

    Published: 22 Jul 2021
    9.8
    Critical

    CVE-2021-25211

    Last Modified: 21 Nov 2024

    Arbitrary file upload vulnerability in SourceCodester Ordering System v 1.0 allows attackers to execute arbitrary code, via the file upload to ordering\admin\products\edit.php.

    Published: 22 Jul 2021
    3.5
    Low

    CVE-2021-3619

    Last Modified: 21 Nov 2024

    Rapid7 Velociraptor 0.5.9 and prior is vulnerable to a post-authentication persistent cross-site scripting (XSS) issue, where an authenticated user could abuse MIME filetype sniffing to embed executable code on a malicious upload. This issue was fixed in version 0.6.0. Note that login rights to Velociraptor is nearly always reserved for trusted and verified users with IT security backgrounds.

    Published: 22 Jul 2021
    9.8
    Critical

    CVE-2021-25213

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in SourceCodester Travel Management System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the catid parameter to subcat.php.

    Published: 22 Jul 2021
    9.8
    Critical

    CVE-2021-25209

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in SourceCodester Theme Park Ticketing System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to view_user.php .

    Published: 22 Jul 2021
    9.8
    Critical

    CVE-2021-25212

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in SourceCodester Alumni Management System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to manage_event.php.

    Published: 22 Jul 2021
    9.8
    Critical

    CVE-2021-25210

    Last Modified: 21 Nov 2024

    Arbitrary file upload vulnerability in SourceCodester Alumni Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to manage_event.php.

    Published: 22 Jul 2021
    6.1
    Medium

    CVE-2021-27332

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the class_name parameter to update_class.php.

    Published: 22 Jul 2021
    6.1
    Medium

    CVE-2021-26224

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in SourceCodester Fantastic-Blog-CMS V 1.0 allows remote attackers to inject arbitrary web script or HTML via the search field to search.php.

    Published: 22 Jul 2021
    9.8
    Critical

    CVE-2021-26223

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to view_pay.php.

    Published: 22 Jul 2021
    6.5
    Medium

    CVE-2021-3540

    Last Modified: 21 Nov 2024

    By abusing the 'install rpm info detail' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issue was fixed in version 11.1.0.0.

    Published: 22 Jul 2021
    6.5
    Medium

    CVE-2021-3198

    Last Modified: 21 Nov 2024

    By abusing the 'install rpm url' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issue was fixed in version 11.1.0.0.

    Published: 22 Jul 2021
    7.9
    High

    CVE-2021-31581

    Last Modified: 21 Nov 2024

    The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Configuration' command. This command launches a standard vi editor interface which can then be escaped. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2 (and later), and Akkadian Appliance Manager 3.3.0.314-4a349e0 (and later).

    Published: 22 Jul 2021
    8.7
    High

    CVE-2021-31580

    Last Modified: 21 Nov 2024

    The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be bypassed by switching the OpenSSH channel from `shell` to `exec` and providing the ssh client a single execution parameter. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2 (and later), and Akkadian Appliance Manager 3.3.0.314-4a349e0 (and later).

    Published: 22 Jul 2021
    8.2
    High

    CVE-2021-31579

    Last Modified: 21 Nov 2024

    Akkadian Provisioning Manager Engine (PME) ships with a hard-coded credential, akkadianuser:haakkadianpassword. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2 (and later), and Akkadian Appliance Manager 3.3.0.314-4a349e0 (and later).

    Published: 22 Jul 2021
    4.6
    Medium

    CVE-2020-7390

    Last Modified: 21 Nov 2024

    Sage X3 Stored XSS Vulnerability on ‘Edit’ Page of User Profile. An authenticated user can pass XSS strings the "First Name," "Last Name," and "Email Address" fields of this web application component. Updates are available for on-premises versions of Version 12 (components shipped with Syracuse 12.10.0 and later) of Sage X3. Other on-premises versions of Sage X3 are unaffected or unsupported by the vendor.

    Published: 22 Jul 2021
    5.5
    Medium

    CVE-2020-7389

    Last Modified: 21 Nov 2024

    Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configuration should not be deployed in production.

    Published: 22 Jul 2021
    10
    Critical

    CVE-2020-7388

    Last Modified: 21 Nov 2024

    Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By editing the client side authentication request, an attacker can bypass credential validation. While exploiting this does require knowledge of the installation path, that information can be learned by exploiting CVE-2020-7387. This issue was fixed in AdxAdmin 93.2.53, which ships with updates for on-premises versions of Sage X3 including Version 9 (components shipped with Syracuse 9.22.7.2 and later), Sage X3 HR & Payroll Version 9 (those components that ship with Syracuse 9.24.1.3), Version 11 (components shipped with Syracuse 11.25.2.6 and later), and Version 12 (components shipped with Syracuse 12.10.2.8 and later) of Sage X3. Other on-premises versions of Sage X3 are unsupported by the vendor.

    Published: 22 Jul 2021
    5.3
    Medium

    CVE-2020-7387

    Last Modified: 21 Nov 2024

    Sage X3 Installation Pathname Disclosure. A specially crafted packet can elicit a response from the AdxDSrv.exe component that reveals the installation directory of the product. Note that this vulnerability can be combined with CVE-2020-7388 to achieve full RCE. This issue was fixed in AdxAdmin 93.2.53, which ships with updates for on-premises versions of Sage X3 Version 9 (components shipped with Syracuse 9.22.7.2 and later), Sage X3 HR & Payroll Version 9 (those components that ship with Syracuse 9.24.1.3), Version 11 (components shipped with Syracuse 11.25.2.6 and later), and Version 12 (components shipped with Syracuse 12.10.2.8 and later) of Sage X3. Other on-premises versions of Sage X3 are unsupported by the vendor.

    Published: 22 Jul 2021
    —
    Unknown

    CVE-2018-11669

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 22 Jul 2021
    —
    Unknown

    CVE-2018-11668

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 22 Jul 2021
    —
    Unknown

    CVE-2018-11666

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 22 Jul 2021
    —
    Unknown

    CVE-2018-11665

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 22 Jul 2021
    —
    Unknown

    CVE-2018-11664

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 22 Jul 2021
    —
    Unknown

    CVE-2018-11663

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 22 Jul 2021
    —
    Unknown

    CVE-2018-11662

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 22 Jul 2021
    —
    Unknown

    CVE-2018-11661

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 22 Jul 2021
    —
    Unknown

    CVE-2018-11659

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 22 Jul 2021