CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2020-20230

    Last Modified: 21 Nov 2024

    Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the sshd process. An authenticated remote attacker can cause a Denial of Service due to overloading the systems CPU.

    Published: 19 Jul 2021
    4.7
    Medium

    CVE-2021-29780

    Last Modified: 21 Nov 2024

    IBM Resilient OnPrem v41.1 of IBM Security SOAR could allow an authenticated user to perform actions that they should not have access to due to improper input validation. IBM X-Force ID: 203085.

    Published: 19 Jul 2021
    7.8
    High

    CVE-2021-29707

    Last Modified: 21 Nov 2024

    IBM HMC (Hardware Management Console) V9.1.910.0 and V9.2.950.0 could allow a local user to escalate their privileges to root access on a restricted shell. IBM X-Force ID: 200879.

    Published: 19 Jul 2021
    5.4
    Medium

    CVE-2021-20507

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198235.

    Published: 19 Jul 2021
    5.4
    Medium

    CVE-2020-5031

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 193738.

    Published: 19 Jul 2021
    9.8
    Critical

    CVE-2021-20110

    Last Modified: 21 Nov 2024

    Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a NEWSCAN request to a listening agent on the network as well as receive the agent's HTTP request verifying its authtoken. In httphandler.cpp, the agent reaching out over HTTP is vulnerable to an Integer Overflow, which can be turned into a Heap Overflow allowing for remote code execution as NT AUTHORITY/SYSTEM on the agent machine. The Integer Overflow occurs when receiving POST response from the Manage Engine server, and the agent calling "HttpQueryInfoW" in order to get the "Content-Length" size from the incoming POST request. This size is taken, but multiplied to a larger amount. If an attacker specifies a Content-Length size of 1073741823 or larger, this integer arithmetic will wrap the value back around to smaller integer, then calls "calloc" with this size to allocate memory. The following API "InternetReadFile" will copy the POST data into this buffer, which will be too small for the contents, and cause heap overflow.

    Published: 19 Jul 2021
    7.5
    High

    CVE-2021-20108

    Last Modified: 21 Nov 2024

    Manage Engine Asset Explorer Agent 1.0.34 listens on port 9000 for incoming commands over HTTPS from Manage Engine Server. The HTTPS certificates are not verified which allows any arbitrary user on the network to send commands over port 9000. While these commands may not be executed (due to authtoken validation), the Asset Explorer agent will reach out to the manage engine server for an HTTP request. During this process, AEAgent.cpp allocates 0x66 bytes using "malloc". This memory is never free-ed in the program, causing a memory leak. Additionally, the instruction sent to aeagent (ie: NEWSCAN, DELTASCAN, etc) is converted to a unicode string, but is never freed. These memory leaks allow a remote attacker to exploit a Denial of Service scenario through repetitively sending these commands to an agent and eventually crashing it the agent due to an out-of-memory condition.

    Published: 19 Jul 2021
    7.5
    High

    CVE-2021-20109

    Last Modified: 21 Nov 2024

    Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a NEWSCAN request to a listening agent on the network as well as receive the agent's HTTP request verifying its authtoken. In AEAgent.cpp, the agent responding back over HTTP is vulnerable to a Heap Overflow if the POST payload response is too large. The POST payload response is converted to Unicode using vswprintf. This is written to a buffer only 0x2000 bytes big. If POST payload is larger, then heap overflow will occur.

    Published: 19 Jul 2021
    7.8
    High

    CVE-2021-35449

    Last Modified: 21 Nov 2024

    The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below, and G4 driver 4.2.1.0 and below are affected by a privilege escalation vulnerability. A standard low priviliged user can use the driver to execute a DLL of their choosing during the add printer process, resulting in escalation of privileges to SYSTEM.

    Published: 19 Jul 2021
    6.1
    Medium

    CVE-2021-34817

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting (XSS) issue in the chat component of Etherpad 1.8.13 allows remote attackers to inject arbitrary JavaScript or HTML by importing a crafted pad.

    Published: 19 Jul 2021
    5.5
    Medium

    CVE-2021-32014

    Last Modified: 21 Nov 2024

    SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (CPU consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js.

    Published: 19 Jul 2021
    5.5
    Medium

    CVE-2021-32013

    Last Modified: 21 Nov 2024

    SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 2 of 2).

    Published: 19 Jul 2021
    5.5
    Medium

    CVE-2021-32012

    Last Modified: 21 Nov 2024

    SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 1 of 2).

    Published: 19 Jul 2021
    8.1
    High

    CVE-2021-31216

    Last Modified: 21 Nov 2024

    Siren Investigate before 11.1.1 contains a server side request forgery (SSRF) defect in the built-in image proxy route (which is enabled by default). An attacker with access to the Investigate installation can specify an arbitrary URL in the parameters of the image proxy route and fetch external URLs as the Investigate process on the host.

    Published: 19 Jul 2021
    6.1
    Medium

    CVE-2021-3279

    Last Modified: 21 Nov 2024

    sz.chat version 4 allows injection of web scripts and HTML in the message box.

    Published: 19 Jul 2021
    4.3
    Medium

    CVE-2021-35968

    Last Modified: 21 Nov 2024

    The directory list page parameter of the Orca HCM digital learning platform fails to filter special characters properly. Remote attackers can access the system directory thru Path Traversal with users’ privileges.

    Published: 19 Jul 2021
    5.3
    Medium

    CVE-2021-35967

    Last Modified: 21 Nov 2024

    The directory page parameter of the Orca HCM digital learning platform does not filter special characters. Remote attackers can access the system directory thru Path Traversal without logging in.

    Published: 19 Jul 2021
    6.1
    Medium

    CVE-2021-35966

    Last Modified: 21 Nov 2024

    The specific function of the Orca HCM digital learning platform does not filter input parameters properly, which causing the URL can be redirected to any website. Remote attackers can use the vulnerability to execute phishing attacks.

    Published: 19 Jul 2021
    9.8
    Critical

    CVE-2021-35965

    Last Modified: 21 Nov 2024

    The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the source code of the webpage in plain text, thus remote attackers can obtain administrator’s privilege without logging in.

    Published: 19 Jul 2021
    7.3
    High

    CVE-2021-35964

    Last Modified: 21 Nov 2024

    The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remote attackers to execute the management function without logging in, access members’ information, modify and delete the courses in system, thus causing users fail to access the learning content.

    Published: 19 Jul 2021
    9.8
    Critical

    CVE-2021-35963

    Last Modified: 21 Nov 2024

    The specific parameter of upload function of the Orca HCM digital learning platform does not filter file format, which allows remote unauthenticated attackers to upload files containing malicious script to execute RCE attacks.

    Published: 19 Jul 2021
    9.8
    Critical

    CVE-2021-33027

    Last Modified: 21 Nov 2024

    Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce.

    Published: 19 Jul 2021
    9.6
    Critical

    CVE-2021-33501

    Last Modified: 21 Nov 2024

    Overwolf Client 0.169.0.22 allows XSS, with resultant Remote Code Execution, via an overwolfstore:// URL.

    Published: 19 Jul 2021
    4.8
    Medium

    CVE-2021-24482

    Last Modified: 21 Nov 2024

    The Related Posts for WordPress plugin through 2.0.4 does not sanitise its heading_text and CSS settings, allowing high privilege users (admin) to set XSS payloads in them, leading to Stored Cross-Site Scripting issues.

    Published: 19 Jul 2021
    8.8
    High

    CVE-2021-24453

    Last Modified: 21 Nov 2024

    The Include Me WordPress plugin through 1.2.1 is vulnerable to path traversal / local file inclusion, which can lead to Remote Code Execution (RCE) of the system due to log poisoning and therefore potentially a full compromise of the underlying structure

    Published: 19 Jul 2021
    6.1
    Medium

    CVE-2021-24452

    Last Modified: 21 Nov 2024

    The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the "extension" parameter in the Extensions dashboard, when the 'Anonymously track usage to improve product quality' setting is enabled, as the parameter is output in a JavaScript context without proper escaping. This could allow an attacker, who can convince an authenticated admin into clicking a link, to run malicious JavaScript within the user's web browser, which could lead to full site compromise.

    Published: 19 Jul 2021
    5.3
    Medium

    CVE-2021-24447

    Last Modified: 21 Nov 2024

    The WP Image Zoom WordPress plugin before 1.47 did not validate its tab parameter before using it in the include_once() function, leading to a local file inclusion issue in the admin dashboard

    Published: 19 Jul 2021
    6.1
    Medium

    CVE-2021-24436

    Last Modified: 21 Nov 2024

    The W3 Total Cache WordPress plugin before 2.1.4 was vulnerable to a reflected Cross-Site Scripting (XSS) security vulnerability within the "extension" parameter in the Extensions dashboard, which is output in an attribute without being escaped first. This could allow an attacker, who can convince an authenticated admin into clicking a link, to run malicious JavaScript within the user's web browser, which could lead to full site compromise.

    Published: 19 Jul 2021
    9.8
    Critical

    CVE-2021-33592

    Last Modified: 21 Nov 2024

    NAVER Toolbar before 4.0.30.323 allows remote attackers to execute arbitrary code via a crafted upgrade.xml file. Special characters in filename parameter can be the cause of bypassing code signing check function.

    Published: 19 Jul 2021
    5.3
    Medium

    CVE-2020-36421

    Last Modified: 3 Dec 2025

    An issue was discovered in Arm Mbed TLS before 2.23.0. Because of a side channel in modular exponentiation, an RSA private key used in a secure enclave could be disclosed.

    Published: 19 Jul 2021
    5.3
    Medium

    CVE-2020-36422

    Last Modified: 21 Nov 2024

    An issue was discovered in Arm Mbed TLS before 2.23.0. A side channel allows recovery of an ECC private key, related to mbedtls_ecp_check_pub_priv, mbedtls_pk_parse_key, mbedtls_pk_parse_keyfile, mbedtls_ecp_mul, and mbedtls_ecp_mul_restartable.

    Published: 19 Jul 2021
    7.5
    High

    CVE-2020-36423

    Last Modified: 21 Nov 2024

    An issue was discovered in Arm Mbed TLS before 2.23.0. A remote attacker can recover plaintext because a certain Lucky 13 countermeasure doesn't properly consider the case of a hardware accelerator.

    Published: 19 Jul 2021
    4.7
    Medium

    CVE-2020-36424

    Last Modified: 21 Nov 2024

    An issue was discovered in Arm Mbed TLS before 2.24.0. An attacker can recover a private key (for RSA or static Diffie-Hellman) via a side-channel attack against generation of base blinding/unblinding values.

    Published: 19 Jul 2021
    5.3
    Medium

    CVE-2020-36425

    Last Modified: 21 Nov 2024

    An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by changing the local clock.

    Published: 19 Jul 2021
    7.5
    High

    CVE-2020-36426

    Last Modified: 21 Nov 2024

    An issue was discovered in Arm Mbed TLS before 2.24.0. mbedtls_x509_crl_parse_der has a buffer over-read (of one byte).

    Published: 19 Jul 2021
    5
    Medium

    CVE-2021-32760

    Last Modified: 21 Nov 2024

    containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Changes to file permissions can deny access to the expected owner of the file, widen access to others, or set extended bits like setuid, setgid, and sticky. This bug does not directly allow files to be read, modified, or executed without an additional cooperating process. This bug has been fixed in containerd 1.5.4 and 1.4.8. As a workaround, ensure that users only pull images from trusted sources. Linux security modules (LSMs) like SELinux and AppArmor can limit the files potentially affected by this bug through policies and profiles that prevent containerd from interacting with specific files.

    Published: 19 Jul 2021
    6.1
    Medium

    CVE-2021-35043

    Last Modified: 21 Nov 2024

    OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with &#00058 as the replacement for the : character.

    Published: 19 Jul 2021
    8.5
    High

    CVE-2021-3682

    Last Modified: 21 Nov 2024

    A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping packets during a bulk transfer from a SPICE client due to the packet queue being full. A malicious SPICE client could use this flaw to make QEMU call free() with faked heap chunk metadata, resulting in a crash of QEMU or potential code execution with the privileges of the QEMU process on the host.

    Published: 19 Jul 2021
    7.5
    High

    CVE-2021-36773

    Last Modified: 21 Nov 2024

    uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking, which allows crafted web sites to cause a denial of service (unbounded recursion that can trigger memory consumption and a loss of all blocking functionality).

    Published: 18 Jul 2021
    7
    High

    CVE-2021-3640

    Last Modified: 21 Nov 2024

    A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIO_REGISTER or other way triggers race condition of the call sco_conn_del() together with the call sco_sock_sendmsg() with the expected controllable faulting memory page. A privileged local user could use this flaw to crash the system or escalate their privileges on the system.

    Published: 18 Jul 2021
    9.8
    Critical

    CVE-2021-33911

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADManager Plus before 7110 allows remote code execution.

    Published: 17 Jul 2021
    6.1
    Medium

    CVE-2021-36771

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADManager Plus before 7110 allows reflected XSS.

    Published: 17 Jul 2021
    6.1
    Medium

    CVE-2021-36772

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADManager Plus before 7110 allows stored XSS.

    Published: 17 Jul 2021
    7.5
    High

    CVE-2021-36213

    Last Modified: 21 Nov 2024

    HashiCorp Consul and Consul Enterprise 1.9.0 through 1.10.0 default deny policy with a single L7 application-aware intention deny action cancels out, causing the intention to incorrectly fail open, allowing L4 traffic. Fixed in 1.9.8 and 1.10.1.

    Published: 17 Jul 2021
    7.5
    High

    CVE-2021-32574

    Last Modified: 21 Nov 2024

    HashiCorp Consul and Consul Enterprise 1.3.0 through 1.10.0 Envoy proxy TLS configuration does not validate destination service identity in the encoded subject alternative name. Fixed in 1.8.14, 1.9.8, and 1.10.1.

    Published: 17 Jul 2021
    5.3
    Medium

    CVE-2021-36769

    Last Modified: 21 Nov 2024

    A reordering issue exists in Telegram before 7.8.1 for Android, Telegram before 7.8.3 for iOS, and Telegram Desktop before 2.8.8. An attacker can cause the server to receive messages in a different order than they were sent a client.

    Published: 16 Jul 2021
    8.2
    High

    CVE-2019-3752

    Last Modified: 21 Nov 2024

    Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2 and 19.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1, 2.2, 2.3 and 2.4. contain an XML External Entity(XXE) Injection vulnerability. A remote unauthenticated malicious user could potentially exploit this vulnerability to cause Denial of Service or information exposure by supplying specially crafted document type definitions (DTDs) in an XML request.

    Published: 16 Jul 2021
    6.4
    Medium

    CVE-2021-3614

    Last Modified: 21 Nov 2024

    A vulnerability was reported on some Lenovo Notebook systems that could allow an attacker with physical access to elevate privileges under certain conditions during a BIOS update performed by Lenovo Vantage.

    Published: 16 Jul 2021
    7.8
    High

    CVE-2021-3550

    Last Modified: 21 Nov 2024

    A DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.500.5102, that could allow privilege escalation.

    Published: 16 Jul 2021
    6.8
    Medium

    CVE-2021-3453

    Last Modified: 16 Dec 2025

    Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage.

    Published: 16 Jul 2021