CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2021-36373

    Last Modified: 25 Aug 2026

    When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.

    Published: 13 Jul 2021
    6.5
    Medium

    CVE-2021-36740

    Last Modified: 21 Nov 2024

    Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x and 6.x before 6.5.2, 6.6.x before 6.6.1, and 6.0 LTS before 6.0.8.

    Published: 13 Jul 2021
    5.5
    Medium

    CVE-2022-1122

    Last Modified: 3 Nov 2025

    A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a segmentation fault and a denial of service.

    Published: 13 Jul 2021
    5.3
    Medium

    CVE-2021-32754

    Last Modified: 21 Nov 2024

    FlowDroid is a data flow analysis tool. FlowDroid versions prior to 2.9.0 contained an XML external entity (XXE) vulnerability that allowed an attacker who had control over the source/sink definition file in XML format to read files from external locations. In order for this to occur, the XML-based format for sources and sinks had to be used and the attacker had to able control the source/sink definition file. The vulnerability was patched in version 2.9.0. As a workaround, do not allow untrusted entities to control the source/sink definition file.

    Published: 12 Jul 2021
    5.3
    Medium

    CVE-2021-32747

    Last Modified: 21 Nov 2024

    Icinga Web 2 is an open source monitoring web interface, framework, and command-line interface. A vulnerability in which custom variables are exposed to unauthorized users exists between versions 2.0.0 and 2.8.2. Custom variables are user-defined keys and values on configuration objects in Icinga 2. These are commonly used to reference secrets in other configurations such as check commands to be able to authenticate with a service being checked. Icinga Web 2 displays these custom variables to logged in users with access to said hosts or services. In order to protect the secrets from being visible to anyone, it's possible to setup protection rules and blacklists in a user's role. Protection rules result in `***` being shown instead of the original value, the key will remain. Backlists will hide a custom variable entirely from the user. Besides using the UI, custom variables can also be accessed differently by using an undocumented URL parameter. By adding a parameter to the affected routes, Icinga Web 2 will show these columns additionally in the respective list. This parameter is also respected when exporting to JSON or CSV. Protection rules and blacklists however have no effect in this case. Custom variables are shown as-is in the result. The issue has been fixed in the 2.9.0, 2.8.3, and 2.7.5 releases. As a workaround, one may set up a restriction to hide hosts and services with the custom variable in question.

    Published: 12 Jul 2021
    5.3
    Medium

    CVE-2021-32746

    Last Modified: 21 Nov 2024

    Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Between versions 2.3.0 and 2.8.2, the `doc` module of Icinga Web 2 allows to view documentation directly in the UI. It must be enabled manually by an administrator and users need explicit access permission to use it. Then, by visiting a certain route, it is possible to gain access to arbitrary files readable by the web-server user. The issue has been fixed in the 2.9.0, 2.8.3, and 2.7.5 releases. As a workaround, an administrator may disable the `doc` module or revoke permission to use it from all users.

    Published: 12 Jul 2021
    5.3
    Medium

    CVE-2021-32741

    Last Modified: 21 Nov 2024

    Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the public share link mount endpoint. This may have allowed an attacker to enumerate potentially valid share tokens. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.

    Published: 12 Jul 2021
    3.1
    Low

    CVE-2021-32734

    Last Modified: 21 Nov 2024

    Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, the Nextcloud Text application shipped with Nextcloud Server returned verbatim exception messages to the user. This could result in a full path disclosure on shared files. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. As a workaround, one may disable the Nextcloud Text application in Nextcloud Server app settings.

    Published: 12 Jul 2021
    4.8
    Medium

    CVE-2021-32733

    Last Modified: 21 Nov 2024

    Nextcloud Text is a collaborative document editing application that uses Markdown. A cross-site scripting vulnerability is present in versions prior to 19.0.13, 20.0.11, and 21.0.3. The Nextcloud Text application shipped with Nextcloud server used a `text/html` Content-Type when serving files to users. Due the strict Content-Security-Policy shipped with Nextcloud, this issue is not exploitable on modern browsers supporting Content-Security-Policy. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. As a workaround, use a browser that has support for Content-Security-Policy.

    Published: 12 Jul 2021
    5.7
    Medium

    CVE-2021-32727

    Last Modified: 21 Nov 2024

    Nextcloud Android Client is the Android client for Nextcloud. Clients using the Nextcloud end-to-end encryption feature download the public and private key via an API endpoint. In versions prior to 3.16.1, the Nextcloud Android client skipped a step that involved the client checking if a private key belonged to a previously downloaded public certificate. If the Nextcloud instance served a malicious public key, the data would be encrypted for this key and thus could be accessible to a malicious actor. The vulnerability is patched in version 3.16.1. As a workaround, do not add additional end-to-end encrypted devices to a user account.

    Published: 12 Jul 2021
    7.1
    High

    CVE-2021-32726

    Last Modified: 21 Nov 2024

    Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, webauthn tokens were not deleted after a user has been deleted. If a victim reused an earlier used username, the previous user could gain access to their account. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.

    Published: 12 Jul 2021
    9.8
    Critical

    CVE-2020-18544

    Last Modified: 21 Nov 2024

    SQL Injection in WMS v1.0 allows remote attackers to execute arbitrary code via the "username" parameter in the component "chkuser.php".

    Published: 12 Jul 2021
    3.5
    Low

    CVE-2021-32725

    Last Modified: 21 Nov 2024

    Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, default share permissions were not being respected for federated reshares of files and folders. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.

    Published: 12 Jul 2021
    6.1
    Medium

    CVE-2021-24454

    Last Modified: 21 Nov 2024

    In the YOP Poll WordPress plugin before 6.2.8, when a pool is created with the options "Allow other answers", "Display other answers in the result list" and "Show results", it can lead to Stored Cross-Site Scripting issues as the 'Other' answer is not sanitised before being output in the page. The execution of the XSS payload depends on the 'Show results' option selected, which could be before or after sending the vote for example.

    Published: 12 Jul 2021
    9.8
    Critical

    CVE-2021-24442

    Last Modified: 21 Nov 2024

    The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to perform SQL Injection attacks

    Published: 12 Jul 2021
    8
    High

    CVE-2021-24441

    Last Modified: 21 Nov 2024

    The Sign-up Sheets WordPress plugin before 1.0.14 does not not sanitise or validate the Sheet title when generating the CSV to export, which could lead to a CSV injection issue

    Published: 12 Jul 2021
    4.8
    Medium

    CVE-2021-24440

    Last Modified: 21 Nov 2024

    The Sign-up Sheets WordPress plugin before 1.0.14 did not sanitise or escape some of its fields when creating a new sheet, allowing high privilege users to add JavaScript in them, leading to a Stored Cross-Site Scripting issue. The payloads will be triggered when viewing the 'All Sheets' page in the admin dashboard

    Published: 12 Jul 2021
    5.4
    Medium

    CVE-2021-24439

    Last Modified: 21 Nov 2024

    The Browser Screenshots WordPress plugin before 1.7.6 allowed authenticated users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks as the image_class parameter of the browser-shot shortcode was not escaped.

    Published: 12 Jul 2021
    6.1
    Medium

    CVE-2021-24434

    Last Modified: 21 Nov 2024

    The Glass WordPress plugin through 1.3.2 does not sanitise or escape its "Glass Pages" setting before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin did not have CSRF check in place when saving its settings, allowing the issue to be exploited via a CSRF attack.

    Published: 12 Jul 2021
    6.1
    Medium

    CVE-2021-24429

    Last Modified: 21 Nov 2024

    The Salon booking system WordPress plugin before 6.3.1 does not properly sanitise and escape the First Name field when booking an appointment, allowing low privilege users such as subscriber to set JavaScript in them, leading to a Stored Cross-Site Scripting (XSS) vulnerability. The Payload will then be triggered when an admin visits the "Calendar" page and the malicious script is executed in the admin context.

    Published: 12 Jul 2021
    4.8
    Medium

    CVE-2021-24426

    Last Modified: 21 Nov 2024

    The Backup by 10Web – Backup and Restore Plugin WordPress plugin through 1.0.20 does not sanitise or escape the tab parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting issue

    Published: 12 Jul 2021
    4.8
    Medium

    CVE-2021-24427

    Last Modified: 21 Nov 2024

    The W3 Total Cache WordPress plugin before 2.1.3 did not sanitise or escape some of its CDN settings, allowing high privilege users to use JavaScript in them, which will be output in the page, leading to an authenticated Stored Cross-Site Scripting issue

    Published: 12 Jul 2021
    5.4
    Medium

    CVE-2021-24424

    Last Modified: 21 Nov 2024

    The WP Reset – Most Advanced WordPress Reset Tool WordPress plugin before 1.90 did not sanitise or escape its extra_data parameter when creating a snapshot via the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue

    Published: 12 Jul 2021
    5.4
    Medium

    CVE-2021-24421

    Last Modified: 21 Nov 2024

    The WP JobSearch WordPress plugin before 1.7.4 did not sanitise or escape multiple of its parameters from the my-resume page before outputting them in the page, allowing low privilege users to use JavaScript payloads in them and leading to a Stored Cross-Site Scripting issue

    Published: 12 Jul 2021
    5.4
    Medium

    CVE-2021-24420

    Last Modified: 21 Nov 2024

    The Request a Quote WordPress plugin before 2.3.4 did not sanitise and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting issues when the quote is output in the 'All Quotes" table.

    Published: 12 Jul 2021
    4.8
    Medium

    CVE-2021-24419

    Last Modified: 21 Nov 2024

    The WP YouTube Lyte WordPress plugin before 1.7.16 did not sanitise or escape its lyte_yt_api_key and lyte_notification settings before outputting them back in the page, allowing high privilege users to set XSS payload on them and leading to stored Cross-Site Scripting issues.

    Published: 12 Jul 2021
    4.8
    Medium

    CVE-2021-24418

    Last Modified: 21 Nov 2024

    The Smooth Scroll Page Up/Down Buttons WordPress plugin through 1.4 does not properly sanitise and validate its psb_positioning settings, allowing high privilege users such as admin to set an XSS payload in it, which will be executed in all pages of the blog

    Published: 12 Jul 2021
    6.1
    Medium

    CVE-2021-24409

    Last Modified: 21 Nov 2024

    The Prismatic WordPress plugin before 2.8 does not escape the 'tab' GET parameter before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator

    Published: 12 Jul 2021
    5.4
    Medium

    CVE-2021-24408

    Last Modified: 21 Nov 2024

    The Prismatic WordPress plugin before 2.8 does not sanitise or validate some of its shortcode parameters, allowing users with a role as low as Contributor to set Cross-Site payload in them. A post made by a contributor would still have to be approved by an admin to have the XSS trigger able in the frontend, however, higher privilege users, such as editor could exploit this without the need of approval, and even when the blog disallows the unfiltered_html capability.

    Published: 12 Jul 2021
    9.8
    Critical

    CVE-2021-24385

    Last Modified: 21 Nov 2024

    The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user input data from a HTTP post request. This is a major vulnerability as the user input is not escaped and passed directly to the get_col function and it allows SQL injection. The Rest API endpoint which invokes this function also does not have any required permissions/authentication and can be accessed by an anonymous user.

    Published: 12 Jul 2021
    5.4
    Medium

    CVE-2021-24365

    Last Modified: 21 Nov 2024

    The Admin Columns WordPress plugin Free before 4.3.2 and Pro before 5.5.2 allowed to configure individual columns for tables. Each column had a type. The type "Custom Field" allowed to choose an arbitrary database column to display in the table. There was no escaping applied to the contents of "Custom Field" columns.

    Published: 12 Jul 2021
    8.8
    High

    CVE-2020-19907

    Last Modified: 21 Nov 2024

    A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command or service.

    Published: 12 Jul 2021
    4.3
    Medium

    CVE-2021-32707

    Last Modified: 21 Nov 2024

    Nextcloud Mail is a mail app for Nextcloud. In versions prior to 1.9.6, the Nextcloud Mail application does not, by default, render images in emails to not leak the read state. The privacy filter failed to filter images with a `background-image` CSS attribute. Note that the images were still passed through the Nextcloud image proxy, and thus there was no IP leakage. The issue was patched in version 1.9.6 and 1.10.0. No workarounds are known to exist.

    Published: 12 Jul 2021
    8.1
    High

    CVE-2021-32689

    Last Modified: 21 Nov 2024

    Nextcloud Talk is a fully on-premises audio/video and chat communication service. In versions prior to 11.2.2, if a user was able to reuse an earlier used username, they could get access to any chat message sent to the previous user with this username. The issue was patched in versions 11.2.2 and 11.3.0. As a workaround, don't allow users to choose usernames themselves. This is the default behaviour of Nextcloud, but some user providers may allow doing so.

    Published: 12 Jul 2021
    9.1
    Critical

    CVE-2020-19038

    Last Modified: 21 Nov 2024

    File Deletion vulnerability in Halo 0.4.3 via delBackup.

    Published: 12 Jul 2021
    5.3
    Medium

    CVE-2020-19037

    Last Modified: 21 Nov 2024

    Incorrect Access Control vulnearbility in Halo 0.4.3, which allows a malicious user to bypass encrption to view encrpted articles via cookies.

    Published: 12 Jul 2021
    7.5
    High

    CVE-2020-23079

    Last Modified: 21 Nov 2024

    SSRF vulnerability in Halo <=1.3.2 exists in the SMTP configuration, which can detect the server intranet.

    Published: 12 Jul 2021
    5.4
    Medium

    CVE-2020-18982

    Last Modified: 21 Nov 2024

    Cross Sie Scripting (XSS) vulnerability in Halo 0.4.3 via CommentAuthorUrl.

    Published: 12 Jul 2021
    5.4
    Medium

    CVE-2021-29822

    Last Modified: 21 Nov 2024

    IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204349.

    Published: 12 Jul 2021
    5.4
    Medium

    CVE-2021-29805

    Last Modified: 21 Nov 2024

    IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204263.

    Published: 12 Jul 2021
    5.4
    Medium

    CVE-2021-29804

    Last Modified: 21 Nov 2024

    IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204262.

    Published: 12 Jul 2021
    5.4
    Medium

    CVE-2021-29803

    Last Modified: 21 Nov 2024

    IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204164.

    Published: 12 Jul 2021
    7.5
    High

    CVE-2021-29794

    Last Modified: 21 Nov 2024

    IBM Tivoli Netcool/Impact 7.1.0.20 and 7.1.0.21 uses an insecure SSH server configuration which enables weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 203556.

    Published: 12 Jul 2021
    7.2
    High

    CVE-2021-29792

    Last Modified: 21 Nov 2024

    IBM Event Streams 10.0, 10.1, 10.2, and 10.3 could allow a user the CA private key to create their own certificates and deploy them in the cluster and gain privileges of another user. IBM X-Force ID: 203450.

    Published: 12 Jul 2021
    4.9
    Medium

    CVE-2021-20414

    Last Modified: 21 Nov 2024

    IBM Guardium Data Encryption (GDE) 3.0.0.2 could allow a user to bruce force sensitive information due to not properly limiting the number of interactions. IBM X-Force ID: 196216.

    Published: 12 Jul 2021
    8.8
    High

    CVE-2020-4938

    Last Modified: 21 Nov 2024

    IBM MQ Appliance 9.1 and 9.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 191815.

    Published: 12 Jul 2021
    5.4
    Medium

    CVE-2020-19201

    Last Modified: 21 Nov 2024

    A Stored Cross-Site Scripting (XSS) vulnerability was found in status_filter_reload.php, a page in the pfSense software WebGUI, on Netgate pfSense version 2.4.4-p2 and earlier. The page did not encode output from the filter reload process, and a stored XSS was possible via the descr (description) parameter on NAT rules.

    Published: 12 Jul 2021
    5.3
    Medium

    CVE-2021-36381

    Last Modified: 21 Nov 2024

    In Edifecs Transaction Management through 2021-07-12, an unauthenticated user can inject arbitrary text into a user's browser via logon.jsp?logon_error= on the login screen of the Web application.

    Published: 12 Jul 2021
    6.4
    Medium

    CVE-2021-21591

    Last Modified: 21 Nov 2024

    Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user.

    Published: 12 Jul 2021
    6.4
    Medium

    CVE-2021-21590

    Last Modified: 21 Nov 2024

    Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user.

    Published: 12 Jul 2021