CVE Feed

    Dashboard / CVE

    5.7
    Medium

    CVE-2021-21589

    Last Modified: 21 Nov 2024

    Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 do not exit on failed Initialization. A local authenticated Service user could potentially exploit this vulnerability to escalate privileges.

    Published: 12 Jul 2021
    6.5
    Medium

    CVE-2021-21588

    Last Modified: 21 Nov 2024

    Dell EMC PowerFlex, v3.5.x contain a Cross-Site WebSocket Hijacking Vulnerability in the Presentation Server/WebUI. An unauthenticated attacker could potentially exploit this vulnerability by tricking the user into performing unwanted actions on the Presentation Server and perform which may lead to configuration changes.

    Published: 12 Jul 2021
    5.4
    Medium

    CVE-2020-19203

    Last Modified: 21 Nov 2024

    An authenticated Cross-Site Scripting (XSS) vulnerability was found in widgets/widgets/wake_on_lan_widget.php, a component of the pfSense software WebGUI, on version 2.4.4-p2 and earlier. The widget did not encode the descr (description) parameter of wake-on-LAN entries in its output, leading to a possible stored XSS.

    Published: 12 Jul 2021
    5.3
    Medium

    CVE-2021-32705

    Last Modified: 21 Nov 2024

    Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the public DAV endpoint. This may have allowed an attacker to enumerate potentially valid share tokens or credentials. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.

    Published: 12 Jul 2021
    5.3
    Medium

    CVE-2021-32703

    Last Modified: 21 Nov 2024

    Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the shareinfo endpoint. This may have allowed an attacker to enumerate potentially valid share tokens. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.

    Published: 12 Jul 2021
    5.4
    Medium

    CVE-2020-19204

    Last Modified: 21 Nov 2024

    An authenticated Stored Cross-Site Scriptiong (XSS) vulnerability exists in Lightning Wire Labs IPFire 2.21 (x86_64) - Core Update 130 in the "routing.cgi" Routing Table Entries via the "Remark" text box or "remark" parameter. It allows an authenticated WebGUI user to execute Stored Cross-site Scripting in the Routing Table Entries.

    Published: 12 Jul 2021
    9.8
    Critical

    CVE-2021-23389

    Last Modified: 21 Nov 2024

    The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.

    Published: 12 Jul 2021
    9.8
    Critical

    CVE-2021-23390

    Last Modified: 21 Nov 2024

    The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.

    Published: 12 Jul 2021
    9.8
    Critical

    CVE-2020-18980

    Last Modified: 21 Nov 2024

    Remote Code Executon vulnerability in Halo 0.4.3 via the remoteAddr and themeName parameters.

    Published: 12 Jul 2021
    7.5
    High

    CVE-2021-33807

    Last Modified: 21 Nov 2024

    Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData.

    Published: 12 Jul 2021
    6.1
    Medium

    CVE-2020-18979

    Last Modified: 21 Nov 2024

    Cross Siste Scripting (XSS) vulnerablity in Halo 0.4.3 via the X-forwarded-for Header parameter.

    Published: 12 Jul 2021
    8.8
    High

    CVE-2021-32688

    Last Modified: 21 Nov 2024

    Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens for authentication purposes. These tokens are supposed to be granted to a specific applications (e.g. DAV sync clients), and can also be configured by the user to not have any filesystem access. Due to a lacking permission check, the tokens were able to change their own permissions in versions prior to 19.0.13, 20.0.11, and 21.0.3. Thus fileystem limited tokens were able to grant themselves access to the filesystem. The issue is patched in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds aside from upgrading.

    Published: 12 Jul 2021
    7.8
    High

    CVE-2020-7872

    Last Modified: 21 Nov 2024

    DaviewIndy v8.98.7.0 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malformed format file that is mishandled by DaviewIndy. Attackers could exploit this and arbitrary code execution.

    Published: 12 Jul 2021
    8.8
    High

    CVE-2021-24013

    Last Modified: 21 Nov 2024

    Multiple Path traversal vulnerabilities in the Webmail of FortiMail before 6.4.4 may allow a regular user to obtain unauthorized access to files and data via specifically crafted web requests.

    Published: 12 Jul 2021
    7.2
    High

    CVE-2021-24015

    Last Modified: 21 Nov 2024

    An improper neutralization of special elements used in an OS Command vulnerability in the administrative interface of FortiMail before 6.4.4 may allow an authenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.

    Published: 12 Jul 2021
    3.3
    Low

    CVE-2021-32680

    Last Modified: 21 Nov 2024

    Nextcloud Server is a Nextcloud package that handles data storage. In versions priot to 19.0.13, 20.0.11, and 21.0.3, Nextcloud Server audit logging functionality wasn't properly logging events for the unsetting of a share expiration date. This event is supposed to be logged. This issue is patched in versions 19.0.13, 20.0.11, and 21.0.3.

    Published: 12 Jul 2021
    7.1
    High

    CVE-2021-26088

    Last Modified: 21 Nov 2024

    An improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user to bypass a FSSO firewall policy and access the protected network via sending specifically crafted UDP login notification packets.

    Published: 12 Jul 2021
    4.3
    Medium

    CVE-2021-36383

    Last Modified: 21 Nov 2024

    Xen Orchestra (with xo-web through 5.80.0 and xo-server through 5.84.0) mishandles authorization, as demonstrated by modified WebSocket resourceSet.getAll data is which the attacker changes the permission field from none to admin. The attacker gains access to data sets such as VMs, Backups, Audit, Users, and Groups.

    Published: 12 Jul 2021
    2.6
    Low

    CVE-2021-36382

    Last Modified: 21 Nov 2024

    Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-the-middle attack against the connections/partial endpoint (which accepts cleartext).

    Published: 12 Jul 2021
    5.3
    Medium

    CVE-2021-26090

    Last Modified: 21 Nov 2024

    A missing release of memory after its effective lifetime vulnerability in the Webmail of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6 may allow an unauthenticated remote attacker to exhaust available memory via specifically crafted login requests.

    Published: 12 Jul 2021
    3.5
    Low

    CVE-2021-32679

    Last Modified: 21 Nov 2024

    Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, filenames where not escaped by default in controllers using `DownloadResponse`. When a user-supplied filename was passed unsanitized into a `DownloadResponse`, this could be used to trick users into downloading malicious files with a benign file extension. This would show in UI behaviours where Nextcloud applications would display a benign file extension (e.g. JPEG), but the file will actually be downloaded with an executable file extension. The vulnerability is patched in versions 19.0.13, 20.0.11, and 21.0.3. Administrators of Nextcloud instances do not have a workaround available, but developers of Nextcloud apps may manually escape the file name before passing it into `DownloadResponse`.

    Published: 12 Jul 2021
    6.7
    Medium

    CVE-2021-26089

    Last Modified: 21 Nov 2024

    An improper symlink following in FortiClient for Mac 6.4.3 and below may allow an non-privileged user to execute arbitrary privileged shell commands during installation phase.

    Published: 12 Jul 2021
    9.8
    Critical

    CVE-2020-21133

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in Metinfo 7.0.0 beta in member/getpassword.php?lang=cn&a=dovalid.

    Published: 12 Jul 2021
    9.8
    Critical

    CVE-2020-21132

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in Metinfo 7.0.0beta in index.php.

    Published: 12 Jul 2021
    7.2
    High

    CVE-2020-21131

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in MetInfo 7.0.0beta via admin/?n=language&c=language_web&a=doAddLanguage.

    Published: 12 Jul 2021
    3.7
    Low

    CVE-2021-32678

    Last Modified: 21 Nov 2024

    Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, ratelimits are not applied to OCS API responses. This affects any OCS API controller (`OCSController`) using the `@BruteForceProtection` annotation. Risk depends on the installed applications on the Nextcloud Server, but could range from bypassing authentication ratelimits or spamming other Nextcloud users. The vulnerability is patched in versions 19.0.13, 20.0.11, and 21.0.3. No workarounds aside from upgrading are known to exist.

    Published: 12 Jul 2021
    7.5
    High

    CVE-2021-36377

    Last Modified: 21 Nov 2024

    Fossil before 2.14.2 and 2.15.x before 2.15.2 often skips the hostname check during TLS certificate validation.

    Published: 12 Jul 2021
    9.8
    Critical

    CVE-2021-35064

    Last Modified: 21 Nov 2024

    KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits running of multiple dangerous commands, including unzip, systemctl and dpkg.

    Published: 12 Jul 2021
    6.1
    Medium

    CVE-2021-35037

    Last Modified: 21 Nov 2024

    Jamf Pro before 10.30.1 allows for an unvalidated URL redirect vulnerability affecting Jamf Pro customers who host their environments on-premises. An attacker may craft a URL that appears to be for a customer's Jamf Pro instance, but when clicked will forward a user to an arbitrary URL that may be malicious. This is tracked via Jamf with the following ID: PI-009822

    Published: 12 Jul 2021
    7.5
    High

    CVE-2021-27293

    Last Modified: 21 Nov 2024

    RestSharp < 106.11.8-alpha.0.13 uses a regular expression which is vulnerable to Regular Expression Denial of Service (ReDoS) when converting strings into DateTimes. If a server responds with a malicious string, the client using RestSharp will be stuck processing it for an exceedingly long time. Thus the remote server can trigger Denial of Service.

    Published: 12 Jul 2021
    7.4
    High

    CVE-2021-3547

    Last Modified: 21 Nov 2024

    OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name option in a client configuration.

    Published: 12 Jul 2021
    6.5
    Medium

    CVE-2021-22917

    Last Modified: 21 Nov 2024

    Brave Browser Desktop between versions 1.17 and 1.20 is vulnerable to information disclosure by way of DNS requests in Tor windows not flowing through Tor if adblocking was enabled.

    Published: 12 Jul 2021
    5.9
    Medium

    CVE-2021-22916

    Last Modified: 21 Nov 2024

    In Brave Desktop between versions 1.17 and 1.26.60, when adblocking is enabled and a proxy browser extension is installed, the CNAME adblocking feature issues DNS requests that used the system DNS settings instead of the extension's proxy settings, resulting in possible information disclosure.

    Published: 12 Jul 2021
    7.8
    High

    CVE-2021-22921

    Last Modified: 30 Apr 2025

    Node.js before 16.4.1, 14.17.2, and 12.22.2 is vulnerable to local privilege escalation attacks under certain conditions on Windows platforms. More specifically, improper configuration of permissions in the installation directory allows an attacker to perform two different escalation attacks: PATH and DLL hijacking.

    Published: 12 Jul 2021
    4.8
    Medium

    CVE-2021-22515

    Last Modified: 21 Nov 2024

    Multi-Factor Authentication (MFA) functionality can be bypassed, allowing the use of single factor authentication in NetIQ Advanced Authentication versions prior to 6.3 SP4 Patch 1.

    Published: 12 Jul 2021
    4.4
    Medium

    CVE-2021-26099

    Last Modified: 21 Nov 2024

    Missing cryptographic steps in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an attacker who comes in possession of the encrypted master keys to compromise their confidentiality by observing a few invariant properties of the ciphertext.

    Published: 12 Jul 2021
    5.3
    Medium

    CVE-2021-33037

    Last Modified: 25 Aug 2026

    Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.

    Published: 12 Jul 2021
    —
    Unknown

    CVE-2021-36593

    Last Modified: 2 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 12 Jul 2021
    —
    Unknown

    CVE-2021-36594

    Last Modified: 2 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 12 Jul 2021
    7.5
    High

    CVE-2021-30639

    Last Modified: 21 Nov 2024

    A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part of a change to improve error handling during non-blocking I/O meant that the error flag associated with the Request object was not reset between requests. This meant that once a non-blocking I/O error occurred, all future requests handled by that request object would fail. Users were able to trigger non-blocking I/O errors, e.g. by dropping a connection, thereby creating the possibility of triggering a DoS. Applications that do not use non-blocking I/O are not exposed to this vulnerability. This issue affects Apache Tomcat 10.0.3 to 10.0.4; 9.0.44; 8.5.64.

    Published: 12 Jul 2021
    6.5
    Medium

    CVE-2021-30640

    Last Modified: 21 Nov 2024

    A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.

    Published: 12 Jul 2021
    7.5
    High

    CVE-2021-36222

    Last Modified: 21 Nov 2024

    ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. This occurs because a return value is not properly managed in a certain situation.

    Published: 12 Jul 2021
    6.5
    Medium

    CVE-2021-30129

    Last Modified: 21 Nov 2024

    A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0

    Published: 12 Jul 2021
    6.1
    Medium

    CVE-2021-29104

    Last Modified: 10 Apr 2025

    A stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote unauthenticated attacker to pass and store malicious strings in the ArcGIS Server Manager application.

    Published: 11 Jul 2021
    9.1
    Critical

    CVE-2021-29102

    Last Modified: 10 Apr 2025

    A Server-Side Request Forgery (SSRF) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote, unauthenticated attacker to forge GET requests to arbitrary URLs from the system, potentially leading to network enumeration or facilitating other attacks.

    Published: 11 Jul 2021
    6.1
    Medium

    CVE-2021-29103

    Last Modified: 10 Apr 2025

    A reflected Cross Site Scripting (XXS) vulnerability in ArcGIS Server version 10.8.1 and below may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the user’s browser.

    Published: 11 Jul 2021
    5.4
    Medium

    CVE-2021-29105

    Last Modified: 10 Apr 2025

    A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server Services Directory version 10.8.1 and below may allow a remote authenticated attacker to pass and store malicious strings in the ArcGIS Services Directory.

    Published: 11 Jul 2021
    6.1
    Medium

    CVE-2021-29106

    Last Modified: 10 Apr 2025

    A reflected Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server version 10.8.1 and below may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the user’s browser.

    Published: 10 Jul 2021
    6.1
    Medium

    CVE-2021-29107

    Last Modified: 10 Apr 2025

    A stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote unauthenticated attacker to pass and store malicious strings in the ArcGIS Server Manager application.

    Published: 10 Jul 2021
    5.4
    Medium

    CVE-2020-25391

    Last Modified: 21 Nov 2024

    A cross site scripting vulnerability in CSZ CMS 1.2.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'New Pages' field under the 'Pages Content' module.

    Published: 9 Jul 2021