CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2021-32639

    Last Modified: 21 Nov 2024

    Emissary is a P2P-based, data-driven workflow engine. Emissary version 6.4.0 is vulnerable to Server-Side Request Forgery (SSRF). In particular, the `RegisterPeerAction` endpoint and the `AddChildDirectoryAction` endpoint are vulnerable to SSRF. This vulnerability may lead to credential leaks. Emissary version 7.0 contains a patch. As a workaround, disable network access to Emissary from untrusted sources.

    Published: 2 Jul 2021
    7.1
    High

    CVE-2021-32735

    Last Modified: 21 Nov 2024

    Kirby is a content management system. In Kirby CMS versions 3.5.5 and 3.5.6, the Panel's `ListItem` component (used in the pages and files section for example) displayed HTML in page titles as it is. This could be used for cross-site scripting (XSS) attacks. Malicious authenticated Panel users can escalate their privileges if they get access to the Panel session of an admin user. Visitors without Panel access can use the attack vector if the site allows changing site data from a frontend form. Kirby 3.5.7 patches the vulnerability. As a partial workaround, site administrators can protect against attacks from visitors without Panel access by validating or sanitizing provided data from the frontend form.

    Published: 2 Jul 2021
    8.8
    High

    CVE-2021-27950

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in azurWebEngine in Sita AzurCMS through 1.2.3.12 allows an authenticated attacker to execute arbitrary SQL commands via the id parameter to mesdocs.ajax.php in azurWebEngine/eShop. By default, the query is executed as DBA.

    Published: 2 Jul 2021
    7.5
    High

    CVE-2021-36125

    Last Modified: 21 Nov 2024

    An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalRenameRequest page is vulnerable to infinite loops and denial of service attacks when a user's current username is beyond an arbitrary maximum configuration value (MaxNameChars).

    Published: 2 Jul 2021
    9.8
    Critical

    CVE-2021-36126

    Last Modified: 21 Nov 2024

    An issue was discovered in the AbuseFilter extension in MediaWiki through 1.36. If the MediaWiki:Abusefilter-blocker message is invalid within the content language, the filter user falls back to the English version, but that English version could also be invalid on a wiki. This would result in a fatal error, and potentially fail to block or restrict a potentially nefarious user.

    Published: 2 Jul 2021
    4.3
    Medium

    CVE-2021-36127

    Last Modified: 21 Nov 2024

    An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalUserRights page provided search results which, for a suppressed MediaWiki user, were different than for any other user, thus easily disclosing suppressed accounts (which are supposed to be completely hidden).

    Published: 2 Jul 2021
    9.8
    Critical

    CVE-2021-36128

    Last Modified: 21 Nov 2024

    An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. Autoblocks for CentralAuth-issued suppression blocks are not properly implemented.

    Published: 2 Jul 2021
    4.3
    Medium

    CVE-2021-36129

    Last Modified: 21 Nov 2024

    An issue was discovered in the Translate extension in MediaWiki through 1.36. The Aggregategroups Action API module does not validate the parameter for aggregategroup when action=remove is set, thus allowing users with the translate-manage right to silently delete various groups' metadata.

    Published: 2 Jul 2021
    4.8
    Medium

    CVE-2021-36130

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in the SocialProfile extension in MediaWiki through 1.36. Within several gift-related special pages, a privileged user with the awardmanage right could inject arbitrary HTML and JavaScript within various gift-related data fields. The attack could easily propagate across many pages for many users.

    Published: 2 Jul 2021
    4.8
    Medium

    CVE-2021-36131

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in the SportsTeams extension in MediaWiki through 1.36. Within several special pages, a privileged user could inject arbitrary HTML and JavaScript within various data fields. The attack could easily propagate across many pages for many users.

    Published: 2 Jul 2021
    8.8
    High

    CVE-2021-36132

    Last Modified: 21 Nov 2024

    An issue was discovered in the FileImporter extension in MediaWiki through 1.36. For certain relaxed configurations of the $wgFileImporterRequiredRight variable, it might not validate all appropriate user rights, thus allowing a user with insufficient rights to perform operations (specifically file uploads) that they should not be allowed to perform.

    Published: 2 Jul 2021
    7.8
    High

    CVE-2021-3613

    Last Modified: 21 Nov 2024

    OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (OpenVPNConnect.exe).

    Published: 2 Jul 2021
    7.8
    High

    CVE-2021-3606

    Last Modified: 21 Nov 2024

    OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (openvpn.exe).

    Published: 2 Jul 2021
    7.8
    High

    CVE-2021-27412

    Last Modified: 21 Nov 2024

    Delta Electronics DOPSoft Versions 4.0.10.17 and prior are vulnerable to an out-of-bounds read, which may allow an attacker to execute arbitrary code.

    Published: 2 Jul 2021
    5.5
    Medium

    CVE-2021-27455

    Last Modified: 21 Nov 2024

    Delta Electronics DOPSoft Versions 4.0.10.17 and prior are vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to disclose information.

    Published: 2 Jul 2021
    9.8
    Critical

    CVE-2021-35029

    Last Modified: 21 Nov 2024

    An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote attacker to execute arbitrary commands on an affected device.

    Published: 2 Jul 2021
    6.5
    Medium

    CVE-2021-26920

    Last Modified: 21 Nov 2024

    In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of the Druid server process. This is not an elevation of privilege when users access Druid directly, since Druid also provides the Local InputSource, which allows the same level of access. But it is problematic when users interact with Druid indirectly through an application that allows users to specify the HTTP InputSource, but not the Local InputSource. In this case, users could bypass the application-level restriction by passing a file URL to the HTTP InputSource.

    Published: 2 Jul 2021
    8.8
    High

    CVE-2020-23219

    Last Modified: 21 Nov 2024

    Monstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" field under the "Edit Snippet" module.

    Published: 1 Jul 2021
    5.4
    Medium

    CVE-2020-23217

    Last Modified: 21 Nov 2024

    A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Add a list" field under the "Import Emails" module.

    Published: 1 Jul 2021
    5.4
    Medium

    CVE-2020-23214

    Last Modified: 21 Nov 2024

    A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Configure categories" field under the "Categorise Lists" module.

    Published: 1 Jul 2021
    5.4
    Medium

    CVE-2020-23209

    Last Modified: 21 Nov 2024

    A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "List Description" field under the "Edit A List" module.

    Published: 1 Jul 2021
    5.4
    Medium

    CVE-2020-23208

    Last Modified: 21 Nov 2024

    A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Send test" field under the "Start or continue campaign" module.

    Published: 1 Jul 2021
    5.4
    Medium

    CVE-2020-23207

    Last Modified: 21 Nov 2024

    A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Edit Values" field under the "Configure Attributes" module.

    Published: 1 Jul 2021
    5.4
    Medium

    CVE-2020-23205

    Last Modified: 21 Nov 2024

    A stored cross site scripting (XSS) vulnerability in Monstra CMS version 3.0.4 allows attackers to execute arbitrary web scripts or HTML via crafted a payload entered into the "Site Name" field under the "Site Settings" module.

    Published: 1 Jul 2021
    5.3
    Medium

    CVE-2021-32731

    Last Modified: 21 Nov 2024

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Between (and including) versions 13.1RC1 and 13.1, the reset password form reveals the email address of users just by giving their username. The problem has been patched on XWiki 13.2RC1. As a workaround, it is possible to manually modify the `resetpasswordinline.vm` to perform the changes made to mitigate the vulnerability.

    Published: 1 Jul 2021
    5.7
    Medium

    CVE-2021-32730

    Last Modified: 21 Nov 2024

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A cross-site request forgery vulnerability exists in versions prior to 12.10.5, and in versions 13.0 through 13.1. It's possible for forge an URL that, when accessed by an admin, will reset the password of any user in XWiki. The problem has been patched in XWiki 12.10.5 and 13.2RC1. As a workaround, it is possible to apply the patch manually by modifying the `register_macros.vm` template.

    Published: 1 Jul 2021
    2
    Low

    CVE-2021-32729

    Last Modified: 21 Nov 2024

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A vulnerability exists in versions prior to 12.6.88, 12.10.4, and 13.0. The script service method used to reset the authentication failures record can be executed by any user with Script rights and does not require Programming rights. An attacher with script rights who is able to reset the authentication failure record might perform a brute force attack, since they would be able to virtually deactivate the mechanism introduced to mitigate those attacks. The problem has been patched in version 12.6.8, 12.10.4 and 13.0. There are no workarounds aside from upgrading.

    Published: 1 Jul 2021
    8.8
    High

    CVE-2020-27362

    Last Modified: 21 Nov 2024

    An issue exists within the SSH console of Akkadian Provisioning Manager 4.50.02 which allows a low-level privileged user to escape the web configuration file editor and escalate privileges.

    Published: 1 Jul 2021
    7.5
    High

    CVE-2020-27361

    Last Modified: 21 Nov 2024

    An issue exists within Akkadian Provisioning Manager 4.50.02 which allows attackers to view sensitive information within the /pme subdirectories.

    Published: 1 Jul 2021
    5.4
    Medium

    CVE-2020-4935

    Last Modified: 21 Nov 2024

    IBM Datacap Fastdoc Capture (IBM Datacap Navigator 9.1.7 ) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191753.

    Published: 1 Jul 2021
    8.8
    High

    CVE-2020-4902

    Last Modified: 21 Nov 2024

    IBM Datacap Taskmaster Capture (IBM Datacap Navigator 9.1.7) is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 191045.

    Published: 1 Jul 2021
    5.4
    Medium

    CVE-2021-28424

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in Teachers Record Management System 1.0 allows remote authenticated users to inject arbitrary web script or HTML via the 'email' POST parameter in adminprofile.php.

    Published: 1 Jul 2021
    8.8
    High

    CVE-2021-28423

    Last Modified: 28 May 2025

    Multiple SQL Injection vulnerabilities in Teachers Record Management System 1.0 thru 2.1 allow remote authenticated users to execute arbitrary SQL commands via the 'editid' GET parameter in edit-subjects-detail.php, edit-teacher-detail.php, or the 'searchdata' POST parameter in search.php.

    Published: 1 Jul 2021
    7.5
    High

    CVE-2021-28127

    Last Modified: 21 Nov 2024

    An issue was discovered in Stormshield SNS through 4.2.1. A brute-force attack can occur.

    Published: 1 Jul 2021
    8.8
    High

    CVE-2021-27661

    Last Modified: 21 Nov 2024

    Successful exploitation of this vulnerability could give an authenticated Facility Explorer SNC Series Supervisory Controller (F4-SNC) user an unintended level of access to the controller’s file system, allowing them to access or modify system files by sending specifically crafted web messages to the F4-SNC.

    Published: 1 Jul 2021
    8.8
    High

    CVE-2021-27660

    Last Modified: 21 Nov 2024

    An insecure client auto update feature in C-CURE 9000 can allow remote execution of lower privileged Windows programs.

    Published: 1 Jul 2021
    4.3
    Medium

    CVE-2021-35337

    Last Modified: 21 Nov 2024

    Sourcecodester Phone Shop Sales Managements System 1.0 is vulnerable to Insecure Direct Object Reference (IDOR). Any attacker will be able to see the invoices of different users by changing the id parameter.

    Published: 1 Jul 2021
    9.8
    Critical

    CVE-2021-35336

    Last Modified: 21 Nov 2024

    Tieline IP Audio Gateway 2.6.4.8 and below is affected by Incorrect Access Control. A vulnerability in the Tieline Web Administrative Interface could allow an unauthenticated user to access a sensitive part of the system with a high privileged account.

    Published: 1 Jul 2021
    7.5
    High

    CVE-2021-27477

    Last Modified: 21 Nov 2024

    When JTEKT Corporation TOYOPUC PLC versions PC10G-CPU, 2PORT-EFR, Plus CPU, Plus EX, Plus EX2, Plus EFR, Plus EFR2, Plus 2P-EFR, PC10P-DP, PC10P-DP-IO, Plus BUS-EX, Nano 10GX, Nano 2ET,PC10PE, PC10PE-16/16P, PC10E, FL/ET-T-V2H, PC10B,PC10B-P, Nano CPU, PC10P, and PC10GE receive an invalid frame, the outside area of a receive buffer for FL-net are overwritten. As a result, the PLC CPU detects a system error, and the affected products stop.

    Published: 1 Jul 2021
    5.4
    Medium

    CVE-2021-31813

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD.

    Published: 1 Jul 2021
    7.5
    High

    CVE-2020-9158

    Last Modified: 21 Nov 2024

    There is a Missing Cryptographic Step vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause DoS of Samgr.

    Published: 1 Jul 2021
    9.1
    Critical

    CVE-2021-22343

    Last Modified: 21 Nov 2024

    There is a Configuration Defect vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service integrity and availability.

    Published: 1 Jul 2021
    5.3
    Medium

    CVE-2021-22344

    Last Modified: 21 Nov 2024

    There is an Improper Access Control vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause temporary DoS.

    Published: 1 Jul 2021
    5.3
    Medium

    CVE-2021-22347

    Last Modified: 21 Nov 2024

    There is an Improper Access Control vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause temporary DoS.

    Published: 1 Jul 2021
    9.8
    Critical

    CVE-2021-35042

    Last Modified: 21 Nov 2024

    Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application.

    Published: 1 Jul 2021
    7.5
    High

    CVE-2021-20778

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in EC-CUBE 4.0.6 (EC-CUBE 4 series) allows a remote attacker to bypass access restriction and obtain sensitive information via unspecified vectors.

    Published: 1 Jul 2021
    6.1
    Medium

    CVE-2021-20752

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in IkaIka RSS Reader all versions allows a remote attacker to inject an arbitrary script via unspecified vectors.

    Published: 1 Jul 2021
    7.8
    High

    CVE-2017-20006

    Last Modified: 21 Nov 2024

    UnRAR 5.6.1.2 and 5.6.1.3 has a heap-based buffer overflow in Unpack::CopyString (called from Unpack::Unpack5 and CmdExtract::ExtractCurrentFile).

    Published: 1 Jul 2021
    7.8
    High

    CVE-2018-25018

    Last Modified: 21 Nov 2024

    UnRAR 5.6.1.7 through 5.7.4 and 6.0.3 has an out-of-bounds write during a memcpy in QuickOpen::ReadRaw when called from QuickOpen::ReadNext.

    Published: 1 Jul 2021
    9.8
    Critical

    CVE-2018-25017

    Last Modified: 21 Nov 2024

    RawSpeed (aka librawspeed) 3.1 has a heap-based buffer overflow in TableLookUp::setTable.

    Published: 1 Jul 2021