CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-34550

    Last Modified: 21 Nov 2024

    An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006. The v3 onion service descriptor parsing allows out-of-bounds memory access, and a client crash, via a crafted onion service descriptor

    Published: 29 Jun 2021
    7.5
    High

    CVE-2021-34549

    Last Modified: 21 Nov 2024

    An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005. Hashing is mishandled for certain retrieval of circuit data. Consequently. an attacker can trigger the use of an attacker-chosen circuit ID to cause algorithm inefficiency.

    Published: 29 Jun 2021
    7.5
    High

    CVE-2021-34548

    Last Modified: 21 Nov 2024

    An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003. An attacker can forge RELAY_END or RELAY_RESOLVED to bypass the intended access control for ending a stream.

    Published: 29 Jun 2021
    8.4
    High

    CVE-2021-31838

    Last Modified: 24 Feb 2026

    A command injection vulnerability in MVISION EDR (MVEDR) prior to 3.4.0 allows an authenticated MVEDR administrator to trigger the EDR client to execute arbitrary commands through PowerShell using the EDR functionality 'execute reaction'.

    Published: 29 Jun 2021
    7.4
    High

    CVE-2021-1134

    Last Modified: 23 Jul 2025

    A vulnerability in the Cisco Identity Services Engine (ISE) integration feature of the Cisco DNA Center Software could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability is due to an incomplete validation of the X.509 certificate used when establishing a connection between DNA Center and an ISE server. An attacker could exploit this vulnerability by supplying a crafted certificate and could then intercept communications between the ISE and DNA Center. A successful exploit could allow the attacker to view and alter sensitive information that the ISE maintains about clients that are connected to the network.

    Published: 29 Jun 2021
    6.5
    Medium

    CVE-2021-3652

    Last Modified: 3 Nov 2025

    A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any password will successfully match during authentication. This flaw allows an attacker to successfully authenticate as a user whose password was disabled.

    Published: 29 Jun 2021
    8.8
    High

    CVE-2021-34824

    Last Modified: 21 Nov 2024

    Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can be accessed from different namespaces.

    Published: 29 Jun 2021
    —
    Unknown

    CVE-2021-35684

    Last Modified: 16 Jan 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is a duplicate of CVE-2022-21306.

    Published: 28 Jun 2021
    —
    Unknown

    CVE-2021-35685

    Last Modified: 16 Jan 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is a duplicate of CVE-2022-21371

    Published: 28 Jun 2021
    6.5
    Medium

    CVE-2021-32722

    Last Modified: 21 Nov 2024

    GlobalNewFiles is a mediawiki extension. Versions prior to 48be7adb70568e20e961ea1cb70904454a671b1d are affected by an uncontrolled resource consumption vulnerability. A large amount of page moves within a short space of time could overwhelm Database servers due to improper handling of load balancing and a lack of an appropriate index. As a workaround, one may avoid use of the extension unless additional rate limit at the MediaWiki level or via PoolCounter / MySQL is enabled. A patch is available in version 48be7adb70568e20e961ea1cb70904454a671b1d.

    Published: 28 Jun 2021
    6.1
    Medium

    CVE-2020-21142

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerabilty in IPFire 2.23 via the IPfire web UI in the mail.cgi.

    Published: 28 Jun 2021
    6.1
    Medium

    CVE-2021-35298

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via multiple models that contain a 'note' field to store additional information.

    Published: 28 Jun 2021
    7.5
    High

    CVE-2021-35299

    Last Modified: 21 Nov 2024

    Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows attackers to obtain sensitive information via email connection configuration probing.

    Published: 28 Jun 2021
    4.3
    Medium

    CVE-2021-35300

    Last Modified: 21 Nov 2024

    Text injection/Content Spoofing in 404 page in Zammad 1.0.x up to 4.0.0 could allow remote attackers to manipulate users into visiting the attackers' page.

    Published: 28 Jun 2021
    5.3
    Medium

    CVE-2021-35301

    Last Modified: 21 Nov 2024

    Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information via the Ticket Article detail view.

    Published: 28 Jun 2021
    5.3
    Medium

    CVE-2021-35302

    Last Modified: 21 Nov 2024

    Incorrect Access Control for linked Tickets in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information.

    Published: 28 Jun 2021
    6.1
    Medium

    CVE-2021-35303

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via the User Avatar attribute.

    Published: 28 Jun 2021
    5.3
    Medium

    CVE-2021-32720

    Last Modified: 21 Nov 2024

    Sylius is an Open Source eCommerce platform on top of Symfony. In versions of Sylius prior to 1.9.5 and 1.10.0-RC.1, part of the details (order ID, order number, items total, and token value) of all placed orders were exposed to unauthorized users. If exploited properly, a few additional information like the number of items in the cart and the date of the shipping may be fetched as well. This data seems to not be crucial nor is personal data, however, could be used for sociotechnical attacks or may expose a few details about shop condition to the third parties. The data possible to aggregate are the number of processed orders or their value in the moment of time. The problem has been patched at Sylius 1.9.5 and 1.10.0-RC.1. There are a few workarounds for the vulnerability. The first possible solution is to hide the problematic endpoints behind the firewall from not logged in users. This would put only the order list under the firewall and allow only authorized users to access it. Once a user is authorized, it will have access to theirs orders only. The second possible solution is to decorate the `\Sylius\Bundle\ApiBundle\Doctrine\QueryCollectionExtension\OrdersByLoggedInUserExtension` and throw `Symfony\Component\Security\Core\Exception\AccessDeniedException` if the class is executed for unauthorized user.

    Published: 28 Jun 2021
    6.1
    Medium

    CVE-2020-22609

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter in include/class.queue.php.

    Published: 28 Jun 2021
    6.1
    Medium

    CVE-2020-22608

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter to include/ajax.search.php.

    Published: 28 Jun 2021
    6.1
    Medium

    CVE-2020-22607

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerabilty in LimeSurvey 4.1.11+200316 via the (1) name and (2) description parameters in application/controllers/admin/PermissiontemplatesController.php.

    Published: 28 Jun 2021
    5.3
    Medium

    CVE-2021-35525

    Last Modified: 21 Nov 2024

    PostSRSd before 1.11 allows a denial of service (subprocess hang) if Postfix sends certain long data fields such as multiple concatenated email addresses. NOTE: the PostSRSd maintainer acknowledges "theoretically, this error should never occur ... I'm not sure if there's a reliable way to trigger this condition by an external attacker, but it is a security bug in PostSRSd nevertheless."

    Published: 28 Jun 2021
    6.1
    Medium

    CVE-2020-20640

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in ECShop 4.0 due to security filtering issues, in the user.php file, we can use the html entity encoding to bypass the security policy of the safety.php file, triggering the xss vulnerability.

    Published: 28 Jun 2021
    8.6
    High

    CVE-2020-23715

    Last Modified: 21 Nov 2024

    Directory Traversal vulnerability in Webport CMS 1.19.10.17121 via the file parameter to file/download.

    Published: 28 Jun 2021
    7.8
    High

    CVE-2021-35523

    Last Modified: 21 Nov 2024

    Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT AUTHORITY\SYSTEM. A non-privileged local user can modify the OpenVPN configuration stored under "%APPDATA%\Securepoint SSL VPN" and add a external script file that is executed as privileged user.

    Published: 28 Jun 2021
    8.8
    High

    CVE-2021-20574

    Last Modified: 21 Nov 2024

    IBM Security Identity Manager Adapters 6.0 and 7.0 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and takeover other accounts. IBM X-Force ID: 199252.

    Published: 28 Jun 2021
    6.5
    Medium

    CVE-2021-20573

    Last Modified: 21 Nov 2024

    IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overflow the and cause the server to crash. IBM X-Force ID: 199249.

    Published: 28 Jun 2021
    6.5
    Medium

    CVE-2021-20572

    Last Modified: 21 Nov 2024

    IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overflow the and cause the server to crash. IBM X-Force ID: 199247.

    Published: 28 Jun 2021
    6.5
    Medium

    CVE-2021-20494

    Last Modified: 21 Nov 2024

    IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a heap based buffer overflow, caused by improper bounds. An authenticared user could overflow the buffer and cause the service to crash. IBM X-Force ID: 197882.

    Published: 28 Jun 2021
    9.8
    Critical

    CVE-2020-23711

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in NavigateCMS 2.9 via the URL encoded GET input category in navigate.php.

    Published: 28 Jun 2021
    5.4
    Medium

    CVE-2021-29775

    Last Modified: 21 Nov 2024

    IBM Business Automation Workflow 19.0.03 and 20.0 and IBM Cloud Pak for Automation 20.0.3-IF002 and 21.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 203029.

    Published: 28 Jun 2021
    4.3
    Medium

    CVE-2021-29751

    Last Modified: 21 Nov 2024

    IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 could allow an authenticated user to obtain sensitive information about another user under nondefault configurations. IBM X-Force ID: 201779.

    Published: 28 Jun 2021
    4.4
    Medium

    CVE-2021-29693

    Last Modified: 21 Nov 2024

    IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user that is in the with elevated group privileges to cause a denial of service due to a vulnerability in the lpd daemon. IBM X-Force ID: 200255.

    Published: 28 Jun 2021
    4.3
    Medium

    CVE-2021-20413

    Last Modified: 21 Nov 2024

    IBM Guardium Data Encryption (GDE) 4.0.0.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196212.

    Published: 28 Jun 2021
    9.8
    Critical

    CVE-2021-34187

    Last Modified: 21 Nov 2024

    main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter.

    Published: 28 Jun 2021
    6.1
    Medium

    CVE-2021-34254

    Last Modified: 21 Nov 2024

    Umbraco CMS before 7.15.7 is vulnerable to Open Redirection due to insufficient url sanitization on booting.aspx.

    Published: 28 Jun 2021
    5.4
    Medium

    CVE-2020-23710

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulneraiblity in LimeSurvey 4.2.5 on textbox via the Notifications & data feature.

    Published: 28 Jun 2021
    —
    Unknown

    CVE-2021-3556

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: Assigned but a duplicate for CVE-2021-3559

    Published: 28 Jun 2021
    9.8
    Critical

    CVE-2021-35456

    Last Modified: 21 Nov 2024

    Online Pet Shop We App 1.0 is vulnerable to remote SQL injection and shell upload

    Published: 28 Jun 2021
    5.5
    Medium

    CVE-2021-28623

    Last Modified: 23 Apr 2025

    Adobe Premiere Elements version 5.2 (and earlier) is affected by an insecure temporary file creation vulnerability. An unauthenticated attacker could leverage this vulnerability to call functions against the installer to perform high privileged actions. Exploitation of this issue does not require user interaction.

    Published: 28 Jun 2021
    5.5
    Medium

    CVE-2021-28597

    Last Modified: 23 Apr 2025

    Adobe Photoshop Elements version 5.2 (and earlier) is affected by an insecure temporary file creation vulnerability. An unauthenticated attacker could leverage this vulnerability to call functions against the installer to perform high privileged actions. Exploitation of this issue does not require user interaction.

    Published: 28 Jun 2021
    8.8
    High

    CVE-2021-28588

    Last Modified: 21 Nov 2024

    Adobe RoboHelp Server version 2019.0.9 (and earlier) is affected by a Path Traversal vulnerability when parsing a crafted HTTP POST request. An authenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.

    Published: 28 Jun 2021
    4.3
    Medium

    CVE-2021-28579

    Last Modified: 23 Apr 2025

    Adobe Connect version 11.2.1 (and earlier) is affected by an Improper access control vulnerability that can lead to the elevation of privileges. An attacker with 'Learner' permissions can leverage this scenario to access the list of event participants.

    Published: 28 Jun 2021
    7.3
    High

    CVE-2021-21084

    Last Modified: 21 Nov 2024

    AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3.8 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

    Published: 28 Jun 2021
    7.8
    High

    CVE-2021-28586

    Last Modified: 21 Nov 2024

    After Effects version 18.0 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 28 Jun 2021
    4.3
    Medium

    CVE-2021-28574

    Last Modified: 23 Apr 2025

    Adobe Animate version 21.0.5 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 28 Jun 2021
    5.4
    Medium

    CVE-2021-28584

    Last Modified: 21 Nov 2024

    Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Path Traversal vulnerability when creating a store with child theme.Successful exploitation could lead to arbitrary file system write by an authenticated attacker. Access to the admin console is required for successful exploitation.

    Published: 28 Jun 2021
    8.3
    High

    CVE-2021-28570

    Last Modified: 23 Apr 2025

    Adobe After Effects version 18.1 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An unauthenticated attacker could exploit this to to plant custom binaries and execute them with System permissions. Exploitation of this issue requires user interaction.

    Published: 28 Jun 2021
    4.3
    Medium

    CVE-2021-28576

    Last Modified: 23 Apr 2025

    Adobe Animate version 21.0.5 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 28 Jun 2021
    3.3
    Low

    CVE-2021-28587

    Last Modified: 21 Nov 2024

    After Effects versions 18.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 28 Jun 2021