CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2021-33528

    Last Modified: 21 Nov 2024

    In Weidmueller Industrial WLAN devices in multiple versions an exploitable privilege escalation vulnerability exists in the iw_console functionality. A specially crafted menu selection string can cause an escape from the restricted console, resulting in system access as the root user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

    Published: 25 Jun 2021
    7.5
    High

    CVE-2021-21005

    Last Modified: 21 Nov 2024

    In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-crafted TCP-Packet with the Urgent-Flag set and the Urgent-Pointer set to 0, the network stack will crash. The device needs to be rebooted afterwards.

    Published: 25 Jun 2021
    7.4
    High

    CVE-2021-21004

    Last Modified: 21 Nov 2024

    In Phoenix Contact FL SWITCH SMCS series products in multiple versions an attacker may insert malicious code via LLDP frames into the web-based management which could then be executed by the client.

    Published: 25 Jun 2021
    5.3
    Medium

    CVE-2021-21003

    Last Modified: 21 Nov 2024

    In Phoenix Contact FL SWITCH SMCS series products in multiple versions fragmented TCP-Packets may cause a Denial of Service of Web-, SNMP- and ICMP-Echo services. The switching functionality of the device is not affected.

    Published: 25 Jun 2021
    7.5
    High

    CVE-2021-21002

    Last Modified: 21 Nov 2024

    In Phoenix Contact FL COMSERVER UNI in versions < 2.40 a invalid Modbus exception response can lead to a temporary denial of service.

    Published: 25 Jun 2021
    5.4
    Medium

    CVE-2021-29677

    Last Modified: 21 Nov 2024

    IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 25 Jun 2021
    5.4
    Medium

    CVE-2021-29676

    Last Modified: 21 Nov 2024

    IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to link injection. By persuading a victim to click on a specially-crafted URL link, a remote attacker could exploit this vulnerability to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking

    Published: 25 Jun 2021
    4.9
    Medium

    CVE-2021-20583

    Last Modified: 21 Nov 2024

    IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) could disclose sensitive information through an HTTP GET request by a privileged user due to improper input validation.. IBM X-Force ID: 199396.

    Published: 25 Jun 2021
    7.8
    High

    CVE-2020-4610

    Last Modified: 21 Nov 2024

    IBM Security Secret Server (IBM Security Verify Privilege Manager 10.8.2 ) could allow a local user to execute code due to improper integrity checks. IBM X-Force ID: 184919.

    Published: 25 Jun 2021
    7.8
    High

    CVE-2020-4609

    Last Modified: 21 Nov 2024

    IBM Security Sevret Server (IBM Security Verify Privilege Manager 10.8.2) is vulnerable to a buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and execute arbitrary code on the system or cause the system to crash. IBM X-Force ID: 184917.

    Published: 25 Jun 2021
    8
    High

    CVE-2021-32702

    Last Modified: 21 Nov 2024

    The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before and including `1.4.1` are vulnerable to reflected XSS. An attacker can execute arbitrary code by providing an XSS payload in the `error` query parameter which is then processed by the callback handler as an error message. You are affected by this vulnerability if you are using `@auth0/nextjs-auth0` version `1.4.1` or lower **unless** you are using custom error handling that does not return the error message in an HTML response. Upgrade to version `1.4.1` to resolve. The fix adds basic HTML escaping to the error message and it should not impact your users.

    Published: 25 Jun 2021
    6.1
    Medium

    CVE-2021-3314

    Last Modified: 21 Nov 2024

    Oracle GlassFish Server 3.1.2.18 and below allows /common/logViewer/logViewer.jsf XSS. A malicious user can cause an administrator user to supply dangerous content to the vulnerable page, which is then reflected back to the user and executed by the web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 25 Jun 2021
    5.4
    Medium

    CVE-2021-35501

    Last Modified: 21 Nov 2024

    PandoraFMS <=7.54 allows Stored XSS by placing a payload in the name field of a visual console. When a user or an administrator visits the console, the XSS payload will be executed.

    Published: 25 Jun 2021
    9.8
    Critical

    CVE-2021-34074

    Last Modified: 21 Nov 2024

    PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a relative path is used in the requests.

    Published: 25 Jun 2021
    9.8
    Critical

    CVE-2021-34184

    Last Modified: 26 Aug 2025

    Miniaudio 0.10.35 has a Double free vulnerability that could cause a buffer overflow in ma_default_vfs_close__stdio in miniaudio.h.

    Published: 25 Jun 2021
    7.8
    High

    CVE-2021-34185

    Last Modified: 26 Aug 2025

    Miniaudio 0.10.35 has an integer-based buffer overflow caused by an out-of-bounds left shift in drwav_bytes_to_u32 in miniaudio.h

    Published: 25 Jun 2021
    7.8
    High

    CVE-2021-27043

    Last Modified: 21 Nov 2024

    An Arbitrary Address Write issue in the Autodesk DWG application can allow a malicious user to leverage the application to write in unexpected paths. In order to exploit this the attacker would need the victim to enable full page heap in the application.

    Published: 25 Jun 2021
    7.8
    High

    CVE-2021-27042

    Last Modified: 21 Nov 2024

    A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. The vulnerability exists because the application fails to handle a crafted DWG file, which causes an unhandled exception. An attacker can leverage this vulnerability to execute arbitrary code.

    Published: 25 Jun 2021
    7.8
    High

    CVE-2021-27041

    Last Modified: 21 Nov 2024

    A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. This vulnerability can be exploited to execute arbitrary code

    Published: 25 Jun 2021
    3.3
    Low

    CVE-2021-27040

    Last Modified: 21 Nov 2024

    A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnerability can be exploited to execute arbitrary code.

    Published: 25 Jun 2021
    5.4
    Medium

    CVE-2020-26801

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability was discovered in /Forms/device_vars_1 on TrippLite SU2200RTXL2Ua with firmware version 12.04.0055. This vulnerability allows authenticated attackers to obtain other users' information via a crafted POST request.

    Published: 25 Jun 2021
    5.3
    Medium

    CVE-2021-31615

    Last Modified: 21 Nov 2024

    Unencrypted Bluetooth Low Energy baseband links in Bluetooth Core Specifications 4.0 through 5.2 may permit an adjacent device to inject a crafted packet during the receive window of the listening device before the transmitting device initiates its packet transmission to achieve full MITM status without terminating the link. When applied against devices establishing or using encrypted links, crafted packets may be used to terminate an existing link, but will not compromise the confidentiality or integrity of the link.

    Published: 25 Jun 2021
    9.8
    Critical

    CVE-2021-28958

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.

    Published: 25 Jun 2021
    9.9
    Critical

    CVE-2021-35049

    Last Modified: 21 Nov 2024

    Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could allow a specially crafted HTTP request to execute system commands on the CommandPost and return results in an HTTP response in an authenticated session. The vulnerability is present in Fidelis Network and Deception versions prior to 9.3.7 and in version 9.4. Patches and updates are available to address this vulnerability.

    Published: 25 Jun 2021
    6.5
    Medium

    CVE-2021-35050

    Last Modified: 21 Nov 2024

    User credentials stored in a recoverable format within Fidelis Network and Deception CommandPost. In the event that an attacker gains access to the CommandPost, these values could be decoded and used to login to the application. The vulnerability is present in Fidelis Network and Deception versions prior to 9.3.3. This vulnerability has been addressed in version 9.3.3 and subsequent versions.

    Published: 25 Jun 2021
    9.9
    Critical

    CVE-2021-35047

    Last Modified: 21 Nov 2024

    Vulnerability in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with user level access to the CLI to inject root level commands into the component and neighboring Fidelis components. The vulnerability is present in Fidelis Network and Deception versions prior to 9.3.7 and in version 9.4. Patches and updates are available to address this vulnerability.

    Published: 25 Jun 2021
    9.8
    Critical

    CVE-2021-35048

    Last Modified: 21 Nov 2024

    Vulnerability in Fidelis Network and Deception CommandPost enables unauthenticated SQL injection through the web interface. The vulnerability could lead to exposure of authentication tokens in some versions of Fidelis software. The vulnerability is present in Fidelis Network and Deception versions prior to 9.3.7 and in version 9.4. Patches and updates are available to address this vulnerability.

    Published: 25 Jun 2021
    5.4
    Medium

    CVE-2021-35475

    Last Modified: 21 Nov 2024

    SAS Environment Manager 2.5 allows XSS through the Name field when creating/editing a server. The XSS will prompt when editing the Configuration Properties.

    Published: 25 Jun 2021
    3.3
    Low

    CVE-2021-21781

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the ARM SIGPAGE functionality of Linux Kernel v5.4.66 and v5.4.54. The latest version (5.11-rc4) seems to still be vulnerable. A userland application can read the contents of the sigpage, which can leak kernel memory contents. An attacker can read a process’s memory at a specific offset to trigger this vulnerability. This was fixed in kernel releases: 4.14.222 4.19.177 5.4.99 5.10.17 5.11

    Published: 25 Jun 2021
    8.1
    High

    CVE-2021-33895

    Last Modified: 21 Nov 2024

    ETINET BACKBOX E4.09 and H4.09 mismanages password access control. When a user uses the User ID of the process running BBSV to login to the Backbox UI application, the system procedure (USER_AUTHENTICATE_) used for verifying the Password returns 0 (no error). The reason is that the user is not running the XYGate application. Hence, BBSV assumes the Password is correct. For H4.09, the affected version isT0954V04^AAO. For E4.09, the affected version is 22SEP2020. Note: If your current version is E4.10-16MAY2021 (version procedure T9999V04_16MAY2022_BPAKETI_10), a hotfix (FIXPAK-19OCT-2022) is available in version E4.10-19OCT2022. Resolution to CVE-2021-33895 in version E4.11-19OCT2022

    Published: 25 Jun 2021
    5.5
    Medium

    CVE-2021-3620

    Last Modified: 13 Feb 2025

    A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.

    Published: 25 Jun 2021
    7.5
    High

    CVE-2021-32717

    Last Modified: 21 Nov 2024

    Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 private files publicly accessible with Cloud Storage providers when the hashed URL is known. Users are recommend to first change their configuration to set the correct visibility according to the documentation. The visibility must be at the same level as `type`. When the Storage is saved on Amazon AWS we recommending disabling public access to the bucket containing the private files: https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-block-public-access.html. Otherwise, update to Shopware 6.4.1.1 or install or update the Security plugin (https://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659) and run the command `./bin/console s3:set-visibility` to correct your cloud file visibilities.

    Published: 24 Jun 2021
    4.4
    Medium

    CVE-2021-32716

    Last Modified: 21 Nov 2024

    Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 the admin api has exposed some internal hidden fields when an association has been loaded with a to many reference. Users are recommend to update to version 6.4.1.1. You can get the update to 6.4.1.1 regularly via the Auto-Updater or directly via the download overview. For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin.

    Published: 24 Jun 2021
    5.3
    Medium

    CVE-2021-32712

    Last Modified: 21 Nov 2024

    Shopware is an open source eCommerce platform. Versions prior to 5.6.10 are vulnerable to system information leakage in error handling. Users are recommend to update to version 5.6.10. You can get the update to 5.6.10 regularly via the Auto-Updater or directly via the download overview.

    Published: 24 Jun 2021
    4.8
    Medium

    CVE-2021-32713

    Last Modified: 21 Nov 2024

    Shopware is an open source eCommerce platform. Versions prior to 5.6.10 suffer from an authenticated stored XSS in administration vulnerability. Users are recommend to update to the version 5.6.10. You can get the update to 5.6.10 regularly via the Auto-Updater or directly via the download overview.

    Published: 24 Jun 2021
    9.1
    Critical

    CVE-2021-32711

    Last Modified: 21 Nov 2024

    Shopware is an open source eCommerce platform. Versions prior to 6.3.5.1 may leak of information via Store-API. The vulnerability could only be fixed by changing the API system, which involves a non-backward-compatible change. Only consumers of the Store-API should be affected by this change. We recommend to update to the current version 6.3.5.1. You can get the update to 6.3.5.1 regularly via the Auto-Updater or directly via the download overview. https://www.shopware.com/en/download/#shopware-6 The vulnerability could only be fixed by changing the API system, which involves a non-backward-compatible change. Only consumers of the Store-API should be affected by this change. Please check your plugins if you have it in use. Detailed technical information can be found in the upgrade information. https://github.com/shopware/platform/blob/v6.3.5.1/UPGRADE-6.3.md#6351 ### Workarounds For older versions of 6.1 and 6.2, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version. https://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659 ### For more information https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-02-2021

    Published: 24 Jun 2021
    5.9
    Medium

    CVE-2021-32710

    Last Modified: 21 Nov 2024

    Shopware is an open source eCommerce platform. Potential session hijacking of store customers in versions below 6.3.5.2. We recommend to update to the current version 6.3.5.2. You can get the update to 6.3.5.2 regularly via the Auto-Updater or directly via the download overview. For older versions of 6.1 and 6.2, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.

    Published: 24 Jun 2021
    7.8
    High

    CVE-2021-35448

    Last Modified: 21 Nov 2024

    Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using the Image Transfer Folder feature to navigate to cmd.exe. It binds to local ports to listen for incoming connections.

    Published: 24 Jun 2021
    9.8
    Critical

    CVE-2020-17752

    Last Modified: 21 Nov 2024

    Integer overflow vulnerability in payable function of a smart contract implementation for an Ethereum token, as demonstrated by the smart contract implemented at address 0xB49E984A83d7A638E7F2889fc8328952BA951AbE, an implementation for MillionCoin (MON).

    Published: 24 Jun 2021
    6.5
    Medium

    CVE-2020-17753

    Last Modified: 21 Nov 2024

    An issue was discovered in function addMeByRC in the smart contract implementation for RC, an Ethereum token, allows attackers to transfer an arbitrary amount of tokens to an arbitrary address.

    Published: 24 Jun 2021
    8.8
    High

    CVE-2020-17759

    Last Modified: 21 Nov 2024

    An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers for arbitrary command execution if the user clicks on a specially crafted URL. AKA: WINNOTE-19941.

    Published: 24 Jun 2021
    4.9
    Medium

    CVE-2021-32709

    Last Modified: 21 Nov 2024

    Shopware is an open source eCommerce platform. Creation of order credits was not validated by ACL in admin orders. Users are recommend to update to the current version 6.4.1.1. You can get the update to 6.4.1.1 regularly via the Auto-Updater or directly via the download overview. For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.

    Published: 24 Jun 2021
    6.5
    Medium

    CVE-2021-29777

    Last Modified: 21 Nov 2024

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5, under specific circumstance of a table being dropped while being accessed in another session, could allow an authenticated user to cause a denial of srevice IBM X-Force ID: 203031.

    Published: 24 Jun 2021
    7.5
    High

    CVE-2021-29703

    Last Modified: 21 Nov 2024

    Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200659.

    Published: 24 Jun 2021
    6.5
    Medium

    CVE-2021-20579

    Last Modified: 21 Nov 2024

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user who can create a view or inline SQL function to obtain sensitive information when AUTO_REVAL is set to DEFFERED_FORCE. IBM X-Force ID: 199283.

    Published: 24 Jun 2021
    8.1
    High

    CVE-2020-4945

    Last Modified: 21 Nov 2024

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite arbirary files due to improper group permissions. IBM X-Force ID: 191945.

    Published: 24 Jun 2021
    4.7
    Medium

    CVE-2020-4885

    Last Modified: 21 Nov 2024

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow a local user to access and change the configuration of Db2 due to a race condition of a symbolic link,. IBM X-Force ID: 190909.

    Published: 24 Jun 2021
    7.8
    High

    CVE-2021-32493

    Last Modified: 21 Nov 2024

    A flaw was found in djvulibre-3.5.28 and earlier. A heap buffer overflow in function DJVU::GBitmap::decode() via crafted djvu file may lead to application crash and other consequences.

    Published: 24 Jun 2021
    7.8
    High

    CVE-2021-32492

    Last Modified: 21 Nov 2024

    A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds read in function DJVU::DataPool::has_data() via crafted djvu file may lead to application crash and other consequences.

    Published: 24 Jun 2021
    7.8
    High

    CVE-2021-32490

    Last Modified: 21 Nov 2024

    A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds write in function DJVU::filter_bv() via crafted djvu file may lead to application crash and other consequences.

    Published: 24 Jun 2021