CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2020-21316

    Last Modified: 21 Nov 2024

    A Cross-site scripting (XSS) vulnerability exists in the comment section in ZrLog 2.1.3, which allows remote attackers to inject arbitrary web script and stolen administrator cookies via the nickname parameter and gain access to the admin panel.

    Published: 15 Jun 2021
    9.8
    Critical

    CVE-2021-34170

    Last Modified: 21 Nov 2024

    Bandai Namco FromSoftware Dark Souls III allows remote attackers to execute arbitrary code.

    Published: 15 Jun 2021
    7.8
    High

    CVE-2020-7864

    Last Modified: 21 Nov 2024

    Parameter manipulation can bypass authentication to cause file upload and execution. This will execute the remote code. This issue affects: Raonwiz DEXT5Editor versions prior to 3.5.1405747.1100.03.

    Published: 15 Jun 2021
    8.8
    High

    CVE-2021-34128

    Last Modified: 21 Nov 2024

    LaikeTui 3.5.0 allows remote authenticated users to execute arbitrary PHP code by using index.php?module=system&action=pay to upload a ZIP archive containing a .php file, as demonstrated by the ../../../../phpinfo.php pathname.

    Published: 15 Jun 2021
    8.1
    High

    CVE-2021-34129

    Last Modified: 21 Nov 2024

    LaikeTui 3.5.0 allows remote authenticated users to delete arbitrary files, as demonstrated by deleting install.lock in order to reinstall the product in an attacker-controlled manner. This deletion is possible via directory traversal in the uploadImg, oldpic, or imgurl parameter.

    Published: 15 Jun 2021
    3.3
    Low

    CVE-2021-3601

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. OpenSSL does not class this issue as a security vulnerability. The trusted CA store should not contain anything that the user does not trust to issue other certificates. Notes: https://github.com/openssl/openssl/issues/5236#issuecomment-119646061

    Published: 15 Jun 2021
    6.2
    Medium

    CVE-2021-32684

    Last Modified: 21 Nov 2024

    magento-scripts contains scripts and configuration used by Create Magento App, a zero-configuration tool-chain which allows one to deploy Magento 2. In versions 1.5.1 and 1.5.2, after changing the function from synchronous to asynchronous there wasn't implemented handler in the start, stop, exec, and logs commands, effectively making them unusable. Version 1.5.3 contains patches for the problems.

    Published: 14 Jun 2021
    7.5
    High

    CVE-2021-20027

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in SonicOS allows a remote attacker to cause a Denial of Service (DoS) by sending a specially crafted request. This vulnerability affects SonicOS Gen5, Gen6, Gen7 platforms, and SonicOSv virtual firewalls.

    Published: 14 Jun 2021
    7.5
    High

    CVE-2021-26845

    Last Modified: 21 Nov 2024

    Information Exposure vulnerability in Hitachi ABB Power Grids eSOMS allows unauthorized user to gain access to report data if the URL used to access the report is discovered. This issue affects: Hitachi ABB Power Grids eSOMS 6.0 versions prior to 6.0.4.2.2; 6.1 versions prior to 6.1.4; 6.3 versions prior to 6.3.

    Published: 14 Jun 2021
    6.3
    Medium

    CVE-2021-27887

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) vulnerability in the main dashboard of Ellipse APM versions allows an authenticated user or integrated application to inject malicious data into the application that can then be executed in a victim’s browser. This issue affects: Hitachi ABB Power Grids Ellipse APM 5.3 version 5.3.0.1 and prior versions; 5.2 version 5.2.0.3 and prior versions; 5.1 version 5.1.0.6 and prior versions.

    Published: 14 Jun 2021
    7.5
    High

    CVE-2021-27196

    Last Modified: 21 Nov 2024

    Improper Input Validation vulnerability in Hitachi ABB Power Grids Relion 670 Series, Relion 670/650 Series, Relion 670/650/SAM600-IO, Relion 650, REB500, RTU500 Series, FOX615 (TEGO1), MSM, GMS600, PWC600 allows an attacker with access to the IEC 61850 network with knowledge of how to reproduce the attack, as well as the IP addresses of the different IEC 61850 access points (of IEDs/products), to force the device to reboot, which renders the device inoperable for approximately 60 seconds. This vulnerability affects only products with IEC 61850 interfaces. This issue affects: Hitachi ABB Power Grids Relion 670 Series 1.1; 1.2.3 versions prior to 1.2.3.20; 2.0 versions prior to 2.0.0.13; 2.1; 2.2.2 versions prior to 2.2.2.3; 2.2.3 versions prior to 2.2.3.2. Hitachi ABB Power Grids Relion 670/650 Series 2.2.0 versions prior to 2.2.0.13. Hitachi ABB Power Grids Relion 670/650/SAM600-IO 2.2.1 versions prior to 2.2.1.6. Hitachi ABB Power Grids Relion 650 1.1; 1.2; 1.3 versions prior to 1.3.0.7. Hitachi ABB Power Grids REB500 7.3; 7.4; 7.5; 7.6; 8.2; 8.3. Hitachi ABB Power Grids RTU500 Series 7.x version 7.x and prior versions; 8.x version 8.x and prior versions; 9.x version 9.x and prior versions; 10.x version 10.x and prior versions; 11.x version 11.x and prior versions; 12.x version 12.x and prior versions. Hitachi ABB Power Grids FOX615 (TEGO1) R1D02 version R1D02 and prior versions. Hitachi ABB Power Grids MSM 2.1.0 versions prior to 2.1.0. Hitachi ABB Power Grids GMS600 1.3.0 version 1.3.0 and prior versions. Hitachi ABB Power Grids PWC600 1.0 versions prior to 1.0.1.4; 1.1 versions prior to 1.1.0.1.

    Published: 14 Jun 2021
    9.8
    Critical

    CVE-2021-0324

    Last Modified: 21 Nov 2024

    Product: AndroidVersions: Android SoCAndroid ID: A-175402462

    Published: 14 Jun 2021
    6.8
    Medium

    CVE-2021-0467

    Last Modified: 21 Nov 2024

    In Chromecast bootROM, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the bootloader, with physical USB access, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-174490700

    Published: 14 Jun 2021
    8.1
    High

    CVE-2021-21557

    Last Modified: 21 Nov 2024

    Dell PowerEdge Server BIOS and select Dell Precision Rack BIOS contain an out-of-bounds array access vulnerability. A local malicious user with high privileges may potentially exploit this vulnerability, leading to a denial of service, arbitrary code execution, or information disclosure in System Management Mode.

    Published: 14 Jun 2021
    6.1
    Medium

    CVE-2021-21556

    Last Modified: 21 Nov 2024

    Dell PowerEdge R640, R740, R740XD, R840, R940, R940xa, MX740c, MX840c, and T640 Server BIOS contain a stack-based buffer overflow vulnerability in systems with NVDIMM-N installed. A local malicious user with high privileges may potentially exploit this vulnerability, leading to a denial of Service, arbitrary code execution, or information disclosure in UEFI or BIOS Preboot Environment.

    Published: 14 Jun 2021
    6.1
    Medium

    CVE-2021-21555

    Last Modified: 21 Nov 2024

    Dell PowerEdge R640, R740, R740XD, R840, R940, R940xa, MX740c, MX840c, and T640 Server BIOS contain a heap-based buffer overflow vulnerability in systems with NVDIMM-N installed. A local malicious user with high privileges may potentially exploit this vulnerability, leading to a denial of Service, arbitrary code execution, or information disclosure in UEFI or BIOS Preboot Environment.

    Published: 14 Jun 2021
    6.1
    Medium

    CVE-2021-21554

    Last Modified: 21 Nov 2024

    Dell PowerEdge R640, R740, R740XD, R840, R940, R940xa, MX740c, MX840c, and, Dell Precision 7920 Rack Workstation BIOS contain a stack-based buffer overflow vulnerability in systems with Intel Optane DC Persistent Memory installed. A local malicious user with high privileges may potentially exploit this vulnerability, leading to a denial of Service, arbitrary code execution, or information disclosure in UEFI or BIOS Preboot Environment.

    Published: 14 Jun 2021
    9.8
    Critical

    CVE-2021-32682

    Last Modified: 21 Nov 2024

    elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hosting the elFinder PHP connector, even with minimal configuration. The issues were patched in version 2.1.59. As a workaround, ensure the connector is not exposed without authentication.

    Published: 14 Jun 2021
    5.4
    Medium

    CVE-2021-24357

    Last Modified: 21 Nov 2024

    In the Best Image Gallery & Responsive Photo Gallery – FooGallery WordPress plugin before 2.0.35, the Custom CSS field of each gallery is not properly sanitised or validated before being being output in the page where the gallery is embed, leading to a stored Cross-Site Scripting issue.

    Published: 14 Jun 2021
    5.4
    Medium

    CVE-2021-24382

    Last Modified: 21 Nov 2024

    The Smart Slider 3 Free and pro WordPress plugins before 3.5.0.9 did not sanitise the Project Name before outputting it back in the page, leading to a Stored Cross-Site Scripting issue. By default, only administrator users could access the affected functionality, limiting the exploitability of the vulnerability. However, some WordPress admins may allow lesser privileged users to access the plugin's functionality, in which case, privilege escalation could be performed.

    Published: 14 Jun 2021
    6.1
    Medium

    CVE-2021-24358

    Last Modified: 21 Nov 2024

    The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.10 did not validate a redirect parameter on a specifically crafted URL before redirecting the user to it, leading to an Open Redirect issue.

    Published: 14 Jun 2021
    5.3
    Medium

    CVE-2021-24359

    Last Modified: 21 Nov 2024

    The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.11 did not properly check that a user requesting a password reset was the legitimate user, allowing an attacker to send an arbitrary reset password email to a registered user on behalf of the WordPress site. Such issue could be chained with an open redirect (CVE-2021-24358) in version below 4.1.10, to include a crafted password reset link in the email, which would lead to an account takeover.

    Published: 14 Jun 2021
    6.5
    Medium

    CVE-2021-24360

    Last Modified: 21 Nov 2024

    The Yes/No Chart WordPress plugin before 1.0.12 did not sanitise its sid shortcode parameter before using it in a SQL statement, allowing medium privilege users (contributor+) to perform Blind SQL Injection attacks

    Published: 14 Jun 2021
    8.8
    High

    CVE-2021-24353

    Last Modified: 21 Nov 2024

    The import_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to import a set of site redirects.

    Published: 14 Jun 2021
    6.1
    Medium

    CVE-2021-24349

    Last Modified: 21 Nov 2024

    This Gallery from files WordPress plugin through 1.6.0 gives the functionality of uploading images to the server. But filenames are not properly sanitized before being output in an error message when they have an invalid extension, leading to a reflected Cross-Site Scripting issue. Due to the lack of CSRF check, the attack could also be performed via such vector.

    Published: 14 Jun 2021
    6.1
    Medium

    CVE-2021-24351

    Last Modified: 21 Nov 2024

    The theplus_more_post AJAX action of The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.12 did not properly sanitise some of its fields, leading to a reflected Cross-Site Scripting (exploitable on both unauthenticated and authenticated users)

    Published: 14 Jun 2021
    8.8
    High

    CVE-2021-24352

    Last Modified: 21 Nov 2024

    The export_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to export a site's redirects.

    Published: 14 Jun 2021
    4.3
    Medium

    CVE-2021-24355

    Last Modified: 21 Nov 2024

    In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, the lack of capability checks and insufficient nonce check on the AJAX actions, simple301redirects/admin/get_wildcard and simple301redirects/admin/wildcard, made it possible for authenticated users to retrieve and update the wildcard value for redirects.

    Published: 14 Jun 2021
    6.1
    Medium

    CVE-2021-24350

    Last Modified: 21 Nov 2024

    The Visitors WordPress plugin through 0.3 is affected by an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. The plugin would display the user's user agent string without validation or encoding within the WordPress admin panel.

    Published: 14 Jun 2021
    8.8
    High

    CVE-2021-24354

    Last Modified: 21 Nov 2024

    A lack of capability checks and insufficient nonce check on the AJAX action in the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, made it possible for authenticated users to install arbitrary plugins on vulnerable sites.

    Published: 14 Jun 2021
    8.8
    High

    CVE-2021-24356

    Last Modified: 21 Nov 2024

    In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, a lack of capability checks and insufficient nonce check on the AJAX action, simple301redirects/admin/activate_plugin, made it possible for authenticated users to activate arbitrary plugins installed on vulnerable sites.

    Published: 14 Jun 2021
    8.8
    High

    CVE-2021-24341

    Last Modified: 21 Nov 2024

    When deleting a date in the Xllentech English Islamic Calendar WordPress plugin before 2.6.8, the year_number and month_number POST parameters are not sanitised, escaped or validated before being used in a SQL statement, leading to SQL injection.

    Published: 14 Jun 2021
    8.8
    High

    CVE-2021-24347

    Last Modified: 21 Nov 2024

    The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that php files could still be uploaded by changing the file extension's case, for example, from "php" to "pHP".

    Published: 14 Jun 2021
    7.2
    High

    CVE-2021-24348

    Last Modified: 21 Nov 2024

    The menu delete functionality of the Side Menu – add fixed side buttons WordPress plugin before 3.1.5, available to Administrator users takes the did GET parameter and uses it into an SQL statement without proper sanitisation, validation or escaping, therefore leading to a SQL Injection issue

    Published: 14 Jun 2021
    6.6
    Medium

    CVE-2021-24345

    Last Modified: 21 Nov 2024

    The page lists-management feature of the Sendit WP Newsletter WordPress plugin through 2.5.1, available to Administrator users does not sanitise, validate or escape the id_lista POST parameter before using it in SQL statement, therefore leading to Blind SQL Injection.

    Published: 14 Jun 2021
    5.4
    Medium

    CVE-2021-24346

    Last Modified: 21 Nov 2024

    The Stock in & out WordPress plugin through 1.0.4 has a search functionality, the lowest accessible level to it being contributor. The srch POST parameter is not validated, sanitised or escaped before using it in the echo statement, leading to a reflected XSS issue

    Published: 14 Jun 2021
    6.5
    Medium

    CVE-2021-21439

    Last Modified: 21 Nov 2024

    DoS attack can be performed when an email contains specially designed URL in the body. It can lead to the high CPU usage and cause low quality of service, or in extreme case bring the system to a halt. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.26 and prior versions; 8.0.x version 8.0.13 and prior versions.

    Published: 14 Jun 2021
    3.8
    Low

    CVE-2021-3594

    Last Modified: 21 Nov 2024

    An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp_input() function and could occur while processing a udp packet that is smaller than the size of the 'udphdr' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.

    Published: 14 Jun 2021
    —
    Unknown

    CVE-2021-34686

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn. Further investigation showed that it was not a vulnerability. Notes: none.

    Published: 14 Jun 2021
    3.8
    Low

    CVE-2021-3592

    Last Modified: 21 Nov 2024

    An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the 'bootp_t' structure. A malicious guest could use this flaw to leak 10 bytes of uninitialized heap memory from the host. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.

    Published: 14 Jun 2021
    3.8
    Low

    CVE-2021-3593

    Last Modified: 21 Nov 2024

    An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp6_input() function and could occur while processing a udp packet that is smaller than the size of the 'udphdr' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.

    Published: 14 Jun 2021
    3.8
    Low

    CVE-2021-3595

    Last Modified: 21 Nov 2024

    An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the 'tftp_t' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.

    Published: 14 Jun 2021
    8.1
    High

    CVE-2021-23394

    Last Modified: 21 Nov 2024

    The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP.

    Published: 13 Jun 2021
    7.5
    High

    CVE-2021-38201

    Last Modified: 21 Nov 2024

    net/sunrpc/xdr.c in the Linux kernel before 5.13.4 allows remote attackers to cause a denial of service (xdr_set_page_base slab-out-of-bounds access) by performing many NFS 4.2 READ_PLUS operations.

    Published: 13 Jun 2021
    3.7
    Low

    CVE-2021-34682

    Last Modified: 21 Nov 2024

    Receita Federal IRPF 2021 1.7 allows a man-in-the-middle attack against the update feature.

    Published: 12 Jun 2021
    5.2
    Medium

    CVE-2021-32557

    Last Modified: 21 Nov 2024

    It was discovered that the process_report() function in data/whoopsie-upload-all allowed arbitrary file writes via symlinks.

    Published: 12 Jun 2021
    3.8
    Low

    CVE-2021-32556

    Last Modified: 21 Nov 2024

    It was discovered that the get_modified_conffiles() function in backends/packaging-apt-dpkg.py allowed injecting modified package names in a manner that would confuse the dpkg(1) call.

    Published: 12 Jun 2021
    7.3
    High

    CVE-2021-32555

    Last Modified: 21 Nov 2024

    It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg-hwe-18.04 package apport hooks, it could expose private data to other local users.

    Published: 12 Jun 2021
    7.3
    High

    CVE-2021-32554

    Last Modified: 21 Nov 2024

    It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg package apport hooks, it could expose private data to other local users.

    Published: 12 Jun 2021
    7.3
    High

    CVE-2021-32553

    Last Modified: 21 Nov 2024

    It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-17 package apport hooks, it could expose private data to other local users.

    Published: 12 Jun 2021