CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-22891

    Last Modified: 21 Nov 2024

    A missing authorization vulnerability exists in Citrix ShareFile Storage Zones Controller before 5.7.3, 5.8.3, 5.9.3, 5.10.1 and 5.11.18 may allow unauthenticated remote compromise of the Storage Zones Controller.

    Published: 27 May 2021
    8.8
    High

    CVE-2021-22894

    Last Modified: 3 Nov 2025

    A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room.

    Published: 27 May 2021
    7.5
    High

    CVE-2021-22892

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be disclosed by enumeration and validation checks.

    Published: 27 May 2021
    9.8
    Critical

    CVE-2021-22911

    Last Modified: 21 Nov 2024

    A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE.

    Published: 27 May 2021
    7.5
    High

    CVE-2021-22909

    Last Modified: 21 Nov 2024

    A vulnerability found in EdgeMAX EdgeRouter V2.0.9 and earlier could allow a malicious actor to execute a man-in-the-middle (MitM) attack during a firmware update. This vulnerability is fixed in EdgeMAX EdgeRouter V2.0.9-hotfix.1 and later.

    Published: 27 May 2021
    8.8
    High

    CVE-2021-22908

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execute arbitrary code as the root user. As of version 9.1R3, this permission is not enabled by default.

    Published: 27 May 2021
    7.8
    High

    CVE-2021-22907

    Last Modified: 21 Nov 2024

    An improper access control vulnerability exists in Citrix Workspace App for Windows potentially allows privilege escalation in CR versions prior to 2105 and 1912 LTSR prior to CU4.

    Published: 27 May 2021
    9.8
    Critical

    CVE-2021-33590

    Last Modified: 21 Nov 2024

    GattLib 0.3-rc1 has a stack-based buffer over-read in get_device_path_from_mac in dbus/gattlib.c.

    Published: 27 May 2021
    6.5
    Medium

    CVE-2021-32459

    Last Modified: 21 Nov 2024

    Trend Micro Home Network Security version 6.6.604 and earlier contains a hard-coded password vulnerability in the log collection server which could allow an attacker to use a specially crafted network request to lead to arbitrary authentication. An attacker must first obtain the ability to execute high-privileged code on the target device in order to exploit this vulnerability.

    Published: 27 May 2021
    7.8
    High

    CVE-2021-32458

    Last Modified: 21 Nov 2024

    Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vulnerability which could allow an attacker to issue a specially crafted iotcl which could lead to code execution on affected devices. An attacker must first obtain the ability to execute low-privileged code on the target device in order to exploit this vulnerability.

    Published: 27 May 2021
    6.1
    Medium

    CVE-2021-20727

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Zettlr from 0.20.0 to 1.8.8 allows an attacker to execute an arbitrary script by loading a file or code snippet containing an invalid iframe into Zettlr.

    Published: 27 May 2021
    4.3
    Medium

    CVE-2021-33586

    Last Modified: 21 Nov 2024

    InspIRCd 3.8.0 through 3.9.x before 3.10.0 allows any user (able to connect to the server) to access recently deallocated memory, aka the "malformed PONG" issue.

    Published: 27 May 2021
    5.5
    Medium

    CVE-2021-46668

    Last Modified: 21 Nov 2024

    MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures.

    Published: 27 May 2021
    7.5
    High

    CVE-2021-33558

    Last Modified: 21 Nov 2024

    Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, log.html, email.html, online-users.html, and config.js. NOTE: multiple third parties report that this is a site-specific issue because those files are not part of Boa.

    Published: 27 May 2021
    7.5
    High

    CVE-2021-3610

    Last Modified: 26 Jan 2026

    A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault.

    Published: 27 May 2021
    5.5
    Medium

    CVE-2021-30501

    Last Modified: 11 Apr 2025

    An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0. The flow allows attackers to cause a denial of service (abort) via a crafted file.

    Published: 26 May 2021
    7.8
    High

    CVE-2021-30500

    Last Modified: 11 Apr 2025

    Null pointer dereference was found in upx PackLinuxElf::canUnpack() in p_lx_elf.cpp,in version UPX 4.0.0. That allow attackers to execute arbitrary code and cause a denial of service via a crafted file.

    Published: 26 May 2021
    7.8
    High

    CVE-2021-30499

    Last Modified: 3 Nov 2025

    A flaw was found in libcaca. A buffer overflow of export.c in function export_troff might lead to memory corruption and other potential consequences.

    Published: 26 May 2021
    7.1
    High

    CVE-2021-32614

    Last Modified: 21 Nov 2024

    A flaw was found in dmg2img through 20170502. fill_mishblk() does not check the length of the read buffer, and copy 0xCC bytes from it. The length of the buffer is controlled by an attacker. By providing a length smaller than 0xCC, memcpy reaches out of the malloc'ed bound. This possibly leads to memory layout information leaking in the data. This might be used in a chain of vulnerability in order to reach code execution.

    Published: 26 May 2021
    7.8
    High

    CVE-2021-30472

    Last Modified: 21 Nov 2024

    A flaw was found in PoDoFo 0.9.7. A stack-based buffer overflow in PdfEncryptMD5Base::ComputeOwnerKey function in PdfEncrypt.cpp is possible because of a improper check of the keyLength value.

    Published: 26 May 2021
    5.5
    Medium

    CVE-2021-30471

    Last Modified: 21 Nov 2024

    A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call in PdfNamesTree::AddToDictionary function in src/podofo/doc/PdfNamesTree.cpp can lead to a stack overflow.

    Published: 26 May 2021
    5.5
    Medium

    CVE-2021-30470

    Last Modified: 21 Nov 2024

    A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call among PdfTokenizer::ReadArray(), PdfTokenizer::GetNextVariant() and PdfTokenizer::ReadDataType() functions can lead to a stack overflow.

    Published: 26 May 2021
    5.5
    Medium

    CVE-2021-30469

    Last Modified: 21 Nov 2024

    A flaw was found in PoDoFo 0.9.7. An use-after-free in PoDoFo::PdfVecObjects::Clear() function can cause a denial of service via a crafted PDF file.

    Published: 26 May 2021
    6.1
    Medium

    CVE-2021-3486

    Last Modified: 21 Nov 2024

    GLPi 9.5.4 does not sanitize the metadata. This way its possible to insert XSS into plugins to execute JavaScript code.

    Published: 26 May 2021
    —
    Unknown

    CVE-2008-3523

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA

    Published: 26 May 2021
    —
    Unknown

    CVE-2008-5084

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA

    Published: 26 May 2021
    —
    Unknown

    CVE-2008-5085

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA

    Published: 26 May 2021
    —
    Unknown

    CVE-2008-5509

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs:CVE-2008-5508. Reason: This candidate is a duplicate of CVE-2008-5508. Notes: All CVE users should reference CVE-2008-5508 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 26 May 2021
    6.5
    Medium

    CVE-2020-22028

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_vertically_8 at libavfilter/vf_avgblur.c, which could cause a remote Denial of Service.

    Published: 26 May 2021
    7.1
    High

    CVE-2021-3548

    Last Modified: 21 Nov 2024

    A flaw was found in dmg2img through 20170502. dmg2img did not validate the size of the read buffer during memcpy() inside the main() function. This possibly leads to memory layout information leaking in the data. This might be used in a chain of vulnerability in order to reach code execution.

    Published: 26 May 2021
    6.5
    Medium

    CVE-2020-22026

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability exists in FFmpeg 4.2 in the config_input function at libavfilter/af_tremolo.c, which could let a remote malicious user cause a Denial of Service.

    Published: 26 May 2021
    6.5
    Medium

    CVE-2020-22024

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in FFmpeg 4.2 at the lagfun_frame16 function in libavfilter/vf_lagfun.c, which could let a remote malicious user cause Denial of Service.

    Published: 26 May 2021
    4.9
    Medium

    CVE-2021-25643

    Last Modified: 21 Nov 2024

    An issue was discovered in Couchbase Server 5.x and 6.x before 6.5.2 and 6.6.x before 6.6.2. Internal users with administrator privileges, @cbq-engine-cbauth and @index-cbauth, leak credentials in cleartext in the indexer.log file when they make a /listCreateTokens, /listRebalanceTokens, or /listMetadataTokens call.

    Published: 26 May 2021
    6.5
    Medium

    CVE-2020-22021

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in FFmpeg 4.2 at filter_edges function in libavfilter/vf_yadif.c, which could let a remote malicious user cause a Denial of Service.

    Published: 26 May 2021
    3.9
    Low

    CVE-2021-22747

    Last Modified: 21 Nov 2024

    Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position. This CVE ID is unique from CVE-2021-22742, CVE-2021-22744, CVE-2021-22745, and CVE-2021-22746.

    Published: 26 May 2021
    3.9
    Low

    CVE-2021-22746

    Last Modified: 21 Nov 2024

    Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position. This CVE ID is unique from CVE-2021-22742, CVE-2021-22744, CVE-2021-22745, and CVE-2021-22747.

    Published: 26 May 2021
    3.9
    Low

    CVE-2021-22745

    Last Modified: 21 Nov 2024

    Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position. This CVE ID is unique from CVE-2021-22742, CVE-2021-22744, CVE-2021-22746, and CVE-2021-22747.

    Published: 26 May 2021
    3.9
    Low

    CVE-2021-22744

    Last Modified: 21 Nov 2024

    Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position. This CVE ID is unique from CVE-2021-22742, CVE-2021-22745, CVE-2021-22746, and CVE-2021-22747.

    Published: 26 May 2021
    3.9
    Low

    CVE-2021-22743

    Last Modified: 21 Nov 2024

    Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex TCM 4351B installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position.

    Published: 26 May 2021
    3.9
    Low

    CVE-2021-22742

    Last Modified: 21 Nov 2024

    Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position.

    Published: 26 May 2021
    6.7
    Medium

    CVE-2021-22741

    Last Modified: 21 Nov 2024

    Use of Password Hash with Insufficient Computational Effort vulnerability exists in ClearSCADA (all versions), EcoStruxure Geo SCADA Expert 2019 (all versions), and EcoStruxure Geo SCADA Expert 2020 (V83.7742.1 and prior), which could cause the revealing of account credentials when server database files are available. Exposure of these files to an attacker can make the system vulnerable to password decryption attacks. Note that “.sde” configuration export files do not contain user account password hashes.

    Published: 26 May 2021
    6.5
    Medium

    CVE-2021-22740

    Last Modified: 21 Nov 2024

    Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause information to be exposed when an unauthorized file is uploaded.

    Published: 26 May 2021
    5.9
    Medium

    CVE-2021-22739

    Last Modified: 21 Nov 2024

    Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a device to be compromised when it is first configured.

    Published: 26 May 2021
    9.8
    Critical

    CVE-2021-22738

    Last Modified: 21 Nov 2024

    Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cause unauthorized access when credentials are discovered after a brute force attack.

    Published: 26 May 2021
    7.5
    High

    CVE-2021-22736

    Last Modified: 21 Nov 2024

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a denial of service when an unauthorized file is uploaded.

    Published: 26 May 2021
    7.2
    High

    CVE-2021-22735

    Last Modified: 21 Nov 2024

    Improper Verification of Cryptographic Signature vulnerability exists inhomeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could allow remote code execution when unauthorized code is copied to the device.

    Published: 26 May 2021
    7.2
    High

    CVE-2021-22734

    Last Modified: 21 Nov 2024

    Improper Verification of Cryptographic Signature vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause remote code execution when an attacker loads unauthorized code.

    Published: 26 May 2021
    7.8
    High

    CVE-2021-22733

    Last Modified: 21 Nov 2024

    Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause shell access when unauthorized code is loaded into the system folder.

    Published: 26 May 2021
    7.8
    High

    CVE-2021-22732

    Last Modified: 21 Nov 2024

    Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a code execution issue when an attacker loads unauthorized code on the web server.

    Published: 26 May 2021
    9.8
    Critical

    CVE-2021-22731

    Last Modified: 21 Nov 2024

    Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on Modicon Managed Switch MCSESM* and MCSESP* V8.21 and prior which could cause an unauthorized password change through HTTP / HTTPS when basic user information is known by a remote attacker.

    Published: 26 May 2021