CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2021-30126

    Last Modified: 21 Nov 2024

    Lightmeter ControlCenter 1.1.0 through 1.5.x before 1.5.1 allows anyone who knows the URL of a publicly available Lightmeter instance to access application settings, possibly including an SMTP password and a Slack access token, via a settings HTTP query.

    Published: 2 Apr 2021
    6.1
    Medium

    CVE-2021-30125

    Last Modified: 21 Nov 2024

    Jamf Pro before 10.28.0 allows XSS related to inventory history, aka PI-009376.

    Published: 2 Apr 2021
    5.3
    Medium

    CVE-2021-28941

    Last Modified: 21 Nov 2024

    Because of no validation on a curl command in MagpieRSS 0.72 in the /extlib/Snoopy.class.inc file, when you send a request to the /scripts/magpie_debug.php or /scripts/magpie_simple.php page, it's possible to request any internal page if you use a https request.

    Published: 2 Apr 2021
    9.8
    Critical

    CVE-2021-28940

    Last Modified: 21 Nov 2024

    Because of a incorrect escaped exec command in MagpieRSS in 0.72 in the /extlib/Snoopy.class.inc file, it is possible to add a extra command to the curl binary. This creates an issue on the /scripts/magpie_debug.php and /scripts/magpie_simple.php page that if you send a specific https url in the RSS URL field, you are able to execute arbitrary commands.

    Published: 2 Apr 2021
    5.4
    Medium

    CVE-2021-29661

    Last Modified: 21 Nov 2024

    Softing AG OPC Toolbox through 4.10.1.13035 allows /en/diag_values.html Stored XSS via the ITEMLISTVALUES##ITEMID parameter, resulting in JavaScript payload injection into the trace file. This payload will then be triggered every time an authenticated user browses the page containing it.

    Published: 2 Apr 2021
    8.8
    High

    CVE-2021-29660

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) vulnerability in en/cfg_setpwd.html in Softing AG OPC Toolbox through 4.10.1.13035 allows attackers to reset the administrative password by inducing the Administrator user to browse a URL controlled by an attacker.

    Published: 2 Apr 2021
    7.8
    High

    CVE-2021-1753

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to arbitrary code execution.

    Published: 2 Apr 2021
    7.2
    High

    CVE-2021-27973

    Last Modified: 21 Nov 2024

    SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages.

    Published: 2 Apr 2021
    7.5
    High

    CVE-2021-1761

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause a denial of service.

    Published: 2 Apr 2021
    5.3
    Medium

    CVE-2021-3374

    Last Modified: 21 Nov 2024

    Directory traversal in RStudio Shiny Server before 1.5.16 allows attackers to read the application source code, involving an encoded slash.

    Published: 2 Apr 2021
    5.5
    Medium

    CVE-2020-11924

    Last Modified: 21 Nov 2024

    An issue was discovered in WiZ Colors A60 1.14.0. Wi-Fi credentials are stored in cleartext in flash memory, which presents an information-disclosure risk for a discarded or resold device.

    Published: 2 Apr 2021
    9.8
    Critical

    CVE-2021-1818

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.

    Published: 2 Apr 2021
    5.5
    Medium

    CVE-2020-11923

    Last Modified: 21 Nov 2024

    An issue was discovered in WiZ Colors A60 1.14.0. API credentials are locally logged.

    Published: 2 Apr 2021
    6.1
    Medium

    CVE-2021-1879

    Last Modified: 23 Oct 2025

    This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS 7.3.3. Processing maliciously crafted web content may lead to universal cross site scripting. Apple is aware of a report that this issue may have been actively exploited..

    Published: 2 Apr 2021
    7.8
    High

    CVE-2021-1805

    Last Modified: 21 Nov 2024

    An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2.1, macOS Catalina 10.15.7 Supplemental Update, macOS Mojave 10.14.6 Security Update 2021-002. An application may be able to execute arbitrary code with kernel privileges.

    Published: 2 Apr 2021
    7
    High

    CVE-2021-1806

    Last Modified: 21 Nov 2024

    A race condition was addressed with additional validation. This issue is fixed in macOS Big Sur 11.2.1, macOS Catalina 10.15.7 Supplemental Update, macOS Mojave 10.14.6 Security Update 2021-002. An application may be able to execute arbitrary code with kernel privileges.

    Published: 2 Apr 2021
    3.3
    Low

    CVE-2021-1803

    Last Modified: 21 Nov 2024

    The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.0.1. A local application may be able to enumerate the user's iCloud documents.

    Published: 2 Apr 2021
    7.8
    High

    CVE-2021-1802

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. A local attacker may be able to elevate their privileges.

    Published: 2 Apr 2021
    5.5
    Medium

    CVE-2021-1800

    Last Modified: 21 Nov 2024

    A path handling issue was addressed with improved validation. This issue is fixed in Xcode 12.4. A malicious application may be able to access arbitrary files on the host device while running an app that uses on-demand resources with Xcode.

    Published: 2 Apr 2021
    5.5
    Medium

    CVE-2021-1797

    Last Modified: 21 Nov 2024

    The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A local user may be able to read arbitrary files.

    Published: 2 Apr 2021
    9.8
    Critical

    CVE-2021-1796

    Last Modified: 21 Nov 2024

    An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution.

    Published: 2 Apr 2021
    7.8
    High

    CVE-2021-1793

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to arbitrary code execution.

    Published: 2 Apr 2021
    9.8
    Critical

    CVE-2021-1795

    Last Modified: 21 Nov 2024

    An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution.

    Published: 2 Apr 2021
    9.8
    Critical

    CVE-2021-1794

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution.

    Published: 2 Apr 2021
    7.8
    High

    CVE-2021-1790

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. Processing a maliciously crafted font may lead to arbitrary code execution.

    Published: 2 Apr 2021
    5.5
    Medium

    CVE-2021-1791

    Last Modified: 21 Nov 2024

    An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application may be able to disclose kernel memory.

    Published: 2 Apr 2021
    8.8
    High

    CVE-2021-1792

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution.

    Published: 2 Apr 2021
    7.8
    High

    CVE-2021-1787

    Last Modified: 21 Nov 2024

    Multiple issues were addressed with improved logic. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A local attacker may be able to elevate their privileges.

    Published: 2 Apr 2021
    7.8
    High

    CVE-2021-1785

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to arbitrary code execution.

    Published: 2 Apr 2021
    7.8
    High

    CVE-2021-1783

    Last Modified: 21 Nov 2024

    An access issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to arbitrary code execution.

    Published: 2 Apr 2021
    5.5
    Medium

    CVE-2021-1786

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A local user may be able to create or modify system files.

    Published: 2 Apr 2021
    7
    High

    CVE-2021-1782

    Last Modified: 23 Oct 2025

    A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited..

    Published: 2 Apr 2021
    5.5
    Medium

    CVE-2021-1781

    Last Modified: 21 Nov 2024

    A privacy issue existed in the handling of Contact cards. This was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A malicious application may be able to leak sensitive user information.

    Published: 2 Apr 2021
    7.8
    High

    CVE-2021-1777

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to arbitrary code execution.

    Published: 2 Apr 2021
    5.5
    Medium

    CVE-2021-1778

    Last Modified: 21 Nov 2024

    An out-of-bounds read issue existed in the curl. This issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to a denial of service.

    Published: 2 Apr 2021
    4.4
    Medium

    CVE-2021-1780

    Last Modified: 21 Nov 2024

    A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 14.4 and iPadOS 14.4. An attacker in a privileged position may be able to perform a denial of service attack.

    Published: 2 Apr 2021
    5.5
    Medium

    CVE-2021-1773

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to a denial of service.

    Published: 2 Apr 2021
    7.8
    High

    CVE-2021-1779

    Last Modified: 21 Nov 2024

    A logic error in kext loading was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. An application may be able to execute arbitrary code with system privileges.

    Published: 2 Apr 2021
    7.8
    High

    CVE-2021-1776

    Last Modified: 21 Nov 2024

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted font file may lead to arbitrary code execution.

    Published: 2 Apr 2021
    7.8
    High

    CVE-2021-1775

    Last Modified: 21 Nov 2024

    This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. Processing a maliciously crafted font may lead to arbitrary code execution.

    Published: 2 Apr 2021
    7.8
    High

    CVE-2021-1774

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to arbitrary code execution.

    Published: 2 Apr 2021
    3.3
    Low

    CVE-2021-1771

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. A user that is removed from an iMessage group could rejoin the group.

    Published: 2 Apr 2021
    7.8
    High

    CVE-2021-1772

    Last Modified: 21 Nov 2024

    A stack overflow was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted text file may lead to arbitrary code execution.

    Published: 2 Apr 2021
    5.5
    Medium

    CVE-2021-1769

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.

    Published: 2 Apr 2021
    7.8
    High

    CVE-2021-1768

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution.

    Published: 2 Apr 2021
    7.5
    High

    CVE-2021-1764

    Last Modified: 21 Nov 2024

    A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause a denial of service.

    Published: 2 Apr 2021
    5.5
    Medium

    CVE-2021-1766

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to a denial of service.

    Published: 2 Apr 2021
    7.8
    High

    CVE-2021-1767

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to heap corruption.

    Published: 2 Apr 2021
    7.8
    High

    CVE-2021-1763

    Last Modified: 21 Nov 2024

    A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution.

    Published: 2 Apr 2021
    5.5
    Medium

    CVE-2021-1760

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application could execute arbitrary code leading to compromise of user information.

    Published: 2 Apr 2021