5.3
    Medium

    CVE-2021-44848

    Last Modified: 16 Dec 2021

    In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication requests depending on whether the username exists.

    Source:Daniel Morales
    Published:13 Dec 2021
    6.6
    Medium

    CVE-2021-44832

    Last Modified: 29 May 2026

    Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

    Published:28 Dec 2021
    8.8
    High

    CVE-2021-44827

    Last Modified: 21 Nov 2024

    There is remote authenticated OS command injection on TP-Link Archer C20i 0.9.1 3.2 v003a.0 Build 170221 Rel.55462n devices vie the X_TP_ExternalIPv6Address HTTP parameter, allowing a remote attacker to run arbitrary commands on the router with root privileges.

    Published:4 Mar 2022
    9.8
    Critical

    CVE-2021-44790

    Last Modified: 7 Jun 2023

    A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.

    Source:Sunil Iyengar
    Published:20 Dec 2021
    7
    High

    CVE-2021-44733

    Last Modified: 21 Nov 2024

    A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object.

    Published:14 Dec 2021
    7.8
    High

    CVE-2021-44731

    Last Modified: 21 Nov 2024

    A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount namespace for a snap. This could allow a local attacker to gain root privileges by bind-mounting their own contents inside the snap's private mount namespace and causing snap-confine to execute arbitrary code and hence gain privilege escalation. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1

    Published:17 Feb 2022
    8.8
    High

    CVE-2021-44673

    Last Modified: 11 Mar 2022

    A Remote Code Execution (RCE) vulnerability exists in Croogo 3.0.2via admin/file-manager/attachments, which lets a malicoius user upload a web shell script.

    Source:Deha Berkin Bir
    Published:10 Mar 2022
    6.1
    Medium

    CVE-2021-44667

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability exists in Nacos 2.0.3 in auth/users via the (1) pageSize and (2) pageNo parameters.

    Published:11 Mar 2022
    6.5
    Medium

    CVE-2021-44665

    Last Modified: 2 Mar 2022

    A Directory Traversal vulnerability exists in the Xerte Project Xerte through 3.10.3 when downloading a project file via download.php.

    Source:Rik Lutz
    Published:24 Feb 2022
    8.8
    High

    CVE-2021-44664

    Last Modified: 2 Mar 2022

    An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by uploading a maliciously crafted PHP file though the project interface disguised as a language file to bypasses the upload filters. Attackers can manipulate the files destination by abusing path traversal in the 'mediapath' variable.

    Source:Rik Lutz
    Published:24 Feb 2022
    9.8
    Critical

    CVE-2021-44655

    Last Modified: 16 Dec 2021

    Online Pre-owned/Used Car Showroom Management System 1.0 contains a SQL injection authentication bypass vulnerability. Admin panel authentication can be bypassed due to SQL injection vulnerability in the login form allowing attacker to get admin access on the application.

    Source:Mohamed habib Smidi
    Published:15 Dec 2021
    9.8
    Critical

    CVE-2021-44653

    Last Modified: 16 Dec 2021

    Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel authentication can be bypassed due to SQL injection vulnerability in the login form allowing attacker to gain access as admin to the application.

    Source:Mohamed habib Smidi
    Published:15 Dec 2021
    9.8
    Critical

    CVE-2021-44596

    Last Modified: 12 May 2022

    Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an unauthenticated user can communicate over UDP with the "InstallAssistService.exe" service(the service is running under SYSTEM privileges) and manipulate it to execute malicious executable without any validation from a remote location and gain SYSTEM privileges

    Source:Netanel Cohen
    Published:29 Apr 2022
    8.8
    High

    CVE-2021-44595

    Last Modified: 27 Jun 2022

    Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send manually crafted packets to the ElevationService.exe and execute arbitrary code without any validation with SYSTEM privileges.

    Source:Netanel Cohen
    Published:29 Apr 2022
    8.1
    High

    CVE-2021-44593

    Last Modified: 21 Nov 2024

    Simple College Website 1.0 is vulnerable to unauthenticated file upload & remote code execution via UNION-based SQL injection in the username parameter on /admin/login.php.

    Published:21 Jan 2022
    8.8
    High

    CVE-2021-44582

    Last Modified: 21 Nov 2024

    A Privilege Escalation vulnerability exists in Sourcecodester Money Transfer Management System 1.0, which allows a remote malicious user to gain elevated privileges to the Admin role via any URL.

    Published:10 Jun 2022
    9.8
    Critical

    CVE-2021-44567

    Last Modified: 13 Apr 2025

    An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php.

    Source:CodeSecLab
    Published:22 Feb 2022
    9.8
    Critical

    CVE-2021-44529

    Last Modified: 23 Mar 2022

    A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

    Source:d7x
    Published:8 Dec 2021
    9.1
    Critical

    CVE-2021-44521

    Last Modified: 21 Nov 2024

    When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on the host. The attacker would need to have enough permissions to create user defined functions in the cluster to be able to exploit this. Note that this configuration is documented as unsafe, and will continue to be considered unsafe after this CVE.

    Published:11 Feb 2022
    7.5
    High

    CVE-2021-44428

    Last Modified: 21 Nov 2024

    Pinkie 2.15 allows remote attackers to cause a denial of service (daemon crash) via a TFTP read (RRQ) request, aka opcode 1.

    Published:29 Nov 2021
    Unknown

    CVE-2021-44270

    https://github.com/pinpinsec/CVE-2021-44270

    7.2
    High

    CVE-2021-44255

    Last Modified: 21 Nov 2024

    Authenticated remote code execution in MotionEye <= 0.42.1 and MotioneEyeOS <= 20200606 allows a remote attacker to upload a configuration backup file containing a malicious python pickle file which will execute arbitrary code on the server.

    Published:31 Jan 2022
    10
    Critical

    CVE-2021-44228

    Last Modified: 1 Apr 2023

    Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

    Source:Chan Nyein Wai
    Published:10 Dec 2021
    6.1
    Medium

    CVE-2021-44217

    Last Modified: 21 Nov 2024

    In Ericsson CodeChecker through 6.18.0, a Stored Cross-site scripting (XSS) vulnerability in the comments component of the reports viewer allows remote attackers to inject arbitrary web script or HTML via the POST JSON data of the /CodeCheckerService API.

    Published:18 Jan 2022
    3.3
    Low

    CVE-2021-44168

    Last Modified: 24 Oct 2025

    A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages.

    Published:4 Jan 2022
    8.8
    High

    CVE-2021-44142

    Last Modified: 23 Apr 2025

    The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.

    Published:31 Jan 2022
    7.8
    High

    CVE-2021-44132

    Last Modified: 21 Nov 2024

    A command injection vulnerability in the function formImportOMCIShell of C-DATA ONU4FERW V2.1.13_X139 allows attackers to execute arbitrary commands via a crafted file.

    Published:25 Feb 2022
    8.8
    High

    CVE-2021-44117

    Last Modified: 21 Nov 2024

    A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/sitevariables/delete/4.

    Published:10 Jun 2022
    Low

    CVE-2021-44103

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-42192. Reason: This candidate is a duplicate of CVE-2021-42192. Notes: All CVE users should reference CVE-2021-42192 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published:28 Mar 2022
    9.8
    Critical

    CVE-2021-44077

    Last Modified: 31 Oct 2025

    Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.

    Published:29 Nov 2021
    9.8
    Critical

    CVE-2021-44026

    Last Modified: 4 Nov 2025

    Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

    Published:19 Nov 2021
    10
    Critical

    CVE-2021-43936

    Last Modified: 13 Dec 2021

    The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's environment or lead to arbitrary code execution.

    Source:Jeremiasz Pluta
    Published:6 Dec 2021
    4.3
    Medium

    CVE-2021-43908

    Last Modified: 21 Nov 2024

    Visual Studio Code Spoofing Vulnerability

    Published:15 Dec 2021
    7.5
    High

    CVE-2021-43893

    Last Modified: 21 Nov 2024

    Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability

    Published:15 Dec 2021
    7.8
    High

    CVE-2021-43891

    Last Modified: 21 Nov 2024

    Visual Studio Code Remote Code Execution Vulnerability

    Published:15 Dec 2021
    7.8
    High

    CVE-2021-43883

    Last Modified: 21 Nov 2024

    Windows Installer Elevation of Privilege Vulnerability

    Published:15 Dec 2021
    7.5
    High

    CVE-2021-43859

    Last Modified: 3 Nov 2025

    XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded. Users are advised to upgrade as soon as possible. Users unable to upgrade may set the NO_REFERENCE mode to prevent recursion. See GHSA-rmr5-cpv2-vgjf for further details on a workaround if an upgrade is not possible.

    Published:29 Jan 2022
    8.8
    High

    CVE-2021-43858

    Last Modified: 21 Nov 2024

    MinIO is a Kubernetes native application for cloud storage. Prior to version `RELEASE.2021-12-27T07-23-18Z`, a malicious client can hand-craft an HTTP API call that allows for updating policy for a user and gaining higher privileges. The patch in version `RELEASE.2021-12-27T07-23-18Z` changes the accepted request body type and removes the ability to apply policy changes through this API. There is a workaround for this vulnerability: Changing passwords can be disabled by adding an explicit `Deny` rule to disable the API for users.

    Published:27 Dec 2021
    9.8
    Critical

    CVE-2021-43857

    Last Modified: 5 Jan 2022

    Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched in version 0.9.8.

    Source:Jeremiasz Pluta
    Published:27 Dec 2021
    7.4
    High

    CVE-2021-43848

    Last Modified: 23 Apr 2025

    h2o is an open source http server. In code prior to the `8c0eca3` commit h2o may attempt to access uninitialized memory. When receiving QUIC frames in certain order, HTTP/3 server-side implementation of h2o can be misguided to treat uninitialized memory as HTTP/3 frames that have been received. When h2o is used as a reverse proxy, an attacker can abuse this vulnerability to send internal state of h2o to backend servers controlled by the attacker or third party. Also, if there is an HTTP endpoint that reflects the traffic sent from the client, an attacker can use that reflector to obtain internal state of h2o. This internal state includes traffic of other connections in unencrypted form and TLS session tickets. This vulnerability exists in h2o server with HTTP/3 support, between commit 93af138 and d1f0f65. None of the released versions of h2o are affected by this vulnerability. There are no known workarounds. Users of unreleased versions of h2o using HTTP/3 are advised to upgrade immediately.

    Published:1 Feb 2022
    9.9
    Critical

    CVE-2021-43821

    Last Modified: 21 Nov 2024

    Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast before version 9.10 or 10.6 allows references to local file URLs in ingested media packages, allowing attackers to include local files from Opencast's host machines and making them available via the web interface. Before Opencast 9.10 and 10.6, Opencast would open and include local files during ingests. Attackers could exploit this to include most local files the process has read access to, extracting secrets from the host machine. An attacker would need to have the privileges required to add new media to exploit this. But these are often widely given. The issue has been fixed in Opencast 10.6 and 11.0. You can mitigate this issue by narrowing down the read access Opencast has to files on the file system using UNIX permissions or mandatory access control systems like SELinux. This cannot prevent access to files Opencast needs to read though and we highly recommend updating.

    Published:14 Dec 2021
    7.8
    High

    CVE-2021-43811

    Last Modified: 21 Nov 2024

    Sockeye is an open-source sequence-to-sequence framework for Neural Machine Translation built on PyTorch. Sockeye uses YAML to store model and data configurations on disk. Versions below 2.3.24 use unsafe YAML loading, which can be made to execute arbitrary code embedded in config files. An attacker can add malicious code to the config file of a trained model and attempt to convince users to download and run it. If users run the model, the embedded code will run locally. The issue is fixed in version 2.3.24.

    Published:8 Dec 2021
    8.6
    High

    CVE-2021-43799

    Last Modified: 23 Apr 2025

    Zulip is an open-source team collaboration tool. Zulip Server installs RabbitMQ for internal message passing. In versions of Zulip Server prior to 4.9, the initial installation (until first reboot, or restart of RabbitMQ) does not successfully limit the default ports which RabbitMQ opens; this includes port 25672, the RabbitMQ distribution port, which is used as a management port. RabbitMQ's default "cookie" which protects this port is generated using a weak PRNG, which limits the entropy of the password to at most 36 bits; in practicality, the seed for the randomizer is biased, resulting in approximately 20 bits of entropy. If other firewalls (at the OS or network level) do not protect port 25672, a remote attacker can brute-force the 20 bits of entropy in the "cookie" and leverage it for arbitrary execution of code as the rabbitmq user. They can also read all data which is sent through RabbitMQ, which includes all message traffic sent by users. Version 4.9 contains a patch for this vulnerability. As a workaround, ensure that firewalls prevent access to ports 5672 and 25672 from outside the Zulip server.

    Published:25 Jan 2022
    7.5
    High

    CVE-2021-43798

    Last Modified: 9 Dec 2021

    Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.

    Source:s1gh
    Published:7 Dec 2021
    7.5
    High

    CVE-2021-43789

    Last Modified: 21 Nov 2024

    PrestaShop is an Open Source e-commerce web application. Versions of PrestaShop prior to 1.7.8.2 are vulnerable to blind SQL injection using search filters with `orderBy` and `sortOrder` parameters. The problem is fixed in version 1.7.8.2.

    Published:7 Dec 2021
    9.1
    Critical

    CVE-2021-43778

    Last Modified: 8 Sept 2025

    Barcode is a GLPI plugin for printing barcodes and QR codes. GLPI instances version 2.x prior to version 2.6.1 with the barcode plugin installed are vulnerable to a path traversal vulnerability. This issue was patched in version 2.6.1. As a workaround, delete the `front/send.php` file.

    Published:24 Nov 2021
    9.8
    Critical

    CVE-2021-43716

    Last Modified: 24 Aug 2026

    Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20. The Epson projector can be updated by encrypted firmware through USB.

    Published:18 Aug 2026
    6.5
    Medium

    CVE-2021-43701

    Last Modified: 30 Mar 2022

    CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injection vulnerability in the endpoint /admin/export/getcsv/article_db, via the fieldS[] and orderby parameters.

    Source:Rahad Chowdhury
    Published:29 Mar 2022
    5.4
    Medium

    CVE-2021-43657

    Last Modified: 16 Apr 2025

    A Stored Cross-site scripting (XSS) vulnerability via MAster.php in Sourcecodetester Simple Client Management System (SCMS) 1.0 allows remote attackers to inject arbitrary web script or HTML via the vulnerable input fields.

    Published:22 Dec 2022
    9.8
    Critical

    CVE-2021-43650

    Last Modified: 22 Apr 2022

    WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process.

    Source:Vinicius Alves
    Published:22 Mar 2022