9.8
    Critical

    CVE-2021-43617

    Last Modified: 16 Nov 2021

    Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for .phar files, which are handled as application/x-httpd-php on systems based on Debian. NOTE: this CVE Record is for Laravel Framework, and is unrelated to any reports concerning incorrectly written user applications for image upload.

    Source:Hosein Vita
    Published:14 Nov 2021
    9
    Critical

    CVE-2021-43616

    Last Modified: 21 Nov 2024

    The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact version match requirement in package-lock.json. NOTE: The npm team believes this is not a vulnerability. It would require someone to socially engineer package.json which has different dependencies than package-lock.json. That user would have to have file system or write access to change dependencies. The npm team states preventing malicious actors from socially engineering or gaining file system access is outside the scope of the npm CLI.

    Published:15 Feb 2021
    9.9
    Critical

    CVE-2021-43609

    Last Modified: 21 Nov 2024

    An issue was discovered in Spiceworks Help Desk Server before 1.3.3. A Blind Boolean SQL injection vulnerability within the order_by_for_ticket function in app/models/reporting/database_query.rb allows an authenticated attacker to execute arbitrary SQL commands via the sort parameter. This can be leveraged to leak local files from the host system, leading to remote code execution (RCE) through deserialization of malicious data.

    Published:8 Nov 2023
    7.8
    High

    CVE-2021-43579

    Last Modified: 29 Oct 2025

    A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linking to a crafted BMP file.

    Source:wulfgarpro
    Published:12 Nov 2021
    7.5
    High

    CVE-2021-43557

    Last Modified: 21 Nov 2024

    The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without verification. The $request_uri is the full original request URI without normalization. This makes it possible to construct a URI to bypass the block list on some occasions. For instance, when the block list contains "^/internal/", a URI like `//internal/` can be used to bypass it. Some other plugins also have the same issue. And it may affect the developer's custom plugin.

    Published:22 Nov 2021
    6.1
    Medium

    CVE-2021-43530

    Last Modified: 21 Nov 2024

    A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a URL scanned from a QR code. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94.

    Published:8 Dec 2021
    7.8
    High

    CVE-2021-43515

    Last Modified: 21 Nov 2024

    CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the Description field with malicious payload, it will be mistreated while exporting to a CSV file.

    Published:8 Apr 2022
    Low

    CVE-2021-43503

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published:8 Apr 2022
    9.8
    Critical

    CVE-2021-43481

    Last Modified: 11 May 2022

    An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php.

    Source:Behrad Taher
    Published:20 Apr 2022
    7.5
    High

    CVE-2021-43471

    Last Modified: 21 Nov 2024

    In Canon LBP223 printers, the System Manager Mode login does not require an account password or PIN. An attacker can remotely shut down the device after entering the background, creating a denial of service vulnerability.

    Published:6 Dec 2021
    8.8
    High

    CVE-2021-43469

    Last Modified: 21 Nov 2024

    VINGA WR-N300U 77.102.1.4853 is affected by a command execution vulnerability in the goahead component.

    Published:6 Dec 2021
    6.5
    Medium

    CVE-2021-43408

    Last Modified: 21 Nov 2024

    The "Duplicate Post" WordPress plugin up to and including version 1.1.9 is vulnerable to SQL Injection. SQL injection vulnerabilities occur when client supplied data is included within an SQL Query insecurely. SQL Injection can typically be exploited to read, modify and delete SQL table data. In many cases it also possible to exploit features of SQL server to execute system commands and/or access the local file system. This particular vulnerability can be exploited by any authenticated user who has been granted access to use the Duplicate Post plugin. By default, this is limited to Administrators, however the plugin presents the option to permit access to the Editor, Author, Contributor and Subscriber roles.

    Published:19 Nov 2021
    8.8
    High

    CVE-2021-43405

    Last Modified: 8 Nov 2021

    An issue was discovered in FusionPBX before 4.5.30. The fax_extension may have risky characters (it is not constrained to be numeric).

    Source:Luska
    Published:5 Nov 2021
    8.8
    High

    CVE-2021-43339

    Last Modified: 16 Nov 2021

    In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export functionality. For example, a new admin user could be created.

    Source:AkkuS
    Published:3 Nov 2021
    Low

    CVE-2021-43338

    Last Modified: 16 Nov 2021

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-43339. Reason: This candidate is a duplicate of CVE-2021-43339. Notes: All CVE users should reference CVE-2021-43339 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:AkkuS
    Published:3 Nov 2021
    7.8
    High

    CVE-2021-43326

    Last Modified: 5 Jan 2022

    Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory.

    Source:Greg Foss
    Published:15 Dec 2021
    9.8
    Critical

    CVE-2021-43297

    Last Modified: 21 Nov 2024

    A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/deserialization protocol, during Hessian catch unexpected exceptions, Hessian will log out some imformation for users, which may cause remote command execution. This issue affects Apache Dubbo Apache Dubbo 2.6.x versions prior to 2.6.12; Apache Dubbo 2.7.x versions prior to 2.7.15; Apache Dubbo 3.0.x versions prior to 3.0.5.

    Published:10 Jan 2022
    7.5
    High

    CVE-2021-43287

    Last Modified: 21 Nov 2024

    An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets known to the GoCD server to unauthenticated attackers.

    Published:14 Apr 2022
    9.8
    Critical

    CVE-2021-43267

    Last Modified: 21 Nov 2024

    An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type.

    Published:2 Nov 2021
    8.8
    High

    CVE-2021-43258

    Last Modified: 28 Apr 2025

    CartView.php in ChurchInfo 1.3.0 allows attackers to achieve remote code execution through insecure uploads. This requires authenticated access tot he ChurchInfo application. Once authenticated, a user can add names to their cart, and compose an email. Uploading an attachment for the email stores the attachment on the site in the /tmp_attach/ folder where it can be accessed with a GET request. There are no limitations on files that can be attached, allowing for malicious PHP code to be uploaded and interpreted by the server.

    Published:23 Nov 2022
    7.8
    High

    CVE-2021-43229

    Last Modified: 21 Nov 2024

    Windows NTFS Elevation of Privilege Vulnerability

    Published:15 Dec 2021
    7.8
    High

    CVE-2021-43226

    Last Modified: 30 Oct 2025

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

    Published:15 Dec 2021
    5.5
    Medium

    CVE-2021-43224

    Last Modified: 21 Nov 2024

    Windows Common Log File System Driver Information Disclosure Vulnerability

    Published:15 Dec 2021
    8.1
    High

    CVE-2021-43217

    Last Modified: 21 Nov 2024

    Windows Encrypting File System (EFS) Remote Code Execution Vulnerability

    Published:15 Dec 2021
    8.8
    High

    CVE-2021-43164

    Last Modified: 11 May 2022

    A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the updateVersion function in /cgi-bin/luci/api/wireless.

    Source:Minh Khoa
    Published:4 May 2022
    Low

    CVE-2021-43149

    Last Modified: 7 Apr 2022

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Source:Marlon Petry
    Published:8 Apr 2022
    6.1
    Medium

    CVE-2021-43141

    Last Modified: 24 Feb 2025

    Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Simple Subscription Website 1.0 via the id parameter in plan_application.

    Published:3 Nov 2021
    9.8
    Critical

    CVE-2021-43140

    Last Modified: 15 Nov 2021

    SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login.

    Source:Daniel Haro
    Published:3 Nov 2021
    9.8
    Critical

    CVE-2021-43136

    Last Modified: 11 Nov 2021

    An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform.

    Source:Cristian \'void\' Giustini
    Published:10 Nov 2021
    6.5
    Medium

    CVE-2021-43129

    Last Modified: 21 Nov 2024

    A bypass exists for Desire2Learn/D2L Brightspace’s “Disable Right Click” option in the quizzing feature, which allows a quiz-taker to access print and copy functionality via the browser’s right click menu even when “Disable Right Click” is enabled on the quiz.

    Published:19 Apr 2022
    8.8
    High

    CVE-2021-43116

    Last Modified: 3 Apr 2023

    An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and then change the returned package, which lets a malicious user login.

    Source:Jenson Zhao
    Published:5 Jul 2022
    6.1
    Medium

    CVE-2021-43062

    Last Modified: 18 Feb 2022

    A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows attacker to execute unauthorized code or commands via crafted HTTP GET requests to the FortiGuard URI protection service.

    Source:Braiant Giraldo Villa
    Published:2 Feb 2022
    4.8
    Medium

    CVE-2021-43032

    Last Modified: 21 Nov 2024

    In XenForo through 2.2.7, a threat actor with access to the admin panel can create a new Advertisement via the Advertising function, and save an XSS payload in the body of the HTML document. This payload will execute globally on the client side.

    Published:3 Nov 2021
    6.1
    Medium

    CVE-2021-43009

    Last Modified: 7 Apr 2022

    A Cross Site Scripting (XSS) vulnerability exists in OpServices OpMon through 9.11 via the search parameter in the request URL.

    Source:Marlon Petry
    Published:8 Apr 2022
    7.5
    High

    CVE-2021-43008

    Last Modified: 21 Nov 2024

    Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on the remote server by requesting the Adminer to connect to a remote MySQL database.

    Published:5 Apr 2022
    9.8
    Critical

    CVE-2021-42949

    Last Modified: 3 Jun 2025

    The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to bypass authentication via bruteforce attacks.

    Published:16 Sept 2022
    3.7
    Low

    CVE-2021-42948

    Last Modified: 21 Nov 2024

    HotelDruid Hotel Management Software v3.0.3 and below was discovered to have exposed session tokens in multiple links via GET parameters, allowing attackers to access user session id's.

    Published:16 Sept 2022
    7.5
    High

    CVE-2021-42913

    Last Modified: 21 Nov 2024

    The SyncThru Web Service on Samsung SCX-6x55X printers allows an attacker to gain access to a list of SMB users and cleartext passwords by reading the HTML source code. Authentication is not required.

    Published:20 Dec 2021
    8.8
    High

    CVE-2021-42840

    Last Modified: 17 Nov 2021

    SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file under the web root, because only the all-lowercase PHP file extensions were blocked. NOTE: this issue exists because of an incomplete fix for CVE-2020-28328.

    Source:M. Cory Billington
    Published:22 Oct 2021
    7
    High

    CVE-2021-42835

    Last Modified: 21 Nov 2024

    An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee. An attacker (with a foothold in a endpoint via a low-privileged user account) can access the exposed RPC service of the update service component. This RPC functionality allows the attacker to interact with the RPC functionality and execute code from a path of his choice (local, or remote via SMB) because of a TOCTOU race condition. This code execution is in the context of the Plex update service (which runs as SYSTEM).

    Published:8 Dec 2021
    9.3
    Critical

    CVE-2021-42756

    Last Modified: 21 Nov 2024

    Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve arbitrary code execution via specifically crafted HTTP requests.

    Published:16 Feb 2023
    4.8
    Medium

    CVE-2021-42751

    Last Modified: 9 Aug 2022

    A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the description of a rule node.

    Source:Steffen Langenfeld
    Published:12 Aug 2022
    4.8
    Medium

    CVE-2021-42750

    Last Modified: 9 Aug 2022

    A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the title of a rule node.

    Source:Steffen Langenfeld
    Published:12 Aug 2022
    7.5
    High

    CVE-2021-42717

    Last Modified: 3 Jul 2025

    ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for minutes and consume almost all of the available CPU on the machine. Modsecurity 2 is similarly vulnerable: the affected versions include 2.8.0 through 2.9.4.

    Published:7 Dec 2021
    7.5
    High

    CVE-2021-42697

    Last Modified: 11 May 2022

    Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, which allows a remote attacker to conduct a Denial of Service attack by sending a User-Agent header with deeply nested comments.

    Source:cxosmo
    Published:2 Nov 2021
    8.3
    High

    CVE-2021-42694

    Last Modified: 21 Nov 2024

    An issue was discovered in the character definitions of the Unicode Specification through 14.0. The specification allows an adversary to produce source code identifiers such as function names using homoglyphs that render visually identical to a target identifier. Adversaries can leverage this to inject code via adversarial identifier definitions in upstream software dependencies invoked deceptively in downstream software. NOTE: the Unicode Consortium offers the following alternative approach to presenting this concern. An issue is noted in the nature of international text that can affect applications that implement support for The Unicode Standard (all versions). Unless mitigated, an adversary could produce source code identifiers using homoglyph characters that render visually identical to but are distinct from a target identifier. In this way, an adversary could inject adversarial identifier definitions in upstream software that are not detected by human reviewers and are invoked deceptively in downstream software. The Unicode Consortium has documented this class of security vulnerability in its document, Unicode Technical Report #36, Unicode Security Considerations. The Unicode Consortium also provides guidance on mitigations for this class of issues in Unicode Technical Standard #39, Unicode Security Mechanisms.

    Published:1 Nov 2021
    7.5
    High

    CVE-2021-42671

    Last Modified: 21 Nov 2024

    An incorrect access control vulnerability exists in Sourcecodester Engineers Online Portal in PHP in nia_munoz_monitoring_system/admin/uploads. An attacker can leverage this vulnerability in order to bypass access controls and access all the files uploaded to the web server without the need of authentication or authorization.

    Published:5 Nov 2021
    9.8
    Critical

    CVE-2021-42670

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to the announcements_student.php web page. As a result a malicious user can extract sensitive data from the web server and in some cases use this vulnerability in order to get a remote code execution on the remote web server.

    Published:5 Nov 2021
    9.8
    Critical

    CVE-2021-42669

    Last Modified: 21 Nov 2024

    A file upload vulnerability exists in Sourcecodester Engineers Online Portal in PHP via dashboard_teacher.php, which allows changing the avatar through teacher_avatar.php. Once an avatar gets uploaded it is getting uploaded to the /admin/uploads/ directory, and is accessible by all users. By uploading a php webshell containing "<?php system($_GET["cmd"]); ?>" the attacker can execute commands on the web server with - /admin/uploads/php-webshell?cmd=id.

    Published:5 Nov 2021
    9.8
    Critical

    CVE-2021-42668

    Last Modified: 21 Nov 2024

    A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter in the my_classmates.php web page.. As a result, an attacker can extract sensitive data from the web server and in some cases can use this vulnerability in order to get a remote code execution on the remote web server.

    Published:5 Nov 2021