7.5
    High

    CVE-2021-41651

    Last Modified: 21 Nov 2024

    A blind SQL injection vulnerability exists in the Raymart DG / Ahmed Helal Hotel-mgmt-system. A malicious attacker can retrieve sensitive database information and interact with the database using the vulnerable cid parameter in process_update_profile.php.

    Published:4 Oct 2021
    9.8
    Critical

    CVE-2021-41649

    Last Modified: 21 Nov 2024

    An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.

    Published:1 Oct 2021
    7.5
    High

    CVE-2021-41648

    Last Modified: 21 Nov 2024

    An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter. Using a post request does not sanitize the user input.

    Published:1 Oct 2021
    9.1
    Critical

    CVE-2021-41647

    Last Modified: 21 Nov 2024

    An un-authenticated error-based and time-based blind SQL injection vulnerability exists in Kaushik Jadhav Online Food Ordering Web App 1.0. An attacker can exploit the vulnerable "username" parameter in login.php and retrieve sensitive database information, as well as add an administrative user.

    Published:1 Oct 2021
    9.8
    Critical

    CVE-2021-41646

    Last Modified: 14 Apr 2026

    Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypasses the image upload filters..

    Published:29 Oct 2021
    8.8
    High

    CVE-2021-41645

    Last Modified: 21 Nov 2024

    Remote Code Execution (RCE) vulnerability exists in Sourcecodester Budget and Expense Tracker System 1.0 that allows a remote malicious user to inject arbitrary code via the image upload field. .

    Published:29 Oct 2021
    9.8
    Critical

    CVE-2021-41644

    Last Modified: 30 Mar 2026

    Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that bypasses the image upload filters.

    Published:29 Oct 2021
    9.8
    Critical

    CVE-2021-41643

    Last Modified: 21 Nov 2024

    Remote Code Execution (RCE) vulnerability exists in Sourcecodester Church Management System 1.0 via the image upload field.

    Published:29 Oct 2021
    7
    High

    CVE-2021-41617

    Last Modified: 12 May 2026

    sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user.

    Published:26 Sept 2021
    7.8
    High

    CVE-2021-41579

    Last Modified: 21 Nov 2024

    LCDS LAquis SCADA through 4.3.1.1085 is vulnerable to a control bypass and path traversal. If an attacker can get a victim to load a malicious els project file and use the play feature, then the attacker can bypass a consent popup and write arbitrary files to OS locations where the user has permission, leading to code execution.

    Published:4 Oct 2021
    9.8
    Critical

    CVE-2021-41560

    Last Modified: 21 Nov 2024

    OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUtility.php.

    Published:15 Dec 2021
    9.8
    Critical

    CVE-2021-41511

    Last Modified: 21 Nov 2024

    The username and password field of login in Lodging Reservation Management System V1 can give access to any user by using SQL injection to bypass authentication.

    Published:4 Oct 2021
    7.5
    High

    CVE-2021-41382

    Last Modified: 18 Oct 2021

    Plastic SCM before 10.0.16.5622 mishandles the WebAdmin server management interface.

    Source:Basavaraj Banakar
    Published:21 Sept 2021
    7.5
    High

    CVE-2021-41381

    Last Modified: 4 Oct 2021

    Payara Micro Community 5.2021.6 and below allows Directory Traversal.

    Source:Yasser Khan
    Published:23 Sept 2021
    4.3
    Medium

    CVE-2021-41351

    Last Modified: 19 Aug 2026

    Microsoft Edge (Chrome based) Spoofing on IE Mode

    Published:10 Nov 2021
    6.5
    Medium

    CVE-2021-41349

    Last Modified: 19 Aug 2026

    Microsoft Exchange Server Spoofing Vulnerability

    Published:10 Nov 2021
    5.5
    Medium

    CVE-2021-41338

    Last Modified: 21 Nov 2024

    Windows AppContainer Firewall Rules Security Feature Bypass Vulnerability

    Published:13 Oct 2021
    6.1
    Medium

    CVE-2021-41318

    Last Modified: 1 Oct 2021

    In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input. which could allow an unauthenticated attacker to execute arbitrary code in a victim's browser.

    Source:Andreas Finstad
    Published:28 Sept 2021
    5.7
    Medium

    CVE-2021-41278

    Last Modified: 21 Nov 2024

    Functions SDK for EdgeX is meant to provide all the plumbing necessary for developers to get started in processing/transforming/exporting data out of the EdgeX IoT platform. In affected versions broken encryption in app-functions-sdk “AES” transform in EdgeX Foundry releases prior to Jakarta allows attackers to decrypt messages via unspecified vectors. The app-functions-sdk exports an “aes” transform that user scripts can optionally call to encrypt data in the processing pipeline. No decrypt function is provided. Encryption is not enabled by default, but if used, the level of protection may be less than the user may expects due to a broken implementation. Version v2.1.0 (EdgeX Foundry Jakarta release and later) of app-functions-sdk-go/v2 deprecates the “aes” transform and provides an improved “aes256” transform in its place. The broken implementation will remain in a deprecated state until it is removed in the next EdgeX major release to avoid breakage of existing software that depends on the broken implementation. As the broken transform is a library function that is not invoked by default, users who do not use the AES transform in their processing pipelines are unaffected. Those that are affected are urged to upgrade to the Jakarta EdgeX release and modify processing pipelines to use the new "aes256" transform.

    Published:18 Nov 2021
    10
    Critical

    CVE-2021-41277

    Last Modified: 24 Oct 2025

    Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the application.

    Published:17 Nov 2021
    10
    Critical

    CVE-2021-41269

    Last Modified: 21 Nov 2024

    cron-utils is a Java library to define, parse, validate, migrate crons as well as get human readable descriptions for them. In affected versions A template Injection was identified in cron-utils enabling attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. Versions up to 9.1.2 are susceptible to this vulnerability. Please note, that only projects using the @Cron annotation to validate untrusted Cron expressions are affected. The issue was patched and a new version was released. Please upgrade to version 9.1.6. There are no known workarounds known.

    Published:15 Nov 2021
    6.5
    Medium

    CVE-2021-41184

    Last Modified: 25 Aug 2026

    jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.

    Published:25 Oct 2021
    6.5
    Medium

    CVE-2021-41182

    Last Modified: 25 Aug 2026

    jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not accept the value of the `altField` option from untrusted sources.

    Published:25 Oct 2021
    10
    Critical

    CVE-2021-41163

    Last Modified: 21 Nov 2024

    Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could lead to remote code execution. This resulted from a lack of validation in subscribe_url values. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. To workaround the issue without updating, requests with a path starting /webhooks/aws path could be blocked at an upstream proxy.

    Published:20 Oct 2021
    5.3
    Medium

    CVE-2021-41160

    Last Modified: 3 Nov 2025

    FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions a malicious server might trigger out of bound writes in a connected client. Connections using GDI or SurfaceCommands to send graphics updates to the client might send `0` width/height or out of bound rectangles to trigger out of bound writes. With `0` width or heigth the memory allocation will be `0` but the missing bounds checks allow writing to the pointer at this (not allocated) region. This issue has been patched in FreeRDP 2.4.1.

    Published:21 Oct 2021
    8.7
    High

    CVE-2021-41117

    Last Modified: 21 Nov 2024

    keypair is a a RSA PEM key generator written in javascript. keypair implements a lot of cryptographic primitives on its own or by borrowing from other libraries where possible, including node-forge. An issue was discovered where this library was generating identical RSA keys used in SSH. This would mean that the library is generating identical P, Q (and thus N) values which, in practical terms, is impossible with RSA-2048 keys. Generating identical values, repeatedly, usually indicates an issue with poor random number generation, or, poor handling of CSPRNG output. Issue 1: Poor random number generation (`GHSL-2021-1012`). The library does not rely entirely on a platform provided CSPRNG, rather, it uses it's own counter-based CMAC approach. Where things go wrong is seeding the CMAC implementation with "true" random data in the function `defaultSeedFile`. In order to seed the AES-CMAC generator, the library will take two different approaches depending on the JavaScript execution environment. In a browser, the library will use [`window.crypto.getRandomValues()`](https://github.com/juliangruber/keypair/blob/87c62f255baa12c1ec4f98a91600f82af80be6db/index.js#L971). However, in a nodeJS execution environment, the `window` object is not defined, so it goes down a much less secure solution, also of which has a bug in it. It does look like the library tries to use node's CSPRNG when possible unfortunately, it looks like the `crypto` object is null because a variable was declared with the same name, and set to `null`. So the node CSPRNG path is never taken. However, when `window.crypto.getRandomValues()` is not available, a Lehmer LCG random number generator is used to seed the CMAC counter, and the LCG is seeded with `Math.random`. While this is poor and would likely qualify in a security bug in itself, it does not explain the extreme frequency in which duplicate keys occur. The main flaw: The output from the Lehmer LCG is encoded incorrectly. The specific [line][https://github.com/juliangruber/keypair/blob/87c62f255baa12c1ec4f98a91600f82af80be6db/index.js#L1008] with the flaw is: `b.putByte(String.fromCharCode(next & 0xFF))` The [definition](https://github.com/juliangruber/keypair/blob/87c62f255baa12c1ec4f98a91600f82af80be6db/index.js#L350-L352) of `putByte` is `util.ByteBuffer.prototype.putByte = function(b) {this.data += String.fromCharCode(b);};`. Simplified, this is `String.fromCharCode(String.fromCharCode(next & 0xFF))`. The double `String.fromCharCode` is almost certainly unintentional and the source of weak seeding. Unfortunately, this does not result in an error. Rather, it results most of the buffer containing zeros. Since we are masking with 0xFF, we can determine that 97% of the output from the LCG are converted to zeros. The only outputs that result in meaningful values are outputs 48 through 57, inclusive. The impact is that each byte in the RNG seed has a 97% chance of being 0 due to incorrect conversion. When it is not, the bytes are 0 through 9. In summary, there are three immediate concerns: 1. The library has an insecure random number fallback path. Ideally the library would require a strong CSPRNG instead of attempting to use a LCG and `Math.random`. 2. The library does not correctly use a strong random number generator when run in NodeJS, even though a strong CSPRNG is available. 3. The fallback path has an issue in the implementation where a majority of the seed data is going to effectively be zero. Due to the poor random number generation, keypair generates RSA keys that are relatively easy to guess. This could enable an attacker to decrypt confidential messages or gain authorized access to an account belonging to the victim.

    Published:11 Oct 2021
    6.3
    Medium

    CVE-2021-41091

    Last Modified: 21 Nov 2024

    Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where the data directory (typically `/var/lib/docker`) contained subdirectories with insufficiently restricted permissions, allowing otherwise unprivileged Linux users to traverse directory contents and execute programs. When containers included executable programs with extended permission bits (such as `setuid`), unprivileged Linux users could discover and execute those programs. When the UID of an unprivileged Linux user on the host collided with the file owner or group inside a container, the unprivileged Linux user on the host could discover, read, and modify those files. This bug has been fixed in Moby (Docker Engine) 20.10.9. Users should update to this version as soon as possible. Running containers should be stopped and restarted for the permissions to be fixed. For users unable to upgrade limit access to the host to trusted users. Limit access to host volumes to trusted containers.

    Published:4 Oct 2021
    9.8
    Critical

    CVE-2021-41081

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a configuration search.

    Published:11 Nov 2021
    7.8
    High

    CVE-2021-41078

    Last Modified: 21 Nov 2024

    Nameko through 2.13.0 can be tricked into performing arbitrary code execution when deserializing the config file.

    Published:26 Oct 2021
    5.4
    Medium

    CVE-2021-41074

    Last Modified: 22 Jan 2026

    A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document.

    Published:12 Jan 2026
    7.8
    High

    CVE-2021-41073

    Last Modified: 21 Nov 2024

    loop_rw_iter in fs/io_uring.c in the Linux kernel 5.10 through 5.14.6 allows local users to gain privileges by using IORING_OP_PROVIDE_BUFFERS to trigger a free of a kernel buffer, as demonstrated by using /proc/<pid>/maps for exploitation.

    Published:19 Sept 2021
    7.5
    High

    CVE-2021-40978

    Last Modified: 21 Nov 2024

    The mkdocs 1.2.2 built-in dev-server allows directory traversal using the port 8000, enabling remote exploitation to obtain :sensitive information. NOTE: the vendor has disputed this as described in https://github.com/mkdocs/mkdocs/issues/2601.] and https://github.com/nisdn/CVE-2021-40978/issues/1

    Published:7 Oct 2021
    6.5
    Medium

    CVE-2021-40964

    Last Modified: 16 Mar 2022

    A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload a file (with Admin credentials or with the CSRF vulnerability) with the "fullpath" parameter containing path traversal strings (../ and ..\) in order to escape the server's intended working directory and write malicious files onto any directory on the computer.

    Source:FEBIN MON SAJI
    Published:15 Sept 2021
    6.1
    Medium

    CVE-2021-40906

    Last Modified: 21 Nov 2024

    CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a backdoor on the device with HTML content and interpreted by the browser (such as JavaScript or other client-side scripts) or to steal the session cookies of a user who has previously authenticated via a man in the middle. Successful exploitation requires access to the web service resource without authentication.

    Published:25 Mar 2022
    8.8
    High

    CVE-2021-40905

    Last Modified: 5 Jul 2026

    The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which are Extension Packages, making remote code execution possible. Successful exploitation requires access to the web management interface, either with valid credentials or with a hijacked session of a user with administrator role. NOTE: the vendor states that this is the intended behavior: admins are supposed to be able to execute code in this manner.

    Published:25 Mar 2022
    8.8
    High

    CVE-2021-40904

    Last Modified: 21 Nov 2024

    The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default), which allows embedded php code. As a result, remote code execution is achieved. Successful exploitation requires access to the web management interface, either with valid credentials or with a hijacked session by a user with the role of administrator.

    Published:25 Mar 2022
    9.8
    Critical

    CVE-2021-40903

    Last Modified: 21 Nov 2024

    A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flask server. Settings file has a predefined secret string, which would be randomly generated, however it is static.

    Published:17 Jun 2022
    7.5
    High

    CVE-2021-40875

    Last Modified: 23 Sept 2021

    Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat actor can access the /files.md5 file on the client side of a Gurock TestRail application, disclosing a full list of application files and the corresponding file paths. The corresponding file paths can be tested, and in some cases, result in the disclosure of hardcoded credentials, API keys, or other sensitive data.

    Source:Sick Codes
    Published:22 Sept 2021
    9.8
    Critical

    CVE-2021-40870

    Last Modified: 10 Nov 2025

    An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

    Published:13 Sept 2021
    6.1
    Medium

    CVE-2021-40868

    Last Modified: 22 Sept 2021

    In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS.

    Source:Akıner Kısa
    Published:21 Sept 2021
    9.8
    Critical

    CVE-2021-40865

    Last Modified: 21 Nov 2024

    An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrade to version 2.1.1. Apache Storm 1.x users should upgrade to version 1.2.4

    Published:25 Oct 2021
    9.8
    Critical

    CVE-2021-40859

    Last Modified: 5 Jan 2022

    Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web based management application full administrative access to the device.

    Source:RedTeam Pentesting GmbH
    Published:7 Dec 2021
    8.8
    High

    CVE-2021-40845

    Last Modified: 21 Nov 2024

    The web part of Zenitel AlphaCom XE Audio Server through 11.2.3.10, called AlphaWeb XE, does not restrict file upload in the Custom Scripts section at php/index.php. Neither the content nor extension of the uploaded files is checked, allowing execution of PHP code under the /cmd directory.

    Published:15 Sept 2021
    7.5
    High

    CVE-2021-40839

    Last Modified: 21 Nov 2024

    The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabling a remote attack that consumes CPU and memory.

    Published:10 Sept 2021
    7.5
    High

    CVE-2021-40822

    Last Modified: 21 Nov 2024

    GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.

    Published:1 May 2022
    7.8
    High

    CVE-2021-40724

    Last Modified: 21 Nov 2024

    Acrobat Reader for Android versions 21.8.0 (and earlier) are affected by a Path traversal vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published:15 Oct 2021
    6.5
    Medium

    CVE-2021-40651

    Last Modified: 22 Oct 2021

    OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary file from the server's filesystem as long as the application has access to the file.

    Source:Eric Salario
    Published:29 Sept 2021
    9.8
    Critical

    CVE-2021-40617

    Last Modified: 3 Dec 2025

    An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php.

    Source:CodeSecLab
    Published:11 Oct 2021
    5.4
    Medium

    CVE-2021-40577

    Last Modified: 1 Dec 2021

    A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Enrollment Management System in PHP and PayPal Free Source Code 1.0 in the Add-Users page via the Name parameter.

    Source:Tushar Jadhav
    Published:8 Nov 2021
    9.8
    Critical

    CVE-2021-40539

    Last Modified: 5 Nov 2025

    Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.

    Published:7 Sept 2021