9.8
    Critical

    CVE-2021-40531

    Last Modified: 21 Nov 2024

    Sketch before 75 allows library feeds to be used to bypass file quarantine. Files are automatically downloaded and opened, without the com.apple.quarantine extended attribute. This results in remote code execution, as demonstrated by CommandString in a terminal profile to Terminal.app.

    Published:6 Sept 2021
    Unknown

    CVE-2021-40514

    https://github.com/war4uthor/CVE-2021-40514

    Unknown

    CVE-2021-40513

    https://github.com/war4uthor/CVE-2021-40513

    Unknown

    CVE-2021-40512

    https://github.com/war4uthor/CVE-2021-40512

    6.1
    Medium

    CVE-2021-40492

    Last Modified: 21 Nov 2024

    A reflected XSS vulnerability exists in multiple pages in version 22 of the Gibbon application that allows for arbitrary execution of JavaScript (gibbonCourseClassID, gibbonPersonID, subpage, currentDate, or allStudents to index.php).

    Published:3 Sept 2021
    7.8
    High

    CVE-2021-40449

    Last Modified: 30 Oct 2025

    Win32k Elevation of Privilege Vulnerability

    Published:13 Oct 2021
    8.8
    High

    CVE-2021-40444

    Last Modified: 10 Aug 2026

    Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents. An attacker could craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine. The attacker would then have to convince the user to open the malicious document. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Microsoft Defender Antivirus and Microsoft Defender for Endpoint both provide detection and protections for the known vulnerability. Customers should keep antimalware products up to date. Customers who utilize automatic updates do not need to take additional action. Enterprise customers who manage updates should select the detection build 1.349.22.0 or newer and deploy it across their environments. Microsoft Defender for Endpoint alerts will be displayed as: “Suspicious Cpl File Execution”. Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs. Please see the Mitigations and Workaround sections for important information about steps you can take to protect your system from this vulnerability. UPDATE September 14, 2021: Microsoft has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. Please see the FAQ for important information about which updates are applicable to your system.

    Published:15 Sept 2021
    9
    Critical

    CVE-2021-40438

    Last Modified: 5 Aug 2026

    A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

    Published:16 Sept 2021
    7.5
    High

    CVE-2021-40382

    Last Modified: 2 Sept 2021

    An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. mjpegStreamer.cgi allows video screenshot access.

    Source:icekam
    Published:1 Sept 2021
    7.5
    High

    CVE-2021-40381

    Last Modified: 2 Sept 2021

    An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. index_MJpeg.cgi allows video access.

    Source:icekam
    Published:1 Sept 2021
    7.5
    High

    CVE-2021-40380

    Last Modified: 2 Sept 2021

    An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. cameralist.cgi and setcamera.cgi disclose credentials.

    Source:icekam
    Published:1 Sept 2021
    7.5
    High

    CVE-2021-40379

    Last Modified: 2 Sept 2021

    An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. rstp://.../medias2 does not require authorization.

    Source:icekam
    Published:1 Sept 2021
    8.1
    High

    CVE-2021-40378

    Last Modified: 29 Oct 2021

    An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. /cgi-bin/support/killps.cgi deletes all data from the device.

    Source:icekam
    Published:1 Sept 2021
    6.5
    Medium

    CVE-2021-40375

    Last Modified: 21 Nov 2024

    Apperta Foundation OpenEyes 3.5.1 allows remote attackers to view the sensitive information of patients without having the intended level of privilege. Despite OpenEyes returning a Forbidden error message, the contents of a patient's profile are still returned in the server response. This response can be read in an intercepting proxy or by viewing the page source. Sensitive information returned in responses includes patient PII and medication records or history.

    Published:6 Apr 2022
    5.4
    Medium

    CVE-2021-40374

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability was identified in Apperta Foundation OpenEyes 3.5.1. Updating a patient's details allows remote attackers to inject arbitrary web script or HTML via the Address1 parameter. This JavaScript then executes when the patient profile is loaded, which could be used in a XSS attack.

    Published:6 Apr 2022
    9.8
    Critical

    CVE-2021-40373

    Last Modified: 21 Nov 2024

    playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then executing that code via the index.php?app=main&inc=core_welcome URI.

    Published:10 Sept 2021
    9.8
    Critical

    CVE-2021-40353

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the index.php USERNAME parameter. NOTE: this issue may exist because of an incomplete fix for CVE-2020-6637.

    Published:1 Sept 2021
    6.5
    Medium

    CVE-2021-40352

    Last Modified: 6 Sept 2021

    OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can read the messages of all users.

    Source:Allen Enosh Upputori
    Published:1 Sept 2021
    7.5
    High

    CVE-2021-40346

    Last Modified: 21 Nov 2024

    An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.

    Published:8 Sept 2021
    7.2
    High

    CVE-2021-40345

    Last Modified: 21 Nov 2024

    An issue was discovered in Nagios XI 5.8.5. In the Manage Dashlets section of the Admin panel, an administrator can upload ZIP files. A command injection (within the name of the first file in the archive) allows an attacker to execute system commands.

    Published:26 Oct 2021
    5.4
    Medium

    CVE-2021-40303

    Last Modified: 1 May 2025

    perfex crm 1.10 is vulnerable to Cross Site Scripting (XSS) via /clients/profile.

    Published:8 Nov 2022
    5.4
    Medium

    CVE-2021-40223

    Last Modified: 21 Nov 2024

    Rittal CMC PU III Web management (version V3.11.00_2) fails to sanitize user input on several parameters of the configuration (User Configuration dialog, Task Configuration dialog and set logging filter dialog). This allows an attacker to backdoor the device with HTML and browser-interpreted content (such as JavaScript or other client-side scripts). The XSS payload will be triggered when the user accesses some specific sections of the application.

    Published:9 Sept 2021
    7.2
    High

    CVE-2021-40222

    Last Modified: 21 Nov 2024

    Rittal CMC PU III Web management Version affected: V3.11.00_2. Version fixed: V3.17.10 is affected by a remote code execution vulnerablity. It is possible to introduce shell code to create a reverse shell in the PU-Hostname field of the TCP/IP Configuration dialog. Web application fails to sanitize user input on Network TCP/IP configuration page. This allows the attacker to inject commands as root on the device which will be executed once the data is received.

    Published:9 Sept 2021
    6.1
    Medium

    CVE-2021-40154

    Last Modified: 21 Nov 2024

    NXP LPC55S69 devices before A3 have a buffer over-read via a crafted wlength value in a GET Descriptor Configuration request during use of USB In-System Programming (ISP) mode. This discloses protected flash memory.

    Published:1 Dec 2021
    10
    Critical

    CVE-2021-40113

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following actions: Log in with a default credential if the Telnet protocol is enabled Perform command injection Modify the configuration For more information about these vulnerabilities, see the Details section of this advisory.

    Published:4 Nov 2021
    7.2
    High

    CVE-2021-40101

    Last Modified: 21 Nov 2024

    An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password.

    Published:30 Nov 2021
    7.8
    High

    CVE-2021-39863

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Buffer Overflow vulnerability when parsing a specially crafted PDF file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published:29 Sept 2021
    7.8
    High

    CVE-2021-39749

    Last Modified: 21 Nov 2024

    In WindowManager, there is a possible way to start non-exported and protected activities due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-205996115

    Published:30 Mar 2022
    7.8
    High

    CVE-2021-39706

    Last Modified: 21 Nov 2024

    In onResume of CredentialStorage.java, there is a possible way to cleanup content of credentials storage due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-200164168

    Published:16 Mar 2022
    7.8
    High

    CVE-2021-39704

    Last Modified: 21 Nov 2024

    In deleteNotificationChannelGroup of NotificationManagerService.java, there is a possible way to run foreground service without user notification due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-209965481

    Published:16 Mar 2022
    7.8
    High

    CVE-2021-39696

    Last Modified: 21 Nov 2024

    In Task.java, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-185810717

    Published:9 Aug 2022
    7.8
    High

    CVE-2021-39692

    Last Modified: 21 Nov 2024

    In onCreate of SetupLayoutActivity.java, there is a possible way to setup a work profile bypassing user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-209611539

    Published:16 Mar 2022
    7.8
    High

    CVE-2021-39685

    Last Modified: 21 Nov 2024

    In various setup methods of the USB gadget subsystem, there is a possible out of bounds write due to an incorrect flag check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-210292376References: Upstream kernel

    Published:15 Dec 2021
    5.5
    Medium

    CVE-2021-39670

    Last Modified: 21 Nov 2024

    In setStream of WallpaperManager.java, there is a possible way to cause a permanent DoS due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-204087139

    Published:10 May 2022
    7.2
    High

    CVE-2021-39608

    Last Modified: 6 Sept 2021

    Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a remote malicious user exeuct arbitrary php code.

    Source:Mason Soroka-Gill
    Published:23 Aug 2021
    Unknown

    CVE-2021-39512

    https://github.com/guusec/CVE-2021-39512-BigTreeCMS-v4.4.14-AccountTakeOver

    Unknown

    CVE-2021-39476

    https://github.com/W4RCL0UD/CVE-2021-39476

    Unknown

    CVE-2021-39475

    https://github.com/W4RCL0UD/CVE-2021-39475

    5.4
    Medium

    CVE-2021-39473

    Last Modified: 2 May 2025

    Saibamen HotelManager v1.2 is vulnerable to Cross Site Scripting (XSS) due to improper sanitization of comment and contact fields.

    Published:4 Nov 2022
    7.5
    High

    CVE-2021-39433

    Last Modified: 21 Nov 2024

    A local file inclusion (LFI) vulnerability exists in version BIQS IT Biqs-drive v1.83 and below when sending a specific payload as the file parameter to download/index.php. This allows the attacker to read arbitrary files from the server with the permissions of the configured web-user.

    Published:4 Oct 2021
    9.8
    Critical

    CVE-2021-39409

    Last Modified: 21 Nov 2024

    A vulnerability exists in Online Student Rate System v1.0 that allows any user to register as an administrator without needing to be authenticated.

    Published:24 Jun 2022
    6.1
    Medium

    CVE-2021-39408

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability exists in Online Student Rate System 1.0 via the page parameter on the index.php file

    Published:24 Jun 2022
    9.8
    Critical

    CVE-2021-39379

    Last Modified: 21 Nov 2024

    A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the ResetUserInfo.php password_stn_id parameter.

    Published:1 Sept 2021
    9.8
    Critical

    CVE-2021-39378

    Last Modified: 21 Nov 2024

    A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the NamesList.php str parameter.

    Published:1 Sept 2021
    9.8
    Critical

    CVE-2021-39377

    Last Modified: 21 Nov 2024

    A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the index.php username parameter.

    Published:1 Sept 2021
    5.3
    Medium

    CVE-2021-39327

    Last Modified: 6 Oct 2021

    The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible ~/db_backup_log.txt file which grants attackers the full path of the site, in addition to the path of database backup files. This affects versions up to, and including, 5.1.

    Source:Ron Jost
    Published:17 Sept 2021
    7.5
    High

    CVE-2021-39316

    Last Modified: 3 Dec 2021

    The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the `dzsap_download` action using directory traversal in the `link` parameter.

    Source:Uriel Yochpaz
    Published:31 Aug 2021
    7.5
    High

    CVE-2021-39312

    Last Modified: 5 Jan 2022

    The True Ranker plugin <= 2.2.2 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be accessed via the src parameter found in the ~/admin/vendor/datatables/examples/resources/examples.php file.

    Source:Liad Levy
    Published:14 Dec 2021
    Unknown

    CVE-2021-39287

    https://github.com/Fearless523/CVE-2021-39287-Stored-XSS

    8.8
    High

    CVE-2021-39273

    Last Modified: 21 Nov 2024

    In XeroSecurity Sn1per 9.0 (free version), insecure permissions (0777) are set upon application execution, allowing an unprivileged user to modify the application, modules, and configuration files. This leads to arbitrary code execution with root privileges.

    Published:19 Aug 2021