8.8
    High

    CVE-2021-39174

    Last Modified: 21 Nov 2024

    Cachet is an open source status page system. Prior to version 2.5.1, authenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret (`APP_KEY`) and various passwords (email, database, etc). This issue was addressed in version 2.5.1 by improving `UpdateConfigCommandHandler` and preventing the use of nested variables in the resulting dotenv configuration file. As a workaround, only allow trusted source IP addresses to access to the administration dashboard.

    Published:27 Aug 2021
    8.8
    High

    CVE-2021-39172

    Last Modified: 21 Nov 2024

    Cachet is an open source status page system. Prior to version 2.5.1, authenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. This issue was addressed in version 2.5.1 by improving `UpdateConfigCommandHandler` and preventing the use of new lines characters in new configuration values. As a workaround, only allow trusted source IP addresses to access to the administration dashboard.

    Published:27 Aug 2021
    8.1
    High

    CVE-2021-39165

    Last Modified: 21 Nov 2024

    Cachet is an open source status page. With Cachet prior to and including 2.3.18, there is a SQL injection which is in the `SearchableTrait#scopeSearch()`. Attackers without authentication can utilize this vulnerability to exfiltrate sensitive data from the database such as administrator's password and session. The original repository of Cachet <https://github.com/CachetHQ/Cachet> is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected.

    Published:26 Aug 2021
    8.1
    High

    CVE-2021-39156

    Last Modified: 21 Nov 2024

    Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. Istio 1.11.0, 1.10.3 and below, and 1.9.7 and below contain a remotely exploitable vulnerability where an HTTP request with `#fragment` in the path may bypass Istio’s URI path based authorization policies. Patches are available in Istio 1.11.1, Istio 1.10.4 and Istio 1.9.8. As a work around a Lua filter may be written to normalize the path.

    Published:24 Aug 2021
    8.5
    High

    CVE-2021-39141

    Last Modified: 23 May 2025

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.

    Published:22 Aug 2021
    7.2
    High

    CVE-2021-39115

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to execute arbitrary Java code or run arbitrary system commands via a Server_Side Template Injection vulnerability in the Email Template feature. The affected versions are before version 4.13.9, and from version 4.14.0 before 4.18.0.

    Published:1 Sept 2021
    8.8
    High

    CVE-2021-38819

    Last Modified: 30 Apr 2025

    A SQL injection vulnerability exits on the Simple Image Gallery System 1.0 application through "id" parameter on the album page.

    Published:16 Nov 2022
    Unknown

    CVE-2021-38817

    https://github.com/HuskyHacks/CVE-2021-38817-Remote-OS-Command-Injection

    9.8
    Critical

    CVE-2021-38759

    Last Modified: 9 Dec 2021

    Raspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not changed, attackers can gain administrator privileges.

    Source:netspooky
    Published:7 Dec 2021
    5.4
    Medium

    CVE-2021-38699

    Last Modified: 21 Nov 2024

    TastyIgniter 3.0.7 allows XSS via /account, /reservation, /admin/dashboard, and /admin/system_logs.

    Published:15 Aug 2021
    8.8
    High

    CVE-2021-38666

    Last Modified: 19 Aug 2026

    Remote Desktop Client Remote Code Execution Vulnerability

    Published:10 Nov 2021
    9.8
    Critical

    CVE-2021-38647

    Last Modified: 10 Aug 2026

    Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

    Published:15 Sept 2021
    7.8
    High

    CVE-2021-38639

    Last Modified: 10 Aug 2026

    Win32k Elevation of Privilege Vulnerability

    Published:15 Sept 2021
    6.1
    Medium

    CVE-2021-38619

    Last Modified: 21 Nov 2024

    openBaraza HCM 3.1.6 does not properly neutralize user-controllable input: an unauthenticated remote attacker can conduct a stored cross-site scripting (XSS) attack against an administrative user from hr/subscription.jsp and hr/application.jsp and and hr/index.jsp (with view=).

    Published:13 Aug 2021
    4.8
    Medium

    CVE-2021-38603

    Last Modified: 21 Nov 2024

    PluXML 5.8.7 allows core/admin/profil.php stored XSS via the Information field.

    Published:12 Aug 2021
    4.8
    Medium

    CVE-2021-38602

    Last Modified: 21 Nov 2024

    PluXML 5.8.7 allows Article Editing stored XSS via Headline or Content.

    Published:12 Aug 2021
    6.1
    Medium

    CVE-2021-38583

    Last Modified: 21 Nov 2024

    openBaraza HCM 3.1.6 does not properly neutralize user-controllable input, which allows reflected cross-site scripting (XSS) on multiple pages: hr/subscription.jsp and hr/application.jsp and and hr/index.jsp (with view= and data=).

    Published:13 Aug 2021
    6.1
    Medium

    CVE-2021-38560

    Last Modified: 21 Nov 2024

    Ivanti Service Manager 2021.1 allows reflected XSS via the appName parameter associated with ConfigDB calls, such as in RelocateAttachments.aspx.

    Published:1 Feb 2022
    9.8
    Critical

    CVE-2021-38540

    Last Modified: 21 Nov 2024

    The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information disclosure or remote code execution. This issue affects Apache Airflow >=2.0.0, <2.1.3.

    Published:9 Sept 2021
    5.3
    Medium

    CVE-2021-38314

    Last Modified: 5 May 2025

    The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions available to unauthenticated users in the `includes` function in `redux-core/class-redux-core.php` that were unique to a given site but deterministic and predictable given that they were based on an md5 hash of the site URL with a known salt value of '-redux' and an md5 hash of the previous hash with a known salt value of '-support'. These AJAX actions could be used to retrieve a list of active plugins and their versions, the site's PHP version, and an unsalted md5 hash of site’s `AUTH_KEY` concatenated with the `SECURE_AUTH_KEY`.

    Published:2 Sept 2021
    7.8
    High

    CVE-2021-38304

    Last Modified: 21 Nov 2024

    Improper input validation in the National Instruments NI-PAL driver in versions 20.0.0 and prior may allow a privileged user to potentially enable escalation of privilege via local access.

    Published:17 Sept 2021
    9.8
    Critical

    CVE-2021-38297

    Last Modified: 21 Nov 2024

    Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM module, when GOARCH=wasm GOOS=js is used.

    Published:7 Oct 2021
    7.3
    High

    CVE-2021-38295

    Last Modified: 21 Nov 2024

    In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document. If a CouchDB admin opens that attachment in a browser, e.g. via the CouchDB admin interface Fauxton, any JavaScript code embedded in that HTML attachment will be executed within the security context of that admin. A similar route is available with the already deprecated _show and _list functionality. This privilege escalation vulnerability allows an attacker to add or remove data in any database or make configuration changes. This issue affected Apache CouchDB prior to 3.1.2

    Published:12 Oct 2021
    7.8
    High

    CVE-2021-38185

    Last Modified: 9 Jun 2025

    GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is unclear whether there are common cases where the pattern file, associated with the -E option, is untrusted data.

    Published:6 Aug 2021
    9.9
    Critical

    CVE-2021-38163

    Last Modified: 25 Feb 2026

    SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.

    Published:14 Sept 2021
    5.4
    Medium

    CVE-2021-38149

    Last Modified: 21 Nov 2024

    index.php/admin/add_user in Chikitsa Patient Management System 2.0.0 allows XSS.

    Published:6 Aug 2021
    8.8
    High

    CVE-2021-38003

    Last Modified: 24 Oct 2025

    Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published:23 Nov 2021
    8.8
    High

    CVE-2021-38001

    Last Modified: 21 Nov 2024

    Type confusion in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published:23 Nov 2021
    7.4
    High

    CVE-2021-37980

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Sandbox in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially bypass site isolation via Windows.

    Published:2 Nov 2021
    8.8
    High

    CVE-2021-37975

    Last Modified: 24 Oct 2025

    Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published:8 Oct 2021
    3.7
    Low

    CVE-2021-37910

    Last Modified: 21 Nov 2024

    ASUS routers Wi-Fi protected access protocol (WPA2 and WPA3-SAE) has improper control of Interaction frequency vulnerability, an unauthenticated attacker can remotely disconnect other users' connections by sending specially crafted SAE authentication frames.

    Published:12 Nov 2021
    8.8
    High

    CVE-2021-37840

    Last Modified: 21 Nov 2024

    aaPanel through 6.8.12 allows Cross-Site WebSocket Hijacking (CSWH) involving OS commands within WebSocket messages at a ws:// URL for /webssh (the victim must have configured Terminal with at least one host). Successful exploitation depends on the browser used by a potential victim (e.g., exploitation can occur with Firefox but not Chrome).

    Published:2 Aug 2021
    6.1
    Medium

    CVE-2021-37833

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability exists in multiple pages in version 3.0.2 of the Hotel Druid application that allows for arbitrary execution of JavaScript commands.

    Published:3 Aug 2021
    9.8
    Critical

    CVE-2021-37832

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists in version 3.0.2 of Hotel Druid when SQLite is being used as the application database. A malicious attacker can issue SQL commands to the SQLite database through the vulnerable idappartamenti parameter.

    Published:3 Aug 2021
    6.5
    Medium

    CVE-2021-37787

    Last Modified: 21 May 2025

    The unprivileged administrative interface in ABO.CMS version 5.8 through v.5.9.3 is affected by a SQL Injection vulnerability via a HTTP POST request to the TinyMCE module

    Published:11 Mar 2025
    8.8
    High

    CVE-2021-37748

    Last Modified: 21 Nov 2024

    Multiple buffer overflows in the limited configuration shell (/sbin/gs_config) on Grandstream HT801 devices before 1.0.29 allow remote authenticated users to execute arbitrary code as root via a crafted manage_if setting, thus bypassing the intended restrictions of this shell and taking full control of the device. There are default weak credentials that can be used to authenticate.

    Published:28 Oct 2021
    7.5
    High

    CVE-2021-37740

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists in MDT's firmware for the KNXnet/IP Secure router SCN-IP100.03 and KNX IP interface SCN-IP000.03 before v3.0.4, that allows a remote attacker to turn the device unresponsive to all requests on the KNXnet/IP Secure layer, until the device is rebooted, via a SESSION_REQUEST frame with a modified total length field.

    Published:20 Apr 2022
    9.3
    Critical

    CVE-2021-37678

    Last Modified: 21 Nov 2024

    TensorFlow is an end-to-end open source platform for machine learning. In affected versions TensorFlow and Keras can be tricked to perform arbitrary code execution when deserializing a Keras model from YAML format. The [implementation](https://github.com/tensorflow/tensorflow/blob/460e000de3a83278fb00b61a16d161b1964f15f4/tensorflow/python/keras/saving/model_config.py#L66-L104) uses `yaml.unsafe_load` which can perform arbitrary code execution on the input. Given that YAML format support requires a significant amount of work, we have removed it for now. We have patched the issue in GitHub commit 23d6383eb6c14084a8fc3bdf164043b974818012. The fix will be included in TensorFlow 2.6.0. We will also cherrypick this commit on TensorFlow 2.5.1, TensorFlow 2.4.3, and TensorFlow 2.3.4, as these are also affected and still in supported range.

    Published:12 Aug 2021
    7.5
    High

    CVE-2021-37624

    Last Modified: 21 Nov 2024

    FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.7, FreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam and message spoofing. By default, SIP requests of the type MESSAGE (RFC 3428) are not authenticated in the affected versions of FreeSWITCH. MESSAGE requests are relayed to SIP user agents registered with the FreeSWITCH server without requiring any authentication. Although this behaviour can be changed by setting the `auth-messages` parameter to `true`, it is not the default setting. Abuse of this security issue allows attackers to send SIP MESSAGE messages to any SIP user agent that is registered with the server without requiring authentication. Additionally, since no authentication is required, chat messages can be spoofed to appear to come from trusted entities. Therefore, abuse can lead to spam and enable social engineering, phishing and similar attacks. This issue is patched in version 1.10.7. Maintainers recommend that this SIP message type is authenticated by default so that FreeSWITCH administrators do not need to be explicitly set the `auth-messages` parameter. When following such a recommendation, a new parameter can be introduced to explicitly disable authentication.

    Published:25 Oct 2021
    9.1
    Critical

    CVE-2021-37593

    Last Modified: 2 Aug 2021

    PEEL Shopping version 9.4.0 allows remote SQL injection. A public user/guest (unauthenticated) can inject a malicious SQL query in order to affect the execution of predefined SQL commands. Upon a successful SQL injection attack, an attacker can read sensitive data from the database and possibly modify database data.

    Source:faisalfs10x
    Published:27 Jul 2021
    7.5
    High

    CVE-2021-37589

    Last Modified: 14 Jun 2022

    Virtua Cobranca before 12R allows SQL Injection on the login page.

    Source:Luca Regne
    Published:7 Jun 2022
    9.8
    Critical

    CVE-2021-37580

    Last Modified: 21 Nov 2024

    A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue affected Apache ShenYu 2.3.0 and 2.4.0

    Published:16 Nov 2021
    9.1
    Critical

    CVE-2021-37425

    Last Modified: 12 Aug 2021

    Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobiletogetherserver.cfg and then reading the certificate and private key.

    Source:RedTeam Pentesting GmbH
    Published:10 Aug 2021
    5.4
    Medium

    CVE-2021-37391

    Last Modified: 2 Feb 2022

    A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator, through main/social/search.php, main/inc/lib/social.lib.php and steal cookies or execute arbitrary code on the administration side via a stored XSS vulnerability via social network the send invitation feature.

    Source:sirpedrotavares
    Published:10 Aug 2021
    5.4
    Medium

    CVE-2021-37152

    Last Modified: 21 Nov 2024

    Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML files to a repository could redirect users to Nexus Repository Manager’s pages with code modifications.

    Published:10 Aug 2021
    8.8
    High

    CVE-2021-36981

    Last Modified: 21 Nov 2024

    In the server in SerNet verinice before 1.22.2, insecure Java deserialization allows remote authenticated attackers to execute arbitrary code.

    Published:31 Aug 2021
    7.8
    High

    CVE-2021-36955

    Last Modified: 10 Aug 2026

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

    Published:15 Sept 2021
    7.1
    High

    CVE-2021-36949

    Last Modified: 10 Aug 2026

    Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability

    Published:12 Aug 2021
    7.8
    High

    CVE-2021-36934

    Last Modified: 10 Aug 2026

    An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker must have the ability to execute code on a victim system to exploit this vulnerability. After installing this security update, you must manually delete all shadow copies of system files, including the SAM database, to fully mitigate this vulnerabilty. Simply installing this security update will not fully mitigate this vulnerability. See KB5005357- Delete Volume Shadow Copies.

    Published:22 Jul 2021
    5.9
    Medium

    CVE-2021-36808

    Last Modified: 21 Nov 2024

    A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115.

    Published:30 Oct 2021