8.8
    High

    CVE-2021-36799

    Last Modified: 21 Nov 2024

    KNX ETS5 through 5.7.6 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project information. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published:19 Jul 2021
    7.5
    High

    CVE-2021-36798

    Last Modified: 21 Nov 2024

    A Denial-of-Service (DoS) vulnerability was discovered in Team Server in HelpSystems Cobalt Strike 4.2 and 4.3. It allows remote attackers to crash the C2 server thread and block beacons' communication with it.

    Published:9 Aug 2021
    9.9
    Critical

    CVE-2021-36782

    Last Modified: 21 Nov 2024

    A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners, Project Members and User Base to use the Kubernetes API to retrieve plaintext version of sensitive data. This issue affects: SUSE Rancher Rancher versions prior to 2.5.16; Rancher versions prior to 2.6.7.

    Published:7 Sept 2022
    8.1
    High

    CVE-2021-36750

    Last Modified: 21 Nov 2024

    ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names).

    Published:22 Dec 2021
    6.5
    Medium

    CVE-2021-36749

    Last Modified: 21 Nov 2024

    In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of the Druid server process. This is not an elevation of privilege when users access Druid directly, since Druid also provides the Local InputSource, which allows the same level of access. But it is problematic when users interact with Druid indirectly through an application that allows users to specify the HTTP InputSource, but not the Local InputSource. In this case, users could bypass the application-level restriction by passing a file URL to the HTTP InputSource. This issue was previously mentioned as being fixed in 0.21.0 as per CVE-2021-26920 but was not fixed in 0.21.0 or 0.21.1.

    Published:23 Sept 2021
    5.4
    Medium

    CVE-2021-36747

    Last Modified: 21 Nov 2024

    Blackboard Learn through 9.1 allows XSS by an authenticated user via the Feedback to Learner form.

    Published:20 Jul 2021
    9.8
    Critical

    CVE-2021-36711

    Last Modified: 1 Aug 2022

    WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled.

    Source:Samy Younsi
    Published:16 Jul 2022
    5.4
    Medium

    CVE-2021-36654

    Last Modified: 5 Aug 2021

    CMSuno 1.7 is vulnerable to an authenticated stored cross site scripting in modifying the filename parameter (tgo) while updating the theme.

    Source:splint3rsec
    Published:3 Aug 2021
    7.5
    High

    CVE-2021-36630

    Last Modified: 4 Apr 2025

    DDOS reflection amplification vulnerability in eAut module of Ruckus Wireless SmartZone controller that allows remote attackers to perform DOS attacks via crafted request.

    Published:18 Jan 2023
    Low

    CVE-2021-36593

    Last Modified: 2 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published:12 Jul 2021
    5.4
    Medium

    CVE-2021-36563

    Last Modified: 21 Nov 2024

    The CheckMK management web console (versions 1.5.0 to 2.0.0) does not sanitise user input in various parameters of the WATO module. This allows an attacker to open a backdoor on the device with HTML content and interpreted by the browser (such as JavaScript or other client-side scripts), the XSS payload will be triggered when the user accesses some specific sections of the application. In the same sense a very dangerous potential way would be when an attacker who has the monitor role (not administrator) manages to get a stored XSS to steal the secretAutomation (for the use of the API in administrator mode) and thus be able to create another administrator user who has high privileges on the CheckMK monitoring web console. Another way is that persistent XSS allows an attacker to modify the displayed content or change the victim's information. Successful exploitation requires access to the web management interface, either with valid credentials or with a hijacked session.

    Published:26 Jul 2021
    7.5
    High

    CVE-2021-36520

    Last Modified: 5 Apr 2023

    A SQL injection vulnerability in I-Tech Trainsmart r1044 exists via a evaluation/assign-evaluation?id= URI.

    Source:Adrian Bondocea
    Published:16 Apr 2023
    7.8
    High

    CVE-2021-36460

    Last Modified: 21 Nov 2024

    VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords. This allows an attacker in possession of a hash to takeover a user's account, rendering the benefits of storing hashed passwords in the database useless.

    Published:25 Apr 2022
    7.5
    High

    CVE-2021-36396

    Last Modified: 5 Mar 2025

    In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF risk.

    Published:6 Mar 2023
    9.8
    Critical

    CVE-2021-36394

    Last Modified: 6 Mar 2025

    In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.

    Published:6 Mar 2023
    9.8
    Critical

    CVE-2021-36393

    Last Modified: 6 Mar 2025

    In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.

    Published:6 Mar 2023
    9.8
    Critical

    CVE-2021-36356

    Last Modified: 7 Apr 2022

    KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames (even though browseSystemFiles.php is no longer reachable via the GUI). NOTE: this issue exists because of an incomplete fix for CVE-2019-17124.

    Source:sharkmoos
    Published:31 Aug 2021
    9.8
    Critical

    CVE-2021-36260

    Last Modified: 25 Oct 2021

    A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.

    Source:bashis
    Published:22 Sept 2021
    7.5
    High

    CVE-2021-36090

    Last Modified: 21 Nov 2024

    When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.

    Published:13 Jul 2021
    5.4
    Medium

    CVE-2021-35956

    Last Modified: 2 Jul 2021

    Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote authenticated attackers to introduce arbitrary JavaScript via the Sensor Description, Email (from/to/cc), System Name, and System Location fields.

    Source:Tyler Butler
    Published:30 Jun 2021
    5.4
    Medium

    CVE-2021-35616

    Last Modified: 21 Nov 2024

    Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: UI Infrastructure). The supported version that is affected is 6.4.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Transportation Management accessible data as well as unauthorized read access to a subset of Oracle Transportation Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).

    Published:20 Oct 2021
    9.8
    Critical

    CVE-2021-35587

    Last Modified: 27 Oct 2025

    Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

    Published:19 Jan 2022
    2.7
    Low

    CVE-2021-35576

    Last Modified: 21 Nov 2024

    Vulnerability in the Oracle Database Enterprise Edition Unified Audit component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having Local Logon privilege with network access via Oracle Net to compromise Oracle Database Enterprise Edition Unified Audit. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Database Enterprise Edition Unified Audit accessible data. CVSS 3.1 Base Score 2.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N).

    Published:20 Oct 2021
    7.5
    High

    CVE-2021-35517

    Last Modified: 21 Nov 2024

    When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package.

    Published:13 Jul 2021
    7.5
    High

    CVE-2021-35516

    Last Modified: 21 Nov 2024

    When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package.

    Published:13 Jul 2021
    7.5
    High

    CVE-2021-35515

    Last Modified: 21 Nov 2024

    When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.

    Published:13 Jul 2021
    6.5
    Medium

    CVE-2021-35492

    Last Modified: 21 Nov 2024

    Wowza Streaming Engine through 4.8.11+5 could allow an authenticated, remote attacker to exhaust filesystem resources via the /enginemanager/server/vhost/historical.jsdata vhost parameter. This is due to the insufficient management of available filesystem resources. An attacker could exploit this vulnerability through the Virtual Host Monitoring section by requesting random virtual-host historical data and exhausting available filesystem resources. A successful exploit could allow the attacker to cause database errors and cause the device to become unresponsive to web-based management. (Manual intervention is required to free filesystem resources and return the application to an operational state.)

    Published:5 Oct 2021
    5.4
    Medium

    CVE-2021-35475

    Last Modified: 21 Nov 2024

    SAS Environment Manager 2.5 allows XSS through the Name field when creating/editing a server. The XSS will prompt when editing the Configuration Properties.

    Published:25 Jun 2021
    9.8
    Critical

    CVE-2021-35464

    Last Modified: 29 Oct 2021

    ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/* request to the server. The vulnerability exists due to the usage of Sun ONE Application Framework (JATO) found in versions of Java 8 or earlier

    Source:Photubias
    Published:22 Jul 2021
    7.8
    High

    CVE-2021-35448

    Last Modified: 1 Aug 2022

    Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using the Image Transfer Folder feature to navigate to cmd.exe. It binds to local ports to listen for incoming connections.

    Source:Salman Asad
    Published:24 Jun 2021
    7.5
    High

    CVE-2021-35380

    Last Modified: 7 Mar 2022

    A Directory Traversal vulnerability exists in Solari di Udine TermTalk Server (TTServer) 3.24.0.2, which lets an unauthenticated malicious user gain access to the files on the remote system by gaining access to the relative path of the file they want to download (http://url:port/file?valore).

    Source:Fabiano Golluscio
    Published:15 Feb 2022
    6.1
    Medium

    CVE-2021-35323

    Last Modified: 17 Nov 2021

    Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.

    Source:Vasu
    Published:19 Oct 2021
    7.8
    High

    CVE-2021-35312

    Last Modified: 26 Aug 2021

    A vulnerability was found in CIR 2000 / Gestionale Amica Prodigy v1.7. The Amica Prodigy's executable "RemoteBackup.Service.exe" has incorrect permissions, allowing a local unprivileged user to replace it with a malicious file that will be executed with "LocalSystem" privileges.

    Source:Andrea Intilangelo
    Published:6 Aug 2021
    9.8
    Critical

    CVE-2021-35296

    Last Modified: 21 Nov 2024

    An issue in the administrator authentication panel of PTCL HG150-Ub v3.0 allows attackers to bypass authentication via modification of the cookie value and Response Path.

    Published:4 Oct 2021
    7.5
    High

    CVE-2021-35250

    Last Modified: 21 Nov 2024

    A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and server files. This issue has been resolved in Serv-U 15.3 Hotfix 1.

    Published:25 Apr 2022
    8.9
    High

    CVE-2021-35215

    Last Modified: 21 Nov 2024

    Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is required to exploit this vulnerability.

    Published:1 Sept 2021
    9
    Critical

    CVE-2021-35211

    Last Modified: 27 Oct 2025

    Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. SolarWinds Serv-U Managed File Transfer and Serv-U Secure FTP for Windows before 15.2.3 HF2 are affected by this vulnerability.

    Published:14 Jul 2021
    9.8
    Critical

    CVE-2021-35064

    Last Modified: 7 Apr 2022

    KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits running of multiple dangerous commands, including unzip, systemctl and dpkg.

    Source:sharkmoos
    Published:12 Jul 2021
    9.8
    Critical

    CVE-2021-35042

    Last Modified: 21 Nov 2024

    Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application.

    Published:1 Jul 2021
    6.5
    Medium

    CVE-2021-35036

    Last Modified: 21 Nov 2024

    A cleartext storage of information vulnerability in the Zyxel VMG3625-T50B firmware version V5.50(ABTL.0)b2k could allow an authenticated attacker to obtain sensitive information from the configuration file.

    Published:1 Mar 2022
    8.8
    High

    CVE-2021-34824

    Last Modified: 21 Nov 2024

    Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can be accessed from different namespaces.

    Published:29 Jun 2021
    7.4
    High

    CVE-2021-34767

    Last Modified: 30 Oct 2025

    A vulnerability in IPv6 traffic processing of Cisco IOS XE Wireless Controller Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, adjacent attacker to cause a Layer 2 (L2) loop in a configured VLAN, resulting in a denial of service (DoS) condition for that VLAN. The vulnerability is due to a logic error when processing specific link-local IPv6 traffic. An attacker could exploit this vulnerability by sending a crafted IPv6 packet that would flow inbound through the wired interface of an affected device. A successful exploit could allow the attacker to cause traffic drops in the affected VLAN, thus triggering the DoS condition.

    Published:23 Sept 2021
    9.8
    Critical

    CVE-2021-34730

    Last Modified: 21 Nov 2024

    A vulnerability in the Universal Plug-and-Play (UPnP) service of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validation of incoming UPnP traffic. An attacker could exploit this vulnerability by sending a crafted UPnP request to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a DoS condition. Cisco has not released software updates that address this vulnerability.

    Published:18 Aug 2021
    9.8
    Critical

    CVE-2021-34646

    Last Modified: 20 Sept 2021

    Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_verification function due to a random token generation weakness in the reset_and_mail_activation_link function found in the ~/includes/class-wcj-emails-verification.php file. This allows attackers to impersonate users and trigger an email address verification for arbitrary accounts, including administrative accounts, and automatically be logged in as that user, including any site administrators. This requires the Email Verification module to be active in the plugin and the Login User After Successful Verification setting to be enabled, which it is by default.

    Source:0xB455
    Published:30 Aug 2021
    9.8
    Critical

    CVE-2021-34621

    Last Modified: 31 Aug 2021

    A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register on sites as an administrator. This issue affects versions 3.0.0 - 3.1.3. .

    Source:Numan Rajkotiya
    Published:7 Jul 2021
    5.5
    Medium

    CVE-2021-34600

    Last Modified: 21 Nov 2024

    Telenot CompasX versions prior to 32.0 use a weak seed for random number generation leading to predictable AES keys used in the NFC tags used for local authorization of users. This may lead to total loss of trustworthiness of the installation.

    Published:20 Jan 2022
    6.5
    Medium

    CVE-2021-34558

    Last Modified: 21 Nov 2024

    The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic.

    Published:13 Jul 2021
    8.8
    High

    CVE-2021-34527

    Last Modified: 10 Aug 2026

    A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. UPDATE July 7, 2021: The security update for Windows Server 2012, Windows Server 2016 and Windows 10, Version 1607 have been released. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. If you are unable to install these updates, see the FAQ and Workaround sections in this CVE for information on how to help protect your system from this vulnerability. In addition to installing the updates, in order to secure your system, you must confirm that the following registry settings are set to 0 (zero) or are not defined (Note: These registry keys do not exist by default, and therefore are already at the secure setting.), also that your Group Policy setting are correct (see FAQ): HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint NoWarningNoElevationOnInstall = 0 (DWORD) or not defined (default setting) UpdatePromptSettings = 0 (DWORD) or not defined (default setting) Having NoWarningNoElevationOnInstall set to 1 makes your system vulnerable by design. UPDATE July 6, 2021: Microsoft has completed the investigation and has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. If you are unable to install these updates, see the FAQ and Workaround sections in this CVE for information on how to help protect your system from this vulnerability. See also KB5005010: Restricting installation of new printer drivers after applying the July 6, 2021 updates. Note that the security updates released on and after July 6, 2021 contain protections for CVE-2021-1675 and the additional remote code execution exploit in the Windows Print Spooler service known as “PrintNightmare”, documented in CVE-2021-34527.

    Published:2 Jul 2021
    9
    Critical

    CVE-2021-34523

    Last Modified: 10 Aug 2026

    Microsoft Exchange Server Elevation of Privilege Vulnerability

    Published:14 Jul 2021
    5.5
    Medium

    CVE-2021-34496

    Last Modified: 10 Aug 2026

    Windows GDI Information Disclosure Vulnerability

    Published:14 Jul 2021