7.8
    High

    CVE-2021-34486

    Last Modified: 10 Aug 2026

    Windows Event Tracing Elevation of Privilege Vulnerability

    Published:12 Aug 2021
    8.8
    High

    CVE-2021-34481

    Last Modified: 10 Aug 2026

    A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. UPDATE August 10, 2021: Microsoft has completed the investigation and has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. This security update changes the Point and Print default behavior; please see KB5005652.

    Published:16 Jul 2021
    9.1
    Critical

    CVE-2021-34473

    Last Modified: 10 Aug 2026

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Published:14 Jul 2021
    8
    High

    CVE-2021-34470

    Last Modified: 10 Aug 2026

    Microsoft Exchange Server Elevation of Privilege Vulnerability

    Published:14 Jul 2021
    5.3
    Medium

    CVE-2021-34429

    Last Modified: 3 Nov 2021

    For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5.

    Source:Mayank Deshmukh
    Published:15 Jul 2021
    2.9
    Low

    CVE-2021-34428

    Last Modified: 21 Nov 2024

    For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.

    Published:22 Jun 2021
    9.8
    Critical

    CVE-2021-34427

    Last Modified: 21 Nov 2024

    In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code into the running instance.

    Published:22 Aug 2018
    9.8
    Critical

    CVE-2021-34371

    Last Modified: 21 Nov 2024

    Neo4j through 3.4.18 (with the shell server enabled) exposes an RMI service that arbitrarily deserializes Java objects, e.g., through setSessionVariable. An attacker can abuse this for remote code execution because there are dependencies with exploitable gadget chains.

    Published:5 Aug 2021
    6.1
    Medium

    CVE-2021-34370

    Last Modified: 14 Jun 2021

    Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS. NOTE: the vendor states "there are configurable security flags and we are unable to reproduce them with the available information.

    Source:Abdulazeez Alaseeri
    Published:9 Jun 2021
    6.5
    Medium

    CVE-2021-34369

    Last Modified: 14 Jun 2021

    portlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensitive information via a modified contactSeqNumber value. NOTE: the vendor states "the information that is being queried is authorized for an authenticated user of that application, so we consider this not applicable.

    Source:Abdulazeez Alaseeri
    Published:9 Jun 2021
    7.8
    High

    CVE-2021-34110

    Last Modified: 12 Jul 2021

    WinWaste.NET version 1.0.6183.16475 has incorrect permissions, allowing a local unprivileged user to replace the executable with a malicious file that will be executed with "LocalSystem" privileges.

    Source:Andrea Intilangelo
    Published:8 Jul 2021
    Unknown

    CVE-2021-34045

    https://github.com/Al1ex/CVE-2021-34045

    9.8
    Critical

    CVE-2021-33990

    Last Modified: 5 Apr 2023

    Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue because the exploit reference link only shows frmfolders.html is accessible and does not demonstrate how an unauthorized user can upload a file.

    Source:Fu2x2000
    Published:16 Apr 2023
    7.5
    High

    CVE-2021-33959

    Last Modified: 4 Apr 2025

    Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.

    Published:18 Jan 2023
    7.8
    High

    CVE-2021-33909

    Last Modified: 21 Nov 2024

    fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged user, aka CID-8cae8cd89f05.

    Published:20 Jul 2021
    6.1
    Medium

    CVE-2021-33904

    Last Modified: 11 Jun 2021

    In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS. NOTE: The vendor states "there are configurable security flags and we are unable to reproduce them with the available information.

    Source:Abdulazeez Alaseeri
    Published:7 Jun 2021
    8.1
    High

    CVE-2021-33879

    Last Modified: 21 Nov 2024

    Tencent GameLoop before 4.1.21.90 downloaded updates over an insecure HTTP connection. A malicious attacker in an MITM position could spoof the contents of an XML document describing an update package, replacing a download URL with one pointing to an arbitrary Windows executable. Because the only integrity check would be a comparison of the downloaded file's MD5 checksum to the one contained within the XML document, the downloaded executable would then be executed on the victim's machine.

    Published:6 Jun 2021
    6.5
    Medium

    CVE-2021-33831

    Last Modified: 21 Nov 2024

    api/account/register in the TH Wildau COVID-19 Contact Tracing application through 2021-09-01 has Incorrect Access Control. An attacker can interfere with tracing of infection chains by creating 500 random users within 2500 seconds.

    Published:7 Sept 2021
    7.5
    High

    CVE-2021-33813

    Last Modified: 21 Nov 2024

    An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.

    Published:8 Jun 2021
    7.3
    High

    CVE-2021-33766

    Last Modified: 10 Aug 2026

    Microsoft Exchange Server Information Disclosure Vulnerability

    Published:14 Jul 2021
    8.4
    High

    CVE-2021-33739

    Last Modified: 30 Oct 2025

    Microsoft DWM Core Library Elevation of Privilege Vulnerability

    Published:8 Jun 2021
    6.5
    Medium

    CVE-2021-33699

    Last Modified: 21 Nov 2024

    Task Hijacking is a vulnerability that affects the applications running on Android devices due to a misconfiguration in their AndroidManifest.xml with their Task Control features. This allows an unauthorized attacker or malware to takeover legitimate apps and to steal user's sensitive information.

    Published:10 Aug 2021
    9.9
    Critical

    CVE-2021-33690

    Last Modified: 21 Nov 2024

    Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50The SAP NetWeaver Development Infrastructure Component Build Service allows a threat actor who has access to the server to perform proxy attacks on server by sending crafted queries. Due to this, the threat actor could completely compromise sensitive data residing on the Server and impact its availability.Note: The impact of this vulnerability depends on whether SAP NetWeaver Development Infrastructure (NWDI) runs on the intranet or internet. The CVSS score reflects the impact considering the worst-case scenario that it runs on the internet.

    Published:15 Sept 2021
    4.7
    Medium

    CVE-2021-33624

    Last Modified: 11 Nov 2025

    In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., because of type confusion) and consequently an unprivileged BPF program can read arbitrary memory locations via a side-channel attack, aka CID-9183671af6db.

    Published:21 Jun 2021
    5.4
    Medium

    CVE-2021-33570

    Last Modified: 27 May 2021

    Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can result in reading local files via vectors involving XMLHttpRequest and open of a file:/// URL, or discovering PostgreSQL passwords via vectors involving Window.localStorage and savedConnections.

    Source:Debshubra Chakraborty
    Published:25 May 2021
    9.8
    Critical

    CVE-2021-33564

    Last Modified: 21 Nov 2024

    An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the verify_url option is disabled. This may lead to code execution. The problem occurs because the generate and process features mishandle use of the ImageMagick convert utility.

    Published:29 May 2021
    4.8
    Medium

    CVE-2021-33562

    Last Modified: 27 May 2021

    A reflected cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via the ref parameter to a page about an arbitrary product, e.g., a product/insert-product-name-here.html/ref= URL.

    Source:Marek Toth
    Published:24 May 2021
    4.8
    Medium

    CVE-2021-33561

    Last Modified: 27 May 2021

    A stored cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via customer_name in various forms of store administration. It is saved in the database. The code is executed for any user of store administration when information is fetched from the backend, e.g., in admin/customers/list.html.

    Source:Marek Toth
    Published:24 May 2021
    7.5
    High

    CVE-2021-33560

    Last Modified: 3 Dec 2025

    Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.

    Published:2 Jun 2021
    7.5
    High

    CVE-2021-33558

    Last Modified: 21 Nov 2024

    Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, log.html, email.html, online-users.html, and config.js. NOTE: multiple third parties report that this is a site-specific issue because those files are not part of Boa.

    Published:27 May 2021
    8.8
    High

    CVE-2021-33393

    Last Modified: 11 Jun 2021

    lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account. It might be owned by an unprivileged account, which could potentially be used to install a Trojan horse backup.pl script that is later executed by root. Similar problems with the ownership/permissions of other files may be present as well.

    Source:Mücahit Saratar
    Published:9 Jun 2021
    9.8
    Critical

    CVE-2021-33216

    Last Modified: 16 Apr 2025

    An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowing shell access via a developer account.

    Source:ub3rsick
    Published:7 Jul 2021
    6.5
    Medium

    CVE-2021-33104

    Last Modified: 27 Jan 2025

    Improper access control in the Intel(R) OFU software before version 14.1.28 may allow an authenticated user to potentially enable denial of service via local access.

    Published:16 Feb 2023
    9.8
    Critical

    CVE-2021-33045

    Last Modified: 13 Jan 2026

    The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

    Published:15 Sept 2021
    9.8
    Critical

    CVE-2021-33044

    Last Modified: 13 Jan 2026

    The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

    Published:15 Sept 2021
    7.8
    High

    CVE-2021-33034

    Last Modified: 21 Nov 2024

    In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409. This leads to writing an arbitrary value.

    Published:22 Mar 2021
    9.8
    Critical

    CVE-2021-33026

    Last Modified: 21 Nov 2024

    The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code execution or local privilege escalation. If an attacker gains access to cache storage (e.g., filesystem, Memcached, Redis, etc.), they can construct a crafted payload, poison the cache, and execute Python code. NOTE: a third party indicates that exploitation is extremely unlikely unless the machine is already compromised; in other cases, the attacker would be unable to write their payload to the cache and generate the required collision

    Published:13 May 2021
    8.8
    High

    CVE-2021-32849

    Last Modified: 22 Apr 2025

    Gerapy is a distributed crawler management framework. Prior to version 0.9.9, an authenticated user could execute arbitrary commands. This issue is fixed in version 0.9.9. There are no known workarounds.

    Published:26 Jan 2022
    8
    High

    CVE-2021-32819

    Last Modified: 21 Nov 2024

    Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration options remote code execution may be triggered in downstream applications. This issue is fixed in version 9.0.0. For complete details refer to the referenced GHSL-2021-023.

    Published:14 May 2021
    8.2
    High

    CVE-2021-32804

    Last Modified: 21 Nov 2024

    The npm package "tar" (aka node-tar) before versions 6.1.1, 5.0.6, 4.4.14, and 3.3.2 has a arbitrary File Creation/Overwrite vulnerability due to insufficient absolute path sanitization. node-tar aims to prevent extraction of absolute file paths by turning absolute paths into relative paths when the `preservePaths` flag is not set to `true`. This is achieved by stripping the absolute path root from any absolute file paths contained in a tar file. For example `/home/user/.bashrc` would turn into `home/user/.bashrc`. This logic was insufficient when file paths contained repeated path roots such as `////home/user/.bashrc`. `node-tar` would only strip a single path root from such paths. When given an absolute file path with repeating path roots, the resulting path (e.g. `///home/user/.bashrc`) would still resolve to an absolute path, thus allowing arbitrary file creation and overwrite. This issue was addressed in releases 3.2.2, 4.4.14, 5.0.6 and 6.1.1. Users may work around this vulnerability without upgrading by creating a custom `onentry` method which sanitizes the `entry.path` or a `filter` method which removes entries with absolute paths. See referenced GitHub Advisory for details. Be aware of CVE-2021-32803 which fixes a similar bug in later versions of tar.

    Published:3 Aug 2021
    7.5
    High

    CVE-2021-32789

    Last Modified: 21 Nov 2024

    woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce Blocks feature plugin between version 2.5.0 and prior to version 2.5.16. Via a carefully crafted URL, an exploit can be executed against the `wc/store/products/collection-data?calculate_attribute_counts[][taxonomy]` endpoint that allows the execution of a read only sql query. There are patches for many versions of this package, starting with version 2.5.16. There are no known workarounds aside from upgrading.

    Published:26 Jul 2021
    9.9
    Critical

    CVE-2021-32724

    Last Modified: 21 Nov 2024

    check-spelling is a github action which provides CI spell checking. In affected versions and for a repository with the [check-spelling action](https://github.com/marketplace/actions/check-spelling) enabled that triggers on `pull_request_target` (or `schedule`), an attacker can send a crafted Pull Request that causes a `GITHUB_TOKEN` to be exposed. With the `GITHUB_TOKEN`, it's possible to push commits to the repository bypassing standard approval processes. Commits to the repository could then steal any/all secrets available to the repository. As a workaround users may can either: [Disable the workflow](https://docs.github.com/en/actions/managing-workflow-runs/disabling-and-enabling-a-workflow) until you've fixed all branches or Set repository to [Allow specific actions](https://docs.github.com/en/github/administering-a-repository/managing-repository-settings/disabling-or-limiting-github-actions-for-a-repository#allowing-specific-actions-to-run). check-spelling isn't a verified creator and it certainly won't be anytime soon. You could then explicitly add other actions that your repository uses. Set repository [Workflow permissions](https://docs.github.com/en/github/administering-a-repository/managing-repository-settings/disabling-or-limiting-github-actions-for-a-repository#setting-the-permissions-of-the-github_token-for-your-repository) to `Read repository contents permission`. Workflows using `check-spelling/check-spelling@main` will get the fix automatically. Workflows using a pinned sha or tagged version will need to change the affected workflows for all repository branches to the latest version. Users can verify who and which Pull Requests have been running the action by looking up the spelling.yml action in the Actions tab of their repositories, e.g., https://github.com/check-spelling/check-spelling/actions/workflows/spelling.yml - you can filter PRs by adding ?query=event%3Apull_request_target, e.g., https://github.com/check-spelling/check-spelling/actions/workflows/spelling.yml?query=event%3Apull_request_target.

    Published:9 Sept 2021
    9.8
    Critical

    CVE-2021-32708

    Last Modified: 21 Nov 2024

    Flysystem is an open source file storage library for PHP. The whitespace normalisation using in 1.x and 2.x removes any unicode whitespace. Under certain specific conditions this could potentially allow a malicious user to execute code remotely. The conditions are: A user is allowed to supply the path or filename of an uploaded file, the supplied path or filename is not checked against unicode chars, the supplied pathname checked against an extension deny-list, not an allow-list, the supplied path or filename contains a unicode whitespace char in the extension, the uploaded file is stored in a directory that allows PHP code to be executed. Given these conditions are met a user can upload and execute arbitrary code on the system under attack. The unicode whitespace removal has been replaced with a rejection (exception). For 1.x users, upgrade to 1.1.4. For 2.x users, upgrade to 2.1.1.

    Published:24 Jun 2021
    7.5
    High

    CVE-2021-32675

    Last Modified: 21 Nov 2024

    Redis is an open source, in-memory database that persists on disk. When parsing an incoming Redis Standard Protocol (RESP) request, Redis allocates memory according to user-specified values which determine the number of elements (in the multi-bulk header) and size of each element (in the bulk header). An attacker delivering specially crafted requests over multiple connections can cause the server to allocate significant amount of memory. Because the same parsing mechanism is used to handle authentication requests, this vulnerability can also be exploited by unauthenticated users. The problem is fixed in Redis versions 6.2.6, 6.0.16 and 5.0.14. An additional workaround to mitigate this problem without patching the redis-server executable is to block access to prevent unauthenticated users from connecting to Redis. This can be done in different ways: Using network access control tools like firewalls, iptables, security groups, etc. or Enabling TLS and requiring users to authenticate using client side certificates.

    Published:4 Oct 2021
    8.2
    High

    CVE-2021-32648

    Last Modified: 24 Oct 2025

    octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. The issue has been patched in Build 472 and v1.1.5.

    Published:26 Aug 2021
    6.4
    Medium

    CVE-2021-32644

    Last Modified: 21 Nov 2024

    Ampache is an open source web based audio/video streaming application and file manager. Due to a lack of input filtering versions 4.x.y are vulnerable to code injection in random.php. The attack requires user authentication to access the random.php page unless the site is running in demo mode. This issue has been resolved in 4.4.3.

    Published:22 Jun 2021
    6.5
    Medium

    CVE-2021-32537

    Last Modified: 21 Nov 2024

    Realtek HAD contains a driver crashed vulnerability which allows local side attackers to send a special string to the kernel driver in a user’s mode. Due to unexpected commands, the kernel driver will cause the system crashed.

    Published:7 Jul 2021
    7.8
    High

    CVE-2021-32471

    Last Modified: 21 Nov 2024

    Insufficient input validation in the Marvin Minsky 1967 implementation of the Universal Turing Machine allows program users to execute arbitrary code via crafted data. For example, a tape head may have an unexpected location after the processing of input composed of As and Bs (instead of 0s and 1s). NOTE: the discoverer states "this vulnerability has no real-world implications."

    Published:10 May 2021
    8.8
    High

    CVE-2021-32403

    Last Modified: 9 Jun 2021

    Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of security mechanisms for token protection and unsafe inputs and modules.

    Source:Rodolfo Mariano
    Published:17 May 2021
    7
    High

    CVE-2021-32399

    Last Modified: 21 Nov 2024

    net/bluetooth/hci_request.c in the Linux kernel through 5.12.2 has a race condition for removal of the HCI controller.

    Published:10 May 2021