9.8
    Critical

    CVE-2021-32305

    Last Modified: 3 Aug 2021

    WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter.

    Source:g0ldm45k
    Published:18 May 2021
    9.8
    Critical

    CVE-2021-32172

    Last Modified: 8 Oct 2021

    Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin.

    Source:DreyAnd
    Published:7 Oct 2021
    8.8
    High

    CVE-2021-32162

    Last Modified: 21 Nov 2024

    A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 through the File Manager feature.

    Published:11 Apr 2022
    6.1
    Medium

    CVE-2021-32161

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the File Manager feature.

    Published:11 Apr 2022
    6.1
    Medium

    CVE-2021-32160

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the Add Users feature.

    Published:11 Apr 2022
    8.8
    High

    CVE-2021-32159

    Last Modified: 21 Nov 2024

    A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Upload and Download feature.

    Published:11 Apr 2022
    6.1
    Medium

    CVE-2021-32158

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Upload and Download feature.

    Published:11 Apr 2022
    9.6
    Critical

    CVE-2021-32157

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.

    Published:11 Apr 2022
    8.8
    High

    CVE-2021-32156

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.

    Published:11 Apr 2022
    9.8
    Critical

    CVE-2021-32099

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileged session via the /include/chart_generator.php session_id parameter, leading to a login bypass.

    Published:7 May 2021
    7.8
    High

    CVE-2021-31956

    Last Modified: 13 Jan 2026

    Windows NTFS Elevation of Privilege Vulnerability

    Published:8 Jun 2021
    5.5
    Medium

    CVE-2021-31955

    Last Modified: 30 Oct 2025

    Windows Kernel Information Disclosure Vulnerability

    Published:8 Jun 2021
    7.6
    High

    CVE-2021-31950

    Last Modified: 11 Jun 2021

    Microsoft SharePoint Server Spoofing Vulnerability

    Source:Alex Birnberg
    Published:8 Jun 2021
    7.2
    High

    CVE-2021-31933

    Last Modified: 1 Dec 2021

    A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and improper file-extension filtering for certain filenames (e.g., .phar or .pht). A remote authenticated administrator is able to upload a file containing arbitrary PHP code into specific directories via main/inc/lib/fileUpload.lib.php directory traversal to achieve PHP code execution.

    Source:M. Cory Billington
    Published:30 Apr 2021
    6.1
    Medium

    CVE-2021-31862

    Last Modified: 21 Nov 2024

    SysAid 20.4.74 allows XSS via the KeepAlive.jsp stamp parameter without any authentication.

    Published:29 Oct 2021
    9.8
    Critical

    CVE-2021-31856

    Last Modified: 21 Nov 2024

    A SQL Injection vulnerability in the REST API in Layer5 Meshery 0.5.2 allows an attacker to execute arbitrary SQL commands via the /experimental/patternfiles endpoint (order parameter in GetMesheryPatterns in models/meshery_pattern_persister.go).

    Published:28 Apr 2021
    9.8
    Critical

    CVE-2021-31805

    Last Modified: 21 Nov 2024

    The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.

    Published:12 Apr 2022
    9.8
    Critical

    CVE-2021-31800

    Last Modified: 21 Nov 2024

    Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a running smbserver instance can list and write to arbitrary files via ../ directory traversal. This could potentially be abused to achieve arbitrary code execution by replacing /etc/shadow or an SSH authorized key.

    Published:5 May 2021
    7.5
    High

    CVE-2021-31796

    Last Modified: 21 Nov 2024

    An inadequate encryption vulnerability discovered in CyberArk Credential Provider before 12.1 may lead to Information Disclosure. An attacker may realistically have enough information that the number of possible keys (for a credential file) is only one, and the number is usually not higher than 2^36.

    Published:2 Sept 2021
    8.8
    High

    CVE-2021-31762

    Last Modified: 20 Jul 2021

    Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse shell through Webmin's running process feature.

    Source:Mesh3l_911
    Published:25 Apr 2021
    9.6
    Critical

    CVE-2021-31761

    Last Modified: 20 Jul 2021

    Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process feature.

    Source:Mesh3l_911
    Published:25 Apr 2021
    8.8
    High

    CVE-2021-31760

    Last Modified: 21 Nov 2024

    Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to achieve Remote Command Execution (RCE) through Webmin's running process feature.

    Published:25 Apr 2021
    7.8
    High

    CVE-2021-31728

    Last Modified: 21 Nov 2024

    Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 allows a non-privileged process to open a handle to \.\ZemanaAntiMalware, register itself with the driver by sending IOCTL 0x80002010, allocate executable memory using a flaw in IOCTL 0x80002040, install a hook with IOCTL 0x80002044 and execute the executable memory using this hook with IOCTL 0x80002014 or 0x80002018, this exposes ring 0 code execution in the context of the driver allowing the non-privileged process to elevate privileges.

    Published:17 May 2021
    7.5
    High

    CVE-2021-31684

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a crafted web request.

    Published:1 Jun 2021
    6.1
    Medium

    CVE-2021-31682

    Last Modified: 29 Oct 2021

    The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for reflected XSS attacks due to the operatorlocale GET parameter not being sanitized. This issue impacts versions 6.5 and below. This issue works by passing in a basic XSS payload to a vulnerable GET parameter that is reflected in the output without sanitization.

    Source:3ndG4me
    Published:22 Oct 2021
    6.1
    Medium

    CVE-2021-31674

    Last Modified: 11 May 2022

    Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacker to execute javascript code via undefine enum constant.

    Source:Tin Pham
    Published:1 May 2022
    6.1
    Medium

    CVE-2021-31673

    Last Modified: 11 May 2022

    A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remote attackers to inject arbitrary web script or HTML via the groupId parameter.

    Source:Tin Pham
    Published:1 May 2022
    6.5
    Medium

    CVE-2021-31642

    Last Modified: 29 Oct 2021

    A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC. The vulnerability can be explored by sending an unexpected integer (> 32 bits) on the page parameter that will crash the web portal and making it unavailable until a reboot of the device.

    Source:sirpedrotavares
    Published:1 Jun 2021
    8.8
    High

    CVE-2021-31630

    Last Modified: 21 Nov 2024

    Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/hardware" page of the application.

    Published:3 Aug 2021
    5.3
    Medium

    CVE-2021-31602

    Last Modified: 21 Nov 2024

    An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The Security Model has different layers of Access Control. One of these layers is the applicationContext security, which is defined in the applicationContext-spring-security.xml file. The default configuration allows an unauthenticated user with no previous knowledge of the platform settings to extract pieces of information without possessing valid credentials.

    Published:8 Nov 2021
    6.1
    Medium

    CVE-2021-31589

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Software version 6.0.1 and older, which allows the injection of unauthenticated, specially-crafted web requests without proper sanitization.

    Published:5 Jan 2022
    7
    High

    CVE-2021-31440

    Last Modified: 21 Nov 2024

    This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.11.15. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of eBPF programs. The issue results from the lack of proper validation of user-supplied eBPF programs prior to executing them. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the kernel. Was ZDI-CAN-13661.

    Published:21 May 2021
    5.4
    Medium

    CVE-2021-31329

    Last Modified: 23 Apr 2021

    Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Chat" and "Personal Address" field on staff/register.php

    Source:Saud Ahmad
    Published:21 Apr 2021
    5.4
    Medium

    CVE-2021-31327

    Last Modified: 23 Apr 2021

    Stored XSS in Remote Clinic v2.0 in /medicines due to Medicine Name Field.

    Source:Saud Ahmad
    Published:21 Apr 2021
    Unknown

    CVE-2021-31290

    https://github.com/qaisarafridi/cve-2021-31290

    9.8
    Critical

    CVE-2021-31251

    Last Modified: 3 Jun 2021

    An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by supplying a specially malformed request and an attacker may force the remote telnet server to believe that the user has already authenticated.

    Source:sirpedrotavares
    Published:4 Jun 2021
    7.5
    High

    CVE-2021-31233

    Last Modified: 10 Jan 2025

    SQL Injection vulnerability found in Fighting Cock Information System v.1.0 allows a remote attacker to obtain sensitive information via the edit_breed.php parameter.

    Published:31 May 2023
    5.5
    Medium

    CVE-2021-31184

    Last Modified: 21 Nov 2024

    Microsoft Windows Infrared Data Association (IrDA) Information Disclosure Vulnerability

    Published:11 May 2021
    9.8
    Critical

    CVE-2021-31166

    Last Modified: 30 Oct 2025

    HTTP Protocol Stack Remote Code Execution Vulnerability

    Published:11 May 2021
    5.3
    Medium

    CVE-2021-31159

    Last Modified: 17 Jun 2021

    Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732.

    Source:Ricardo Ruiz
    Published:16 Jun 2021
    8.8
    High

    CVE-2021-31152

    Last Modified: 26 Apr 2021

    Multilaser Router AC1200 V02.03.01.45_pt contains a cross-site request forgery (CSRF) vulnerability. An attacker can enable remote access, change passwords, and perform other actions through misconfigured requests, entries, and headers.

    Source:Rodolfo Mariano
    Published:14 Apr 2021
    2.4
    Low

    CVE-2021-30956

    Last Modified: 21 Nov 2024

    A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue is fixed in iOS 15.2 and iPadOS 15.2. An attacker with physical access to a device may be able to see private contact information.

    Published:24 Aug 2021
    7
    High

    CVE-2021-30955

    Last Modified: 21 Nov 2024

    A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPadOS 15.2, tvOS 15.2. A malicious application may be able to execute arbitrary code with kernel privileges.

    Published:24 Aug 2021
    7.8
    High

    CVE-2021-30937

    Last Modified: 21 Nov 2024

    A memory corruption vulnerability was addressed with improved locking. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. A malicious application may be able to execute arbitrary code with kernel privileges.

    Published:24 Aug 2021
    6.1
    Medium

    CVE-2021-30862

    Last Modified: 21 Nov 2024

    A validation issue was addressed with improved input sanitization. This issue is fixed in iTunes U 3.8.3. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.

    Published:24 Aug 2021
    7.8
    High

    CVE-2021-30860

    Last Modified: 27 Oct 2025

    An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

    Published:24 Aug 2021
    8.8
    High

    CVE-2021-30858

    Last Modified: 27 Oct 2025

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

    Published:24 Aug 2021
    5.5
    Medium

    CVE-2021-30853

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6. A malicious application may bypass Gatekeeper checks.

    Published:24 Aug 2021
    8.8
    High

    CVE-2021-30809

    Last Modified: 21 Nov 2024

    A use after free issue was addressed with improved memory management. This issue is fixed in Safari 15, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published:28 Oct 2021
    7.8
    High

    CVE-2021-30807

    Last Modified: 23 Oct 2025

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS 14.7.1, watchOS 7.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.

    Published:19 Oct 2021