5.5
    Medium

    CVE-2021-30731

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-004 Catalina. An unprivileged application may be able to capture USB devices.

    Published:8 Sept 2021
    5.5
    Medium

    CVE-2021-30682

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. A malicious application may be able to leak sensitive user information.

    Published:28 Jul 2021
    5.5
    Medium

    CVE-2021-30657

    Last Modified: 23 Oct 2025

    A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited..

    Published:8 Sept 2021
    5.3
    Medium

    CVE-2021-30641

    Last Modified: 21 Nov 2024

    Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'

    Published:4 Jun 2021
    5.4
    Medium

    CVE-2021-30637

    Last Modified: 15 Apr 2021

    htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php.

    Source:nu11secur1ty
    Published:13 Apr 2021
    8.8
    High

    CVE-2021-30632

    Last Modified: 24 Oct 2025

    Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published:8 Oct 2021
    8.8
    High

    CVE-2021-30573

    Last Modified: 21 Nov 2024

    Use after free in GPU in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published:3 Aug 2021
    8.8
    High

    CVE-2021-30551

    Last Modified: 24 Oct 2025

    Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published:15 Jun 2021
    8
    High

    CVE-2021-30481

    Last Modified: 3 Nov 2025

    Valve Steam before 2021-04-17, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because of a buffer overflow that occurs for a Steam invite after one click.

    Published:10 Apr 2021
    9.8
    Critical

    CVE-2021-30461

    Last Modified: 21 Nov 2024

    A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used, the user-supplied SPOOLDIR value (which might contain PHP code) is injected into config/configuration.php.

    Published:29 May 2021
    5.3
    Medium

    CVE-2021-30357

    Last Modified: 21 Nov 2024

    SSL Network Extender Client for Linux before build 800008302 reveals part of the contents of the configuration file supplied, which allows partially disclosing files to which the user did not have access.

    Published:8 Jun 2021
    7.5
    High

    CVE-2021-30327

    Last Modified: 21 Nov 2024

    Buffer overflow in sahara protocol while processing commands leads to overwrite of secure configuration data in Snapdragon Mobile, Snapdragon Compute, Snapdragon Auto, Snapdragon IOT, Snapdragon Connectivity, Snapdragon Voice & Music

    Published:14 Jun 2022
    9.8
    Critical

    CVE-2021-30181

    Last Modified: 21 Nov 2024

    Apache Dubbo prior to 2.6.9 and 2.7.9 supports Script routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When parsing these rules, Dubbo customers use ScriptEngine and run the rule provided by the script which by default may enable executing arbitrary code.

    Published:29 May 2021
    9.8
    Critical

    CVE-2021-30180

    Last Modified: 21 Nov 2024

    Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When parsing these YAML rules, Dubbo customers may enable calling arbitrary constructors.

    Published:31 May 2021
    6.1
    Medium

    CVE-2021-30150

    Last Modified: 7 Apr 2021

    Composr 10.0.36 allows XSS in an XML script.

    Source:Orion Hridoy
    Published:6 Apr 2021
    9.8
    Critical

    CVE-2021-30149

    Last Modified: 8 Apr 2021

    Composr 10.0.36 allows upload and execution of PHP files.

    Source:Orion Hridoy
    Published:6 Apr 2021
    8.8
    High

    CVE-2021-30147

    Last Modified: 8 Apr 2021

    DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.

    Source:Issac Briones
    Published:7 Apr 2021
    5.4
    Medium

    CVE-2021-30146

    Last Modified: 21 Nov 2024

    Seafile 7.0.5 (2019) allows Persistent XSS via the "share of library functionality."

    Published:6 Apr 2021
    9.8
    Critical

    CVE-2021-30128

    Last Modified: 21 Nov 2024

    Apache OFBiz has unsafe deserialization prior to 17.12.07 version

    Published:27 Apr 2021
    6.1
    Medium

    CVE-2021-30109

    Last Modified: 21 Nov 2024

    Froala Editor 3.2.6 is affected by Cross Site Scripting (XSS). Under certain conditions, a base64 crafted string leads to persistent Cross-site scripting (XSS) vulnerability within the hyperlink creation module.

    Published:5 Apr 2021
    5.4
    Medium

    CVE-2021-30044

    Last Modified: 22 Apr 2021

    Cross Site Scripting (XSS) in Remote Clinic v2.0 via the First Name or Last Name field on staff/register.php.

    Source:nu11secur1ty
    Published:12 Apr 2021
    5.4
    Medium

    CVE-2021-30042

    Last Modified: 23 Apr 2021

    Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Clinic Name", "Clinic Address", "Clinic City", or "Clinic Contact" field on clinics/register.php

    Source:Saud Ahmad
    Published:12 Apr 2021
    5.4
    Medium

    CVE-2021-30039

    Last Modified: 23 Apr 2021

    Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Fever" or "Blood Pressure" field on the patients/register-report.php.

    Source:Saud Ahmad
    Published:12 Apr 2021
    5.4
    Medium

    CVE-2021-30034

    Last Modified: 23 Apr 2021

    Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Symptons field on patients/register-report.php.

    Source:Saud Ahmad
    Published:12 Apr 2021
    5.4
    Medium

    CVE-2021-30030

    Last Modified: 23 Apr 2021

    Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Full Name field on register-patient.php.

    Source:Saud Ahmad
    Published:12 Apr 2021
    7.8
    High

    CVE-2021-30005

    Last Modified: 21 Nov 2024

    In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.

    Published:11 May 2021
    8.8
    High

    CVE-2021-29995

    Last Modified: 29 Oct 2021

    A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in user (including script execution). The issue is resolved in CloverDX 5.10, CloverDX 5.9.1, CloverDX 5.8.2, and CloverDX 5.7.1.

    Source:niebardzo
    Published:9 Jun 2021
    7.8
    High

    CVE-2021-29627

    Last Modified: 21 Nov 2024

    In FreeBSD 13.0-STABLE before n245050, 12.2-STABLE before r369525, 13.0-RC4 before p0, and 12.2-RELEASE before p6, listening socket accept filters implementing the accf_create callback incorrectly freed a process supplied argument string. Additional operations on the socket can lead to a double free or use after free.

    Published:7 Apr 2021
    7.5
    High

    CVE-2021-29505

    Last Modified: 30 May 2025

    XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types is affected. The vulnerability is patched in version 1.4.17.

    Published:14 May 2021
    7.6
    High

    CVE-2021-29460

    Last Modified: 28 Apr 2021

    Kirby is an open source CMS. An editor with write access to the Kirby Panel can upload an SVG file that contains harmful content like `<script>` tags. The direct link to that file can be sent to other users or visitors of the site. If the victim opens that link in a browser where they are logged in to Kirby, the script will run and can for example trigger requests to Kirby's API with the permissions of the victim. This vulnerability is critical if you might have potential attackers in your group of authenticated Panel users, as they can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Visitors without Panel access can only use this attack vector if your site allows SVG file uploads in frontend forms and you don't already sanitize uploaded SVG files. The problem has been patched in Kirby 3.5.4. Please update to this or a later version to fix the vulnerability. Frontend upload forms need to be patched separately depending on how they store the uploaded file(s). If you use `File::create()`, you are protected by updating to 3.5.4+. As a work around you can disable the upload of SVG files in your file blueprints.

    Source:Sreenath Raghunathan
    Published:27 Apr 2021
    7.1
    High

    CVE-2021-29447

    Last Modified: 20 Sept 2021

    Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is possible in a successful XXE attack. This has been patched in WordPress version 5.7.1, along with the older affected versions via a minor release. We strongly recommend you keep auto-updates enabled.

    Source:David Utón
    Published:15 Apr 2021
    8.6
    High

    CVE-2021-29442

    Last Modified: 21 Nov 2024

    Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, the ConfigOpsController lets the user perform management operations like querying the database or even wiping it out. While the /data/remove endpoint is properly protected with the @Secured annotation, the /derby endpoint is not protected and can be openly accessed by unauthenticated users. These endpoints are only valid when using embedded storage (derby DB) so this issue should not affect those installations using external storage (e.g. mysql)

    Published:27 Apr 2021
    8.6
    High

    CVE-2021-29441

    Last Modified: 21 Nov 2024

    Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, when configured to use authentication (-Dnacos.core.auth.enabled=true) Nacos uses the AuthFilter servlet filter to enforce authentication. This filter has a backdoor that enables Nacos servers to bypass this filter and therefore skip authentication checks. This mechanism relies on the user-agent HTTP header so it can be easily spoofed. This issue may allow any user to carry out any administrative tasks on the Nacos server.

    Published:27 Apr 2021
    8.4
    High

    CVE-2021-29440

    Last Modified: 7 Jun 2021

    Grav is a file based Web-platform. Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or edit pages. As the Twig processor runs unsandboxed, this behavior can be used to gain arbitrary code execution and elevate privileges on the instance. The issue was addressed in version 1.7.11.

    Source:enox
    Published:13 Apr 2021
    8
    High

    CVE-2021-29427

    Last Modified: 21 Nov 2024

    In Gradle from version 5.1 and before version 7.0 there is a vulnerability which can lead to information disclosure and/or dependency poisoning. Repository content filtering is a security control Gradle introduced to help users specify what repositories are used to resolve specific dependencies. This feature was introduced in the wake of the "A Confusing Dependency" blog post. In some cases, Gradle may ignore content filters and search all repositories for dependencies. This only occurs when repository content filtering is used from within a `pluginManagement` block in a settings file. This may change how dependencies are resolved for Gradle plugins and build scripts. For builds that are vulnerable, there are two risks: 1) Information disclosure: Gradle could make dependency requests to repositories outside your organization and leak internal package identifiers. 2) Dependency poisoning/Dependency confusion: Gradle could download a malicious binary from a repository outside your organization due to name squatting. For a full example and more details refer to the referenced GitHub Security Advisory. The problem has been patched and released with Gradle 7.0. Users relying on this feature should upgrade their build as soon as possible. As a workaround, users may use a company repository which has the right rules for fetching packages from public repositories, or use project level repository content filtering, inside `buildscript.repositories`. This option is available since Gradle 5.1 when the feature was introduced.

    Published:9 Apr 2021
    4.8
    Medium

    CVE-2021-29425

    Last Modified: 25 Aug 2026

    In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.

    Published:12 Apr 2021
    6.5
    Medium

    CVE-2021-29349

    Last Modified: 21 Nov 2024

    Mahara 20.10 is affected by Cross Site Request Forgery (CSRF) that allows a remote attacker to remove inbox-mail on the server. The application fails to validate the CSRF token for a POST request. An attacker can craft a module/multirecipientnotification/inbox.php pieform_delete_all_notifications request, which leads to removing all messages from a mailbox.

    Published:31 Mar 2021
    7.8
    High

    CVE-2021-29337

    Last Modified: 21 Nov 2024

    MODAPI.sys in MSI Dragon Center 2.0.104.0 allows low-privileged users to access kernel memory and potentially escalate privileges via a crafted IOCTL 0x9c406104 call. This IOCTL provides the MmMapIoSpace feature for mapping physical memory.

    Published:21 Jun 2021
    6.1
    Medium

    CVE-2021-29267

    Last Modified: 21 Nov 2024

    Sherlock SherlockIM through 2021-03-29 allows Cross Site Scripting (XSS) by leveraging the api/Files/Attachment URI to attack help-desk staff via the chatbot feature.

    Published:29 Mar 2021
    9.8
    Critical

    CVE-2021-29200

    Last Modified: 21 Nov 2024

    Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack

    Published:27 Apr 2021
    7.5
    High

    CVE-2021-29156

    Last Modified: 3 Nov 2021

    ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-character retrieval of password hashes, or retrieve a session token or a private key.

    Source:Charlton Trezevant
    Published:25 Mar 2021
    5.5
    Medium

    CVE-2021-29155

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 5.11.x. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory. Specifically, for sequences of pointer arithmetic operations, the pointer modification performed by the first operation is not correctly accounted for when restricting subsequent operations.

    Published:18 Apr 2021
    9.8
    Critical

    CVE-2021-29003

    Last Modified: 14 Apr 2021

    Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacters to sys_config_valid.xgi, as demonstrated by the sys_config_valid.xgi?exeshell=%60telnetd%20%26%60 URI.

    Source:Jay Sharma
    Published:13 Apr 2021
    7.2
    High

    CVE-2021-28976

    Last Modified: 13 Apr 2025

    Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess.

    Source:CodeSecLab
    Published:23 Jun 2021
    5.4
    Medium

    CVE-2021-28935

    Last Modified: 22 Apr 2021

    CMS Made Simple (CMSMS) 2.2.15 allows authenticated XSS via the /admin/addbookmark.php script through the Site Admin > My Preferences > Title field.

    Source:bt0
    Published:30 Mar 2021
    Unknown

    CVE-2021-28750

    https://github.com/PfalzPrince/CVE-2021-28750-site

    8.8
    High

    CVE-2021-28664

    Last Modified: 3 Nov 2025

    The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r8p0 through r30p0 before r31p0.

    Published:10 May 2021
    8.8
    High

    CVE-2021-28663

    Last Modified: 3 Nov 2025

    The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29p0, and Midgard r4p0 through r30p0.

    Published:10 May 2021
    8.8
    High

    CVE-2021-28482

    Last Modified: 21 Nov 2024

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Published:13 Apr 2021
    9.8
    Critical

    CVE-2021-28480

    Last Modified: 21 Nov 2024

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Published:13 Apr 2021