9.9
    Critical

    CVE-2021-28476

    Last Modified: 21 Nov 2024

    Windows Hyper-V Remote Code Execution Vulnerability

    Published:11 May 2021
    4.8
    Medium

    CVE-2021-28420

    Last Modified: 3 Jun 2021

    A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via alerts.php and the "from_time" parameter.

    Source:Piyush Patil
    Published:18 Mar 2021
    7.2
    High

    CVE-2021-28419

    Last Modified: 26 Apr 2021

    The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads to the ability to retrieve all databases.

    Source:nu11secur1ty
    Published:18 Mar 2021
    4.8
    Medium

    CVE-2021-28418

    Last Modified: 2 Jun 2021

    A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via settings.php and the "category" parameter.

    Source:Piyush Patil
    Published:18 Mar 2021
    4.8
    Medium

    CVE-2021-28417

    Last Modified: 2 Jun 2021

    A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php and the "search_name" parameter.

    Source:Piyush Patil
    Published:18 Mar 2021
    8.8
    High

    CVE-2021-28379

    Last Modified: 17 Mar 2021

    web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different origin.

    Source:Fady Mohammed Osman
    Published:15 Mar 2021
    3.7
    Low

    CVE-2021-28378

    Last Modified: 21 Nov 2024

    Gitea 1.12.x and 1.13.x before 1.13.4 allows XSS via certain issue data in some situations.

    Published:15 Mar 2021
    3.3
    Low

    CVE-2021-28312

    Last Modified: 21 Nov 2024

    Windows NTFS Denial of Service Vulnerability

    Published:13 Apr 2021
    7.8
    High

    CVE-2021-28310

    Last Modified: 30 Oct 2025

    Win32k Elevation of Privilege Vulnerability

    Published:13 Apr 2021
    8.8
    High

    CVE-2021-28242

    Last Modified: 6 May 2021

    SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by injecting SQL commands into the "cf_name" parameter when creating a new filter under the "Collections" tab.

    Source:nu11secur1ty
    Published:15 Apr 2021
    9.8
    Critical

    CVE-2021-28235

    Last Modified: 18 Feb 2025

    Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.

    Published:4 Apr 2023
    7.5
    High

    CVE-2021-28165

    Last Modified: 27 Aug 2025

    In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.

    Published:1 Apr 2021
    5.3
    Medium

    CVE-2021-28164

    Last Modified: 22 Oct 2021

    In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.

    Source:Mayank Deshmukh
    Published:1 Apr 2021
    8.8
    High

    CVE-2021-28142

    Last Modified: 14 Apr 2021

    CITSmart before 9.1.2.28 mishandles the "filtro de autocomplete."

    Source:skysbsb
    Published:6 Apr 2021
    6.1
    Medium

    CVE-2021-28079

    Last Modified: 21 Nov 2024

    Jamovi <=1.6.18 is affected by a cross-site scripting (XSS) vulnerability. The column-name is vulnerable to XSS in the ElectronJS Framework. An attacker can make a .omv (Jamovi) document containing a payload. When opened by victim, the payload is triggered.

    Published:26 Apr 2021
    7.2
    High

    CVE-2021-27973

    Last Modified: 3 May 2021

    SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages.

    Source:nu11secur1ty
    Published:2 Apr 2021
    9.8
    Critical

    CVE-2021-27965

    Last Modified: 21 Nov 2024

    The MsIo64.sys driver before 1.1.19.1016 in MSI Dragon Center before 2.0.98.0 has a buffer overflow that allows privilege escalation via a crafted 0x80102040, 0x80102044, 0x80102050, or 0x80102054 IOCTL request.

    Published:5 Mar 2021
    9.8
    Critical

    CVE-2021-27964

    Last Modified: 15 Mar 2021

    SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Config/SaveUploadedHotspotLogoFile without any authentication or session header. There is no check for the file extension or content of the uploaded file.

    Source:Berkan Er
    Published:5 Mar 2021
    8.2
    High

    CVE-2021-27963

    Last Modified: 21 Nov 2024

    SonLogger before 6.4.1 is affected by user creation with any user permissions profile (e.g., SuperAdmin). An anonymous user can send a POST request to /User/saveUser without any authentication or session header.

    Published:5 Mar 2021
    8.8
    High

    CVE-2021-27946

    Last Modified: 23 Mar 2021

    SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. (issue 1 of 3).

    Source:SivertPL
    Published:15 Mar 2021
    7.2
    High

    CVE-2021-27928

    Last Modified: 29 Oct 2021

    A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL. An untrusted search path leads to eval injection, in which a database SUPER user can execute OS commands after modifying wsrep_provider and wsrep_notify_cmd. NOTE: this does not affect an Oracle product.

    Source:Central InfoSec
    Published:19 Mar 2021
    9.8
    Critical

    CVE-2021-27905

    Last Modified: 21 Nov 2024

    The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate another ReplicationHandler on another Solr core to replicate index data into the local core. To prevent a SSRF vulnerability, Solr ought to check these parameters against a similar configuration it uses for the "shards" parameter. Prior to this bug getting fixed, it did not. This problem affects essentially all Solr versions prior to it getting fixed in 8.8.2.

    Published:12 Apr 2021
    8.8
    High

    CVE-2021-27890

    Last Modified: 23 Mar 2021

    SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.

    Source:SivertPL
    Published:15 Mar 2021
    6.1
    Medium

    CVE-2021-27889

    Last Modified: 23 Mar 2021

    Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages.

    Source:SivertPL
    Published:15 Mar 2021
    8.8
    High

    CVE-2021-27885

    Last Modified: 4 Mar 2021

    usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.

    Source:Tadjmen
    Published:2 Mar 2021
    8.2
    High

    CVE-2021-27877

    Last Modified: 3 Nov 2025

    An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer used in current versions of the product, but hadn't yet been disabled. An attacker could remotely exploit this scheme to gain unauthorized access to an Agent and execute privileged commands.

    Published:1 Mar 2021
    8.1
    High

    CVE-2021-27876

    Last Modified: 3 Nov 2025

    An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. By using crafted input parameters in one of these commands, an attacker can access an arbitrary file on the system using System privileges.

    Published:1 Mar 2021
    9.8
    Critical

    CVE-2021-27850

    Last Modified: 21 Nov 2024

    A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5, 5.5.0, 5.6.2 and 5.7.0. The vulnerability I have found is a bypass of the fix for CVE-2019-0195. Recap: Before the fix of CVE-2019-0195 it was possible to download arbitrary class files from the classpath by providing a crafted asset file URL. An attacker was able to download the file `AppModule.class` by requesting the URL `http://localhost:8080/assets/something/services/AppModule.class` which contains a HMAC secret key. The fix for that bug was a blacklist filter that checks if the URL ends with `.class`, `.properties` or `.xml`. Bypass: Unfortunately, the blacklist solution can simply be bypassed by appending a `/` at the end of the URL: `http://localhost:8080/assets/something/services/AppModule.class/` The slash is stripped after the blacklist check and the file `AppModule.class` is loaded into the response. This class usually contains the HMAC secret key which is used to sign serialized Java objects. With the knowledge of that key an attacker can sign a Java gadget chain that leads to RCE (e.g. CommonsBeanUtils1 from ysoserial). Solution for this vulnerability: * For Apache Tapestry 5.4.0 to 5.6.1, upgrade to 5.6.2 or later. * For Apache Tapestry 5.7.0, upgrade to 5.7.1 or later.

    Published:15 Apr 2021
    9.1
    Critical

    CVE-2021-27828

    Last Modified: 3 Jun 2021

    SQL injection in In4Suite ERP 3.2.74.1370 allows attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.

    Source:Gulab Mondal
    Published:1 Jun 2021
    7.5
    High

    CVE-2021-27825

    Last Modified: 7 Apr 2023

    A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-static/ URL.

    Source:Chunlei Shang_ Jiangsu Public Information Co._ Ltd.
    Published:29 May 2023
    6.1
    Medium

    CVE-2021-27695

    Last Modified: 16 Mar 2021

    Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbitrary web script or HTML via any "Add" sections, such as Add Card Building & Floor, or others in the Name and Code Parameters.

    Source:Hosein Vita
    Published:15 Mar 2021
    9.8
    Critical

    CVE-2021-27651

    Last Modified: 21 Nov 2024

    In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks.

    Published:29 Apr 2021
    5.9
    Medium

    CVE-2021-27568

    Last Modified: 21 Nov 2024

    An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.

    Published:23 Feb 2021
    6.1
    Medium

    CVE-2021-27520

    Last Modified: 3 Jun 2021

    A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "author" parameter.

    Source:Piyush Patil
    Published:19 Mar 2021
    6.1
    Medium

    CVE-2021-27519

    Last Modified: 3 Jun 2021

    A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "srch" parameter.

    Source:Piyush Patil
    Published:19 Mar 2021
    8.8
    High

    CVE-2021-27513

    Last Modified: 21 Nov 2024

    The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files because it relies on "le filtre userside."

    Published:21 Feb 2021
    6.1
    Medium

    CVE-2021-27404

    Last Modified: 21 Nov 2024

    Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow injection of a Host HTTP header.

    Published:19 Feb 2021
    6.1
    Medium

    CVE-2021-27403

    Last Modified: 21 Nov 2024

    Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow cgi-bin/te_acceso_router.cgi curWebPage XSS.

    Published:19 Feb 2021
    5.4
    Medium

    CVE-2021-27370

    Last Modified: 23 Feb 2021

    The Contact page in Monica 2.19.1 allows stored XSS via the Last Name field.

    Source:BouSalman
    Published:22 Feb 2021
    7.8
    High

    CVE-2021-27365

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink message.

    Published:5 Mar 2021
    5.9
    Medium

    CVE-2021-27342

    Last Modified: 21 Nov 2024

    An authentication brute-force protection mechanism bypass in telnetd in D-Link Router model DIR-842 firmware version 3.0.2 allows a remote attacker to circumvent the anti-brute-force cool-down delay period via a timing-based side-channel attack

    Published:17 May 2021
    5.4
    Medium

    CVE-2021-27338

    Last Modified: 21 Nov 2024

    Faraday Edge before 3.7 allows XSS via the network/create/ page and its network name parameter.

    Published:20 Jul 2021
    6.5
    Medium

    CVE-2021-27328

    Last Modified: 21 Nov 2024

    Yeastar NeoGate TG400 91.3.0.3 devices are affected by Directory Traversal. An authenticated user can decrypt firmware and can read sensitive information, such as a password or decryption key.

    Published:19 Feb 2021
    4.8
    Medium

    CVE-2021-27308

    Last Modified: 3 Jun 2021

    A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to inject JavaScript via the "redirect" parameter.

    Source:Piyush Patil
    Published:22 Mar 2021
    9.1
    Critical

    CVE-2021-27289

    Last Modified: 15 Apr 2026

    A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gateway Module = v1.0.3, Door Sensor = v1.0.7, Motion Sensor = v1.0.12), where the Zigbee anti-replay mechanism - based on the frame counter field - is improperly implemented. As a result, an attacker within wireless range can resend captured packets with a higher sequence number, which the devices incorrectly accept as legitimate messages. This allows spoofed commands to be injected without authentication, triggering false alerts and misleading the user through notifications in the mobile application used to monitor the network.

    Published:15 Apr 2025
    8.4
    High

    CVE-2021-27285

    Last Modified: 5 Sept 2025

    An issue was discovered in Inspur ClusterEngine v4.0 that allows attackers to gain escalated Local privileges and execute arbitrary commands via /opt/tsce4/torque6/bin/getJobsByShell.

    Published:6 Jan 2025
    8
    High

    CVE-2021-27246

    Last Modified: 21 Nov 2024

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 AC1750 1.0.15 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of MAC addresses by the tdpServer endpoint. A crafted TCP message can write stack pointers to the stack. An attacker can leverage this vulnerability to execute code in the context of the root user. Was ZDI-CAN-12306.

    Published:14 Apr 2021
    7.5
    High

    CVE-2021-27211

    Last Modified: 21 Nov 2024

    steghide 0.5.1 relies on a certain 32-bit seed value, which makes it easier for attackers to detect hidden data.

    Published:15 Feb 2021
    9.8
    Critical

    CVE-2021-27198

    Last Modified: 21 Nov 2024

    An issue was discovered in Visualware MyConnection Server before v11.1a. Unauthenticated Remote Code Execution can occur via Arbitrary File Upload in the web service when using a myspeed/sf?filename= URI. This application is written in Java and is thus cross-platform. The Windows installation runs as SYSTEM, which means that exploitation gives one Administrator privileges on the target system.

    Published:26 Feb 2021
    5.4
    Medium

    CVE-2021-27190

    Last Modified: 21 Nov 2024

    A Stored Cross Site Scripting(XSS) Vulnerability was discovered in PEEL SHOPPING 9.3.0 and 9.4.0, which are publicly available. The user supplied input containing polyglot payload is echoed back in javascript code in HTML response. This allows an attacker to input malicious JavaScript which can steal cookie, redirect them to other malicious website, etc.

    Published:12 Feb 2021