7.5
    High

    CVE-2021-27188

    Last Modified: 21 Nov 2024

    The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 allows attackers to cause a denial of service (access suspended for five hours) by making five invalid login attempts to a victim's account.

    Published:12 Feb 2021
    7.5
    High

    CVE-2021-27187

    Last Modified: 21 Nov 2024

    The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 stores authentication credentials in cleartext in login.sav when the Save Password box is checked.

    Published:12 Feb 2021
    6.1
    Medium

    CVE-2021-27180

    Last Modified: 21 Nov 2024

    An issue was discovered in MDaemon before 20.0.4. There is Reflected XSS in Webmail (aka WorldClient). It can be exploited via a GET request. It allows performing any action with the privileges of the attacked user.

    Published:14 Apr 2021
    9.8
    Critical

    CVE-2021-27101

    Last Modified: 3 Nov 2025

    Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA_9_12_380 and later.

    Published:16 Feb 2021
    7.8
    High

    CVE-2021-27065

    Last Modified: 1 Nov 2021

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Source:testanull
    Published:2 Mar 2021
    8.2
    High

    CVE-2021-26943

    Last Modified: 21 Nov 2024

    The UX360CA BIOS through 303 on ASUS laptops allow an attacker (with the ring 0 privilege) to overwrite nearly arbitrary physical memory locations, including SMRAM, and execute arbitrary code in the SMM (issue 3 of 3).

    Published:31 Mar 2021
    6.1
    Medium

    CVE-2021-26929

    Last Modified: 15 Apr 2021

    An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library before 2.3.7 is used). The attacker can send a plain text e-mail message, with JavaScript encoded as a link or email that is mishandled by preProcess in Text2html.php, because bespoke use of \x00\x00\x00 and \x01\x01\x01 interferes with XSS defenses.

    Source:nu11secur1ty
    Published:14 Feb 2021
    9.8
    Critical

    CVE-2021-26904

    Last Modified: 21 Nov 2024

    LMA ISIDA Retriever 5.2 allows SQL Injection.

    Published:26 Feb 2021
    6.1
    Medium

    CVE-2021-26903

    Last Modified: 21 Nov 2024

    LMA ISIDA Retriever 5.2 is vulnerable to XSS via query['text'].

    Published:26 Feb 2021
    7.8
    High

    CVE-2021-26882

    Last Modified: 19 Aug 2026

    Remote Access API Elevation of Privilege Vulnerability

    Published:11 Mar 2021
    7.8
    High

    CVE-2021-26871

    Last Modified: 19 Aug 2026

    Windows WalletService Elevation of Privilege Vulnerability

    Published:11 Mar 2021
    7.8
    High

    CVE-2021-26868

    Last Modified: 19 Aug 2026

    Windows Graphics Component Elevation of Privilege Vulnerability

    Published:11 Mar 2021
    7.8
    High

    CVE-2021-26857

    Last Modified: 19 Aug 2026

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Published:2 Mar 2021
    Unknown

    CVE-2021-26856

    https://github.com/avi8892/CVE-2021-26856

    9.1
    Critical

    CVE-2021-26855

    Last Modified: 1 Nov 2021

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Source:F5
    Published:2 Mar 2021
    9.8
    Critical

    CVE-2021-26837

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in SearchTextBox parameter in Fortra (Formerly HelpSystems) DeliverNow before version 1.2.18, allows attackers to execute arbitrary code, escalate privileges, and gain sensitive information.

    Published:18 Sept 2023
    6.1
    Medium

    CVE-2021-26832

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in the "Reset Password" page form of Priority Enterprise Management System v8.00 allows attackers to execute javascript on behalf of the victim by sending a malicious URL or directing the victim to a malicious site.

    Published:14 Apr 2021
    9.1
    Critical

    CVE-2021-26830

    Last Modified: 26 Apr 2021

    SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is accomplished via the `ID` input field of ajax.php in the `Pugin library - delete` module.

    Source:Balaji Ayyasamy
    Published:16 Apr 2021
    8.8
    High

    CVE-2021-26828

    Last Modified: 4 Dec 2025

    OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.

    Published:11 Jun 2021
    8.8
    High

    CVE-2021-26814

    Last Modified: 21 Nov 2024

    Wazuh API in Wazuh from 4.0.0 to 4.0.3 allows authenticated users to execute arbitrary code with administrative privileges via /manager/files URI. An authenticated user to the service may exploit incomplete input validation on the /manager/files API to inject arbitrary code within the API service script.

    Published:6 Mar 2021
    9.8
    Critical

    CVE-2021-26714

    Last Modified: 21 Nov 2024

    The Enterprise License Manager portal in Mitel MiContact Center Enterprise before 9.4 could allow a user to access restricted files and folders due to insufficient access control. A successful exploit could allow an attacker to view and modify application data via Directory Traversal.

    Published:29 Mar 2021
    7
    High

    CVE-2021-26708

    Last Modified: 21 Nov 2024

    A local privilege escalation was discovered in the Linux kernel before 5.10.13. Multiple race conditions in the AF_VSOCK implementation are caused by wrong locking in net/vmw_vsock/af_vsock.c. The race conditions were implicitly introduced in the commits that added VSOCK multi-transport support.

    Published:5 Feb 2021
    7.8
    High

    CVE-2021-26700

    Last Modified: 16 Jul 2025

    Visual Studio Code npm-script Extension Remote Code Execution Vulnerability

    Published:25 Feb 2021
    9.8
    Critical

    CVE-2021-26691

    Last Modified: 21 Nov 2024

    In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow

    Published:4 Jun 2021
    7.5
    High

    CVE-2021-26690

    Last Modified: 21 Nov 2024

    Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service

    Published:4 Jun 2021
    9.8
    Critical

    CVE-2021-26599

    Last Modified: 30 Mar 2022

    ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.

    Source:Egidio Romano
    Published:28 Mar 2022
    7.8
    High

    CVE-2021-26415

    Last Modified: 21 Nov 2024

    Windows Installer Elevation of Privilege Vulnerability

    Published:13 Apr 2021
    4.8
    Medium

    CVE-2021-26414

    Last Modified: 21 Nov 2024

    Windows DCOM Server Security Feature Bypass

    Published:8 Jun 2021
    8.8
    High

    CVE-2021-26411

    Last Modified: 19 Aug 2026

    Internet Explorer Memory Corruption Vulnerability

    Published:11 Mar 2021
    9.8
    Critical

    CVE-2021-26295

    Last Modified: 13 Feb 2025

    Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.

    Published:22 Mar 2021
    9.1
    Critical

    CVE-2021-26291

    Last Modified: 21 Nov 2024

    Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior. See this link for more information about repository management: https://maven.apache.org/repository-management.html

    Published:23 Apr 2021
    7.8
    High

    CVE-2021-26258

    Last Modified: 5 May 2025

    Improper access control for the Intel(R) Killer(TM) Control Center software before version 2.4.3337.0 may allow an authorized user to potentially enable escalation of privilege via local access.

    Published:12 May 2022
    Unknown

    CVE-2021-26121

    https://github.com/sourceincite/CVE-2021-26121

    9.8
    Critical

    CVE-2021-26102

    Last Modified: 21 Jan 2025

    A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated attacker to delete files on the system by sending a crafted POST request. In particular, deleting specific configuration files will reset the Admin password to its default value.

    Published:19 Dec 2024
    7.1
    High

    CVE-2021-26088

    Last Modified: 21 Nov 2024

    An improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user to bypass a FSSO firewall policy and access the protected network via sending specifically crafted UDP login notification packets.

    Published:12 Jul 2021
    5.3
    Medium

    CVE-2021-26086

    Last Modified: 28 Oct 2021

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1.

    Source:Mayank Deshmukh
    Published:16 Aug 2021
    5.3
    Medium

    CVE-2021-26085

    Last Modified: 5 Oct 2021

    Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.

    Source:Mayank Deshmukh
    Published:3 Aug 2021
    9.8
    Critical

    CVE-2021-26084

    Last Modified: 1 Sept 2021

    In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.

    Source:Fellipe Oliveira
    Published:30 Aug 2021
    6.1
    Medium

    CVE-2021-26078

    Last Modified: 29 Oct 2021

    The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from version 8.14.0 before version 8.16.1 allows remote attackers inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability.

    Source:Captain_hook
    Published:7 Jun 2021
    7.5
    High

    CVE-2021-25837

    Last Modified: 21 Nov 2024

    Cosmos Network Ethermint <= v0.4.0 is affected by cache lifecycle inconsistency in the EVM module. Due to the inconsistency between the Storage caching cycle and the Tx processing cycle, Storage changes caused by a failed transaction are improperly reserved in memory. Although the bad storage cache data will be discarded at EndBlock, it is still valid in the current block, which enables many possible attacks such as an "arbitrary mint token".

    Published:8 Feb 2021
    7.5
    High

    CVE-2021-25804

    Last Modified: 21 Nov 2024

    A NULL-pointer dereference in "Open" in avi.c of VideoLAN VLC Media Player 3.0.11 can a denial of service (DOS) in the application.

    Published:26 Jul 2021
    7.1
    High

    CVE-2021-25801

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in the __Parse_indx component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.

    Published:26 Jul 2021
    5.4
    Medium

    CVE-2021-25791

    Last Modified: 5 Aug 2021

    Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in the First Name, Last Name, and Address text fields.

    Source:Mohamed habib Smidi
    Published:23 Jul 2021
    5.4
    Medium

    CVE-2021-25790

    Last Modified: 21 Nov 2024

    Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in all text fields except for Phone Number and Alternate Phone Number.

    Published:23 Jul 2021
    8.8
    High

    CVE-2021-25741

    Last Modified: 21 Nov 2024

    A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.

    Published:15 Sept 2021
    6.5
    Medium

    CVE-2021-25735

    Last Modified: 21 Nov 2024

    A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some previous fields.

    Published:14 Apr 2021
    7.5
    High

    CVE-2021-25681

    Last Modified: 21 Apr 2021

    AdTran Personal Phone Manager 10.8.1 software is vulnerable to an issue that allows for exfiltration of data over DNS. This could allow for exposed AdTran Personal Phone Manager web servers to be used as DNS redirectors to tunnel arbitrary data over DNS. NOTE: The affected appliances NetVanta 7060 and NetVanta 7100 are considered End of Life and as such this issue will not be patched.

    Source:3ndG4me
    Published:20 Apr 2021
    6.1
    Medium

    CVE-2021-25680

    Last Modified: 21 Apr 2021

    The AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) issues. These issues impact at minimum versions 10.8.1 and below but potentially impact later versions as well since they have not previously been disclosed. Only version 10.8.1 was able to be confirmed during primary research. NOTE: The affected appliances NetVanta 7060 and NetVanta 7100 are considered End of Life and as such this issue will not be patched.

    Source:3ndG4me
    Published:20 Apr 2021
    5.4
    Medium

    CVE-2021-25679

    Last Modified: 21 Apr 2021

    The AdTran Personal Phone Manager software is vulnerable to an authenticated stored cross-site scripting (XSS) issues. These issues impact at minimum versions 10.8.1 and below but potentially impact later versions as well since they have not previously been disclosed. Only version 10.8.1 was able to be confirmed during primary research. NOTE: The affected appliances NetVanta 7060 and NetVanta 7100 are considered End of Life and as such this issue will not be patched.

    Source:3ndG4me
    Published:20 Apr 2021
    8.8
    High

    CVE-2021-25646

    Last Modified: 13 Feb 2025

    Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it is possible for an authenticated user to send a specially-crafted request that forces Druid to run user-provided JavaScript code for that request, regardless of server configuration. This can be leveraged to execute code on the target machine with the privileges of the Druid server process.

    Published:29 Jan 2021