CVE Vulnerabilities
CVE vulnerability database enriched with CISA KEV and NVD data
| CVE ID | CVSS | Severity | KEV | Sightings |
|---|---|---|---|---|
| CVE-2021-39318 The H5P CSS Editor WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the h5p-css-file parameter found in the ~/h5p-css-editor.php file which allows attackers to inject arbitrary web... | 6.1 | MEDIUM | — | 0 |
| CVE-2021-39319 The duoFAQ - Responsive, Flat, Simple FAQ WordPess plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in the ~/duogeek/duogeek-panel.php file which allows attackers to ... | 6.1 | MEDIUM | — | 0 |
| CVE-2021-3836 dbeaver is vulnerable to Improper Restriction of XML External Entity Reference | 5.5 | MEDIUM | — | 0 |
| CVE-2021-41065 An issue was discovered in Listary through 6. An attacker can create a \\.\pipe\Listary.listaryService named pipe and wait for a privileged user to open a session on the Listary installed host. Listar... | 7.3 | HIGH | — | 0 |
| CVE-2021-41066 An issue was discovered in Listary through 6. When Listary is configured as admin, Listary will not ask for permissions again if a user tries to access files on the system from Listary itself (it will... | 7.5 | HIGH | — | 0 |
| CVE-2021-41067 An issue was discovered in Listary through 6. Improper implementation of the update process leads to the download of software updates with a /check-update HTTP-based connection. This can be exploited ... | 7.5 | HIGH | — | 0 |
| CVE-2021-41836 The Fathom Analytics WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and escaping via the $site_id parameter found in the ~/fathom-analytics.php file... | 4.8 | MEDIUM | — | 0 |
| CVE-2021-42061 SAP BusinessObjects Business Intelligence Platform (Web Intelligence) - version 420, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This al... | 5.4 | MEDIUM | — | 0 |
| CVE-2021-42070 When a user opens manipulated Jupiter Tessellation (.jt) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavaila... | 3.3 | LOW | — | 0 |
| CVE-2021-42063 A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. The usage of one SAP KW component within a Web browser enables unauthorized attackers to ... | 6.1 | MEDIUM | — | 0 |
| CVE-2021-42064 If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterized "in" clause, SAP Commerce - versions 1905, 2005, 2105, 2011, allows attacker t... | 9.8 | CRITICAL | — | 0 |
| CVE-2021-42066 SAP Business One - version 10.0, allows an admin user to view DB password in plain text over the network, which should otherwise be encrypted. For an attacker to discover vulnerable function in-depth ... | 4.4 | MEDIUM | — | 0 |
| CVE-2021-42068 When a user opens a manipulated GIF (.gif) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the use... | 3.3 | LOW | — | 0 |
| CVE-2021-42069 When a user opens manipulated Tagged Image File Format (.tif) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily una... | 3.3 | LOW | — | 0 |
| CVE-2021-43388 Unisys Cargo Mobile Application before 1.2.29 uses cleartext to store sensitive information, which might be revealed in a backup. The issue is addressed by ensuring that the allowBackup flag (in the m... | 7.5 | HIGH | — | 0 |
| CVE-2021-42367 The Variation Swatches for WooCommerce WordPress plugin is vulnerable to Stored Cross-Site Scripting via several parameters found in the ~/includes/class-menu-page.php file which allows attackers to i... | 6.4 | MEDIUM | — | 0 |
| CVE-2021-44231 Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application. | 9.8 | CRITICAL | — | 0 |
| CVE-2021-44232 SAF-T Framework Transaction SAFTN_G allows an attacker to exploit insufficient validation of path information provided by normal user, leading to full server directory access. The attacker can see the... | 7.7 | HIGH | — | 0 |
| CVE-2021-44233 SAP GRC Access Control - versions V1100_700, V1100_731, V1200_750, does not perform necessary authorization checks for an authenticated user, which could lead to escalation of privileges. | 8.8 | HIGH | — | 0 |
| CVE-2021-41870 An issue was discovered in the firmware update form in Socomec REMOTE VIEW PRO 2.0.41.4. An authenticated attacker can bypass a client-side file-type check and upload arbitrary .php files. | 8.8 | HIGH | — | 0 |
| CVE-2021-44235 Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allow an attacker with high privileges and has direct acce... | 6.7 | MEDIUM | — | 0 |
| CVE-2021-44549 Apache Sling Commons Messaging Mail provides a simple layer on top of JavaMail/Jakarta Mail for OSGi to send mails via SMTPS. To reduce the risk of "man in the middle" attacks additional server identi... | 7.4 | HIGH | — | 0 |
| CVE-2021-4073 The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identit... | 9.8 | CRITICAL | — | 0 |
| CVE-2021-38950 IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation attack when SharedBindingsUserId is set to effective. IBM X-ForceID: 211404. | 7.8 | HIGH | — | 0 |
| CVE-2021-40882 A Cross Site Scripting (XSS) vulnerability exists in Piwigo 11.5.0 via the system album name and description of the location. | 6.1 | MEDIUM | — | 0 |
| CVE-2023-21557 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | 7.5 | HIGH | — | 0 |
| CVE-2021-43807 Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast versions prior to 9.10 allow HTTP method spoofing, allowing to change the assumed HTTP method via URL parameter. T... | 7.5 | HIGH | — | 0 |
| CVE-2021-44041 UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI handler for uipath-assistant://. This allows an attacker to e... | 9.8 | CRITICAL | — | 0 |
| CVE-2021-44042 An issue was discovered in UiPath Assistant 21.4.4. User-controlled data supplied to the --process-start argument of the URI handler for uipath-assistant:// is not correctly encoded, resulting in atta... | 9.8 | CRITICAL | — | 0 |
| CVE-2021-44043 An issue was discovered in UiPath App Studio 21.4.4. There is a persistent XSS vulnerability in the file-upload functionality for uploading icons when attempting to create new Apps. An attacker with m... | 5.4 | MEDIUM | — | 0 |
| CVE-2018-10228 Cross-site scripting (XSS) vulnerability in /application/controller/admin/theme.php in LimeSurvey 3.6.2+180406 allows remote attackers to inject arbitrary web script or HTML via the changes_cp paramet... | 6.1 | MEDIUM | — | 0 |
| CVE-2021-40883 A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-19138 Ivanti Workspace Control before 10.4.50.0 allows attackers to degrade integrity. | 7.5 | HIGH | — | 0 |
| CVE-2021-43820 Seafile is an open source cloud storage system. A sync token is used in Seafile file syncing protocol to authorize access to library data. To improve performance, the token is cached in memory in seaf... | 7.4 | HIGH | — | 0 |
| CVE-2021-4044 Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate an internal error (f... | 7.5 | HIGH | — | 0 |
| CVE-2021-34425 The Zoom Client for Meetings before version 5.7.3 (for Android, iOS, Linux, macOS, and Windows) contain a server side request forgery vulnerability in the chat\'s "link preview" functionality. In vers... | 4.7 | MEDIUM | — | 0 |
| CVE-2021-34426 A vulnerability was discovered in the Keybase Client for Windows before version 5.6.0 when a user executed the "keybase git lfs-config" command on the command-line. In versions prior to 5.6.0, a malic... | 5.3 | MEDIUM | — | 0 |
| CVE-2021-39183 Owncast is an open source, self-hosted live video streaming and chat server. In affected versions inline scripts are executed when Javascript is parsed via a paste action. This issue is patched in 0.0... | 8.2 | HIGH | — | 0 |
| CVE-2021-43051 The Spotfire Server component of TIBCO Software Inc.'s TIBCO Spotfire Server, TIBCO Spotfire Server, and TIBCO Spotfire Server contains a difficult to exploit vulnerability that allows malicious custo... | 7.1 | HIGH | — | 0 |
| CVE-2021-43821 Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast before version 9.10 or 10.6 allows references to local file URLs in ingested media packages, allowing attackers to... | 9.9 | CRITICAL | — | 0 |
| CVE-2021-43828 PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.77 an improper privilege management (IDOR) has been found in PatrowlManager. All imports findin... | 7.5 | HIGH | — | 0 |
| CVE-2021-43829 PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.7.7 PatrowlManager unrestrictly handle upload files in the findings import feature. This vulner... | 7.4 | HIGH | — | 0 |
| CVE-2021-40452 HEVC Video Extensions Remote Code Execution Vulnerability | 7.8 | HIGH | — | 0 |
| CVE-2021-43830 OpenProject is a web-based project management software. OpenProject versions >= 12.0.0 are vulnerable to a SQL injection in the budgets module. For authenticated users with the "Edit budgets" permissi... | 7.4 | HIGH | — | 0 |
| CVE-2021-4108 snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | 6.1 | MEDIUM | — | 0 |
| CVE-2021-44942 glFusion CMS 1.7.9 is affected by a Cross Site Request Forgery (CSRF) vulnerability in /public_html/admin/plugins/bad_behavior2/blacklist.php. Using the CSRF vulnerability to trick the administrator t... | 4.3 | MEDIUM | — | 0 |
| CVE-2021-43827 discourse-footnote is a library providing footnotes for posts in Discourse. ### Impact When posting an inline footnote wrapped in `<a>` tags (e.g. `<a>^[footnote]</a>`, the resulting rendered HTML wou... | 4.3 | MEDIUM | — | 0 |
| CVE-2021-4110 mruby is vulnerable to NULL Pointer Dereference | 7.5 | HIGH | — | 0 |
| CVE-2021-41844 Crocoblock JetEngine before 2.9.1 does not properly validate and sanitize form data. | 9.8 | CRITICAL | — | 0 |
| CVE-2021-26787 A cross site scripting (XSS) vulnerability in Genesys Workforce Management 8.5.214.20 can occur (during record deletion) via the Time-off parameter. | 6.1 | MEDIUM | — | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.