Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-0408 1 Google 1 Android 2021-08-24 2.1 LOW 5.5 MEDIUM
In asf extractor, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489195; Issue ID: ALPS05489220.
CVE-2021-0407 1 Google 1 Android 2021-08-24 4.6 MEDIUM 6.7 MEDIUM
In clk driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05479659; Issue ID: ALPS05479659.
CVE-2020-4992 1 Ibm 1 Datapower Gateway 2021-08-24 4.3 MEDIUM 6.5 MEDIUM
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.16 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 192737.
CVE-2021-38583 1 Openbaraza 1 Openbaraza Human Capital Management 2021-08-24 4.3 MEDIUM 6.1 MEDIUM
openBaraza HCM 3.1.6 does not properly neutralize user-controllable input, which allows reflected cross-site scripting (XSS) on multiple pages: hr/subscription.jsp and hr/application.jsp and and hr/index.jsp (with view= and data=).
CVE-2021-3573 3 Fedoraproject, Linux, Redhat 3 Fedora, Linux Kernel, Enterprise Linux 2021-08-24 6.9 MEDIUM 6.4 MEDIUM
A use-after-free in function hci_sock_bound_ioctl() of the Linux kernel HCI subsystem was found in the way user calls ioct HCIUNBLOCKADDR or other way triggers race condition of the call hci_unregister_dev() together with one of the calls hci_sock_blacklist_add(), hci_sock_blacklist_del(), hci_get_conn_info(), hci_get_auth_info(). A privileged local user could use this flaw to crash the system or escalate their privileges on the system. This flaw affects the Linux kernel versions prior to 5.13-rc5.
CVE-2021-37598 1 Wpcerber 1 Wp Cerber 2021-08-24 5.0 MEDIUM 5.3 MEDIUM
WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character.
CVE-2021-3707 1 D-link 2 Dsl-2750u, Dsl-2750u Firmware 2021-08-24 2.1 LOW 5.5 MEDIUM
D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to unauthorized configuration modification. An unauthenticated attacker on the local network may exploit this, with CVE-2021-3708, to execute any OS commands on the vulnerable device.
CVE-2021-27999 1 Local Services Search Engine Management System Project 1 Local Services Search Engine Management System 2021-08-24 4.0 MEDIUM 4.9 MEDIUM
A SQL injection vulnerability was discovered in the editid parameter in Local Services Search Engine Management System Project 1.0. This vulnerability gives admin users the ability to dump all data from the database.
CVE-2020-18878 1 Skycaiji 1 Skycaiji 2021-08-24 5.0 MEDIUM 5.3 MEDIUM
Directory Traversal in Skycaiji v1.3 allows remote attackers to obtain sensitive information via the component 'index.php?m=admin&c=Tool&a=log&file=D%3A%5CphpStudy%5CWWW%5Cindex.php'.
CVE-2021-0642 1 Google 1 Android 2021-08-24 4.3 MEDIUM 5.5 MEDIUM
In onResume of VoicemailSettingsFragment.java, there is a possible way to retrieve a trackable identifier without permissions due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-185126149
CVE-2021-0641 1 Google 1 Android 2021-08-24 2.1 LOW 5.5 MEDIUM
In getAvailableSubscriptionInfoList of SubscriptionController.java, there is a possible disclosure of unique identifiers due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-185235454
CVE-2021-0639 1 Google 1 Android 2021-08-24 2.1 LOW 5.5 MEDIUM
In multiple functions of libl3oemcrypto.cpp, there is a possible weakness in the existing obfuscation mechanism due to the way sensitive data is handled. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-190724551
CVE-2021-0584 1 Google 1 Android 2021-08-24 2.1 LOW 5.5 MEDIUM
In verifyBufferObject of Parcel.cpp, there is a possible out of bounds read due to an improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-179289794
CVE-2021-0582 1 Google 1 Android 2021-08-24 3.3 LOW 6.5 MEDIUM
In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-187149601
CVE-2021-0581 1 Google 1 Android 2021-08-24 3.3 LOW 6.5 MEDIUM
In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-187231638
CVE-2021-0580 1 Google 1 Android 2021-08-24 3.3 LOW 6.5 MEDIUM
In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-187231637
CVE-2021-0579 1 Google 1 Android 2021-08-24 3.3 LOW 6.5 MEDIUM
In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-187231636
CVE-2021-0578 1 Google 1 Android 2021-08-24 3.3 LOW 6.5 MEDIUM
In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-187161772
CVE-2020-25353 1 Rconfig 1 Rconfig 2021-08-24 4.0 MEDIUM 6.5 MEDIUM
A server-side request forgery (SSRF) vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability allowed remote authenticated attackers to open a connection to the machine via the deviceIpAddr and connPort parameters.
CVE-2021-29313 1 Seacms 1 Seacms 2021-08-24 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability exists in SeaCMS 12.6 via the (1) v_company and (2) v_tvs parameters in /admin_video.php,
CVE-2021-34656 1 Videowhisper 1 2way Videocalls And Random Chat 2021-08-24 4.3 MEDIUM 6.1 MEDIUM
The 2Way VideoCalls and Random Chat - HTML5 Webcam Videochat WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `vws_notice` function found in the ~/inc/requirements.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 5.2.7.
CVE-2021-34653 1 Wp Fountain Project 1 Wp Fountain 2021-08-24 4.3 MEDIUM 6.1 MEDIUM
The WP Fountain WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/wp-fountain.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.5.9.
CVE-2021-34654 1 Custom Post Type Relations Project 1 Custom Post Type Relations 2021-08-24 4.3 MEDIUM 6.1 MEDIUM
The Custom Post Type Relations WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the cptr[name] parameter found in the ~/pages/admin-page.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.
CVE-2021-39283 1 Live555 1 Live555 2021-08-24 4.3 MEDIUM 5.5 MEDIUM
liveMedia/FramedSource.cpp in Live555 through 1.08 allows an assertion failure and application exit via multiple SETUP and PLAY commands.
CVE-2021-34655 1 Wp Songbook Project 1 Wp Songbook 2021-08-24 4.3 MEDIUM 6.1 MEDIUM
The WP Songbook WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the url parameter found in the ~/inc/class.ajax.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.11.
CVE-2021-34663 1 Arvtard 1 Jquery Tagline Rotator 2021-08-24 4.3 MEDIUM 6.1 MEDIUM
The jQuery Tagline Rotator WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/jquery-tagline-rotator.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.1.5.
CVE-2021-34664 1 Moova 1 Moova For Woocommerce 2021-08-24 4.3 MEDIUM 6.1 MEDIUM
The Moova for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the lat parameter in the ~/Checkout/Checkout.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.5.
CVE-2020-23069 1 Webtareas Project 1 Webtareas 2021-08-24 4.0 MEDIUM 6.5 MEDIUM
Path Traversal vulneraility exists in webTareas 2.0 via the extpath parameter in general_serv.php, which could let a malicious user read arbitrary files.
CVE-2021-38710 1 Yclas 1 Yclas 2021-08-24 4.3 MEDIUM 6.1 MEDIUM
Static (Persistent) XSS Vulnerability exists in version 4.3.0 of Yclas when using the install/view/form.php script. An attacker can store XSS in the database through the vulnerable SITE_NAME parameter.
CVE-2020-28146 1 Eyoucms 1 Eyoucms 2021-08-24 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter.
CVE-2021-39286 1 Webrecorder 1 Pywb 2021-08-24 4.3 MEDIUM 6.1 MEDIUM
Webrecorder pywb before 2.6.0 allows XSS because it does not ensure that Jinja2 templates are autoescaped.
CVE-2021-34665 1 Wp Seo Tags Project 1 Wp Seo Tags 2021-08-24 4.3 MEDIUM 6.1 MEDIUM
The WP SEO Tags WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the saq_txt_the_filter parameter in the ~/wp-seo-tags.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.2.7.
CVE-2021-34666 1 Add Sidebar Project 1 Add Sidebar 2021-08-24 4.3 MEDIUM 6.1 MEDIUM
The Add Sidebar WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the add parameter in the ~/wp_sidebarMenu.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.0.
CVE-2021-29056 1 Pixelimity 1 Pixelimity 2021-08-24 3.5 LOW 4.8 MEDIUM
Cross Site Scripting (XSS) vulnerability exists in Pixelimity 1.0 via the HTTP POST parameter to admin/setting.php.
CVE-2021-20775 1 Cybozu 1 Garoon 2021-08-24 4.0 MEDIUM 4.3 MEDIUM
Improper input validation vulnerability in Bulletin of Cybozu Garoon 4.10.0 to 5.5.0 allows a remote authenticated attacker to obtain the data of Comment and Space without the viewing privilege.
CVE-2021-20774 1 Cybozu 1 Garoon 2021-08-24 3.5 LOW 5.4 MEDIUM
Cross-site scripting vulnerability in some functions of E-mail of Cybozu Garoon 4.0.0 to 5.5.0 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
CVE-2021-20772 1 Cybozu 1 Garoon 2021-08-24 4.0 MEDIUM 4.3 MEDIUM
Information disclosure vulnerability in Bulletin of Cybozu Garoon 4.10.0 to 5.5.0 allows a remote authenticated attacker to obtain the title of Bulletin without the viewing privilege.
CVE-2021-22933 1 Pulsesecure 1 Pulse Connect Secure 2021-08-24 5.5 MEDIUM 6.5 MEDIUM
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform an arbitrary file delete via a maliciously crafted web request.
CVE-2021-20770 1 Cybozu 1 Garoon 2021-08-24 3.5 LOW 5.4 MEDIUM
Cross-site scripting vulnerability in Message of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
CVE-2021-20769 1 Cybozu 1 Garoon 2021-08-24 3.5 LOW 5.4 MEDIUM
Cross-site scripting vulnerability in Bulletin of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
CVE-2021-20767 1 Cybozu 1 Garoon 2021-08-24 3.5 LOW 5.4 MEDIUM
Cross-site scripting vulnerability in Full Text Search of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
CVE-2021-20766 1 Cybozu 1 Garoon 2021-08-24 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Message of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to inject an arbitrary script via unspecified vectors.
CVE-2021-20765 1 Cybozu 1 Garoon 2021-08-24 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to inject an arbitrary script via unspecified vectors.
CVE-2018-20956 1 Swann 2 Swwhd-intcam-hd, Swwhd-intcam-hd Firmware 2021-08-24 2.1 LOW 5.5 MEDIUM
Swann SWWHD-INTCAM-HD devices leave the PSK in logs after a factory reset. NOTE: all affected customers were migrated by 2020-08-31.
CVE-2021-20764 1 Cybozu 1 Garoon 2021-08-24 5.0 MEDIUM 5.3 MEDIUM
Improper input validation vulnerability in Attaching Files of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to alter the data of Attaching Files.
CVE-2021-20762 1 Cybozu 1 Garoon 2021-08-24 4.0 MEDIUM 4.3 MEDIUM
Improper input validation vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated to alter the data of E-mail without the appropriate privilege.
CVE-2021-20760 1 Cybozu 1 Garoon 2021-08-24 4.0 MEDIUM 4.3 MEDIUM
Improper input validation vulnerability in User Profile of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of User Profile without the appropriate privilege.
CVE-2021-20759 1 Cybozu 1 Garoon 2021-08-24 4.0 MEDIUM 4.3 MEDIUM
Operational restrictions bypass vulnerability in Bulletin of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Portal without the appropriate privilege.
CVE-2021-20757 1 Cybozu 1 Garoon 2021-08-24 4.0 MEDIUM 4.3 MEDIUM
Operational restrictions bypass vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Portal without the appropriate privilege.
CVE-2021-20754 1 Cybozu 1 Garoon 2021-08-24 4.0 MEDIUM 4.3 MEDIUM
Improper input validation vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Workflow without the appropriate privilege.