Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-20781 1 Ucms Project 1 Ucms 2021-10-02 3.5 LOW 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in /ucms/index.php?do=list_edit of UCMS 1.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the title, key words, description or content text fields.
CVE-2020-20131 1 Laracms Project 1 Laracms 2021-10-02 3.5 LOW 5.4 MEDIUM
LaraCMS v1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows atackers to execute arbitrary web scripts or HTML via a crafted payload in the page management module.
CVE-2020-20129 1 Laracms Project 1 Laracms 2021-10-02 3.5 LOW 5.4 MEDIUM
LaraCMS v1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the content editor.
CVE-2020-20128 1 Laracms Project 1 Laracms 2021-10-02 5.0 MEDIUM 7.5 HIGH
LaraCMS v1.0.1 transmits sensitive information in cleartext which can be intercepted by attackers.
CVE-2021-32466 2 Microsoft, Trendmicro 2 Windows, Housecall For Home Networks 2021-10-02 6.9 MEDIUM 7.0 HIGH
An uncontrolled search path element privilege escalation vulnerability in Trend Micro HouseCall for Home Networks version 5.3.1225 and below could allow an attacker to escalate privileges by placing a custom crafted file in a specific directory to load a malicious library. Please note that an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
CVE-2021-35028 1 Zyxel 2 Zywall Vpn2s, Zywall Vpn2s Firmware 2021-10-02 7.2 HIGH 7.8 HIGH
A command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12 could allow an authenticated, local user to execute arbitrary OS commands.
CVE-2021-35027 1 Zyxel 2 Zywall Vpn2s, Zywall Vpn2s Firmware 2021-10-02 5.0 MEDIUM 7.5 HIGH
A directory traversal vulnerability in the web server of the Zyxel VPN2S firmware version 1.12 could allow a remote attacker to gain access to sensitive information.
CVE-2021-29834 1 Ibm 2 Business Automation Workflow, Business Process Manager 2021-10-02 3.5 LOW 5.4 MEDIUM
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3,20.0.0.1, 20.0.0.2, and 21.0.2 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204832.
CVE-2021-34636 1 Wpdevart 1 Countdown And Countup\, Woocommerce Sales Timer 2021-10-02 6.8 MEDIUM 8.8 HIGH
The Countdown and CountUp, WooCommerce Sales Timers WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_theme function found in the ~/includes/admin/coundown_theme_page.php file due to a missing nonce check which allows attackers to inject arbitrary web scripts, in versions up to and including 1.5.7.
CVE-2021-41558 1 Set User Project 1 Set User 2021-10-02 7.5 HIGH 9.8 CRITICAL
The set_user extension module before 3.0.0 for PostgreSQL allows ProcessUtility_hook bypass via set_config.
CVE-2021-31606 1 Openvpn-monitor Project 1 Openvpn-monitor 2021-10-02 5.0 MEDIUM 7.5 HIGH
furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect arbitrary clients.
CVE-2021-31605 1 Openvpn-monitor Project 1 Openvpn-monitor 2021-10-02 7.8 HIGH 7.5 HIGH
furlongm openvpn-monitor through 1.1.3 allows %0a command injection via the OpenVPN management interface socket. This can shut down the server via signal%20SIGTERM.
CVE-2021-40969 1 Spotweb Project 1 Spotweb 2021-10-01 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the firstname parameter.
CVE-2021-32275 1 Grame 1 Faust 2021-10-01 4.3 MEDIUM 5.5 MEDIUM
An issue was discovered in faust through v2.30.5. A NULL pointer dereference exists in the function CosPrim::computeSigOutput() located in cosprim.hh. It allows an attacker to cause Denial of Service.
CVE-2021-32281 1 Creolabs 1 Gravity 2021-10-01 6.8 MEDIUM 7.8 HIGH
An issue was discovered in gravity through 0.8.1. A heap-buffer-overflow exists in the function gnode_function_add_upvalue located in gravity_ast.c. It allows an attacker to cause code Execution.
CVE-2021-32284 1 Creolabs 1 Gravity 2021-10-01 6.8 MEDIUM 7.8 HIGH
An issue was discovered in gravity through 0.8.1. A NULL pointer dereference exists in the function ircode_register_pop_context_protect() located in gravity_ircode.c. It allows an attacker to cause Denial of Service.
CVE-2021-32283 1 Creolabs 1 Gravity 2021-10-01 4.3 MEDIUM 5.5 MEDIUM
An issue was discovered in gravity through 0.8.1. A NULL pointer dereference exists in the function gravity_string_to_value() located in gravity_value.c. It allows an attacker to cause Denial of Service.
CVE-2021-32285 1 Creolabs 1 Gravity 2021-10-01 4.3 MEDIUM 5.5 MEDIUM
An issue was discovered in gravity through 0.8.1. A NULL pointer dereference exists in the function list_iterator_next() located in gravity_core.c. It allows an attacker to cause Denial of Service.
CVE-2021-32287 1 Nokia 1 Heif 2021-10-01 6.8 MEDIUM 7.8 HIGH
An issue was discovered in heif through v3.6.2. A global-buffer-overflow exists in the function HevcDecoderConfigurationRecord::getPicWidth() located in hevcdecoderconfigrecord.cpp. It allows an attacker to cause code Execution.
CVE-2021-32286 1 Hcxtools Project 1 Hcxtoold 2021-10-01 6.8 MEDIUM 7.8 HIGH
An issue was discovered in hcxtools through 6.1.6. A global-buffer-overflow exists in the function pcapngoptionwalk located in hcxpcapngtool.c. It allows an attacker to cause code Execution.