LiveActive security incident?Get immediate response
CVE archive

January 2021

Browse CVE records published in January 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2235 matching CVEs · Page 5 of 45.

Medium · CVSS 4

CVE-2021-23566: Information Exposure

The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.

Published Jan 14, 2022 · Updated Nov 3, 2025

Medium · CVSS 4.7

CVE-2021-36647: Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed...

Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions before 3.0.0, 2.27.0 or 2.16.11 allows attackers with access to precise enough timing and memory access information (typically an untrusted operating system attacking a secure enclave such as SGX or the TrustZone secure world) to recover the private keys used in RSA.

Published Jan 17, 2023 · Updated Nov 3, 2025

Medium · CVSS 4.3 · CISA KEV

CVE-2021-35247: Improper Input Validation Vulnerability in Serv-U

Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.

Published Jan 7, 2022 · Updated Oct 21, 2025

Critical · CVSS 9.8 · CISA KEV

CVE-2021-35587: Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent).

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Published Jan 19, 2022 · Updated Oct 21, 2025

Medium · CVSS 6.6 · CISA KEV

CVE-2021-22600: Double Free in net/packet/af_packet.c leading to priviledge escalation

A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755

Published Jan 26, 2022 · Updated Oct 21, 2025

High · CVSS 7.8 · CISA KEV

CVE-2021-4034: A local privilege escalation vulnerability was found on polkit's pkexec utility.

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

Published Jan 28, 2022 · Updated Oct 21, 2025

Critical · CVSS 9.1 · CISA KEV

CVE-2021-40407: An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-41...

An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->domain variable, that has the value of the domain parameter provided through the SetDdns API, is not validated properly. This would lead to an OS command injection. An attacker can send an HTTP request to trigger this vulnerability.

Published Jan 28, 2022 · Updated Oct 21, 2025

High · CVSS 8

CVE-2021-22825: A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could allow...

A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could allow an attacker to access the system with elevated privileges when a privileged account clicks on a malicious URL that compromises the security token. Affected Products: AP7xxxx and AP8xxx with NMC2 (V6.9.6 or earlier), AP7xxx and AP8xxx with NMC3 (V1.1.0.3 or earlier), and APDU9xxx with NMC3 (V1.0.0.28 or earlier)

Published Jan 28, 2022 · Updated Sep 8, 2025

Critical · CVSS 9.9

CVE-2021-43779: Remote Command Execution vulnerability

GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin in versions < 2.9.1 suffers from authenticated Remote Code Execution vulnerability, allowing access to the server's underlying operating system using command injection abuse of functionality. There is no workaround for this issue and users are advised to upgrade or to disable the addressing plugin.

Published Jan 5, 2022 · Updated Sep 8, 2025

High · CVSS 8.1

CVE-2021-20190: A flaw was found in jackson-databind before 2.9.10.7.

A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Published Jan 19, 2021 · Updated Aug 27, 2025

High · CVSS 7.5

CVE-2021-42146: An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97.

An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers allow remote attackers to reuse the same epoch number within two times the TCP maximum segment lifetime, which is prohibited in RFC6347. This vulnerability allows remote attackers to obtain sensitive application (data of connected clients).

Published Jan 24, 2024 · Updated Jun 20, 2025

Critical · CVSS 9.1

CVE-2021-42143: An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97.

An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. An infinite loop bug exists during the handling of a ClientHello handshake message. This bug allows remote attackers to cause a denial of service by sending a malformed ClientHello handshake message with an odd length of cipher suites, which triggers an infinite loop (consuming all resources) and a buffer over-read that can disclose sensitive information.

Published Jan 24, 2024 · Updated Jun 20, 2025

Medium · CVSS 5.4

CVE-2021-24559: Qyrr < 0.7 - Authenticated (contributor+) Stored XSS

The Qyrr WordPress plugin before 0.7 does not escape the data-uri of the QR Code when outputting it in a src attribute, allowing for Cross-Site Scripting attacks. Furthermore, the data_uri_to_meta AJAX action, available to all authenticated users, only had a CSRF check in place, with the nonce available to users with a role as low as Contributor allowing any user with such role (and above) to set a malicious data-uri in arbitrary QR Code posts, leading to a Stored Cross-Site Scripting issue.

Published Jan 16, 2024 · Updated Jun 20, 2025

High · CVSS 7.2

CVE-2021-24151: WP Editor < 1.2.7 - Authenticated SQL injection

The WP Editor WordPress plugin before 1.2.7 did not sanitise or validate its setting fields leading to an authenticated (admin+) blind SQL injection issue via an arbitrary parameter when making a request to save the settings.

Published Jan 16, 2024 · Updated Jun 20, 2025

Medium · CVSS 5.3

CVE-2021-4432: PCMan FTP Server USER Command denial of service

A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as problematic. This affects an unknown part of the component USER Command Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250719.

Published Jan 16, 2024 · Updated Jun 17, 2025

High · CVSS 7.8

CVE-2021-42028: A vulnerability has been identified in syngo fastView (All versions).

A vulnerability has been identified in syngo fastView (All versions). The affected application lacks proper validation of user-supplied data when parsing BMP files. This could result in an out-of-bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-14860)

Published Jan 4, 2024 · Updated Jun 17, 2025

High · CVSS 7.8

CVE-2021-40367: A vulnerability has been identified in syngo fastView (All versions).

A vulnerability has been identified in syngo fastView (All versions). The affected application lacks proper validation of user-supplied data when parsing DICOM files. This could result in an out-of-bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-15097)

Published Jan 4, 2024 · Updated Jun 17, 2025

Medium · CVSS 4.8

CVE-2021-25117: WP Postratings < 1.86.1 - Admin+ Stored Cross-Site Scripting

The WP-PostRatings WordPress plugin before 1.86.1 does not sanitise the postratings_image parameter from its options page (wp-admin/admin.php?page=wp-postratings/postratings-options.php). Even though the page is only accessible to administrators, and protected against CSRF attacks, the issue is still exploitable when the unfiltered_html capability is disabled.

Published Jan 16, 2024 · Updated Jun 17, 2025

High · CVSS 7.8

CVE-2021-45465: A vulnerability has been identified in syngo fastView (All versions).

A vulnerability has been identified in syngo fastView (All versions). The affected application lacks proper validation of user-supplied data when parsing BMP files. This could result in a write-what-where condition and an attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-15696)

Published Jan 4, 2024 · Updated Jun 3, 2025

Medium · CVSS 5.4

CVE-2021-24433: Simple Sort&Search <= 0.0.3 - Ccontributor+ Stored XSS

The simple sort&search WordPress plugin through 0.0.3 does not make sure that the indexurl parameter of the shortcodes "category_sims", "order_sims", "orderby_sims", "period_sims", and "tag_sims" use allowed URL protocols, which can lead to stored cross-site scripting by users with a role as low as Contributor

Published Jan 16, 2024 · Updated Jun 2, 2025

High · CVSS 8.8

CVE-2021-24869: WP Fastest Cache < 0.9.5 - Subscriber+ SQL Injection

The WP Fastest Cache WordPress plugin before 0.9.5 does not escape user input in the set_urls_with_terms method before using it in a SQL statement, leading to an SQL injection exploitable by low privilege users such as subscriber

Published Jan 16, 2024 · Updated Jun 2, 2025

Medium · CVSS 5.3

CVE-2021-4227: Ark Comment Editor <= 2.15.6 - Iframe Injection via Comment

The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source editor, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page to the comment section

Published Jan 16, 2024 · Updated Jun 2, 2025

Medium · CVSS 5.5

CVE-2021-4297: trampgeek jobe Restapi.php runs_post Privilege Escalation

A vulnerability has been found in trampgeek jobe up to 1.6.4 and classified as problematic. This vulnerability affects the function runs_post of the file application/controllers/Restapi.php. The manipulation of the argument sourcefilename leads to an unknown weakness. Upgrading to version 1.6.5 is able to address this issue. The patch is identified as 694da5013dbecc8d30dd83e2a83e78faadf93771. It is recommended to upgrade the affected component. VDB-217174 is the identifier assigned to this vulnerability.

Published Jan 1, 2023 · Updated May 28, 2025

Medium · CVSS 6.5

CVE-2021-4304: eprintsug ulcc-core toolbox command injection

A vulnerability was found in eprintsug ulcc-core. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file cgi/toolbox/toolbox. The manipulation of the argument password leads to command injection. The attack can be launched remotely. The patch is named 811edaae81eb044891594f00062a828f51b22cb1. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217447.

Published Jan 5, 2023 · Updated May 28, 2025

Medium · CVSS 6.1

CVE-2021-25022: UpdraftPlus < 1.16.66 - Reflected Cross-Site Scripting

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.66 does not sanitise and escape the backup_timestamp and job_id parameter before outputting then back in admin pages, leading to Reflected Cross-Site Scripting issues

Published Jan 3, 2022 · Updated May 22, 2025