LiveActive security incident?Get immediate response
CVE archive

April 2021

Browse CVE records published in April 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2026 matching CVEs · Page 4 of 41.

High · CVSS 7.5

CVE-2021-32961: MDT AutoSave Unrestricted Upload of File with Dangerous Type

A getfile function in MDT AutoSave versions prior to v6.02.06 enables a user to supply an optional parameter, resulting in the processing of a request in a special manner. This can result in the execution of an unzip command and place a malicious .exe file in one of the locations the function looks for and get execution capabilities.

Published Apr 1, 2022 · Updated Apr 16, 2025

Critical · CVSS 9.8

CVE-2021-32953: MDT AutoSave SQL Injection

An attacker could utilize SQL commands to create a new user MDT AutoSave versions prior to v6.02.06 and update the user’s permissions, granting the attacker the ability to login.

Published Apr 1, 2022 · Updated Apr 16, 2025

Critical · CVSS 10

CVE-2021-32933: MDT AutoSave Command Injection

An attacker could leverage an API to pass along a malicious file that could then manipulate the process creation command line in MDT AutoSave versions prior to v6.02.06 and run a command line argument. This could then be leveraged to run a malicious process.

Published Apr 1, 2022 · Updated Apr 16, 2025

High · CVSS 7.5

CVE-2021-32937: MDT AutoSave Generation of Error Message Containing Sensitive Information

An attacker can gain knowledge of a session temporary working folder where the getfile and putfile commands are used in MDT AutoSave versions prior to v6.02.06. An attacker can leverage this knowledge to provide a malicious command to the working directory where the read and write activity can be initiated.

Published Apr 1, 2022 · Updated Apr 16, 2025

High · CVSS 7.5

CVE-2021-32957: MDT AutoSave Uncontrolled Search Path Element

A function in MDT AutoSave versions prior to v6.02.06 is used to retrieve system information for a specific process, and this information collection executes multiple commands and summarizes the information into an XML. This function and subsequent process gives full path to the executable and is therefore vulnerable to binary hijacking.

Published Apr 1, 2022 · Updated Apr 16, 2025

High · CVSS 7.5

CVE-2021-32949: MDT AutoSave Relative Path Traversal

An attacker could utilize a function in MDT AutoSave versions prior to v6.02.06 that permits changing a designated path to another path and traversing the directory, allowing the replacement of an existing file with a malicious file.

Published Apr 1, 2022 · Updated Apr 16, 2025

High · CVSS 8.2

CVE-2021-33020: Philips Vue PACS Use of a Key Past its Expiration Date

Philips Vue PACS versions 12.2.x.x and prior uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.

Published Apr 1, 2022 · Updated Apr 16, 2025

High · CVSS 7.5

CVE-2021-33010: AVEVA System Platform Uncaught Exception

An exception is thrown from a function in AVEVA System Platform versions 2017 through 2020 R2 P01, but it is not caught, which may cause a denial-of-service condition.

Published Apr 4, 2022 · Updated Apr 16, 2025

High · CVSS 7.5

CVE-2021-32978: Automation Direct CLICK PLC CPU Modules Plaintext Storage of a Password

The programming protocol allows for a previously entered password and lock state to be read by an attacker. If the previously entered password was successful, the attacker can then use the password to unlock Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00.

Published Apr 4, 2022 · Updated Apr 16, 2025

Critical · CVSS 9.8

CVE-2021-32986: Automation Direct CLICK PLC CPU Modules Authentication Bypass Using an Alternate Path or Channel

After Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, the unlocked state does not timeout. If the programming software is interrupted, the PLC remains unlocked. All subsequent programming connections are allowed without authorization. The PLC is only relocked by a power cycle, or when the programming software disconnects correctly.

Published Apr 4, 2022 · Updated Apr 16, 2025

Medium · CVSS 6

CVE-2021-43986: ICSA-22-109-03 FANUC ROBOGUIDE Simulation Platform

The setup program for the affected product configures its files and folders with full access, which may allow unauthorized users permission to replace original binaries and achieve privilege escalation.

Published Apr 20, 2022 · Updated Apr 16, 2025

Medium · CVSS 6.1

CVE-2021-43933: ICSA-22-109-03 FANUC ROBOGUIDE Simulation Platform

The affected product is vulnerable to a network-based attack by threat actors sending unimpeded requests to the receiving server, which could cause a denial-of-service condition due to lack of heap memory resources.

Published Apr 20, 2022 · Updated Apr 16, 2025

Medium · CVSS 4.9

CVE-2021-43930: Elcomplus SmartPtt Path Traversal

Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate download requests, enabling malicious users to perform path traversal attacks and potentially download arbitrary files from the system.

Published Apr 28, 2022 · Updated Apr 16, 2025

Critical · CVSS 9.1

CVE-2021-27289: A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gatewa...

A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gateway Module = v1.0.3, Door Sensor = v1.0.7, Motion Sensor = v1.0.12), where the Zigbee anti-replay mechanism - based on the frame counter field - is improperly implemented. As a result, an attacker within wireless range can resend captured packets with a higher sequence number, which the devices incorrectly accept as legitimate messages. This allows spoofed commands to be injected without authentication, triggering false alerts and misleading the user through notifications in the mobile application used to monitor the network.

Published Apr 15, 2025 · Updated Apr 16, 2025

Critical · CVSS 9.8

CVE-2021-21944: Two heap-based buffer overflow vulnerabilities exist in the TIFF parser functionality of Accusoft ImageGear...

Two heap-based buffer overflow vulnerabilities exist in the TIFF parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger these vulnerabilities.This heap-based buffer oveflow takes place trying to copy the first 12 bits from local variable.

Published Apr 14, 2022 · Updated Apr 15, 2025

Critical · CVSS 9.8

CVE-2021-21945: Two heap-based buffer overflow vulnerabilities exist in the TIFF parser functionality of Accusoft ImageGear...

Two heap-based buffer overflow vulnerabilities exist in the TIFF parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger these vulnerabilities.This heap-based buffer oveflow takes place trying to copy the second 12 bits from local variable.

Published Apr 14, 2022 · Updated Apr 15, 2025

Critical · CVSS 9.8

CVE-2021-21946: Two heap-based buffer overflow vulnerabilities exists in the JPEG-JFIF lossless Huffman image parser functi...

Two heap-based buffer overflow vulnerabilities exists in the JPEG-JFIF lossless Huffman image parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger these vulnerabilities.This heap-based buffer overflow takes place when the `SOF3` precision is lower than 9.

Published Apr 14, 2022 · Updated Apr 15, 2025

Critical · CVSS 9.8

CVE-2021-21947: Two heap-based buffer overflow vulnerabilities exists in the JPEG-JFIF lossless Huffman image parser functi...

Two heap-based buffer overflow vulnerabilities exists in the JPEG-JFIF lossless Huffman image parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger these vulnerabilities.This heap-based buffer overflow takes place when the `SOF3` precision is greater or equal than 9.

Published Apr 14, 2022 · Updated Apr 15, 2025

Critical · CVSS 9.3

CVE-2021-40400: An out-of-bounds read vulnerability exists in the RS-274X aperture macro outline primitive functionality of...

An out-of-bounds read vulnerability exists in the RS-274X aperture macro outline primitive functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit d7f42a9a). A specially-crafted Gerber file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.

Published Apr 14, 2022 · Updated Apr 15, 2025