LiveActive security incident?Get immediate response
CVE archive

May 2021

Browse CVE records published in May 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1909 matching CVEs · Page 19 of 39.

Unknown · CVSS Not scored

CVE-2021-46440: Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and...

Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attacker to access a victim's HTTP request, get the victim's cookie, perform a base64 decode on the victim's cookie, and obtain a cleartext password, leading to getting API documentation for further API attacks.

Published May 3, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-42969: Certain Anaconda3 2021.05 are affected by OS command injection.

Certain Anaconda3 2021.05 are affected by OS command injection. When a user installs Anaconda, an attacker can create a new file and write something in usercustomize.py. When the user opens the terminal or activates Anaconda, the command will be executed.

Published May 13, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-42860: A stack buffer overflow exists in Mini-XML v3.2.

A stack buffer overflow exists in Mini-XML v3.2. When inputting an unformed XML string to the mxmlLoadString API, it will cause a stack-buffer-overflow in mxml_string_getc:2611. NOTE: it is unclear whether this input is allowed by the API specification

Published May 26, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-42646: XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Manageme...

XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; and WSO2 IS as Key Manager 5.7.0, 5.9.0, and 5.10.0; and WSO2 Identity Server 5.7.0, 5.8.0, 5.9.0, 5.10.0, and 5.11.0. Allows attackers to gain read access to sensitive information or cause a denial of service via crafted GET requests.

Published May 11, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-42581: Prototype poisoning in function mapObjIndexed in Ramda 0.27.0 and earlier allows attackers to compromise in...

Prototype poisoning in function mapObjIndexed in Ramda 0.27.0 and earlier allows attackers to compromise integrity or availability of application via supplying a crafted object (that contains an own property "__proto__") as an argument to the function. NOTE: the vendor disputes this because the observed behavior only means that a user can create objects that the user didn't know would contain custom prototypes

Published May 10, 2022 · Updated Aug 4, 2024