LiveActive security incident?Get immediate response
CVE archive

May 2021

Browse CVE records published in May 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1909 matching CVEs · Page 24 of 39.

Unknown · CVSS Not scored

CVE-2021-32101: The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/_m...

The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/_machine_config.php. To exploit the vulnerability, an unauthenticated attacker can register an account, bypassing the permission check of this portal's API. Then, the attacker can then manipulate and read data of every registered patient.

Published May 7, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-32077: Primary Source Verification in VerityStream MSOW Solutions before 3.1.1 allows an anonymous internet user t...

Primary Source Verification in VerityStream MSOW Solutions before 3.1.1 allows an anonymous internet user to discover Social Security Number (SSN) values via a brute-force attack on a (sometimes hidden) search field, because the last four SSN digits are part of the supported combination of search selectors. This discloses doctors' and nurses' social security numbers and PII.

Published May 6, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-32053: JPA Server in HAPI FHIR before 5.4.0 allows a user to deny service (e.g., disable access to the database af...

JPA Server in HAPI FHIR before 5.4.0 allows a user to deny service (e.g., disable access to the database after the attack stops) via history requests. This occurs because of a SELECT COUNT statement that requires a full index scan, with an accompanying large amount of server resources if there are many simultaneous history requests.

Published May 10, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-32089: An issue was discovered on Zebra (formerly Motorola Solutions) Fixed RFID Reader FX9500 devices.

An issue was discovered on Zebra (formerly Motorola Solutions) Fixed RFID Reader FX9500 devices. An unauthenticated attacker can upload arbitrary files to the filesystem that can then be accessed through the web interface. This can lead to information disclosure and code execution. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

Published May 11, 2021 · Updated Aug 3, 2024

Medium · CVSS 5.6

CVE-2021-32010: Clients may connect to a GateManager with TLS 1.0

Inadequate Encryption Strength vulnerability in TLS stack of Secomea SiteManager, LinkManager, GateManager may facilitate man in the middle attacks. This issue affects: Secomea SiteManager All versions prior to 9.7. Secomea LinkManager versions prior to 9.7. Secomea GateManager versions prior to 9.7.

Published May 4, 2022 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-32052: In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator doe...

In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because HttpResponse prohibits newlines in HTTP headers.

Published May 6, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-31924: Yubico pam-u2f before 1.1.1 has a logic issue that, depending on the pam-u2f configuration and the applicat...

Yubico pam-u2f before 1.1.1 has a logic issue that, depending on the pam-u2f configuration and the application used, could lead to a local PIN bypass. This issue does not allow user presence (touch) or cryptographic signature verification to be bypassed, so an attacker would still need to physically possess and interact with the YubiKey or another enrolled authenticator. If pam-u2f is configured to require PIN authentication, and the application using pam-u2f allows the user to submit NULL as the PIN, pam-u2f will attempt to perform a FIDO2 authentication without PIN. If this authentication is successful, the PIN requirement is bypassed.

Published May 25, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-31930: Persistent cross-site scripting (XSS) in the web interface of Concerto through 2.3.6 allows an unauthentica...

Persistent cross-site scripting (XSS) in the web interface of Concerto through 2.3.6 allows an unauthenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into the First Name or Last Name parameter upon registration. When a privileged user attempts to delete the account, the XSS payload will be executed.

Published May 19, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-31876: Bitcoin Core 0.12.0 through 0.21.1 does not properly implement the replacement policy specified in BIP125,...

Bitcoin Core 0.12.0 through 0.21.1 does not properly implement the replacement policy specified in BIP125, which makes it easier for attackers to trigger a loss of funds, or a denial of service attack against downstream projects such as Lightning network nodes. An unconfirmed child transaction with nSequence = 0xff_ff_ff_ff, spending an unconfirmed parent with nSequence <= 0xff_ff_ff_fd, should be replaceable because there is inherited signaling by the child transaction. However, the actual PreChecks implementation does not enforce this. Instead, mempool rejects the replacement attempt of the unconfirmed child transaction.

Published May 13, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-31800: Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22.

Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a running smbserver instance can list and write to arbitrary files via ../ directory traversal. This could potentially be abused to achieve arbitrary code execution by replacing /etc/shadow or an SSH authorized key.

Published May 5, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-31916: An out-of-bounds (OOB) memory write flaw was found in list_devices in drivers/md/dm-ioctl.c in the Multi-de...

An out-of-bounds (OOB) memory write flaw was found in list_devices in drivers/md/dm-ioctl.c in the Multi-device driver module in the Linux kernel before 5.12. A bound check failure allows an attacker with special user (CAP_SYS_ADMIN) privilege to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability.

Published May 6, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-31827: In Progress MOVEit Transfer before 2021.0 (13.0), a SQL injection vulnerability has been found in the MOVEi...

In Progress MOVEit Transfer before 2021.0 (13.0), a SQL injection vulnerability has been found in the MOVEit Transfer web app that could allow an authenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or destroy database elements. This is in MOVEit.DMZ.WebApp in SILHuman.vb.

Published May 18, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-31829: kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to...

kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of stack content via side-channel attacks, aka CID-801c6058d14a. The specific concern is not protecting the BPF stack area against speculative loads. Also, the BPF stack can contain uninitialized data that might represent sensitive information previously operated on by the kernel.

Published May 6, 2021 · Updated Aug 3, 2024