LiveActive security incident?Get immediate response
CVE archive

July 2021

Browse CVE records published in July 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1517 matching CVEs · Page 14 of 31.

Unknown · CVSS Not scored

CVE-2021-37436: Amazon Echo Dot devices through 2021-07-02 sometimes allow attackers, who have physical access to a device...

Amazon Echo Dot devices through 2021-07-02 sometimes allow attackers, who have physical access to a device after a factory reset, to obtain sensitive information via a series of complex hardware and software attacks. NOTE: reportedly, there were vendor marketing statements about safely removing personal content via a factory reset. Also, the vendor has reportedly indicated that they are working on mitigations.

Published Jul 24, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-37444: NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a...

NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive. This can lead to code execution if a ZIP element's pathname is set to a Windows startup folder, a file for the inbuilt Out-Going Message function, or a file for the the inbuilt Autodial function.

Published Jul 25, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-37392: In RPCMS v1.8 and below, the "nickname" variable is not properly sanitized before being displayed on page.

In RPCMS v1.8 and below, the "nickname" variable is not properly sanitized before being displayed on page. When the API functions are enabled, the attacker can use API to update user nickname with XSS payload and achieve stored XSS. Users who view the articles published by the injected user will trigger the XSS.

Published Jul 26, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-37144: CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion.

CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion. This occurs in PHP when the unlink() function is called and user input might affect portions of or the whole affected parameter, which represents the path of the file to remove, without sufficient sanitization.

Published Jul 29, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-36766: Concrete5 through 8.5.5 deserializes Untrusted Data.

Concrete5 through 8.5.5 deserializes Untrusted Data. The vulnerable code is located within the controllers/single_page/dashboard/system/environment/logging.php Logging::update_logging() method. User input passed through the logFile request parameter is not properly sanitized before being used in a call to the file_exists() PHP function. This can be exploited by malicious users to inject arbitrary PHP objects into the application scope (PHP Object Injection via phar:// stream wrapper), allowing them to carry out a variety of attacks, such as executing arbitrary PHP code.

Published Jul 27, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-36758: 1Password Connect server before 1.2 is missing validation checks, permitting users to create Secrets Automa...

1Password Connect server before 1.2 is missing validation checks, permitting users to create Secrets Automation access tokens that can be used to perform privilege escalation. Malicious users authorized to create Secrets Automation access tokens can create tokens that have access beyond what the user is authorized to access, but limited to the existing authorizations of the Secret Automation the token is created in.

Published Jul 15, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-36621: Sourcecodester Online Covid Vaccination Scheduler System 1.0 is vulnerable to SQL Injection.

Sourcecodester Online Covid Vaccination Scheduler System 1.0 is vulnerable to SQL Injection. The username parameter is vulnerable to time-based SQL injection. Upon successful dumping the admin password hash, an attacker can decrypt and obtain the plain-text password. Hence, the attacker could authenticate as Administrator.

Published Jul 29, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-36563: The CheckMK management web console (versions 1.5.0 to 2.0.0) does not sanitise user input in various parame...

The CheckMK management web console (versions 1.5.0 to 2.0.0) does not sanitise user input in various parameters of the WATO module. This allows an attacker to open a backdoor on the device with HTML content and interpreted by the browser (such as JavaScript or other client-side scripts), the XSS payload will be triggered when the user accesses some specific sections of the application. In the same sense a very dangerous potential way would be when an attacker who has the monitor role (not administrator) manages to get a stored XSS to steal the secretAutomation (for the use of the API in administrator mode) and thus be able to create another administrator user who has high privileges on the CheckMK monitoring web console. Another way is that persistent XSS allows an attacker to modify the displayed content or change the victim's information. Successful exploitation requires access to the web management interface, either with valid credentials or with a hijacked session.

Published Jul 26, 2021 · Updated Aug 4, 2024