LiveActive security incident?Get immediate response
CVE archive

July 2021

Browse CVE records published in July 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1517 matching CVEs · Page 17 of 31.

Unknown · CVSS Not scored

CVE-2021-36371: Emissary-Ingress (formerly Ambassador API Gateway) through 1.13.9 allows attackers to bypass client certifi...

Emissary-Ingress (formerly Ambassador API Gateway) through 1.13.9 allows attackers to bypass client certificate requirements (i.e., mTLS cert_required) on backend upstreams when more than one TLSContext is defined and at least one configuration exists that does not require client certificate authentication. The attacker must send an SNI specifying an unprotected backend and an HTTP Host header specifying a protected backend. (2.x versions are unaffected. 1.x versions are unaffected with certain configuration settings involving prune_unreachable_routes and a wildcard Host resource.)

Published Jul 9, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-36124: An issue was discovered in Echo ShareCare 8.15.5.

An issue was discovered in Echo ShareCare 8.15.5. It does not perform authentication or authorization checks when accessing a subset of sensitive resources, leading to the ability for unauthenticated users to access pages that are vulnerable to attacks such as SQL injection.

Published Jul 13, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-36123: An issue was discovered in Echo ShareCare 8.15.5.

An issue was discovered in Echo ShareCare 8.15.5. The TextReader feature in General/TextReader/TextReader.cfm is susceptible to a local file inclusion vulnerability when processing remote input in the textFile parameter from an authenticated user, leading to the ability to read arbitrary files on the server filesystems as well any files accessible via Universal Naming Convention (UNC) paths.

Published Jul 13, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-36126: An issue was discovered in the AbuseFilter extension in MediaWiki through 1.36.

An issue was discovered in the AbuseFilter extension in MediaWiki through 1.36. If the MediaWiki:Abusefilter-blocker message is invalid within the content language, the filter user falls back to the English version, but that English version could also be invalid on a wiki. This would result in a fatal error, and potentially fail to block or restrict a potentially nefarious user.

Published Jul 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-36090: Apache Commons Compress 1.0 to 1.20 denial of service vulnerability

When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.

Published Jul 13, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-36121: An issue was discovered in Echo ShareCare 8.15.5.

An issue was discovered in Echo ShareCare 8.15.5. The file-upload feature in Access/DownloadFeed_Mnt/FileUpload_Upd.cfm is susceptible to an unrestricted upload vulnerability via the name1 parameter, when processing remote input from an authenticated user, leading to the ability for arbitrary files to be written to arbitrary filesystem locations via ../ Directory Traversal on the Z: drive (a hard-coded drive letter where ShareCare application files reside) and remote code execution as the ShareCare service user (NT AUTHORITY\SYSTEM).

Published Jul 13, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-36132: An issue was discovered in the FileImporter extension in MediaWiki through 1.36.

An issue was discovered in the FileImporter extension in MediaWiki through 1.36. For certain relaxed configurations of the $wgFileImporterRequiredRight variable, it might not validate all appropriate user rights, thus allowing a user with insufficient rights to perform operations (specifically file uploads) that they should not be allowed to perform.

Published Jul 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-36122: An issue was discovered in Echo ShareCare 8.15.5.

An issue was discovered in Echo ShareCare 8.15.5. The UnzipFile feature in Access/EligFeedParse_Sup/UnzipFile_Upd.cfm is susceptible to a command argument injection vulnerability when processing remote input in the zippass parameter from an authenticated user, leading to the ability to inject arbitrary arguments to 7z.exe.

Published Jul 13, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-35472: An issue was discovered in LemonLDAP::NG before 2.0.12.

An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spoofing. By running a loop that makes many authentication attempts, an attacker might alternately be authenticated as one of two different users.

Published Jul 27, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-35517: Apache Commons Compress 1.1 to 1.20 denial of service vulnerability

When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package.

Published Jul 13, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-35516: Apache Commons Compress 1.6 to 1.20 denial of service vulnerability

When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package.

Published Jul 13, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-35449: The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0...

The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below, and G4 driver 4.2.1.0 and below are affected by a privilege escalation vulnerability. A standard low priviliged user can use the driver to execute a DLL of their choosing during the add printer process, resulting in escalation of privileges to SYSTEM.

Published Jul 19, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-35440: Smashing 1.3.4 is vulnerable to Cross Site Scripting (XSS).

Smashing 1.3.4 is vulnerable to Cross Site Scripting (XSS). A URL for a widget can be crafted and used to execute JavaScript on the victim's computer. The JavaScript code can then steal data available in the session/cookies depending on the user environment (e.g. if re-using internal URL's for deploying, or cookies that are very permissive) private information may be retrieved by the attacker.

Published Jul 6, 2021 · Updated Aug 4, 2024