LiveActive security incident?Get immediate response
CVE archive

August 2021

Browse CVE records published in August 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2044 matching CVEs · Page 16 of 41.

Unknown · CVSS Not scored

CVE-2021-38160: In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggere...

In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is not a vulnerability in any existing use case; the length validation was added solely for robustness in the face of anomalous host OS behavior

Published Aug 7, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-38154: Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Ca...

Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access, allow remote attackers to modify an e-mail address setting, and thus cause the device to send sensitive information through e-mail to the attacker. For example, an incoming FAX may be sent through e-mail to the attacker. This occurs when a PIN is not required for General User Mode, as exploited in the wild in August 2021.

Published Aug 29, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-38145: An issue was discovered in Form Tools through 3.0.20.

An issue was discovered in Form Tools through 3.0.20. SQL Injection can occur via the export_group_id field when a low-privileged user (client) tries to export a form with data, e.g., manipulation of modules/export_manager/export.php?export_group_id=1&export_group_1_results=all&export_type_id=1.

Published Aug 31, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-38144: An issue was discovered in Form Tools through 3.0.20.

An issue was discovered in Form Tools through 3.0.20. A low-privileged user can trigger Reflected XSS when a viewing a form via the submission_id parameter, e.g., clients/forms/edit_submission.php?form_id=1&view_id=1&submission_id=[XSS].

Published Aug 31, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-38143: An issue was discovered in Form Tools through 3.0.20.

An issue was discovered in Form Tools through 3.0.20. When an administrator creates a customer account, it is possible for the customer to log in and proceed with a change of name and last name. However, these fields are vulnerable to XSS payload insertion, being triggered in the admin panel when the admin tries to see the client list. This type of XSS (stored) can lead to the extraction of the PHPSESSID cookie belonging to the admin.

Published Aug 31, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-38138: OneNav beta 0.9.12 allows XSS via the Add Link feature.

OneNav beta 0.9.12 allows XSS via the Add Link feature. NOTE: the vendor's position is that there intentionally is not any XSS protection at present, because the attack risk is largely limited to a compromised account; however, XSS protection is planned for a future release.

Published Aug 5, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-37788: A vulnerability in the web UI of Gurock TestRail v5.3.0.3603 could allow an unauthenticated, remote attacke...

A vulnerability in the web UI of Gurock TestRail v5.3.0.3603 could allow an unauthenticated, remote attacker to affect the integrity of a device via a clickjacking attack. The vulnerability is due to insufficient input validation of iFrame data in HTTP requests that are sent to an affected device. An attacker could exploit this vulnerability by sending crafted HTTP packets with malicious iFrame data. A successful exploit could allow the attacker to perform a clickjacking attack where the user is tricked into clicking a malicious link.

Published Aug 9, 2021 · Updated Aug 4, 2024

High · CVSS 7.1

CVE-2021-37859: Reflected XSS in OAuth Flow

Fixed a bypass for a reflected cross-site scripting vulnerability affecting OAuth-enabled instances of Mattermost.

Published Aug 5, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-38085: The Canon TR150 print driver through 3.71.2.10 is vulnerable to a privilege escalation issue.

The Canon TR150 print driver through 3.71.2.10 is vulnerable to a privilege escalation issue. During the add printer process, a local attacker can overwrite CNMurGE.dll and, if timed properly, the overwritten DLL will be loaded into a SYSTEM process resulting in escalation of privileges. This occurs because the driver drops a world-writable DLL into a CanonBJ %PROGRAMDATA% location that gets loaded by printisolationhost (a system process).

Published Aug 11, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-37840: aaPanel through 6.8.12 allows Cross-Site WebSocket Hijacking (CSWH) involving OS commands within WebSocket...

aaPanel through 6.8.12 allows Cross-Site WebSocket Hijacking (CSWH) involving OS commands within WebSocket messages at a ws:// URL for /webssh (the victim must have configured Terminal with at least one host). Successful exploitation depends on the browser used by a potential victim (e.g., exploitation can occur with Firefox but not Chrome).

Published Aug 2, 2021 · Updated Aug 4, 2024

Critical · CVSS 9.8

CVE-2021-37843: The resolution SAML SSO apps for Atlassian products allow a remote attacker to login to a user account when...

The resolution SAML SSO apps for Atlassian products allow a remote attacker to login to a user account when only the username is known (i.e., no other authentication is provided). The fixed versions are for Jira: 3.6.6.1, 4.0.12, 5.0.5; for Confluence 3.6.6, 4.0.12, 5.0.5; for Bitbucket 2.5.9, 3.6.6, 4.0.12, 5.0.5; for Bamboo 2.5.9, 3.6.6, 4.0.12, 5.0.5; and for Fisheye 2.5.9.

Published Aug 2, 2021 · Updated Aug 4, 2024