Unknown · CVSS Not scored
In JetBrains Hub before 2021.1.13262, a potentially insufficient CSP for the Widget deployment feature was used.
Published Aug 6, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used.
Published Aug 6, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In JetBrains TeamCity before 2021.1.1, insufficient authentication checks for agent requests were made.
Published Aug 6, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthenticated attacker to execute arbitrary SQL commands via the day, month, or year parameter to the controllers/front/archive.php archive controller, or the id_category parameter to the controllers/front/category.php category controller.
Published Aug 24, 2021 · Updated Aug 4, 2024
High · CVSS 8
Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is possible to gain privileged rights in the Contao back end. Installations are only affected if they have untrusted back end users who have access to the form generator. All users are advised to update to Contao 4.4.56, 4.9.18 or 4.11.7. As a workaround users may disable the form generator or disable the login for untrusted back end users.
Published Aug 11, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A SQL injection vulnerability in reporting export in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-privileged) attackers to execute arbitrary SQL commands via the include/reporting/dashboard/csvExport/csv_HostGroupLogs.php start and end parameters.
Published Aug 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In JetBrains RubyMine before 2021.1.1, code execution without user confirmation was possible for untrusted projects.
Published Aug 6, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In JetBrains TeamCity before 2021.1, passwords in cleartext sometimes could be stored in VCS.
Published Aug 6, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.
Published Aug 6, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Nagios XI before version 5.8.5 is vulnerable to local file inclusion through improper limitation of a pathname in index.php.
Published Aug 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator, through main/social/search.php, main/inc/lib/social.lib.php and steal cookies or execute arbitrary code on the administration side via a stored XSS vulnerability via social network the send invitation feature.
Published Aug 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post authenticated RCE under security context of the user running Nagios.
Published Aug 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Nagios XI before version 5.8.5 is vulnerable to SQL injection vulnerability in Bulk Modifications Tool due to improper input sanitisation.
Published Aug 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Chamilo LMS 1.11.14 reflected XSS vulnerability exists in main/social/search.php=q URI (social network search feature).
Published Aug 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
CTparental before 4.45.07 is affected by a code execution vulnerability in the CTparental admin panel. Because The file "bl_categories_help.php" is vulnerable to directory traversal, an attacker can create a file that contains scripts and run arbitrary commands.
Published Aug 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
CTparental before 4.45.03 is vulnerable to cross-site request forgery (CSRF) in the CTparental admin panel. By combining CSRF with XSS, an attacker can trick the administrator into clicking a link that cancels the filtering for all standard users.
Published Aug 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation.
Published Aug 30, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Nagios XI before version 5.8.5 is vulnerable to insecure permissions and allows unauthenticated users to access guarded pages through a crafted HTTP request to the server.
Published Aug 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because getprofile.sh does not validate the directory name it receives as an argument.
Published Aug 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Parsers in the open source project RCDCAP before 1.0.5 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via specially crafted packets.
Published Aug 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an attacker to crash the webserver and might even gain remote code execution.
Published Aug 6, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Southsoft GMIS 5.0 is vulnerable to CSRF attacks. Attackers can access other users' private information such as photos through CSRF. For example: any student's photo information can be accessed through /gmis/(S([1]))/student/grgl/PotoImageShow/?bh=[2]. Among them, the code in [1] is a random string generated according to the user's login related information. It can protect the user's identity, but it can not effectively prevent unauthorized access. The code in [2] is the student number of any student. The attacker can carry out CSRF attack on the system by modifying [2] without modifying [1].
Published Aug 6, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Nagios XI Docker Wizard before version 1.1.3 is vulnerable to SSRF due to improper sanitation in table_population.php.
Published Aug 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS Command (OS Command injection).
Published Aug 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobiletogetherserver.cfg and then reading the certificate and private key.
Published Aug 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
NetSarang Xshell 7 before Build 0077 includes unintended code strings in paste operations.
Published Aug 15, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page.
Published Aug 30, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A buffer overflow issue was discovered in the HMI3 Control Panel contained within the Swisslog Healthcare Nexus Panel, operated by released versions of software before Nexus Software 7.2.5.7. A buffer overflow allows an attacker to overwrite an internal queue data structure and can lead to remote code execution.
Published Aug 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issue.
Published Aug 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. When a message is sent to the HMI TCP socket, it is forwarded to the hmiProcessMsg function through the pendingQ, and may lead to remote code execution.
Published Aug 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A stack overflow vulnerability occurs in Atomicparsley 20210124.204813.840499f through APar_read64() in src/util.cpp due to the lack of buffer size of uint32_buffer while reading more bytes in APar_read64.
Published Aug 4, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
CTparental before 4.45.03 is vulnerable to cross-site scripting (XSS) in the CTparental admin panel. In bl_categires_help.php, the 'categories' variable is assigned with the content of the query string param 'cat' without sanitization or encoding, enabling an attacker to inject malicious code into the output webpage.
Published Aug 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Insecure Permissions in administration interface in Planex MZK-DP150N 1.42 and 1.43 allows attackers to execute system command as root via etc_ro/web/syscmd.asp.
Published Aug 22, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. If an attacker sends a malformed UDP message, a buffer underflow occurs, leading to an out-of-bounds copy and possible remote code execution.
Published Aug 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A vulnerability has been identified in Solid Edge SE2021 (All Versions < SE2021MP7). The PSKERNEL.dll library in affected application lacks proper validation while parsing user-supplied OBJ files that could lead to a use-after-free condition. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-13777)
Published Aug 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Umbraco Forms version 4.0.0 up to and including 8.7.5 and below are vulnerable to a security flaw that could lead to a remote code execution attack and/or arbitrary file deletion. A vulnerability occurs because validation of the file extension is performed after the file has been stored in a temporary directory. By default, files are stored within the application directory structure at %BASEDIR%/APP_DATA/TEMP/FileUploads/. Whilst access to this directory is restricted by the root web.config file, it is possible to override this restriction by uploading another specially crafted web.config file to the temporary directory. It is possible to exploit this flaw to upload a malicious script file to execute arbitrary code and system commands on the server.
Published Aug 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Nagios XI WatchGuard Wizard before version 1.4.8 is vulnerable to remote code execution through Improper neutralisation of special elements used in an OS Command (OS Command injection).
Published Aug 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=checkrepeat&v_name=".
Published Aug 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A firmware validation issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. There is no firmware validation (e.g., cryptographic signature validation) during a File Upload for a firmware update.
Published Aug 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass.
Published Aug 30, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A vulnerability has been identified in Solid Edge SE2021 (All Versions < SE2021MP7). The PSKERNEL.dll library lacks proper validation while parsing user-supplied OBJ files that could cause an out of bounds access to an uninitialized pointer. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-13775)
Published Aug 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A stack-buffer-overflow occurs in Atomicparsley 20210124.204813.840499f through APar_readX() in src/util.cpp while parsing a crafted mp4 file because of the missing boundary check.
Published Aug 4, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An open redirect vulnerability exists in Nagios XI before version 5.8.5 that could lead to spoofing. To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link.
Published Aug 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus operated by released versions of software before Nexus Software 7.2.5.7. The device has two user accounts with passwords that are hardcoded.
Published Aug 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. A user logged in using the default credentials can gain root access to the device, which provides permissions for all of the functionality of the device.
Published Aug 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (V4.5.0). Affected devices fail to authenticate against configured passwords when provisioned using TIA Portal V13. This could allow an attacker using TIA Portal V13 or later versions to bypass authentication and download arbitrary programs to the PLC. The vulnerability does not occur when TIA Portal V13 SP1 or any later version was used to provision the device.
Published Aug 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because cleaner.php does not sanitise input read from the database.
Published Aug 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.
Published Aug 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Chamilo 1.11.14 allows stored XSS via main/install/index.php and main/install/ajax.php through the port parameter.
Published Aug 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML files to a repository could redirect users to Nexus Repository Manager’s pages with code modifications.
Published Aug 10, 2021 · Updated Aug 4, 2024