LiveActive security incident?Get immediate response
CVE archive

August 2021

Browse CVE records published in August 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2044 matching CVEs · Page 20 of 41.

Unknown · CVSS Not scored

CVE-2021-37538: Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote...

Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthenticated attacker to execute arbitrary SQL commands via the day, month, or year parameter to the controllers/front/archive.php archive controller, or the id_category parameter to the controllers/front/category.php category controller.

Published Aug 24, 2021 · Updated Aug 4, 2024

High · CVSS 8

CVE-2021-37627: Privilege escalation via form generator

Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is possible to gain privileged rights in the Contao back end. Installations are only affected if they have untrusted back end users who have access to the form generator. All users are advised to update to Contao 4.4.56, 4.9.18 or 4.11.7. As a workaround users may disable the form generator or disable the login for untrusted back end users.

Published Aug 11, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-37391: A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the...

A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator, through main/social/search.php, main/inc/lib/social.lib.php and steal cookies or execute arbitrary code on the administration side via a stored XSS vulnerability via social network the send invitation feature.

Published Aug 10, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-37388: A buffer overflow in D-Link DIR-615 C2 3.03WW.

A buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an attacker to crash the webserver and might even gain remote code execution.

Published Aug 6, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-37381: Southsoft GMIS 5.0 is vulnerable to CSRF attacks.

Southsoft GMIS 5.0 is vulnerable to CSRF attacks. Attackers can access other users' private information such as photos through CSRF. For example: any student's photo information can be accessed through /gmis/(S([1]))/student/grgl/PotoImageShow/?bh=[2]. Among them, the code in [1] is a random string generated according to the user's login related information. It can protect the user's identity, but it can not effectively prevent unauthorized access. The code in [2] is the student number of any student. The attacker can carry out CSRF attack on the system by modifying [2] without modifying [1].

Published Aug 6, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-37161: A buffer overflow issue was discovered in the HMI3 Control Panel contained within the Swisslog Healthcare N...

A buffer overflow issue was discovered in the HMI3 Control Panel contained within the Swisslog Healthcare Nexus Panel, operated by released versions of software before Nexus Software 7.2.5.7. A buffer overflow allows an attacker to overwrite an internal queue data structure and can lead to remote code execution.

Published Aug 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-37165: A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by...

A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. When a message is sent to the HMI TCP socket, it is forwarded to the hmiProcessMsg function through the pendingQ, and may lead to remote code execution.

Published Aug 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-37365: CTparental before 4.45.03 is vulnerable to cross-site scripting (XSS) in the CTparental admin panel.

CTparental before 4.45.03 is vulnerable to cross-site scripting (XSS) in the CTparental admin panel. In bl_categires_help.php, the 'categories' variable is assigned with the content of the query string param 'cat' without sanitization or encoding, enabling an attacker to inject malicious code into the output webpage.

Published Aug 10, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-37162: A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by...

A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. If an attacker sends a malformed UDP message, a buffer underflow occurs, leading to an out-of-bounds copy and possible remote code execution.

Published Aug 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-37179: A vulnerability has been identified in Solid Edge SE2021 (All Versions < SE2021MP7).

A vulnerability has been identified in Solid Edge SE2021 (All Versions < SE2021MP7). The PSKERNEL.dll library in affected application lacks proper validation while parsing user-supplied OBJ files that could lead to a use-after-free condition. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-13777)

Published Aug 10, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-37334: Umbraco Forms version 4.0.0 up to and including 8.7.5 and below are vulnerable to a security flaw that coul...

Umbraco Forms version 4.0.0 up to and including 8.7.5 and below are vulnerable to a security flaw that could lead to a remote code execution attack and/or arbitrary file deletion. A vulnerability occurs because validation of the file extension is performed after the file has been stored in a temporary directory. By default, files are stored within the application directory structure at %BASEDIR%/APP_DATA/TEMP/FileUploads/. Whilst access to this directory is restricted by the root web.config file, it is possible to override this restriction by uploading another specially crafted web.config file to the temporary directory. It is possible to exploit this flaw to upload a malicious script file to execute arbitrary code and system commands on the server.

Published Aug 25, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-37180: A vulnerability has been identified in Solid Edge SE2021 (All Versions < SE2021MP7).

A vulnerability has been identified in Solid Edge SE2021 (All Versions < SE2021MP7). The PSKERNEL.dll library lacks proper validation while parsing user-supplied OBJ files that could cause an out of bounds access to an uninitialized pointer. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-13775)

Published Aug 10, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-37167: An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel opera...

An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. A user logged in using the default credentials can gain root access to the device, which provides permissions for all of the functionality of the device.

Published Aug 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-37172: A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl.

A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (V4.5.0). Affected devices fail to authenticate against configured passwords when provisioned using TIA Portal V13. This could allow an attacker using TIA Portal V13 or later versions to bypass authentication and download arbitrary programs to the PLC. The vulnerability does not occur when TIA Portal V13 SP1 or any later version was used to provision the device.

Published Aug 10, 2021 · Updated Aug 4, 2024