LiveActive security incident?Get immediate response
CVE archive

August 2021

Browse CVE records published in August 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2047 matching CVEs · Page 38 of 41.

Unknown · CVSS Not scored

CVE-2021-20809: Cross-site scripting vulnerability in Create screens of Entry, Page, and Content Type of Movable Type (Mova...

Cross-site scripting vulnerability in Create screens of Entry, Page, and Content Type of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type 6.8.0 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.44 and earlier, and Movable Type Premium Advanced 1.44 and earlier) allows remote attackers to inject arbitrary script or HTML via unspecified vectors.

Published Aug 26, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-20814: Cross-site scripting vulnerability in Setting screen of ContentType Information Widget Plugin of Movable Ty...

Cross-site scripting vulnerability in Setting screen of ContentType Information Widget Plugin of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series), and Movable Type Premium 1.44 and earlier) allows remote attackers to inject arbitrary script or HTML via unspecified vectors.

Published Aug 26, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-20815: Cross-site scripting vulnerability in Edit Boilerplate screen of Movable Type (Movable Type 7 r.4903 and ea...

Cross-site scripting vulnerability in Edit Boilerplate screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type 6.8.0 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.44 and earlier, and Movable Type Premium Advanced 1.44 and earlier) allows remote attackers to inject arbitrary script or HTML via unspecified vectors.

Published Aug 26, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-20811: Cross-site scripting vulnerability in List of Assets screen of Movable Type (Movable Type 7 r.4903 and earl...

Cross-site scripting vulnerability in List of Assets screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type 6.8.0 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.44 and earlier, and Movable Type Premium Advanced 1.44 and earlier) allows remote attackers to inject arbitrary script or HTML via unspecified vectors.

Published Aug 26, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-20813: Cross-site scripting vulnerability in Edit screen of Content Data of Movable Type (Movable Type 7 r.4903 an...

Cross-site scripting vulnerability in Edit screen of Content Data of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series) and Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series)) allows remote attackers to inject arbitrary script or HTML via unspecified vectors.

Published Aug 26, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-20810: Cross-site scripting vulnerability in Website Management screen of Movable Type (Movable Type 7 r.4903 and...

Cross-site scripting vulnerability in Website Management screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type 6.8.0 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.44 and earlier, and Movable Type Premium Advanced 1.44 and earlier) allows remote attackers to inject arbitrary script or HTML via unspecified vectors.

Published Aug 26, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-20597: Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU mod...

Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to login to the target unauthorizedly by sniffing network traffic and obtaining credentials when registering user information in the target or changing a password.

Published Aug 6, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-20594: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Mitsubishi Electric MELSEC iQ-R...

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to acquire legitimate user names registered in the module via brute-force attack on user names.

Published Aug 6, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-20592: Missing synchronization vulnerability in GOT2000 series GT27 model communication driver versions 01.19.000...

Missing synchronization vulnerability in GOT2000 series GT27 model communication driver versions 01.19.000 through 01.39.010, GT25 model communication driver versions 01.19.000 through 01.39.010 and GT23 model communication driver versions 01.19.000 through 01.39.010 and GT SoftGOT2000 versions 1.170C through 1.256S allows a remote unauthenticated attacker to cause DoS condition on the MODBUS/TCP slave communication function of the products by rapidly and repeatedly connecting and disconnecting to and from the MODBUS/TCP communication port on a target. Restart or reset is required to recover.

Published Aug 5, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-20304: A flaw was found in OpenEXR's hufDecode functionality.

A flaw was found in OpenEXR's hufDecode functionality. This flaw allows an attacker who can pass a crafted file to be processed by OpenEXR, to trigger an undefined right shift error. The highest threat from this vulnerability is to system availability.

Published Aug 23, 2022 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-20298: A flaw was found in OpenEXR's B44Compressor.

A flaw was found in OpenEXR's B44Compressor. This flaw allows an attacker who can submit a crafted file to be processed by OpenEXR, to exhaust all memory accessible to the application. The highest threat from this vulnerability is to system availability.

Published Aug 23, 2022 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-20260: A flaw was found in the Foreman project.

A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Published Aug 26, 2022 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-20116: A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4.

A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4. The paths provided in the f, d, and dir parameters in tce_select_mediafile.php were not properly validated and could cause reflected XSS via the unsanitized output of the path supplied. An attacker could craft a malicious link which, if triggered by an administrator, could result in the attacker hijacking the victim's session or performing actions on their behalf.

Published Aug 5, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-20224: An integer overflow issue was discovered in ImageMagick's ExportIndexQuantum() function in MagickCore/quant...

An integer overflow issue was discovered in ImageMagick's ExportIndexQuantum() function in MagickCore/quantum-export.c. Function calls to GetPixelIndex() could result in values outside the range of representable for the 'unsigned char'. When ImageMagick processes a crafted pdf file, this could lead to an undefined behaviour or a crash.

Published Aug 25, 2022 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-20115: A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3.

A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3. The paths provided in the f, d, and dir parameters in tce_filemanager.php were not properly validated and could cause reflected XSS via the unsanitized output of the path supplied. An attacker could craft a malicious link which, if triggered by an administrator, could result in the attacker hijacking the victim's session or performing actions on their behalf.

Published Aug 5, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-4217: A flaw was found in unzip.

A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.

Published Aug 24, 2022 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-4213: A flaw was found in JSS, where it did not properly free up all memory.

A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service.

Published Aug 24, 2022 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-4209: A NULL pointer dereference flaw was found in GnuTLS.

A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances.

Published Aug 24, 2022 · Updated Aug 3, 2024