LiveActive security incident?Get immediate response
CVE archive

September 2021

Browse CVE records published in September 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1832 matching CVEs · Page 13 of 37.

High · CVSS 7.4

CVE-2021-40699: ColdFusion CFIDE Improper Access Control Leads To Privilege Escalation

ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an improper access control vulnerability when checking permissions in the CFIDE path. An authenticated attacker could leverage this vulnerability to access and manipulate arbitrary data on the environment.

Published Sep 7, 2023 · Updated Sep 4, 2024

Unknown · CVSS Not scored

CVE-2021-44426: An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.5.

An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.5. An upload of an arbitrary file to a victim's local ~/Downloads/ directory is possible if the victim is using the AnyDesk Windows client to connect to a remote machine, if an attacker is also connected remotely with AnyDesk to the same remote machine. The upload is done without any approval or action taken by the victim.

Published Sep 12, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-44425: An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.3.

An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.3. An unnecessarily open listening port on a machine in the LAN of an attacker, opened by the Anydesk Windows client when using the tunneling feature, allows the attacker unauthorized access to the local machine's AnyDesk tunneling protocol stack (and also to any remote destination machine software that is listening to the AnyDesk tunneled port).

Published Sep 12, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-44076: An issue was discovered in CrushFTP 9.

An issue was discovered in CrushFTP 9. The creation of a new user through the /WebInterface/UserManager/ interface allows an attacker, with access to the administration panel, to perform Stored Cross-Site Scripting (XSS). The payload can be executed in multiple scenarios, for example when the user's page appears in the Most Visited section of the page.

Published Sep 15, 2022 · Updated Aug 4, 2024

Medium · CVSS 5.5

CVE-2021-42734: Adobe Photoshop TIF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

Adobe Photoshop version 22.5.1  and earlier versions   are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Published Sep 7, 2023 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-41795: The Safari app extension bundled with 1Password for Mac 7.7.0 through 7.8.x before 7.8.7 is vulnerable to a...

The Safari app extension bundled with 1Password for Mac 7.7.0 through 7.8.x before 7.8.7 is vulnerable to authorization bypass. By targeting a vulnerable component of this extension, a malicious web page could read a subset of 1Password vault items that would normally be fillable by the user on that web page. These items are usernames and passwords for vault items associated with its domain, usernames and passwords without a domain association, credit cards, and contact items. (1Password must be unlocked for these items to be accessible, but no further user interaction is required.)

Published Sep 29, 2021 · Updated Aug 4, 2024

High · CVSS 8.2

CVE-2021-41732: An issue was discovered in zeek version 4.1.0.

An issue was discovered in zeek version 4.1.0. There is a HTTP request splitting vulnerability that will invalidate any ZEEK HTTP based security analysis. NOTE: the vendor's position is that the observed behavior is intended

Published Sep 29, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-41580: The passport-oauth2 package before 1.6.1 for Node.js mishandles the error condition of failure to obtain an...

The passport-oauth2 package before 1.6.1 for Node.js mishandles the error condition of failure to obtain an access token. This is exploitable in certain use cases where an OAuth identity provider uses an HTTP 200 status code for authentication-failure error reports, and an application grants authorization upon simply receiving the access token (i.e., does not try to use the token). NOTE: the passport-oauth2 vendor does not consider this a passport-oauth2 vulnerability

Published Sep 27, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-41764: A cross-site request forgery (CSRF) vulnerability exists in Streama up to and including v1.10.3.

A cross-site request forgery (CSRF) vulnerability exists in Streama up to and including v1.10.3. The application does not have CSRF checks in place when performing actions such as uploading local files. As a result, attackers could make a logged-in administrator upload arbitrary local files via a CSRF attack and send them to the attacker.

Published Sep 29, 2021 · Updated Aug 4, 2024

High · CVSS 7.5

CVE-2021-41573: Hitachi Content Platform Anywhere (HCP-AW) 4.4.5 and later allows information disclosure.

Hitachi Content Platform Anywhere (HCP-AW) 4.4.5 and later allows information disclosure. If authenticated user creates a link to a file or folder while the system was running version 4.3.x or earlier and then shares the link and then later deletes the file or folder without deleting the link and before the link expires. If the system has been upgraded to version 4.4.5 or 4.5.0 a malicious user with the link could browse and download all files of the authenticated user that created the link .

Published Sep 29, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-41538: A vulnerability has been identified in NX 1953 Series (All versions < V1973.3700), NX 1980 Series (All vers...

A vulnerability has been identified in NX 1953 Series (All versions < V1973.3700), NX 1980 Series (All versions < V1988), Solid Edge SE2021 (All versions < SE2021MP8). The affected application is vulnerable to information disclosure by unexpected access to an uninitialized pointer while parsing user-supplied OBJ files. An attacker could leverage this vulnerability to leak information from unexpected memory locations (ZDI-CAN-13770).

Published Sep 28, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-41583: vpn-user-portal (aka eduVPN or Let's Connect!) before 2.3.14, as packaged for Debian 10, Debian 11, and Fed...

vpn-user-portal (aka eduVPN or Let's Connect!) before 2.3.14, as packaged for Debian 10, Debian 11, and Fedora, allows remote authenticated users to obtain OS filesystem access, because of the interaction of QR codes with an exec that uses the -r option. This can be leveraged to obtain additional VPN access.

Published Sep 24, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-41504: An Elevated Privileges issue exists in D-Link DCS-5000L v1.05 and DCS-932L v2.17 and older.

An Elevated Privileges issue exists in D-Link DCS-5000L v1.05 and DCS-932L v2.17 and older. The use of the digest-authentication for the devices command interface may allow further attack vectors that may compromise the cameras configuration and allow malicious users on the LAN to access the device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

Published Sep 24, 2021 · Updated Aug 4, 2024

High · CVSS 8

CVE-2021-41503: DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control.

DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authentication for the devices command interface allows attack vectors that may compromise the cameras configuration and allow malicious users on the LAN to access the device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

Published Sep 24, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-41534: A vulnerability has been identified in NX 1980 Series (All versions < V1984), Solid Edge SE2021 (All versio...

A vulnerability has been identified in NX 1980 Series (All versions < V1984), Solid Edge SE2021 (All versions < SE2021MP8). The affected application is vulnerable to an out of bounds read past the end of an allocated buffer when parsing JT files. An attacker could leverage this vulnerability to leak information in the context of the current process (ZDI-CAN-13703).

Published Sep 28, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-41535: A vulnerability has been identified in NX 1953 Series (All versions < V1973.3700), NX 1980 Series (All vers...

A vulnerability has been identified in NX 1953 Series (All versions < V1973.3700), NX 1980 Series (All versions < V1988), Solid Edge SE2021 (All versions < SE2021MP8). The affected application contains a use-after-free vulnerability while parsing OBJ files. An attacker could leverage this vulnerability to execute code in the context of the current process (ZDI-CAN-13771).

Published Sep 28, 2021 · Updated Aug 4, 2024