LiveActive security incident?Get immediate response
CVE archive

December 2021

Browse CVE records published in December 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2052 matching CVEs · Page 9 of 42.

High · CVSS 8.8

CVE-2021-27859: Missing authorization vulnerability in FatPipe software

A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows an authenticated, remote attacker with read-only privileges to create an account with administrative privileges. Older versions of FatPipe software may also be vulnerable. This does not appear to be a CSRF vulnerability. The FatPipe advisory identifier for this vulnerability is FPSA005.

Published Dec 15, 2021 · Updated Sep 16, 2024

Medium · CVSS 5.3

CVE-2021-38680: Reflected XSS in Kazoo Server

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Kazoo Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Kazoo Server: Kazoo Server 4.11.20 and later

Published Dec 29, 2021 · Updated Sep 16, 2024

High · CVSS 7.5

CVE-2021-23727: Stored Command Injection

This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access to, or somehow manipulate the metadata within a celery backend, they could trigger a stored command injection vulnerability and potentially gain further access to the system.

Published Dec 29, 2021 · Updated Sep 16, 2024

High · CVSS 7.5

CVE-2021-23450: Prototype Pollution

All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.

Published Dec 17, 2021 · Updated Sep 16, 2024

High · CVSS 8.1

CVE-2021-38687: Stack Overflow Vulnerability in Surveillance Station

A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of Surveillance Station: QTS 5.0.0 (64 bit): Surveillance Station 5.2.0.4.2 ( 2021/10/26 ) and later QTS 5.0.0 (32 bit): Surveillance Station 5.2.0.3.2 ( 2021/10/26 ) and later QTS 4.3.6 (64 bit): Surveillance Station 5.1.5.4.6 ( 2021/10/26 ) and later QTS 4.3.6 (32 bit): Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later QTS 4.3.3: Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later

Published Dec 29, 2021 · Updated Sep 16, 2024

High · CVSS 7.5

CVE-2021-23574: Prototype Pollution

All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn and the set functions. This is an incomplete fix of [CVE-2020-28442](https://snyk.io/vuln/SNYK-JS-JSDATA-1023655).

Published Dec 24, 2021 · Updated Sep 16, 2024

Critical · CVSS 10

CVE-2021-43981: mySCADA myPRO

mySCADA myPRO: Versions 8.20.0 and prior has a feature to send emails, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.

Published Dec 23, 2021 · Updated Sep 16, 2024

Medium · CVSS 6.1

CVE-2021-36724: ForeScout - SecureConnector Local Service DoS

ForeScout - SecureConnector Local Service DoS - A low privilaged user which doesn't have permissions to shutdown the secure connector service writes a large amount of characters in the installationPath. This will cause the buffer to overflow and override the stack cookie causing the service to crash.

Published Dec 29, 2021 · Updated Sep 16, 2024

High · CVSS 7.5

CVE-2021-23772: Arbitrary File Write

This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12. The unsafe handling of file names during upload using UploadFormFiles method may enable attackers to write to arbitrary locations outside the designated target folder.

Published Dec 24, 2021 · Updated Sep 16, 2024

High · CVSS 7.8

CVE-2021-43556: FATEK Automation WinProladder

FATEK WinProladder Versions 3.30_24518 and prior are vulnerable to a stack-based buffer overflow while processing project files, which may allow an attacker to execute arbitrary code.

Published Dec 28, 2021 · Updated Sep 16, 2024

High · CVSS 7.5

CVE-2021-43989: mySCADA myPRO

mySCADA myPRO Versions 8.20.0 and prior stores passwords using MD5, which may allow an attacker to crack the previously retrieved password hashes.

Published Dec 23, 2021 · Updated Sep 16, 2024

Critical · CVSS 9.1

CVE-2021-23859: Denial of Service and Authentication Bypass Vulnerability in multiple Bosch products

An unauthenticated attacker is able to send a special HTTP request, that causes a service to crash. In case of a standalone VRM or BVMS with VRM installation this crash also opens the possibility to send further unauthenticated commands to the service. On some products the interface is only local accessible lowering the CVSS base score. For a list of modified CVSS scores, please see the official Bosch Advisory Appendix chapter Modified CVSS Scores for CVE-2021-23859

Published Dec 8, 2021 · Updated Sep 16, 2024

High · CVSS 7.5

CVE-2021-23797: Directory Traversal

All versions of package http-server-node are vulnerable to Directory Traversal via use of --path-as-is.

Published Dec 17, 2021 · Updated Sep 16, 2024

High · CVSS 7.2

CVE-2021-23862: Authenticated Remote Code Execution

A crafted configuration packet sent by an authenticated administrative user can be used to execute arbitrary commands in system context. This issue also affects installations of the VRM, DIVAR IP, BVMS with VRM installed, the VIDEOJET decoder (VJD-7513 and VJD-8000).

Published Dec 8, 2021 · Updated Sep 16, 2024

Medium · CVSS 5.4

CVE-2021-38883: IBM Business Automation Workflow 18.0, 19.0, 20,0 and 21.0 and IBM Business Process Manager 8.5 and 8.6 are...

IBM Business Automation Workflow 18.0, 19.0, 20,0 and 21.0 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 209165.

Published Dec 17, 2021 · Updated Sep 16, 2024

Critical · CVSS 9.8

CVE-2021-4161: ICSA-21-357-01 Moxa MGate Protocol Gateways

The affected products contain vulnerable firmware, which could allow an attacker to sniff the traffic and decrypt login credential details. This could give an attacker admin rights through the HTTP web server.

Published Dec 27, 2021 · Updated Sep 16, 2024

High · CVSS 7.5

CVE-2021-40851: TCMAN GIM SQL injection vulnerability

TCMAN GIM is vulnerable to a lack of authorization in all available webservice methods listed in /PC/WebService.asmx. The exploitation of this vulnerability might allow a remote attacker to obtain information.

Published Dec 17, 2021 · Updated Sep 16, 2024

High · CVSS 8

CVE-2021-35234: Exposed Dangerous Functions - Privileged Escalation

Numerous exposed dangerous functions within Orion Core has allows for read-only SQL injection leading to privileged escalation. An attacker with low-user privileges may steal password hashes and password salt information.

Published Dec 20, 2021 · Updated Sep 16, 2024

Medium · CVSS 6.1

CVE-2021-40852: TCMAN GIM open redirect vulnerability

TCMAN GIM is affected by an open redirect vulnerability. This vulnerability allows the redirection of user navigation to pages controlled by the attacker. The exploitation of this vulnerability might allow a remote attacker to obtain information.

Published Dec 17, 2021 · Updated Sep 16, 2024

High · CVSS 8.8

CVE-2021-43359: Sunnet eHRD - Broken Access Control

Sunnet eHRD has broken access control vulnerability, which allows a remote attacker to access account management page after being authenticated as a general user, then perform privilege escalation to execute arbitrary code and control the system or interrupt services.

Published Dec 1, 2021 · Updated Sep 16, 2024

Medium · CVSS 6.5

CVE-2021-31558: Delta Electronics DIAEnergie (Update A)

DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “descr” of the script “DIAE_hierarchyHandler.ashx”.

Published Dec 22, 2021 · Updated Sep 16, 2024

High · CVSS 7.1

CVE-2021-36722: Emuse - eServices / eNvoice SQL injection

Emuse - eServices / eNvoice SQL injection can be used in various ways ranging from bypassing login authentication or dumping the whole database to full RCE on the affected endpoints. The SQLi caused by CWE-209: Generation of Error Message Containig Sensetive Information, showing parts of the aspx code and the webroot location , information an attacker can leverage to further compromise the host.

Published Dec 29, 2021 · Updated Sep 16, 2024

Medium · CVSS 4.2

CVE-2021-23259: Groovy Sandbox Bypass

Authenticated users with Administrator or Developer roles may execute OS commands by Groovy Script which uses Groovy lib to render a webpage. The groovy script does not have security restrictions, which will cause attackers to execute arbitrary commands remotely(RCE).

Published Dec 2, 2021 · Updated Sep 16, 2024

Medium · CVSS 6.5

CVE-2021-23663: Prototype Pollution

All versions of package sey are vulnerable to Prototype Pollution via the deepmerge() function.

Published Dec 10, 2021 · Updated Sep 16, 2024

Medium · CVSS 4.2

CVE-2021-23562: Arbitrary File Upload

This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker would need to trick a user to upload this kind of file.

Published Dec 3, 2021 · Updated Sep 16, 2024

Medium · CVSS 6.5

CVE-2021-23861: Possible Access to Debug Functions in Bosch VRM / BVMS

By executing a special command, an user with administrative rights can get access to extended debug functionality on the VRM allowing an impact on integrity or availability of the installed software. This issue also affects installations of the DIVAR IP and BVMS with VRM installed.

Published Dec 8, 2021 · Updated Sep 16, 2024

Critical · CVSS 9.8

CVE-2021-23803: Access Control Bypass

This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the security of the application. When the template is set to allow/disallow the use of certain functions, adding control characters (x00-x08) after the function will bypass these restrictions.

Published Dec 17, 2021 · Updated Sep 16, 2024

Critical · CVSS 9.8

CVE-2021-22279: OmniCore RobotWare Missing Authentication Vulnerability

A Missing Authentication vulnerability in RobotWare for the OmniCore robot controller allows an attacker to read and modify files on the robot controller if the attacker has access to the Connected Services Gateway Ethernet port.

Published Dec 13, 2021 · Updated Sep 16, 2024

High · CVSS 7.8

CVE-2021-43554: FATEK Automation WinProladder

FATEK WinProladder Versions 3.30_24518 and prior are vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code.

Published Dec 28, 2021 · Updated Sep 16, 2024

Medium · CVSS 6.5

CVE-2021-20330: Specific replication command with malformed oplog entries can crash secondaries

An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in a potential denial of service on secondaries. This issue affects MongoDB Server v4.0 versions prior to 4.0.27; MongoDB Server v4.2 versions prior to 4.2.16; MongoDB Server v4.4 versions prior to 4.4.9.

Published Dec 15, 2021 · Updated Sep 16, 2024

Medium · CVSS 5.3

CVE-2021-35243: HTTP PUT & DELETE Methods Enabled

The HTTP PUT and DELETE methods were enabled in the Web Help Desk web server (12.7.7 and earlier), allowing users to execute dangerous HTTP requests. The HTTP PUT method is normally used to upload data that is saved on the server with a user-supplied URL. While the DELETE method requests that the origin server removes the association between the target resource and its current functionality. Improper use of these methods may lead to a loss of integrity.

Published Dec 23, 2021 · Updated Sep 16, 2024