آسیبپذیریهای حیاتی هفته چهارم مردادماه

??? ???? ?????????????? «?????» ? «?????» ?????? ?? ??????? ??? Cisco ????? ? ??????? ? ???????????????? ?? ????? ??? ????? ????? ??. ?????? ?? ??????? ???????? Apache? Adobe? Google? IBM? Mozilla? ?????????? WordPress ? ???? ?????? ????? ?????????? «?????» ? «?????» ???? ????.
???? ??? ????????????? ???????? ??? ??? ????? ?? ???? ??? ???? ???.
|
????? ?????????? |
?????? ???? |
????? ?????????? |
???? ??? ??? |
??? ?????????? |
|
CVE-2021-35992 |
?.? |
Adobe Bridge out-of-bounds read |
$?-$?k |
Official Fix |
|
CVE-2021-35990 |
?.? |
Adobe Bridge out-of-bounds write |
$?k-$25k |
Official Fix |
|
CVE-2021-35989 |
?.? |
Adobe Bridge out-of-bounds write |
$?k-$25k |
Official Fix |
|
CVE-2021-35991 |
?.? |
Adobe Bridge uninitialized pointer |
$?-$?k |
Official Fix |
|
CVE-2021-36000 |
?.? |
Adobe Character Animator memory corruption |
$?k-$25k |
Official Fix |
|
CVE-2021-36001 |
?.? |
Adobe Character Animator out-of-bounds read |
$?-$?k |
Official Fix |
|
CVE-2021-28624 |
?.? |
Adobe Context heap-based overflow |
$?k-$25k |
Official Fix |
|
CVE-2021-28595 |
?.? |
Adobe Dimension uncontrolled search path |
$?k-$25k |
Official Fix |
|
CVE-2021-36009 |
?.? |
Adobe Illustrator memory corruption |
$?k-$25k |
Official Fix |
|
CVE-2021-36011 |
?.? |
Adobe Illustrator os command injection |
$?k-$25k |
Official Fix |
|
CVE-2021-36010 |
?.? |
Adobe Illustrator out-of-bounds read |
$?-$?k |
Official Fix |
|
CVE-2021-28592 |
?.? |
Adobe Illustrator out-of-bounds write |
$?k-$25k |
Official Fix |
|
CVE-2021-28591 |
?.? |
Adobe Illustrator out-of-bounds write |
$?k-$25k |
Official Fix |
|
CVE-2021-36008 |
?.? |
Adobe Illustrator use after free |
$?k-$25k |
Official Fix |
|
CVE-2021-28593 |
?.? |
Adobe Illustrator use after free |
$?k-$25k |
Official Fix |
|
CVE-2021-36015 |
?.? |
Adobe Media Encoder memory corruption |
$?k-$25k |
Official Fix |
|
CVE-2021-36016 |
?.? |
Adobe Media Encoder out-of-bounds read |
$?-$?k |
Official Fix |
|
CVE-2021-28590 |
?.? |
Adobe Media Encoder out-of-bounds read |
$?-$?k |
Official Fix |
|
CVE-2021-28589 |
?.? |
Adobe Media Encoder out-of-bounds read |
$?-$?k |
Official Fix |
|
CVE-2021-36014 |
?.? |
Adobe Media Encoder uninitialized pointer |
$?-$?k |
Official Fix |
|
CVE-2021-36006 |
?.? |
Adobe Photoshop input validation |
$?k-$25k |
Official Fix |
|
CVE-2021-36005 |
?.? |
Adobe Photoshop stack-based overflow |
$?k-$25k |
Official Fix |
|
CVE-2021-35999 |
?.? |
Adobe Prelude memory corruption |
$?k-$25k |
Official Fix |
|
CVE-2021-36007 |
?.? |
Adobe Prelude uninitialized pointer |
$?-$?k |
Official Fix |
|
CVE-2021-35997 |
?.? |
Adobe Premiere Pro memory corruption |
$?k-$25k |
Official Fix |
|
CVE-2021-35936 |
?.? |
Apache Airflow CeleryExecutor/LocalExecutor information disclosure |
$?k-$10k |
Official Fix |
|
CVE-2021-33193 |
?.? |
Apache HTTP Server mod_proxy access control |
$??k-$50k |
Official Fix |
|
CVE-2021-37608 |
?.? |
Apache OFBiz unrestricted upload |
$??k-$25k |
Official Fix |
|
CVE-2021-30785 |
?.? |
Apple iCloud ImageIO buffer overflow |
$??k-$25k |
Official Fix |
|
CVE-2021-30779 |
?.? |
Apple iCloud ImageIO Remote Code Execution |
$??k-$25k |
Official Fix |
|
CVE-2021-21814 |
?.? |
AT&T Xmill Command Line HandleFileArg buffer overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-21815 |
?.? |
AT&T Xmill Command Line HandleFileArg stack-based overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-21813 |
?.? |
AT&T Xmill Command Line HandleFileArg stack-based overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-21812 |
?.? |
AT&T Xmill Command Line HandleFileArg stack-based overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-21828 |
?.? |
AT&T Xmill XML Decompression AddLabel heap-based overflow |
$?-$?k |
Not Defined |
|
CVE-2021-21826 |
?.? |
AT&T Xmill XML Decompression DecodeTreeBlock heap-based overflow |
$?-$?k |
Not Defined |
|
CVE-2021-21827 |
?.? |
AT&T Xmill XML Decompression heap-based overflow |
$?-$?k |
Not Defined |
|
CVE-2021-21830 |
?.? |
AT&T Xmill XML Decompression Load heap-based overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-21825 |
?.? |
AT&T Xmill XML Decompression UncompressItem heap-based overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-21829 |
?.? |
AT&T Xmill XML Decompression UncompressItem heap-based overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-21810 |
?.? |
AT&T Xmill XML File heap-based overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-26086 |
?.? |
Atlassian JIRA Server/Data Center Endpoint web.xml path traversal |
$?k-$2k |
Official Fix |
|
CVE-2020-23334 |
?.? |
Bento4 AP4_NullTerminatedStringAtom memory corruption |
$?k-$2k |
Not Defined |
|
CVE-2020-21066 |
?.? |
Bento4 Ap4Dec3Atom.cpp AP4_Dec3Atom heap-based overflow |
$?k-$2k |
Not Defined |
|
CVE-2020-23331 |
?.? |
Bento4 Ap4Descriptor.h WriteFields null pointer dereference |
$?-$?k |
Not Defined |
|
CVE-2020-21064 |
?.? |
Bento4 Ap4RtpAtom.cpp AP4_RtpAtom buffer overflow |
$?k-$2k |
Not Defined |
|
CVE-2020-23332 |
?.? |
Bento4 Ap4StdCFileByteStream.cpp ReadPartial heap-based overflow |
$?k-$2k |
Not Defined |
|
CVE-2020-23330 |
?.? |
Bento4 Ap4Stz2Atom.cpp GetSampleSize null pointer dereference |
$?-$?k |
Not Defined |
|
CVE-2020-23333 |
?.? |
Bento4 Ap4Utils.h AP4_CttsAtom heap-based overflow |
$?k-$2k |
Not Defined |
|
CVE-2021-23423 |
?.? |
bikeshed Source File code injection |
$?k-$2k |
Official Fix |
|
CVE-2021-23422 |
?.? |
bikeshed Source File os command injection |
$?k-$2k |
Official Fix |
|
CVE-2021-34715 |
?.? |
Cisco Expressway/TelePresence Video Communication Server Administrative Web Interface signature verification |
$?k-$10k |
Official Fix |
|
CVE-2021-34716 |
?.? |
Cisco Expressway/TelePresence Video Communication Server Web-based Management Interface unrestricted upload |
$??k-$25k |
Official Fix |
|
CVE-2021-34730 |
?.? |
Cisco RV110W/RV130/RV130W/RV215W UPnP Request stack-based overflow |
$??k-$50k |
Official Fix |
|
CVE-2021-1561 |
?.? |
Cisco Secure Email and Web Manager Spam Quarantine access control |
$??k-$25k |
Official Fix |
|
CVE-2021-34734 |
?.? |
Cisco Video Surveillance 7000 Link Layer Discovery Protocol double free |
$??k-$25k |
Official Fix |
|
CVE-2021-34749 |
?.? |
Cisco Web Security Appliance SNI Filter access control |
$??k-$50k |
Official Fix |
|
CVE-2021-22932 |
?.? |
Citrix ShareFile Storage Zones Controller Mitigation Tool missing encryption |
$?k-$5k |
Not Defined |
|
CVE-2021-21867 |
?.? |
CODESYS Development System ObjectStream.ProfileByteArray deserialization |
$?k-$5k |
Not Defined |
|
CVE-2021-21868 |
?.? |
CODESYS Development System Project.get_MissingTypes deserialization |
$?k-$5k |
Not Defined |
|
CVE-2021-24536 |
?.? |
Custom Login Redirect Plugin cross-site request forgery |
$?-$?k |
Not Defined |
|
CVE-2021-34655 |
?.? |
Custom Post Type Relations Plugin Parameter admin-page.php cross site scripting |
$?-$?k |
Official Fix |
|
CVE-2021-34654 |
?.? |
Custom Post Type Relations Plugin Parameter admin-page.php cross site scripting |
$?-$?k |
Official Fix |
|
CVE-2021-20756 |
?.? |
Cybozu Garoon Address access control |
$?k-$5k |
Not Defined |
|
CVE-2021-20764 |
?.? |
Cybozu Garoon Attachment access control |
$?k-$5k |
Not Defined |
|
CVE-2021-20772 |
?.? |
Cybozu Garoon Bulletin Title information disclosure |
$?k-$2k |
Not Defined |
|
CVE-2021-20775 |
?.? |
Cybozu Garoon Comment access control |
$?k-$5k |
Not Defined |
|
CVE-2021-20774 |
?.? |
Cybozu Garoon cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2021-20771 |
?.? |
Cybozu Garoon cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2021-20770 |
?.? |
Cybozu Garoon cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2021-20769 |
?.? |
Cybozu Garoon cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2021-20766 |
?.? |
Cybozu Garoon cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2021-20765 |
?.? |
Cybozu Garoon cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2021-20753 |
?.? |
Cybozu Garoon cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2021-20762 |
?.? |
Cybozu Garoon E-Mail access control |
$?k-$5k |
Not Defined |
|
CVE-2021-20761 |
?.? |
Cybozu Garoon E-Mail access control |
$?k-$2k |
Not Defined |
|
CVE-2021-20767 |
?.? |
Cybozu Garoon Full Text Search cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2021-20755 |
?.? |
Cybozu Garoon Portal access control |
$?k-$5k |
Not Defined |
|
CVE-2021-20763 |
?.? |
Cybozu Garoon Portal Data access control |
$?k-$5k |
Not Defined |
|
CVE-2021-20759 |
?.? |
Cybozu Garoon Portal Data access control |
$?k-$5k |
Not Defined |
|
CVE-2021-20757 |
?.? |
Cybozu Garoon Portal Data access control |
$?k-$5k |
Not Defined |
|
CVE-2021-20773 |
?.? |
Cybozu Garoon Route access control |
$?k-$5k |
Not Defined |
|
CVE-2021-20768 |
?.? |
Cybozu Garoon Scheduler/MultiReport access control |
$?k-$5k |
Not Defined |
|
CVE-2021-20760 |
?.? |
Cybozu Garoon User Profile access control |
$?k-$5k |
Not Defined |
|
CVE-2021-20754 |
?.? |
Cybozu Garoon Workflow Data access control |
$?k-$5k |
Not Defined |
|
CVE-2021-20758 |
?.? |
Cybozu Request cross-site request forgery |
$?-$?k |
Not Defined |
|
CVE-2021-36792 |
?.? |
dated_news Extension access control |
$?k-$2k |
Not Defined |
|
CVE-2021-36791 |
?.? |
dated_news Extension Application Registration information disclosure |
$?-$?k |
Not Defined |
|
CVE-2021-36790 |
?.? |
dated_news Extension cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2021-36789 |
?.? |
dated_news Extension sql injection |
$?k-$2k |
Not Defined |
|
CVE-2021-36281 |
?.? |
Dell EMC PowerScale OneFS default permission |
$??k-$25k |
Not Defined |
|
CVE-2021-21592 |
?.? |
Dell EMC PowerScale OneFS exceptional condition |
$??k-$25k |
Not Defined |
|
CVE-2021-21594 |
?.? |
Dell EMC PowerScale OneFS GET Request information disclosure |
$?k-$10k |
Not Defined |
|
CVE-2021-36282 |
?.? |
Dell EMC PowerScale OneFS ifs uninitialized resource |
$?k-$10k |
Not Defined |
|
CVE-2021-21568 |
?.? |
Dell EMC PowerScale OneFS Log denial of service |
$?k-$5k |
Not Defined |
|
CVE-2021-36278 |
?.? |
Dell EMC PowerScale OneFS Log File log file |
$?k-$10k |
Not Defined |
|
CVE-2021-36280 |
?.? |
Dell EMC PowerScale OneFS permission assignment |
$??k-$25k |
Not Defined |
|
CVE-2021-36279 |
?.? |
Dell EMC PowerScale OneFS permission assignment |
$??k-$25k |
Not Defined |
|
CVE-2021-21595 |
?.? |
Dell EMC PowerScale OneFS Smartlock WORM Compliance Mode command injection |
$??k-$25k |
Official Fix |
|
CVE-2021-21599 |
?.? |
Dell EMC PowerScale OneFS Smartlock WORM Compliance Mode os command injection |
$??k-$25k |
Official Fix |
|
CVE-2021-37693 |
?.? |
Discourse Email session expiration |
$?k-$2k |
Official Fix |
|
CVE-2021-37703 |
?.? |
Discourse information disclosure |
$?k-$2k |
Official Fix |
|
CVE-2020-18704 |
?.? |
Django-Widgy Change Widgy Page unrestricted upload |
$?k-$5k |
Not Defined |
|
CVE-2021-3707 |
?.? |
D-Link DSL-2750U Configuration os command injection |
$??k-$25k |
Not Defined |
|
CVE-2021-3708 |
?.? |
D-Link DSL-2750U os command injection |
$??k-$25k |
Not Defined |
|
CVE-2021-25956 |
?.? |
Dolibarr access control |
$?k-$2k |
Official Fix |
|
CVE-2021-25955 |
?.? |
Dolibarr ERP WYSIWYG Editor Module cross site scripting |
$?-$?k |
Official Fix |
|
CVE-2021-25957 |
?.? |
Dolibarr password recovery |
$?k-$5k |
Official Fix |
|
CVE-2020-18759 |
?.? |
Dut Computer Control Engineering PLC MAC1100 EPA Protocol information disclosure |
$?-$?k |
Not Defined |
|
CVE-2020-18756 |
?.? |
Dut Computer Control Engineering PLC MAC1100 EPA Protocol memory corruption |
$?k-$2k |
Not Defined |
|
CVE-2020-18754 |
?.? |
Dut Computer Control Engineering PLC MAC1100 information disclosure |
$?-$?k |
Not Defined |
|
CVE-2020-18757 |
?.? |
Dut Computer Control Engineering PLC MAC1100 Packet denial of service |
$?-$?k |
Not Defined |
|
CVE-2020-18753 |
?.? |
Dut Computer Control Engineering PLC MAC1100 Packet Privilege Escalation |
$?k-$5k |
Not Defined |
|
CVE-2020-18758 |
?.? |
Dut Computer Control Engineering PLC MAC1100 Privilege Escalation |
$?k-$5k |
Not Defined |
|
CVE-2020-18899 |
?.? |
Exiv2 DataBufdata resource consumption |
$?-$?k |
Not Defined |
|
CVE-2020-18898 |
?.? |
Exiv2 printIFDStructure denial of service |
$?-$?k |
Not Defined |
|
CVE-2020-20645 |
?.? |
EyouCMS cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2020-20642 |
?.? |
EyouCMS cross-site request forgery |
$?-$?k |
Not Defined |
|
CVE-2020-19669 |
?.? |
Eyoucms cross-site request forgery |
$?-$?k |
Not Defined |
|
CVE-2020-28146 |
?.? |
Eyoucms Parameter cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2021-24038 |
?.? |
Facebook Oculus Desktop Handle Management OVRServiceLauncher.exe privileges management |
$?k-$10k |
Official Fix |
|
CVE-2021-38171 |
?.? |
FFmpeg Argument adtsenc.c adts_decode_extradata return value |
$?-$?k |
Official Fix |
|
CVE-2021-32602 |
?.? |
Fortinet FortiPortal GUI Web Page Generation cross site scripting |
$?-$?k |
Official Fix |
|
CVE-2021-32588 |
?.? |
Fortinet FortiPortal hard-coded credentials |
$?k-$5k |
Official Fix |
|
CVE-2021-22254 |
?.? |
GitLab Community Edition/Enterprise Edition Shell information disclosure |
$?-$?k |
Not Defined |
|
CVE-2021-22238 |
?.? |
GitLab Design Feature cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2021-22246 |
?.? |
GitLab Webhook denial of service |
$?-$?k |
Official Fix |
|
CVE-2021-0574 |
?.? |
Google Android ASF Extractor out-of-bounds write |
$??k-$50k |
Official Fix |
|
CVE-2021-0573 |
?.? |
Google Android ASF Extractor out-of-bounds write |
$??k-$50k |
Official Fix |
|
CVE-2021-0591 |
?.? |
Google Android BluetoothPermissionActivity.java sendReplyIntentToReceiver permission |
$??k-$50k |
Official Fix |
|
CVE-2021-0593 |
?.? |
Google Android DevicePickerFragment.java sendDevicePickedtent Local Privilege Escalation |
$??k-$50k |
Official Fix |
|
CVE-2021-0645 |
?.? |
Google Android ExternalStorageProvider.java shouldBlockFromTree permission |
$??k-$50k |
Official Fix |
|
CVE-2021-0576 |
?.? |
Google Android FLV Extractor out-of-bounds write |
$??k-$50k |
Official Fix |
|
CVE-2021-0519 |
?.? |
Google Android ih264e_bitstream.h BITSTREAM_FLUSH out-of-bounds write |
$??k-$50k |
Official Fix |
|
CVE-2021-0639 |
?.? |
Google Android libl3oemcrypto.cpp information disclosure |
$??k-$25k |
Official Fix |
|
CVE-2021-0584 |
?.? |
Google Android Parcel.cpp verifyBufferObject out-of-bounds read |
$??k-$25k |
Official Fix |
|
CVE-2021-0646 |
?.? |
Google Android sqlite3.c sqlite3_str_vappendf out-of-bounds write |
$??k-$50k |
Official Fix |
|
CVE-2021-0640 |
?.? |
Google Android StatsdStats.cpp noteAtomLogged out-of-bounds write |
$??k-$50k |
Official Fix |
|
CVE-2021-0641 |
?.? |
Google Android SubscriptionController.java getAvailableSubscriptionInfoList information disclosure |
$??k-$25k |
Official Fix |
|
CVE-2021-0642 |
?.? |
Google Android VoicemailSettingsFragment.java onResume information disclosure |
$??k-$25k |
Official Fix |
|
CVE-2021-0582 |
?.? |
Google Android WiFi Driver out-of-bounds read |
$?-$?k |
Official Fix |
|
CVE-2021-0581 |
?.? |
Google Android WiFi Driver out-of-bounds read |
$?-$?k |
Official Fix |
|
CVE-2021-0580 |
?.? |
Google Android WiFi Driver out-of-bounds read |
$?-$?k |
Official Fix |
|
CVE-2021-0579 |
?.? |
Google Android WiFi Driver out-of-bounds read |
$?-$?k |
Official Fix |
|
CVE-2021-0578 |
?.? |
Google Android WiFi Driver out-of-bounds read |
$?k-$5k |
Official Fix |
|
CVE-2021-30604 |
?.? |
Google Chrome ANGLE use after free |
$??k-$100k |
Official Fix |
|
CVE-2021-30601 |
?.? |
Google Chrome Extensions API use after free |
$??k-$100k |
Official Fix |
|
CVE-2021-30600 |
?.? |
Google Chrome Printing use after free |
$??k-$100k |
Official Fix |
|
CVE-2021-30599 |
?.? |
Google Chrome V8 type confusion |
$??k-$100k |
Official Fix |
|
CVE-2021-30598 |
?.? |
Google Chrome V8 type confusion |
$??k-$100k |
Official Fix |
|
CVE-2021-30603 |
?.? |
Google Chrome WebAudio race condition |
$??k-$50k |
Official Fix |
|
CVE-2021-30602 |
?.? |
Google Chrome WebRTC use after free |
$??k-$100k |
Official Fix |
|
CVE-2021-21843 |
?.? |
GPAC Advanced Content MPEG-4 Decoding GF_SubsegmentRangeInfo integer overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-21862 |
?.? |
GPAC Advanced Content MPEG-4 Decoding integer overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-21858 |
?.? |
GPAC Advanced Content MPEG-4 Decoding integer overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-21857 |
?.? |
GPAC Advanced Content MPEG-4 Decoding integer overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-21856 |
?.? |
GPAC Advanced Content MPEG-4 Decoding integer overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-21855 |
?.? |
GPAC Advanced Content MPEG-4 Decoding integer overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-21854 |
?.? |
GPAC Advanced Content MPEG-4 Decoding integer overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-21853 |
?.? |
GPAC Advanced Content MPEG-4 Decoding integer overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-21852 |
?.? |
GPAC Advanced Content MPEG-4 Decoding integer overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-21851 |
?.? |
GPAC Advanced Content MPEG-4 Decoding integer overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-21847 |
?.? |
GPAC Advanced Content MPEG-4 Decoding integer overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-21846 |
?.? |
GPAC Advanced Content MPEG-4 Decoding integer overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-21845 |
?.? |
GPAC Advanced Content MPEG-4 Decoding integer overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-21844 |
?.? |
GPAC Advanced Content MPEG-4 Decoding integer overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-21839 |
?.? |
GPAC Advanced Content MPEG-4 Decoding integer overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-21838 |
?.? |
GPAC Advanced Content MPEG-4 Decoding integer overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-21837 |
?.? |
GPAC Advanced Content MPEG-4 Decoding integer overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-21861 |
?.? |
GPAC Advanced Content MPEG-4 heap-based overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-21860 |
?.? |
GPAC Advanced Content MPEG-4 heap-based overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-21859 |
?.? |
GPAC Advanced Content stri_box_read Remote Code Execution |
$?k-$5k |
Not Defined |
|
CVE-2021-39242 |
?.? |
HAProxy HTTP Host Header access control |
$?k-$5k |
Official Fix |
|
CVE-2021-39241 |
?.? |
HAProxy HTTP Method admin access control |
$?k-$5k |
Official Fix |
|
CVE-2021-39240 |
?.? |
HAProxy URL injection |
$?k-$5k |
Official Fix |
|
CVE-2021-38553 |
?.? |
Hashicorp Vault/Vault Enterprise default permission |
$?k-$2k |
Official Fix |
|
CVE-2021-38554 |
?.? |
Hashicorp Vault/Vault Enterprise UI information disclosure |
$?-$?k |
Official Fix |
|
CVE-2021-27741 |
?.? |
HCL Commerce Management Center xml external entity reference |
$?k-$2k |
Not Defined |
|
CVE-2021-38757 |
?.? |
Hospital Management System contact.php cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2021-38755 |
?.? |
Hospital Management System Doctor Entry admin-panel1.php denial of service |
$?-$?k |
Not Defined |
|
CVE-2021-38754 |
?.? |
Hospital Management System messearch.php sql injection |
$?k-$2k |
Not Defined |
|
CVE-2021-38756 |
?.? |
Hospital Management System prescribe.php cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2021-34656 |
?.? |
HTML5 Webcam Videochat Plugin requirements.php vws_notice cross site scripting |
$?-$?k |
Official Fix |
|
CVE-2021-37028 |
?.? |
Huawei HG8045Q Command-Line Interface command injection |
$??k-$25k |
Not Defined |
|
CVE-2020-4706 |
?.? |
IBM API Connect HTTP Host Header injection |
$??k-$25k |
Official Fix |
|
CVE-2020-4992 |
?.? |
IBM DataPower Gateway cross-site request forgery |
$?k-$10k |
Official Fix |
|
CVE-2021-29880 |
?.? |
IBM QRadar SIEM information disclosure |
$?k-$10k |
Official Fix |
|
CVE-2021-0114 |
?.? |
Intel BSSA DFT initialization |
$?k-$10k |
Official Fix |
|
CVE-2021-31228 |
?.? |
InterNiche NicheStack DNS Response entropy |
$?-$?k |
Not Defined |
|
CVE-2021-31227 |
?.? |
InterNiche NicheStack HTTP POST Request wbs_multidata heap-based overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-31226 |
?.? |
InterNiche NicheStack HTTP POST Request wbs_post heap-based overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-27565 |
?.? |
InterNiche NicheStack HTTP Request wbs_loop infinite loop |
$?-$?k |
Not Defined |
|
CVE-2020-35683 |
?.? |
InterNiche NicheStack ICMP Checksum denial of service |
$?-$?k |
Not Defined |
|
CVE-2020-35684 |
?.? |
InterNiche NicheStack IP Header out-of-bounds read |
$?k-$2k |
Not Defined |
|
CVE-2020-25767 |
?.? |
InterNiche NicheStack IPv4 DNS Domain Name Parser dnc_copy_in out-of-bounds read |
$?-$?k |
Not Defined |
|
CVE-2020-35685 |
?.? |
InterNiche NicheStack ISN Gene random values |
$?-$?k |
Not Defined |
|
CVE-2021-31401 |
?.? |
InterNiche NicheStack TCP Header nptcp.c tcp_rcv integer overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-31400 |
?.? |
InterNiche NicheStack TCP Segment tcp_in.c tcp_pulloutofband infinite loop |
$?-$?k |
Not Defined |
|
CVE-2020-25926 |
?.? |
InterNiche NicheStack TCPIP DNS dns_query_type entropy |
$?k-$2k |
Not Defined |
|
CVE-2020-25928 |
?.? |
InterNiche NicheStack TCPIP DNS Response dnc_set_answer buffer overflow |
$?k-$5k |
Not Defined |
|
CVE-2020-25927 |
?.? |
InterNiche NicheStack TCPIP DNS Response dns_upcall out-of-bounds read |
$?k-$2k |
Not Defined |
|
CVE-2021-36762 |
?.? |
InterNiche NicheStack TFTP Packet tfshnd:tftpsrv.c out-of-bounds read |
$?k-$2k |
Not Defined |
|
CVE-2021-39249 |
?.? |
Invision Power Services Community Suite Filename mt_rand cross site scripting |
$?-$?k |
Official Fix |
|
CVE-2021-39250 |
?.? |
Invision Power Services Community Suite IFRAME cross site scripting |
$?-$?k |
Official Fix |
|
CVE-2021-34663 |
?.? |
jQuery Tagline Rotator Plugin jquery-tagline-rotator.php cross site scripting |
$?-$?k |
Official Fix |
|
CVE-2021-0284 |
?.? |
Juniper Junos OS TCP/IP Stack buffer overflow |
$??k-$25k |
Official Fix |
|
CVE-2021-3633 |
?.? |
Lenovo Driver Management signature verification |
$?k-$5k |
Official Fix |
|
CVE-2021-3616 |
?.? |
Lenovo Smart Camera X3/Smart Camera X5/Smart Camera C2E improper authorization |
$?k-$5k |
Official Fix |
|
CVE-2021-3617 |
?.? |
Lenovo Smart Camera X3/Smart Camera X5/Smart Camera C2E Network Configuration os command injection |
$?k-$5k |
Official Fix |
|
CVE-2021-3615 |
?.? |
Lenovo Smart Camera X3/Smart Camera X5/Smart Camera C2E SD Card code injection |
$?-$?k |
Official Fix |
|
CVE-2020-18900 |
?.? |
libyal libexe libexe_io_handle_read_coff_optional_header heap-based overflow |
$?-$?k |
Official Fix |
|
CVE-2020-18897 |
?.? |
libyal Libpff pff File libpff_item_tree_create_node use after free |
$?-$?k |
Official Fix |
|
CVE-2021-24535 |
?.? |
Light Messages Plugin Message Content cross-site request forgery |
$?-$?k |
Not Defined |
|
CVE-2020-18701 |
?.? |
Lin-CMS-Flask Authentication Token session fixiation |
$?k-$2k |
Not Defined |
|
CVE-2020-18699 |
?.? |
Lin-CMS-Flask user.py cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2020-18698 |
?.? |
Lin-CMS-Flask user.py login excessive authentication |
$?k-$2k |
Not Defined |
|
CVE-2021-21781 |
?.? |
Linux Kernel ARM SIGPAGE information disclosure |
$?k-$10k |
Official Fix |
|
CVE-2021-39282 |
?.? |
Live555 AC3 File memory leak |
$?-$?k |
Not Defined |
|
CVE-2021-39283 |
?.? |
Live555 Command FramedSource.cpp assertion |
$?k-$5k |
Not Defined |
|
CVE-2021-28000 |
?.? |
Local Services Search Engine Management System Project cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2021-27999 |
?.? |
Local Services Search Engine Management System Project sql injection |
$?k-$2k |
Not Defined |
|
CVE-2021-34652 |
?.? |
Media Usage Plugin Parameter mmu_admin.php cross site scripting |
$?-$?k |
Official Fix |
|
CVE-2021-0626 |
?.? |
MediaTek MT6768/MT6771/MT6779/MT6785 ged out-of-bounds write |
$?k-$2k |
Official Fix |
|
CVE-2021-0627 |
?.? |
MediaTek MT6885 OMA DRM integer overflow |
$?k-$2k |
Official Fix |
|
CVE-2021-0628 |
?.? |
MediaTek MT6885 OMA DRM memory corruption |
$?k-$2k |
Official Fix |
|
CVE-2021-0408 |
?.? |
MediaTek MT6893 ASF Extractor out-of-bounds read |
$?-$?k |
Official Fix |
|
CVE-2021-0420 |
?.? |
MediaTek MT6893 Memory Management Driver denial of service |
$?-$?k |
Official Fix |
|
CVE-2021-0419 |
?.? |
MediaTek MT6893 Memory Management Driver denial of service |
$?-$?k |
Official Fix |
|
CVE-2021-0418 |
?.? |
MediaTek MT6893 Memory Management Driver denial of service |
$?-$?k |
Official Fix |
|
CVE-2021-0417 |
?.? |
MediaTek MT6893 Memory Management Driver denial of service |
$?-$?k |
Official Fix |
|
CVE-2021-0416 |
?.? |
MediaTek MT6893 Memory Management Driver denial of service |
$?-$?k |
Official Fix |
|
CVE-2021-0415 |
?.? |
MediaTek MT6893 Memory Management Driver information disclosure |
$?-$?k |
Official Fix |
|
CVE-2021-0407 |
?.? |
MediaTek MT6893 out-of-bounds write |
$?k-$2k |
Official Fix |
|
CVE-2021-36786 |
?.? |
miniorange_saml Extension API Credential information disclosure |
$?-$?k |
Official Fix |
|
CVE-2021-36785 |
?.? |
miniorange_saml Extension cross site scripting |
$?-$?k |
Official Fix |
|
CVE-2021-39302 |
?.? |
MISP Log.php sql injection |
$?k-$2k |
Official Fix |
|
CVE-2021-37586 |
?.? |
Mitel Interaction Recording Multitenancy System PowerPlay Web information disclosure |
$?-$?k |
Official Fix |
|
CVE-2021-32069 |
?.? |
Mitel MiCollab AWV channel accessible |
$?k-$2k |
Official Fix |
|
CVE-2021-32068 |
?.? |
Mitel MiCollab AWV/Client Service channel accessible |
$?k-$2k |
Official Fix |
|
CVE-2021-32070 |
?.? |
Mitel MiCollab Client Service clickjacking |
$?k-$2k |
Official Fix |
|
CVE-2021-32067 |
?.? |
Mitel MiCollab Client Service information disclosure |
$?-$?k |
Official Fix |
|
CVE-2021-32072 |
?.? |
Mitel MiCollab Client Service information disclosure |
$?k-$2k |
Official Fix |
|
CVE-2021-32071 |
?.? |
Mitel MiCollab Client Service Remote Code Execution |
$?k-$5k |
Official Fix |
|
CVE-2021-27402 |
?.? |
Mitel MiCollab SAS Admin Portal pathname traversal |
$?k-$2k |
Official Fix |
|
CVE-2021-27401 |
?.? |
Mitel MiCollab Web Client Join Meeting Page cross site scripting |
$?-$?k |
Official Fix |
|
CVE-2021-3352 |
?.? |
Mitel MiContact Center Business Software Development Kit improper authorization |
$?k-$5k |
Not Defined |
|
CVE-2021-24526 |
?.? |
Mobile-Friendly Drag & Drop Contact Form Builder Plugin Form Title cross site scripting |
$?-$?k |
Official Fix |
|
CVE-2021-24363 |
?.? |
Mobile-Friendly Image Gallery Plugin path traversal |
$?k-$2k |
Official Fix |
|
CVE-2021-24362 |
?.? |
Mobile-Friendly Image Gallery Plugin SVG File cross site scripting |
$?-$?k |
Official Fix |
|
CVE-2021-3458 |
?.? |
Motorola MM1000 Device Configuration Portal improper authentication |
$?-$?k |
Not Defined |
|
CVE-2021-3459 |
?.? |
Motorola MM1000 Device Configuration Web Server os command injection |
$?-$?k |
Not Defined |
|
CVE-2021-29983 |
?.? |
Mozilla Firefox Fullscreen Mode denial of service |
$??k-$25k |
Official Fix |
|
CVE-2021-29990 |
?.? |
Mozilla Firefox memory corruption |
$??k-$50k |
Official Fix |
|
CVE-2021-29980 |
?.? |
Mozilla Firefox/Firefox ESR/Thunderbird Canvas Object free uninitialized resource |
$??k-$25k |
Official Fix |
|
CVE-2021-29984 |
?.? |
Mozilla Firefox/Firefox ESR/Thunderbird Garbage Collection memory corruption |
$??k-$50k |
Official Fix |
|
CVE-2021-29986 |
?.? |
Mozilla Firefox/Firefox ESR/Thunderbird getaddrinfo memory corruption |
$??k-$50k |
Official Fix |
|
CVE-2021-29988 |
?.? |
Mozilla Firefox/Firefox ESR/Thunderbird List-Item Element out-of-bounds read |
$??k-$25k |
Official Fix |
|
CVE-2021-29989 |
?.? |
Mozilla Firefox/Firefox ESR/Thunderbird memory corruption |
$??k-$50k |
Official Fix |
|
CVE-2021-29985 |
?.? |
Mozilla Firefox/Firefox ESR/Thunderbird use after free |
$??k-$50k |
Official Fix |
|
CVE-2021-29981 |
?.? |
Mozilla Firefox/Thunderbird JIT Code denial of service |
$??k-$25k |
Official Fix |
|
CVE-2021-29982 |
?.? |
Mozilla Firefox/Thunderbird JIT Optimizer information disclosure |
$??k-$25k |
Official Fix |
|
CVE-2021-29987 |
?.? |
Mozilla Firefox/Thunderbird Permissions improper restriction of rendered ui layers |
$??k-$25k |
Official Fix |
|
CVE-2021-32728 |
?.? |
Nextcloud Desktop Client Key certificate validation |
$?k-$2k |
Official Fix |
|
CVE-2021-37617 |
?.? |
Nextcloud Desktop Client Uninstallation Uninstall.exe untrusted search path |
$?k-$5k |
Official Fix |
|
CVE-2021-22931 |
?.? |
Node.js Domain Name Server null termination |
$?k-$5k |
Official Fix |
|
CVE-2021-22939 |
?.? |
Node.js https API certificate validation |
$?k-$2k |
Not Defined |
|
CVE-2021-22940 |
?.? |
Node.js use after free |
$?k-$5k |
Official Fix |
|
CVE-2021-34398 |
?.? |
NVIDIA DCGM DIAG Module uncontrolled search path |
$?k-$5k |
Official Fix |
|
CVE-2021-38708 |
?.? |
ocProducts Composr CMS Comcode cross site scripting |
$?-$?k |
Official Fix |
|
CVE-2021-38709 |
?.? |
ocProducts Composr CMS staff_messaging System cross site scripting |
$?-$?k |
Official Fix |
|
CVE-2021-31820 |
?.? |
Octopus Server/Server Web Request Proxy information disclosure |
$?-$?k |
Not Defined |
|
CVE-2021-38583 |
?.? |
openBaraza HCM subscription.jsp cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2021-38619 |
?.? |
openBaraza HCM subscription.jsp cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2021-28490 |
?.? |
OWASP CSRFGuard Cookie cross-site request forgery |
$?-$?k |
Not Defined |
|
CVE-2020-18886 |
?.? |
PHPMyWind upload_file_do.php unrestricted upload |
$?-$?k |
Not Defined |
|
CVE-2020-18885 |
?.? |
PHPMyWind web_config.php command injection |
$?-$?k |
Not Defined |
|
CVE-2021-39270 |
?.? |
Ping Identity RSA SecurID Integration Kit Privilege Escalation |
$?k-$5k |
Official Fix |
|
CVE-2021-22938 |
?.? |
Pulse Secure Pulse Connect Secure Administrator Web Console command injection |
$?k-$2k |
Official Fix |
|
CVE-2021-22937 |
?.? |
Pulse Secure Pulse Connect Secure Administrator Web Interface unrestricted upload |
$?k-$2k |
Official Fix |
|
CVE-2021-22935 |
?.? |
Pulse Secure Pulse Connect Secure Web Parameter command injection |
$?k-$2k |
Official Fix |
|
CVE-2021-22936 |
?.? |
Pulse Secure Pulse Connect Secure Web Parameter cross site scripting |
$?-$?k |
Official Fix |
|
CVE-2021-22934 |
?.? |
Pulse Secure Pulse Connect Secure Web Request buffer overflow |
$?k-$2k |
Official Fix |
|
CVE-2021-22933 |
?.? |
Pulse Secure Pulse Connect Secure Web Request path traversal |
$?-$?k |
Official Fix |
|
CVE-2020-18702 |
?.? |
Quokka actions.py cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2020-18703 |
?.? |
Quokka atom.py xml external entity reference |
$?k-$2k |
Not Defined |
|
CVE-2020-18705 |
?.? |
Quokka views.py xml external entity reference |
$?k-$2k |
Not Defined |
|
CVE-2021-31868 |
?.? |
Rapid7 Nexpose Security Console missing authentication |
$?k-$2k |
Official Fix |
|
CVE-2020-25351 |
?.? |
rConfig configcompare.crud.php information disclosure |
$?-$?k |
Official Fix |
|
CVE-2020-25353 |
?.? |
rConfig Connection server-side request forgery |
$?-$?k |
Official Fix |
|
CVE-2020-25352 |
?.? |
rConfig devices.php cross site scripting |
$?-$?k |
Official Fix |
|
CVE-2020-27466 |
?.? |
rConfig File ajaxEditTemplate.php Remote Code Execution |
$?-$?k |
Not Defined |
|
CVE-2020-25359 |
?.? |
rConfig Parameter ajaxDeleteAllLoggingFiles.php unknown vulnerability |
$?-$?k |
Official Fix |
|
CVE-2020-27464 |
?.? |
rConfig ZIP File updater.php Remote Code Execution |
$?-$?k |
Official Fix |
|
CVE-2021-35395 |
?.? |
Realtek Jungle SDK HTTP Web Server stack-based overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-35394 |
?.? |
Realtek Jungle SDK MP Daemon UDPServer memory corruption |
$?k-$5k |
Not Defined |
|
CVE-2021-35392 |
?.? |
Realtek Jungle SDK WiFi Simple Config Server heap-based overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-35393 |
?.? |
Realtek Jungle SDK WiFi Simple Config Server stack-based overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-32829 |
?.? |
REST API code injection |
$?k-$5k |
Official Fix |
|
CVE-2020-13589 |
?.? |
Rukovoditel Project Management App Fields Page copy_selected sql injection |
$?k-$2k |
Not Defined |
|
CVE-2020-13588 |
?.? |
Rukovoditel Project Management App Fields Page heading_field_id cross-site request forgery |
$?-$?k |
Not Defined |
|
CVE-2020-28846 |
?.? |
SeaCMS admin_manager.php cross-site request forgery |
$?-$?k |
Not Defined |
|
CVE-2021-29313 |
?.? |
SeaCMS admin_video.php cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2021-37358 |
?.? |
SeaCMS sql injection |
$?k-$2k |
Not Defined |
|
CVE-2020-27461 |
?.? |
SEOPanel Import Website unrestricted upload |
$?-$?k |
Official Fix |
|
CVE-2021-34641 |
?.? |
SEOPress Plugin TitleDescriptionMeta.php processPut cross site scripting |
$?-$?k |
Official Fix |
|
CVE-2021-24380 |
?.? |
Shantz WordPress QOTD Plugin cross-site request forgery |
$?-$?k |
Not Defined |
|
CVE-2021-37707 |
?.? |
Shopware API input validation |
$?k-$5k |
Official Fix |
|
CVE-2021-37709 |
?.? |
Shopware Import/Export resource injection |
$?k-$5k |
Official Fix |
|
CVE-2021-37708 |
?.? |
Shopware Mail Agent String command injection |
$?k-$5k |
Official Fix |
|
CVE-2021-37711 |
?.? |
Shopware server-side request forgery |
$?k-$2k |
Official Fix |
|
CVE-2021-37710 |
?.? |
Shopware SVG Media File cross site scripting |
$?-$?k |
Official Fix |
|
CVE-2021-31338 |
?.? |
Siemens SINEMA Remote Connect Client Configuration access control |
$??k-$25k |
Official Fix |
|
CVE-2021-34649 |
?.? |
Simple Behance Portfolio Plugin Parameter iframe-font-preview.php cross site scripting |
$?-$?k |
Official Fix |
|
CVE-2021-38753 |
?.? |
Simple Image Gallery Web App unrestricted upload |
$?k-$2k |
Not Defined |
|
CVE-2021-34658 |
?.? |
Simple Popup Newsletter Plugin simple-popup-newsletter.php cross site scripting |
$?-$?k |
Official Fix |
|
CVE-2021-38752 |
?.? |
Sourcecodester Online Catering Reservation System Search Bar cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2021-27822 |
?.? |
SourceCodester Vehicle Parking Management System Add Categories cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2021-39268 |
?.? |
SuiteCRM Web Interface cross site scripting |
$?-$?k |
Official Fix |
|
CVE-2021-39267 |
?.? |
SuiteCRM Web Interface cross site scripting |
$?-$?k |
Official Fix |
|
CVE-2021-28002 |
?.? |
Textpattern CMS Articles Page cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2021-28001 |
?.? |
Textpattern CMS Parameter welcome-to-your-site#comments-head cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2021-34207 |
?.? |
TOTOLINK A3002R ddns.htm cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2021-34228 |
?.? |
TOTOLINK A3002R parent_control.htm cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2021-34215 |
?.? |
TOTOLINK A3002R tcpipwan.htm cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2021-34220 |
?.? |
TOTOLINK A3002R tr069config.htm cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2021-34223 |
?.? |
TOTOLINK A3002R urlfilter.htm cross site scripting |
$?-$?k |
Not Defined |
|
CVE-2021-34218 |
?.? |
TOTOLINK A702R Login Portal file information disclosure |
$?-$?k |
Not Defined |
|
CVE-2021-29280 |
?.? |
TP-Link WR840N ARP buffer overflow |
$?k-$5k |
Not Defined |
|
CVE-2021-24541 |
?.? |
Wonder PDF Embed Plugin Shortcode escape output |
$?k-$2k |
Official Fix |
|
CVE-2021-24540 |
?.? |
Wonder Video Embed Plugin Shortcode cross site scripting |
$?-$?k |
Official Fix |
|
CVE-2021-37597 |
?.? |
WP Cerber MFA improper authentication |
$?-$?k |
Official Fix |
|
CVE-2021-37598 |
?.? |
WP Cerber wp-json access control |
$?-$?k |
Official Fix |
|
CVE-2021-34653 |
?.? |
WP Fountain Plugin Scripting wp-fountain.php cross site scripting |
$?-$?k |
Official Fix |
|
CVE-2021-34665 |
?.? |
WP SEO Tags Plugin Parameter wp-seo-tags.php cross site scripting |
$?-$?k |
Official Fix |
|
CVE-2021-24518 |
?.? |
WPFront Notification Bar Plugin Custom CSS Setting cross site scripting |
$?-$?k |
Official Fix |
|
CVE-2021-39274 |
?.? |
XeroSecurity Sn1per Configuration File permission |
$?k-$5k |
Not Defined |
|
CVE-2021-39273 |
?.? |
XeroSecurity Sn1per default permission |
$?k-$5k |
Not Defined |
??????? :
???? ??????
???? :
???? ??? ??????? ????? ??????





