This is a list of recent vulnerabilities for which exploits are available.
CVE, Title, Vendor
Description
CVSS v3.1 Base Score
Date Created
Date Updated
CVE-2021-27112
Remote Code Execution in Light CMS
Light CMS Project
LightCMS v1.3.5 contains a remote code execution vulnerability in /app/Http/Controllers/Admin/NEditorController.php during the downloading of external images. This vulnerability can be exploited remotely and attackers can exploit this vulnerability to deliver malicious code to end users.
9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
04/15/2021
04/19/2021
CVE-2021-25360
Arbitrary Code Execution in Android Devices
Google Android
An improper input validation vulnerability in libswmfextractor library prior to SMR APR-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
04/09/2021
04/21/2021
CVE-2021-24223
Malicious File Upload Vulnerability in WP Library
Wordpress
The N5 Upload Form WordPress plugin through 1.0 suffers from an arbitrary file upload issue in page where a Form from the plugin is embed, as any file can be uploaded. The uploaded filename might be hard to guess as it's generated with md5(uniqid(rand())), however, in the case of misconfigured servers with Directory listing enabled, accessing it is trivial.
9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
04/12/2021
04/19/2021
CVE-2021-22507
Authentication Bypass Vulnerability in MicroFocus Device
Microfocus
Authentication bypass vulnerability in Micro Focus Operations Bridge Manager affects versions 2019.05, 2019.11, 2020.05 and 2020.10. The vulnerability could allow remote attackers to bypass user authentication and get unauthorized access.
9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
04/08/2021
04/14/2021
CVE-2021-20021
Privilege Escalation Vulnerability in SonicWall Email Security
PHPNuke
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
04/09/2021
04/14/2021
CVE-2021-1479
Remote Code Execution Vulnerability in Cisco vManage Software
Cisco
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system. For more information about these vulnerabilities, see the Details section of this advisory.
9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
04/08/2021
04/19/2021
CVE-2020-27236
SQL Injection Vulnerability in Openclinic
Openclinic
An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the compnomenclature parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability.