CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2021-37032

    Last Modified: 21 Nov 2024

    There is a Bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause Digital Balance to fail to work.

    Published: 23 Nov 2021
    7.5
    High

    CVE-2021-37031

    Last Modified: 21 Nov 2024

    There is a Remote DoS vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the app to exit unexpectedly.

    Published: 23 Nov 2021
    7.5
    High

    CVE-2021-37030

    Last Modified: 21 Nov 2024

    There is an Improper permission vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.

    Published: 23 Nov 2021
    5.3
    Medium

    CVE-2021-37029

    Last Modified: 21 Nov 2024

    There is an Identity verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.

    Published: 23 Nov 2021
    5.9
    Medium

    CVE-2021-22356

    Last Modified: 21 Nov 2024

    There is a weak secure algorithm vulnerability in Huawei products. A weak secure algorithm is used in a module. Attackers can exploit this vulnerability by capturing and analyzing the messages between devices to obtain information. This can lead to information leak.Affected product versions include: IPS Module V500R005C00SPC100, V500R005C00SPC200; NGFW Module V500R005C00SPC100, V500R005C00SPC200; Secospace USG6300 V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200; Secospace USG6500 V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200; Secospace USG6600 V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200; USG9500 V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200.

    Published: 23 Nov 2021
    8.8
    High

    CVE-2021-37102

    Last Modified: 21 Nov 2024

    There is a command injection vulnerability in CMA service module of FusionCompute product when processing the default certificate file. The software constructs part of a command using external special input from users, but the software does not sufficiently validate the user input. Successful exploit could allow the attacker to inject certain commands to the system. Affected product versions include: FusionCompute 6.0.0, 6.3.0, 6.3.1, 6.5.0, 6.5.1, 8.0.0.

    Published: 23 Nov 2021
    5.5
    Medium

    CVE-2021-37036

    Last Modified: 21 Nov 2024

    There is an information leakage vulnerability in FusionCompute 6.5.1, eCNS280_TD V100R005C00 and V100R005C10. Due to the improperly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may cause the information leak.

    Published: 23 Nov 2021
    5.4
    Medium

    CVE-2021-22410

    Last Modified: 21 Nov 2024

    There is a XSS injection vulnerability in iMaster NCE-Fabric V100R019C10. A module of the client does not verify the input sufficiently. Attackers can exploit this vulnerability by modifying input after logging onto the client. This may compromise the normal service of the client.

    Published: 23 Nov 2021
    7.8
    High

    CVE-2021-39976

    Last Modified: 21 Nov 2024

    There is a privilege escalation vulnerability in CloudEngine 5800 V200R020C00SPC600. Due to lack of privilege restrictions, an authenticated local attacker can perform specific operation to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege.

    Published: 23 Nov 2021
    7.5
    High

    CVE-2021-20601

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in GOT2000 series GT27 model all versions, GOT2000 series GT25 model all versions, GOT2000 series GT23 model all versions, GOT2000 series GT21 model all versions, GOT SIMPLE series GS21 model all versions, and GT SoftGOT2000 all versions allows an remote unauthenticated attacker to write a value that exceeds the configured input range limit by sending a malicious packet to rewrite the device value. As a result, the system operation may be affected, such as malfunction.

    Published: 23 Nov 2021
    7.8
    High

    CVE-2021-4019

    Last Modified: 29 May 2026

    vim is vulnerable to Heap-based Buffer Overflow

    Published: 23 Nov 2021
    7.8
    High

    CVE-2020-16156

    Last Modified: 3 Nov 2025

    CPAN 2.28 allows Signature Verification Bypass.

    Published: 23 Nov 2021
    5.5
    Medium

    CVE-2021-44269

    Last Modified: 21 Nov 2024

    An out of bounds read was found in Wavpack 5.4.0 in processing *.WAV files. This issue triggered in function WavpackPackSamples of file src/pack_utils.c, tainted variable cnt is too large, that makes pointer sptr read beyond heap bound.

    Published: 23 Nov 2021
    7.8
    High

    CVE-2020-16154

    Last Modified: 21 Nov 2024

    The App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass.

    Published: 23 Nov 2021
    6.5
    Medium

    CVE-2020-28163

    Last Modified: 6 Feb 2025

    libdwarf before 20201201 allows a dwarf_print_lines.c NULL pointer dereference and application crash via a DWARF5 line-table header that has an invalid FORM for a pathname.

    Published: 23 Nov 2021
    6.3
    Medium

    CVE-2021-40831

    Last Modified: 21 Nov 2024

    The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the root CAs instead of overriding it on macOS systems. Additionally, SNI validation is also not enabled when the CA has been “overridden”. TLS handshakes will thus succeed if the peer can be verified either from the user-supplied CA or the system’s default trust-store. Attackers with access to a host’s trust stores or are able to compromise a certificate authority already in the host's trust store (note: the attacker must also be able to spoof DNS in this case) may be able to use this issue to bypass CA pinning. An attacker could then spoof the MQTT broker, and either drop traffic and/or respond with the attacker's data, but they would not be able to forward this data on to the MQTT broker because the attacker would still need the user's private keys to authenticate against the MQTT broker. The 'aws_tls_ctx_options_override_default_trust_store_*' function within the aws-c-io submodule has been updated to address this behavior. This issue affects: Amazon Web Services AWS IoT Device SDK v2 for Java versions prior to 1.5.0 on macOS. Amazon Web Services AWS IoT Device SDK v2 for Python versions prior to 1.7.0 on macOS. Amazon Web Services AWS IoT Device SDK v2 for C++ versions prior to 1.14.0 on macOS. Amazon Web Services AWS IoT Device SDK v2 for Node.js versions prior to 1.6.0 on macOS. Amazon Web Services AWS-C-IO 0.10.7 on macOS.

    Published: 22 Nov 2021
    6.3
    Medium

    CVE-2021-40830

    Last Modified: 21 Nov 2024

    The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the root CAs instead of overriding it on Unix systems. TLS handshakes will thus succeed if the peer can be verified either from the user-supplied CA or the system’s default trust-store. Attackers with access to a host’s trust stores or are able to compromise a certificate authority already in the host's trust store (note: the attacker must also be able to spoof DNS in this case) may be able to use this issue to bypass CA pinning. An attacker could then spoof the MQTT broker, and either drop traffic and/or respond with the attacker's data, but they would not be able to forward this data on to the MQTT broker because the attacker would still need the user's private keys to authenticate against the MQTT broker. The 'aws_tls_ctx_options_override_default_trust_store_*' function within the aws-c-io submodule has been updated to override the default trust store. This corrects this issue. This issue affects: Amazon Web Services AWS IoT Device SDK v2 for Java versions prior to 1.5.0 on Linux/Unix. Amazon Web Services AWS IoT Device SDK v2 for Python versions prior to 1.6.1 on Linux/Unix. Amazon Web Services AWS IoT Device SDK v2 for C++ versions prior to 1.12.7 on Linux/Unix. Amazon Web Services AWS IoT Device SDK v2 for Node.js versions prior to 1.5.3 on Linux/Unix. Amazon Web Services AWS-C-IO 0.10.4 on Linux/Unix.

    Published: 22 Nov 2021
    6.3
    Medium

    CVE-2021-40829

    Last Modified: 21 Nov 2024

    Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.4.2), Python (versions prior to 1.6.1), C++ (versions prior to 1.12.7) and Node.js (versions prior to 1.5.3) did not verify server certificate hostname during TLS handshake when overriding Certificate Authorities (CA) in their trust stores on MacOS. This issue has been addressed in aws-c-io submodule versions 0.10.5 onward. This issue affects: Amazon Web Services AWS IoT Device SDK v2 for Java versions prior to 1.4.2 on macOS. Amazon Web Services AWS IoT Device SDK v2 for Python versions prior to 1.6.1 on macOS. Amazon Web Services AWS IoT Device SDK v2 for C++ versions prior to 1.12.7 on macOS. Amazon Web Services AWS IoT Device SDK v2 for Node.js versions prior to 1.5.3 on macOS. Amazon Web Services AWS-C-IO 0.10.4 on macOS.

    Published: 22 Nov 2021
    6.3
    Medium

    CVE-2021-40828

    Last Modified: 21 Nov 2024

    Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.3.3), Python (versions prior to 1.5.18), C++ (versions prior to 1.12.7) and Node.js (versions prior to 1.5.1) did not verify server certificate hostname during TLS handshake when overriding Certificate Authorities (CA) in their trust stores on Windows. This issue has been addressed in aws-c-io submodule versions 0.9.13 onward. This issue affects: Amazon Web Services AWS IoT Device SDK v2 for Java versions prior to 1.3.3 on Microsoft Windows. Amazon Web Services AWS IoT Device SDK v2 for Python versions prior to 1.5.18 on Microsoft Windows. Amazon Web Services AWS IoT Device SDK v2 for C++ versions prior to 1.12.7 on Microsoft Windows. Amazon Web Services AWS IoT Device SDK v2 for Node.js versions prior to 1.5.3 on Microsoft Windows.

    Published: 22 Nov 2021
    5.4
    Medium

    CVE-2020-22719

    Last Modified: 21 Nov 2024

    Shimo Document v2.0.1 contains a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the table content text field.

    Published: 22 Nov 2021
    7.5
    High

    CVE-2021-44150

    Last Modified: 21 Nov 2024

    The client in tusdotnet through 2.5.0 relies on SHA-1 to prevent spoofing of file content.

    Published: 22 Nov 2021
    5.5
    Medium

    CVE-2021-44147

    Last Modified: 21 Nov 2024

    An XML External Entity issue in Claris FileMaker Pro and Server (including WebDirect) before 19.4.1 allows a remote attacker to disclose local files via a crafted XML/Excel document and perform server-side request forgery attacks.

    Published: 22 Nov 2021
    3.7
    Low

    CVE-2021-32004

    Last Modified: 21 Nov 2024

    This issue affects: Secomea GateManager All versions prior to 9.6. Improper Check of host header in web server of Secomea GateManager allows attacker to cause browser cache poisoning.

    Published: 22 Nov 2021
    9.1
    Critical

    CVE-2021-44144

    Last Modified: 21 Nov 2024

    Croatia Control Asterix 2.8.1 has a heap-based buffer over-read, with additional details to be disclosed at a later date.

    Published: 22 Nov 2021
    9.8
    Critical

    CVE-2021-44143

    Last Modified: 21 Nov 2024

    A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted mail message that lacks headers (i.e., one that starts with an empty line) to provoke a heap overflow, which could conceivably be exploited for remote code execution.

    Published: 22 Nov 2021
    7.8
    High

    CVE-2021-42705

    Last Modified: 21 Nov 2024

    PLC Editor Versions 1.3.8 and prior is vulnerable to a stack-based buffer overflow while processing project files, which may allow an attacker to execute arbitrary code.

    Published: 22 Nov 2021
    7.8
    High

    CVE-2021-42707

    Last Modified: 21 Nov 2024

    PLC Editor Versions 1.3.8 and prior is vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code.

    Published: 22 Nov 2021
    7.5
    High

    CVE-2021-38448

    Last Modified: 21 Nov 2024

    The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software.

    Published: 22 Nov 2021
    5.4
    Medium

    CVE-2021-23673

    Last Modified: 21 Nov 2024

    This affects all versions of package pekeupload. If an attacker induces a user to upload a file whose name contains javascript code, the javascript code will be executed.

    Published: 22 Nov 2021
    9
    Critical

    CVE-2021-23732

    Last Modified: 21 Nov 2024

    This affects all versions of package docker-cli-js. If the command parameter of the Docker.command method can at least be partially controlled by a user, they will be in a position to execute any arbitrary OS commands on the host system.

    Published: 22 Nov 2021
    6.5
    Medium

    CVE-2021-23718

    Last Modified: 21 Nov 2024

    The package ssrf-agent before 1.0.5 are vulnerable to Server-side Request Forgery (SSRF) via the defaultIpChecker function. It fails to properly validate if the IP requested is private.

    Published: 22 Nov 2021
    3.3
    Low

    CVE-2019-5640

    Last Modified: 21 Nov 2024

    Rapid7 Nexpose versions prior to 6.6.114 suffer from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the inspect element browser feature to remove the login panel and view the details available in the last webpage visited by previous user

    Published: 22 Nov 2021
    5.3
    Medium

    CVE-2021-43560

    Last Modified: 21 Nov 2024

    A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.

    Published: 22 Nov 2021
    8.8
    High

    CVE-2021-43559

    Last Modified: 21 Nov 2024

    A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.

    Published: 22 Nov 2021
    6.1
    Medium

    CVE-2021-43558

    Last Modified: 21 Nov 2024

    A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A URL parameter in the filetype site administrator tool required extra sanitizing to prevent a reflected XSS risk.

    Published: 22 Nov 2021
    9.8
    Critical

    CVE-2021-3943

    Last Modified: 21 Nov 2024

    A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A remote code execution risk when restoring backup files was identified.

    Published: 22 Nov 2021
    8.1
    High

    CVE-2021-3935

    Last Modified: 3 Nov 2025

    When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encryption. This flaw affects PgBouncer versions prior to 1.16.1.

    Published: 22 Nov 2021
    7.8
    High

    CVE-2021-42727

    Last Modified: 21 Nov 2024

    Adobe Bridge 11.1.1 (and earlier) is affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file in Bridge.

    Published: 22 Nov 2021
    5.5
    Medium

    CVE-2021-43016

    Last Modified: 23 Apr 2025

    Adobe InCopy version 16.4 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 22 Nov 2021
    7.8
    High

    CVE-2021-43015

    Last Modified: 23 Apr 2025

    Adobe InCopy version 16.4 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious GIF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must open a specially crafted file to exploit this vulnerability.

    Published: 22 Nov 2021
    7.8
    High

    CVE-2021-42738

    Last Modified: 23 Apr 2025

    Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious MXF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must open a specially crafted file to exploit this vulnerability.

    Published: 22 Nov 2021
    7.8
    High

    CVE-2021-42737

    Last Modified: 23 Apr 2025

    Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must open a specially crafted file to exploit this vulnerability.

    Published: 22 Nov 2021
    5.5
    Medium

    CVE-2021-42733

    Last Modified: 23 Apr 2025

    Adobe Bridge version 11.1.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 22 Nov 2021
    7.8
    High

    CVE-2021-40775

    Last Modified: 23 Apr 2025

    Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious SVG file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must open a specially crafted file to exploit this vulnerability.

    Published: 22 Nov 2021
    5.5
    Medium

    CVE-2021-40774

    Last Modified: 23 Apr 2025

    Adobe Prelude version 10.1 (and earlier) is affected by a null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 22 Nov 2021
    5.5
    Medium

    CVE-2021-40773

    Last Modified: 23 Apr 2025

    Adobe Prelude version 10.1 (and earlier) is affected by a null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 22 Nov 2021
    7.8
    High

    CVE-2021-40772

    Last Modified: 23 Apr 2025

    Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must open a specially crafted file to exploit this vulnerability.

    Published: 22 Nov 2021
    7.8
    High

    CVE-2021-40771

    Last Modified: 21 Nov 2024

    Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must open a specially crafted file to exploit this vulnerability.

    Published: 22 Nov 2021
    7.8
    High

    CVE-2021-40770

    Last Modified: 23 Apr 2025

    Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must open a specially crafted file to exploit this vulnerability.

    Published: 22 Nov 2021
    7.5
    High

    CVE-2020-7882

    Last Modified: 21 Nov 2024

    Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')

    Published: 22 Nov 2021