CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2020-23331

    Last Modified: 21 Nov 2024

    An issue was discovered in Bento4 version 06c39d9. A NULL pointer dereference exists in the AP4_DescriptorListWriter::Action component located in /Core/Ap4Descriptor.h. It allows an attacker to cause a denial of service (DOS).

    Published: 17 Aug 2021
    7.5
    High

    CVE-2020-23332

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow exists in the AP4_StdcFileByteStream::ReadPartial component located in /StdC/Ap4StdCFileByteStream.cpp of Bento4 version 06c39d9. This issue can lead to a denial of service (DOS).

    Published: 17 Aug 2021
    7.5
    High

    CVE-2020-23330

    Last Modified: 21 Nov 2024

    An issue was discovered in Bento4 version 06c39d9. A NULL pointer dereference exists in the AP4_Stz2Atom::GetSampleSize component located in /Core/Ap4Stz2Atom.cpp. It allows an attacker to cause a denial of service (DOS).

    Published: 17 Aug 2021
    6.1
    Medium

    CVE-2021-39248

    Last Modified: 21 Nov 2024

    Open edX through Lilac.1 allows XSS in common/static/common/js/discussion/utils.js via crafted LaTeX content within a discussion.

    Published: 17 Aug 2021
    6.5
    Medium

    CVE-2021-39247

    Last Modified: 21 Nov 2024

    Zint Barcode Generator before 2.10.0 has a one-byte buffer over-read, related to is_last_single_ascii in code1.c, and rs_encode_uint in reedsol.c.

    Published: 17 Aug 2021
    7.5
    High

    CVE-2021-39131

    Last Modified: 21 Nov 2024

    ced detects character encoding using Google’s compact_enc_det library. In ced v0.1.0, passing data types other than `Buffer` causes the Node.js process to crash. The problem has been patched in ced v1.0.0. As a workaround, before passing an argument to ced, verify it’s a `Buffer` using `Buffer.isBuffer(obj)`.

    Published: 17 Aug 2021
    6.1
    Medium

    CVE-2021-38702

    Last Modified: 21 Nov 2024

    Cyberoam NetGenie C0101B1-20141120-NG11VO devices through 2021-08-14 allow tweb/ft.php?u=[XSS] attacks.

    Published: 17 Aug 2021
    9.8
    Critical

    CVE-2021-21810

    Last Modified: 21 Nov 2024

    A memory corruption vulnerability exists in the XML-parsing ParseAttribs functionality of AT&T Labs’ Xmill 0.7. A specially crafted XML file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 17 Aug 2021
    9.8
    Critical

    CVE-2020-18164

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability exists in tp-shop 2.x-3.x via the /index.php/home/api/shop fBill parameter.

    Published: 17 Aug 2021
    7.8
    High

    CVE-2020-28594

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability exists in the _3MF_Importer::_handle_end_model() functionality of Prusa Research PrusaSlicer 2.2.0 and Master (commit 4b040b856). A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 17 Aug 2021
    8.8
    High

    CVE-2020-13589

    Last Modified: 21 Nov 2024

    An exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management App 2.7.2. The entities_id parameter in the 'entities/fields page (mulitple_edit or copy_selected or export function) is vulnerable to authenticated SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability, this can be done either with administrator credentials or through cross-site request forgery.

    Published: 17 Aug 2021
    8.8
    High

    CVE-2020-13588

    Last Modified: 21 Nov 2024

    An exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management App 2.7.2. The heading_field_id parameter in ‘‘entities/fields’ page is vulnerable to authenticated SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability, this can be done either with administrator credentials or through cross-site request forgery.

    Published: 17 Aug 2021
    8.8
    High

    CVE-2021-29981

    Last Modified: 21 Nov 2024

    An issue present in lowering/register allocation could have led to obscure but deterministic register confusion failures in JITted code that would lead to a potentially exploitable crash. This vulnerability affects Firefox < 91 and Thunderbird < 91.

    Published: 17 Aug 2021
    6.5
    Medium

    CVE-2021-29982

    Last Modified: 21 Nov 2024

    Due to incorrect JIT optimization, we incorrectly interpreted data from the wrong type of object, resulting in the potential leak of a single bit of memory. This vulnerability affects Firefox < 91 and Thunderbird < 91.

    Published: 17 Aug 2021
    6.5
    Medium

    CVE-2021-29983

    Last Modified: 21 Nov 2024

    Firefox for Android could get stuck in fullscreen mode and not exit it even after normal interactions that should cause it to exit. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 91.

    Published: 17 Aug 2021
    6.5
    Medium

    CVE-2021-29987

    Last Modified: 21 Nov 2024

    After requesting multiple permissions, and closing the first permission panel, subsequent permission panels will be displayed in a different position but still record a click in the default location, making it possible to trick a user into accepting a permission they did not want to. *This bug only affects Firefox on Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 91 and Thunderbird < 91.

    Published: 17 Aug 2021
    8.8
    High

    CVE-2021-29990

    Last Modified: 21 Nov 2024

    Mozilla developers and community members reported memory safety bugs present in Firefox 90. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 91.

    Published: 17 Aug 2021
    9.8
    Critical

    CVE-2021-21832

    Last Modified: 21 Nov 2024

    A memory corruption vulnerability exists in the ISO Parsing functionality of Disc Soft Ltd Deamon Tools Pro 8.3.0.0767. A specially crafted malformed file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 17 Aug 2021
    9.8
    Critical

    CVE-2020-22937

    Last Modified: 21 Nov 2024

    A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to the install file.

    Published: 17 Aug 2021
    9
    Critical

    CVE-2021-22156

    Last Modified: 22 Aug 2025

    An integer overflow vulnerability in the calloc() function of the C runtime library of affected versions of BlackBerry® QNX Software Development Platform (SDP) version(s) 6.5.0SP1 and earlier, QNX OS for Medical 1.1 and earlier, and QNX OS for Safety 1.0.1 and earlier that could allow an attacker to potentially perform a denial of service or execute arbitrary code.

    Published: 17 Aug 2021
    7.8
    High

    CVE-2021-25263

    Last Modified: 21 Nov 2024

    Local privilege vulnerability in Yandex Browser for Windows prior to 21.9.0.390 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating files in directory with insecure permissions during Yandex Browser update process.

    Published: 17 Aug 2021
    5.5
    Medium

    CVE-2021-0639

    Last Modified: 21 Nov 2024

    In multiple functions of libl3oemcrypto.cpp, there is a possible weakness in the existing obfuscation mechanism due to the way sensitive data is handled. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-190724551

    Published: 17 Aug 2021
    7.8
    High

    CVE-2021-0640

    Last Modified: 21 Nov 2024

    In noteAtomLogged of StatsdStats.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-9Android ID: A-187957589

    Published: 17 Aug 2021
    7.8
    High

    CVE-2021-0576

    Last Modified: 21 Nov 2024

    In flv extractor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-187236084

    Published: 17 Aug 2021
    7.8
    High

    CVE-2021-0574

    Last Modified: 21 Nov 2024

    In asf extractor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-187234876

    Published: 17 Aug 2021
    6.5
    Medium

    CVE-2021-0581

    Last Modified: 21 Nov 2024

    In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-187231638

    Published: 17 Aug 2021
    6.5
    Medium

    CVE-2021-0580

    Last Modified: 21 Nov 2024

    In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-187231637

    Published: 17 Aug 2021
    6.5
    Medium

    CVE-2021-0579

    Last Modified: 21 Nov 2024

    In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-187231636

    Published: 17 Aug 2021
    7.8
    High

    CVE-2021-0573

    Last Modified: 21 Nov 2024

    In asf extractor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-187231635

    Published: 17 Aug 2021
    6.5
    Medium

    CVE-2021-0578

    Last Modified: 21 Nov 2024

    In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-187161772

    Published: 17 Aug 2021
    6.5
    Medium

    CVE-2021-0582

    Last Modified: 21 Nov 2024

    In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-187149601

    Published: 17 Aug 2021
    5.5
    Medium

    CVE-2021-0641

    Last Modified: 25 Feb 2026

    In getAvailableSubscriptionInfoList of SubscriptionController.java, there is a possible disclosure of unique identifiers due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-185235454

    Published: 17 Aug 2021
    5.5
    Medium

    CVE-2021-0642

    Last Modified: 25 Feb 2026

    In onResume of VoicemailSettingsFragment.java, there is a possible way to retrieve a trackable identifier without permissions due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-185126149

    Published: 17 Aug 2021
    7.3
    High

    CVE-2021-0591

    Last Modified: 21 Nov 2024

    In sendReplyIntentToReceiver of BluetoothPermissionActivity.java, there is a possible way to invoke privileged broadcast receivers due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-179386960

    Published: 17 Aug 2021
    7.8
    High

    CVE-2021-0593

    Last Modified: 21 Nov 2024

    In sendDevicePickedIntent of DevicePickerFragment.java, there is a possible way to invoke a privileged broadcast receiver due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-179386068

    Published: 17 Aug 2021
    5.5
    Medium

    CVE-2021-0584

    Last Modified: 25 Feb 2026

    In verifyBufferObject of Parcel.cpp, there is a possible out of bounds read due to an improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-179289794

    Published: 17 Aug 2021
    7.8
    High

    CVE-2021-0519

    Last Modified: 21 Nov 2024

    In BITSTREAM_FLUSH of ih264e_bitstream.h, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-176533109

    Published: 17 Aug 2021
    7.8
    High

    CVE-2021-0645

    Last Modified: 21 Nov 2024

    In shouldBlockFromTree of ExternalStorageProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege, allowing an app to read private app directories in external storage, which should be restricted in Android 11, with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157320644

    Published: 17 Aug 2021
    7.8
    High

    CVE-2021-0646

    Last Modified: 21 Nov 2024

    In sqlite3_str_vappendf of sqlite3.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege if the user can also inject a printf into a privileged process's SQL with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-153352319

    Published: 17 Aug 2021
    6.1
    Medium

    CVE-2021-29313

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability exists in SeaCMS 12.6 via the (1) v_company and (2) v_tvs parameters in /admin_video.php,

    Published: 17 Aug 2021
    3.9
    Low

    CVE-2021-32830

    Last Modified: 21 Nov 2024

    The @diez/generation npm package is a client for Diez. The locateFont method of @diez/generation has a command injection vulnerability. Clients of the @diez/generation library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. All versions of this package are vulnerable as of the writing of this CVE.

    Published: 17 Aug 2021
    4.8
    Medium

    CVE-2021-29056

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability exists in Pixelimity 1.0 via the HTTP POST parameter to admin/setting.php.

    Published: 17 Aug 2021
    8.1
    High

    CVE-2020-29548

    Last Modified: 21 Nov 2024

    An issue was discovered in SmarterTools SmarterMail through 100.0.7537. Meddler-in-the-middle attackers can pipeline commands after a POP3 STLS command, injecting plaintext commands into an encrypted user session.

    Published: 17 Aug 2021
    5.9
    Medium

    CVE-2020-15955

    Last Modified: 21 Nov 2024

    In s/qmail through 4.0.07, an active MitM can inject arbitrary plaintext commands into a STARTTLS encrypted session between an SMTP client and s/qmail. This allows e-mail messages and user credentials to be sent to the MitM attacker.

    Published: 17 Aug 2021
    7.3
    High

    CVE-2021-3633

    Last Modified: 21 Nov 2024

    A DLL preloading vulnerability was reported in Lenovo Driver Management prior to version 2.9.0719.1104 that could allow privilege escalation.

    Published: 17 Aug 2021
    7.2
    High

    CVE-2021-3617

    Last Modified: 21 Nov 2024

    A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow command injection by setting a specially crafted network configuration. This vulnerability is the same as CNVD-2020-68652.

    Published: 17 Aug 2021
    9.4
    Critical

    CVE-2021-3616

    Last Modified: 21 Nov 2024

    A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device information, alter firmware content and device configuration. This vulnerability is the same as CNVD-2020-68651.

    Published: 17 Aug 2021
    6.6
    Medium

    CVE-2021-3615

    Last Modified: 21 Nov 2024

    A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow code execution if a specific file exists on the attached SD card. This vulnerability is the same as CNVD-2021-45262.

    Published: 17 Aug 2021
    6.8
    Medium

    CVE-2021-3459

    Last Modified: 21 Nov 2024

    A privilege escalation vulnerability was reported in the MM1000 device configuration web server, which could allow privileged shell access and/or arbitrary privileged commands to be executed on the adapter.

    Published: 17 Aug 2021
    6.1
    Medium

    CVE-2021-3458

    Last Modified: 21 Nov 2024

    The Motorola MM1000 device configuration portal can be accessed without authentication, which could allow adapter settings to be modified.

    Published: 17 Aug 2021