CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2020-22761

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) vulnerability in FlatPress 1.1 via the DeleteFile function in flat/admin.php.

    Published: 29 Jul 2021
    4.4
    Medium

    CVE-2021-20505

    Last Modified: 21 Nov 2024

    The PowerVM Logical Partition Mobility(LPM) (PowerVM Hypervisor FW920, FW930, FW940, and FW950) encryption key exchange protocol can be compromised. If an attacker has the ability to capture encrypted LPM network traffic and is able to gain service access to the FSP they can use this information to perform a series of PowerVM service procedures to decrypt the captured migration traffic IBM X-Force ID: 198232

    Published: 29 Jul 2021
    9.8
    Critical

    CVE-2021-30124

    Last Modified: 21 Nov 2024

    The unofficial vscode-phpmd (aka PHP Mess Detector) extension before 1.3.0 for Visual Studio Code allows remote attackers to execute arbitrary code via a crafted phpmd.command value in a workspace folder.

    Published: 29 Jul 2021
    9.8
    Critical

    CVE-2020-36239

    Last Modified: 21 Nov 2024

    Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17.0 and Jira Service Management Data Center from version 2.0.2 before 4.5.16, from version 4.6.0 before 4.13.8, and from version 4.14.0 before 4.17.0 exposed a Ehcache RMI network service which attackers, who can connect to the service, on port 40001 and potentially 40011[0][1], could execute arbitrary code of their choice in Jira through deserialization due to a missing authentication vulnerability. While Atlassian strongly suggests restricting access to the Ehcache ports to only Data Center instances, fixed versions of Jira will now require a shared secret in order to allow access to the Ehcache service. [0] In Jira Data Center, Jira Core Data Center, and Jira Software Data Center versions prior to 7.13.1, the Ehcache object port can be randomly allocated. [1] In Jira Service Management Data Center versions prior to 3.16.1, the Ehcache object port can be randomly allocated.

    Published: 29 Jul 2021
    9.8
    Critical

    CVE-2021-37578

    Last Modified: 21 Nov 2024

    Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provides an alternate transport for accessing UDDI services. RMI uses the default Java serialization mechanism to pass parameters in RMI invocations. A remote attacker can send a malicious serialized object to the above RMI entries. The objects get deserialized without any check on the incoming data. In the worst case, it may let the attacker run arbitrary code remotely. For both jUDDI web service applications and jUDDI clients, the usage of RMI is disabled by default. Since this is an optional feature and an extension to the UDDI protocol, the likelihood of impact is low. Starting with 3.3.10, all RMI related code was removed.

    Published: 29 Jul 2021
    9.8
    Critical

    CVE-2021-22930

    Last Modified: 30 Apr 2025

    Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.

    Published: 29 Jul 2021
    6.1
    Medium

    CVE-2021-3639

    Last Modified: 21 Nov 2024

    A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.

    Published: 29 Jul 2021
    6.1
    Medium

    CVE-2020-15948

    Last Modified: 21 Nov 2024

    eGain Chat 15.5.5 allows XSS via the Name (aka full_name) field.

    Published: 28 Jul 2021
    5.3
    Medium

    CVE-2021-37606

    Last Modified: 21 Nov 2024

    Meow hash 0.5/calico does not sufficiently thwart key recovery by an attacker who can query whether there's a collision in the bottom bits of the hashes of two messages, as demonstrated by an attack against a long-running web service that allows the attacker to infer collisions by measuring timing differences.

    Published: 28 Jul 2021
    6.1
    Medium

    CVE-2020-21854

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerabiity exists in WDScanner 1.1 in the system management page.

    Published: 28 Jul 2021
    7.5
    High

    CVE-2021-23415

    Last Modified: 21 Nov 2024

    This affects the package elFinder.AspNet before 1.1.1. The user-controlled file name is not properly sanitized before it is used to create a file system path.

    Published: 28 Jul 2021
    5.4
    Medium

    CVE-2021-23416

    Last Modified: 21 Nov 2024

    This affects all versions of package curly-bracket-parser. When used as a template library, it does not properly sanitize the user input.

    Published: 28 Jul 2021
    5.6
    Medium

    CVE-2021-23417

    Last Modified: 21 Nov 2024

    All versions of package deepmergefn are vulnerable to Prototype Pollution via deepMerge function.

    Published: 28 Jul 2021
    9.8
    Critical

    CVE-2021-25200

    Last Modified: 21 Nov 2024

    Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to \lms\student_avatar.php.

    Published: 28 Jul 2021
    9.8
    Critical

    CVE-2021-34166

    Last Modified: 21 Nov 2024

    A SQL INJECTION vulnerability in Sourcecodester Simple Food Website 1.0 allows a remote attacker to Bypass Authentication and become Admin.

    Published: 28 Jul 2021
    9.8
    Critical

    CVE-2021-34165

    Last Modified: 21 Nov 2024

    A SQL Injection vulnerability in Sourcecodester Basic Shopping Cart 1.0 allows a remote attacker to Bypass Authentication and become Admin.

    Published: 28 Jul 2021
    7.5
    High

    CVE-2021-37601

    Last Modified: 21 Nov 2024

    muc.lib.lua in Prosody 0.11.0 through 0.11.9 allows remote attackers to obtain sensitive information (list of admins, members, owners, and banned entities of a Multi-User chat room) in some common configurations.

    Published: 28 Jul 2021
    5.4
    Medium

    CVE-2020-5004

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192957.

    Published: 28 Jul 2021
    6.3
    Medium

    CVE-2020-4974

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 192434.

    Published: 28 Jul 2021
    7.5
    High

    CVE-2020-10590

    Last Modified: 21 Nov 2024

    Replicated Classic 2.x versions have an improperly secured API that exposes sensitive data from the Replicated Admin Console configuration. An attacker with network access to the Admin Console port (8800) on the Replicated Classic server could retrieve the TLS Keypair (Cert and Key) used to configure the Admin Console.

    Published: 28 Jul 2021
    3.2
    Low

    CVE-2021-32000

    Last Modified: 21 Nov 2024

    A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up in SUSE Linux Enterprise Server 12 SP3, SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allows local attackers to delete arbitrary files. This issue affects: SUSE Linux Enterprise Server 12 SP3 clone-master-clean-up version 1.6-4.6.1 and prior versions. SUSE Linux Enterprise Server 15 SP1 clone-master-clean-up version 1.6-3.9.1 and prior versions. openSUSE Factory clone-master-clean-up version 1.6-1.4 and prior versions.

    Published: 28 Jul 2021
    6.5
    Medium

    CVE-2021-32001

    Last Modified: 21 Nov 2024

    K3s in SUSE Rancher allows any user with direct access to the datastore, or a copy of a datastore backup, to extract the cluster's confidential keying material (cluster certificate authority private keys, secrets encryption configuration passphrase, etc.) and decrypt it, without having to know the token value. This issue affects: SUSE Rancher K3s version v1.19.12+k3s1, v1.20.8+k3s1, v1.21.2+k3s1 and prior versions; RKE2 version v1.19.12+rke2r1, v1.20.8+rke2r1, v1.21.2+rke2r1 and prior versions.

    Published: 28 Jul 2021
    6.5
    Medium

    CVE-2021-23414

    Last Modified: 21 Nov 2024

    This affects the package video.js before 7.14.3. The src attribute of track tag allows to bypass HTML escaping and execute arbitrary code.

    Published: 28 Jul 2021
    7.8
    High

    CVE-2021-36983

    Last Modified: 21 Nov 2024

    replay-sorcery-kms in Replay Sorcery 0.6.0 allows a local attacker to gain root privileges via a symlink attack on /tmp/replay-sorcery or /tmp/replay-sorcery/device.sock.

    Published: 28 Jul 2021
    6.1
    Medium

    CVE-2021-20789

    Last Modified: 21 Nov 2024

    Open redirect vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the version prior to ver5.1.0) allows a remote attacker to redirect a user to an arbitrary web site and conduct a phishing attack via a specially crafted URL.

    Published: 28 Jul 2021
    4.3
    Medium

    CVE-2021-20788

    Last Modified: 21 Nov 2024

    Server-side request forgery (SSRF) vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the version prior to ver5.1.0) allows a remote authenticated attacker to conduct a port scan from the product and/or obtain information from the internal Web server.

    Published: 28 Jul 2021
    4.8
    Medium

    CVE-2021-20787

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the version prior to ver5.1.0) allows a remote attacker to inject an arbitrary script by sending a specially crafted request to a specific URL.

    Published: 28 Jul 2021
    4.3
    Medium

    CVE-2021-20786

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the version prior to ver5.1.0) allows a remote attacker to hijack the authentication of administrators via a specially crafted URL.

    Published: 28 Jul 2021
    4.8
    Medium

    CVE-2021-20785

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the version prior to ver5.1.0) allows a remote attacker to inject an arbitrary script by sending a specially crafted request to a specific URL.

    Published: 28 Jul 2021
    8.8
    High

    CVE-2021-20783

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in Optical BB unit E-WMTA2.3 allows a remote attacker to hijack the authentication of administrators via a specially crafted page.

    Published: 28 Jul 2021
    7.5
    High

    CVE-2020-5351

    Last Modified: 21 Nov 2024

    Dell EMC Data Protection Advisor versions 6.4, 6.5 and 18.1 contain an undocumented account with limited privileges that is protected with a hard-coded password. A remote unauthenticated malicious user with the knowledge of the hard-coded password may login to the system and gain read-only privileges.

    Published: 28 Jul 2021
    9.8
    Critical

    CVE-2020-5341

    Last Modified: 21 Nov 2024

    Deserialization of Untrusted Data Vulnerability Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2, 19.1 and 19.2 and Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, 2.4 and 2.4.1 contain a Deserialization of Untrusted Data Vulnerability. A remote unauthenticated attacker could exploit this vulnerability to send a serialized payload that would execute code on the system.

    Published: 28 Jul 2021
    6.3
    Medium

    CVE-2020-26180

    Last Modified: 21 Nov 2024

    Dell EMC Isilon OneFS supported versions 8.1 and later and Dell EMC PowerScale OneFS supported version 9.0.0 contain an access issue with the remotesupport user account. A remote malicious user with low privileges may gain access to data stored on the /ifs directory through most protocols.

    Published: 28 Jul 2021
    7.5
    High

    CVE-2021-36386

    Last Modified: 21 Nov 2024

    report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.

    Published: 28 Jul 2021
    8.8
    High

    CVE-2021-30762

    Last Modified: 23 Oct 2025

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

    Published: 28 Jul 2021
    6.1
    Medium

    CVE-2021-1826

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing maliciously crafted web content may lead to universal cross site scripting.

    Published: 28 Jul 2021
    6.5
    Medium

    CVE-2021-1820

    Last Modified: 21 Nov 2024

    A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing maliciously crafted web content may result in the disclosure of process memory.

    Published: 28 Jul 2021
    8.8
    High

    CVE-2021-1817

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 28 Jul 2021
    8.8
    High

    CVE-2021-30758

    Last Modified: 21 Nov 2024

    A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 28 Jul 2021
    7.8
    High

    CVE-2021-0929

    Last Modified: 21 Nov 2024

    In ion_dma_buf_end_cpu_access and related functions of ion.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-187527909References: Upstream kernel

    Published: 28 Jul 2021
    6.1
    Medium

    CVE-2021-1825

    Last Modified: 21 Nov 2024

    An input validation issue was addressed with improved input validation. This issue is fixed in iTunes 12.11.3 for Windows, iCloud for Windows 12.3, macOS Big Sur 11.3, Safari 14.1, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may lead to a cross site scripting attack.

    Published: 28 Jul 2021
    8.8
    High

    CVE-2021-30795

    Last Modified: 21 Nov 2024

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 28 Jul 2021
    8.8
    High

    CVE-2021-30797

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing maliciously crafted web content may lead to code execution.

    Published: 28 Jul 2021
    6.1
    Medium

    CVE-2021-30689

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead to universal cross site scripting.

    Published: 28 Jul 2021
    8.8
    High

    CVE-2021-30734

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 28 Jul 2021
    6.1
    Medium

    CVE-2021-30744

    Last Modified: 21 Nov 2024

    Description: A cross-origin issue with iframe elements was addressed with improved tracking of security origins. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead to universal cross site scripting.

    Published: 28 Jul 2021
    8.8
    High

    CVE-2021-30799

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 28 Jul 2021
    5.5
    Medium

    CVE-2021-30682

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. A malicious application may be able to leak sensitive user information.

    Published: 28 Jul 2021
    5.4
    Medium

    CVE-2021-30720

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. A malicious website may be able to access restricted ports on arbitrary servers.

    Published: 28 Jul 2021
    8.8
    High

    CVE-2021-30749

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 28 Jul 2021