CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2021-20498

    Last Modified: 21 Nov 2024

    IBM Security Verify Access Docker 10.0.0 reveals version information in HTTP requests that could be used in further attacks against the system. IBM X-Force ID: 197972.

    Published: 15 Jul 2021
    7.5
    High

    CVE-2021-20497

    Last Modified: 21 Nov 2024

    IBM Security Verify Access Docker 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 197969

    Published: 15 Jul 2021
    4.9
    Medium

    CVE-2021-20496

    Last Modified: 21 Nov 2024

    IBM Security Verify Access Docker 10.0.0 could allow an authenticated user to bypass input due to improper input validation. IBM X-Force ID: 197966.

    Published: 15 Jul 2021
    9.8
    Critical

    CVE-2020-11633

    Last Modified: 21 Nov 2024

    The Zscaler Client Connector for Windows prior to 2.1.2.74 had a stack based buffer overflow when connecting to misconfigured TLS servers. An adversary would potentially have been able to execute arbitrary code with system privileges.

    Published: 15 Jul 2021
    7.5
    High

    CVE-2021-3043

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability exists in the Prisma Cloud Compute web console that enables a remote attacker to execute arbitrary JavaScript code in the browser-based web console while an authenticated administrator is using that web interface. Prisma Cloud Compute SaaS versions were automatically upgraded to the fixed release. No additional action is required for these instances. This issue impacts: Prisma Cloud Compute 20.12 versions earlier than Prisma Cloud Compute 20.12.552; Prisma Cloud Compute 21.04 versions earlier than Prisma Cloud Compute 21.04.439.

    Published: 15 Jul 2021
    7.8
    High

    CVE-2021-3042

    Last Modified: 21 Nov 2024

    A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables an authenticated local Windows user to execute programs with SYSTEM privileges. Exploiting this vulnerability requires the user to have file creation privilege in the Windows root directory (such as C:\). This issue impacts: All versions of Cortex XDR agent 6.1 without content update 181 or a later version; All versions of Cortex XDR agent 7.2 without content update 181 or a later version; All versions of Cortex XDR agent 7.3 without content update 181 or a later version. Cortex XDR agent 5.0 versions are not impacted by this issue. Content updates are required to resolve this issue and are automatically applied for the agent.

    Published: 15 Jul 2021
    6.8
    Medium

    CVE-2021-32750

    Last Modified: 21 Nov 2024

    MuWire is a file publishing and networking tool that protects the identity of its users by using I2P technology. Users of MuWire desktop client prior to version 0.8.8 can be de-anonymized by an attacker who knows their full ID. An attacker could send a message with a subject line containing a URL with an HTML image tag and the MuWire client would try to fetch that image via clearnet, thus exposing the IP address of the user. The problem is fixed in MuWire 0.8.8. As a workaround, users can disable messaging functionality to prevent other users from sending them malicious messages.

    Published: 15 Jul 2021
    5.3
    Medium

    CVE-2021-21587

    Last Modified: 21 Nov 2024

    Dell Wyse Management Suite versions 3.2 and earlier contain a full path disclosure vulnerability. A local unauthenticated attacker could exploit this vulnerability in order to obtain the path of files and folders.

    Published: 15 Jul 2021
    8.1
    High

    CVE-2021-21586

    Last Modified: 21 Nov 2024

    Wyse Management Suite versions 3.2 and earlier contain an absolute path traversal vulnerability. A remote authenticated malicious user could exploit this vulnerability in order to read arbitrary files on the system.

    Published: 15 Jul 2021
    8.8
    High

    CVE-2021-32743

    Last Modified: 3 Nov 2025

    Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions prior to 2.11.10 and from version 2.12.0 through version 2.12.4, some of the Icinga 2 features that require credentials for external services expose those credentials through the API to authenticated API users with read permissions for the corresponding object types. IdoMysqlConnection and IdoPgsqlConnection (every released version) exposes the password of the user used to connect to the database. IcingaDB (added in 2.12.0) exposes the password used to connect to the Redis server. ElasticsearchWriter (added in 2.8.0)exposes the password used to connect to the Elasticsearch server. An attacker who obtains these credentials can impersonate Icinga to these services and add, modify and delete information there. If credentials with more permissions are in use, this increases the impact accordingly. Starting with the 2.11.10 and 2.12.5 releases, these passwords are no longer exposed via the API. As a workaround, API user permissions can be restricted to not allow querying of any affected objects, either by explicitly listing only the required object types for object query permissions, or by applying a filter rule.

    Published: 15 Jul 2021
    5.4
    Medium

    CVE-2021-29749

    Last Modified: 21 Nov 2024

    IBM Secure External Authentication Server 6.0.2 and IBM Secure Proxy 6.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 201777.

    Published: 15 Jul 2021
    7.5
    High

    CVE-2021-29725

    Last Modified: 21 Nov 2024

    IBM Secure External Authentication Server 2.4.3.2, 6.0.1, 6.0.2 and IBM Secure Proxy 3.4.3.2, 6.0.1, 6.0.2 could allow a remote user to consume resources causing a denial of service due to a resource leak.

    Published: 15 Jul 2021
    7.5
    High

    CVE-2021-20439

    Last Modified: 21 Nov 2024

    IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by an unauthorized user.

    Published: 15 Jul 2021
    5.5
    Medium

    CVE-2021-27845

    Last Modified: 21 Nov 2024

    A Divide-by-zero vulnerability exists in JasPer Image Coding Toolkit 2.0 in jasper/src/libjasper/jpc/jpc_enc.c

    Published: 15 Jul 2021
    6.5
    Medium

    CVE-2021-27847

    Last Modified: 21 Nov 2024

    Division-By-Zero vulnerability in Libvips 8.10.5 in the function vips_eye_point, eye.c#L83, and function vips_mask_point, mask.c#L85.

    Published: 15 Jul 2021
    6.5
    Medium

    CVE-2020-12732

    Last Modified: 21 Nov 2024

    DEPSTECH WiFi Digital Microscope 3 has a default SSID of Jetion_xxxxxxxx with a password of 12345678.

    Published: 15 Jul 2021
    7.5
    High

    CVE-2020-12733

    Last Modified: 21 Nov 2024

    Certain Shenzhen PENGLIXIN components on DEPSTECH WiFi Digital Microscope 3, as used by Shekar Endoscope, allow a TELNET connection with the molinkadmin password for the molink account.

    Published: 15 Jul 2021
    8.1
    High

    CVE-2020-12734

    Last Modified: 21 Nov 2024

    DEPSTECH WiFi Digital Microscope 3 allows remote attackers to change the SSID and password, and demand a ransom payment from the rightful device owner, because there is no way to reset to Factory Default settings.

    Published: 15 Jul 2021
    4.6
    Medium

    CVE-2020-12729

    Last Modified: 21 Nov 2024

    MagicMotion Flamingo 2 has a lack of access control for reading from device descriptors.

    Published: 15 Jul 2021
    5.3
    Medium

    CVE-2020-12730

    Last Modified: 21 Nov 2024

    MagicMotion Flamingo 2 lacks BLE encryption, enabling data sniffing and packet forgery.

    Published: 15 Jul 2021
    7.5
    High

    CVE-2020-12731

    Last Modified: 21 Nov 2024

    The MagicMotion Flamingo 2 application for Android stores data on an sdcard under com.vt.magicmotion/files/Pictures, whence it can be read by other applications.

    Published: 15 Jul 2021
    8.8
    High

    CVE-2021-32739

    Last Modified: 3 Nov 2025

    Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. From version 2.4.0 through version 2.12.4, a vulnerability exists that may allow privilege escalation for authenticated API users. With a read-ony user's credentials, an attacker can view most attributes of all config objects including `ticket_salt` of `ApiListener`. This salt is enough to compute a ticket for every possible common name (CN). A ticket, the master node's certificate, and a self-signed certificate are enough to successfully request the desired certificate from Icinga. That certificate may in turn be used to steal an endpoint or API user's identity. Versions 2.12.5 and 2.11.10 both contain a fix the vulnerability. As a workaround, one may either specify queryable types explicitly or filter out ApiListener objects.

    Published: 15 Jul 2021
    7.8
    High

    CVE-2020-15495

    Last Modified: 21 Nov 2024

    Acronis True Image 2019 update 1 through 2020 on macOS allows local privilege escalation due to an insecure XPC service configuration.

    Published: 15 Jul 2021
    6.7
    Medium

    CVE-2020-25593

    Last Modified: 21 Nov 2024

    Acronis True Image through 2021 on macOS allows local privilege escalation from admin to root due to insecure folder permissions.

    Published: 15 Jul 2021
    5.5
    Medium

    CVE-2021-3602

    Last Modified: 21 Nov 2024

    An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Dockerfile RUN commands) can access environment variables from parent and grandparent processes. When run in a container in a CI/CD environment, environment variables may include sensitive information that was shared with the container in order to be used only by Buildah itself (e.g. container registry credentials).

    Published: 15 Jul 2021
    7.8
    High

    CVE-2020-15496

    Last Modified: 21 Nov 2024

    Acronis True Image for Mac before 2021 Update 4 allowed local privilege escalation due to insecure folder permissions.

    Published: 15 Jul 2021
    7.8
    High

    CVE-2021-34692

    Last Modified: 21 Nov 2024

    iDrive RemotePC before 7.6.48 on Windows allows privilege escalation. A local and low-privileged user can force RemotePC to execute an attacker-controlled executable with SYSTEM privileges.

    Published: 15 Jul 2021
    7.5
    High

    CVE-2021-34691

    Last Modified: 21 Nov 2024

    iDrive RemotePC before 4.0.1 on Linux allows denial of service. A remote and unauthenticated attacker can disconnect a valid user session by connecting to an ephemeral port.

    Published: 15 Jul 2021
    9.8
    Critical

    CVE-2021-34690

    Last Modified: 21 Nov 2024

    iDrive RemotePC before 7.6.48 on Windows allows authentication bypass. A remote and unauthenticated attacker can bypass cloud authentication to connect and control a system via TCP port 5970 and 5980.

    Published: 15 Jul 2021
    5.5
    Medium

    CVE-2021-34689

    Last Modified: 21 Nov 2024

    iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A locally authenticated attacker can read the system's Personal Key in world-readable %PROGRAMDATA% log files.

    Published: 15 Jul 2021
    3.3
    Low

    CVE-2021-34688

    Last Modified: 21 Nov 2024

    iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A locally authenticated attacker can read an encrypted version of the system's Personal Key in world-readable %PROGRAMDATA% log files. The encryption is done using a hard-coded static key and is therefore reversible by an attacker.

    Published: 15 Jul 2021
    5.3
    Medium

    CVE-2021-34687

    Last Modified: 21 Nov 2024

    iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A man in the middle can recover a system's Personal Key when a client attempts to make a LAN connection. The Personal Key is transmitted over the network while only being encrypted via a substitution cipher.

    Published: 15 Jul 2021
    7.8
    High

    CVE-2021-33505

    Last Modified: 21 Nov 2024

    A local malicious user can circumvent the Falco detection engine through 0.28.1 by running a program that alters arguments of system calls being executed. Issue is fixed in Falco versions >= 0.29.1.

    Published: 15 Jul 2021
    5.5
    Medium

    CVE-2021-3759

    Last Modified: 21 Nov 2024

    A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial of service. The highest threat from this vulnerability is to system availability.

    Published: 15 Jul 2021
    8.8
    High

    CVE-2021-31999

    Last Modified: 21 Nov 2024

    A Reliance on Untrusted Inputs in a Security Decision vulnerability in Rancher allows users in the cluster to act as others users in the cluster by forging the "Impersonate-User" or "Impersonate-Group" headers. This issue affects: Rancher versions prior to 2.5.9. Rancher versions prior to 2.4.16.

    Published: 15 Jul 2021
    9.9
    Critical

    CVE-2021-25320

    Last Modified: 21 Nov 2024

    A Improper Access Control vulnerability in Rancher, allows users in the cluster to make request to cloud providers by creating requests with the cloud-credential ID. Rancher in this case would attach the requested credentials without further checks This issue affects: Rancher versions prior to 2.5.9; Rancher versions prior to 2.4.16.

    Published: 15 Jul 2021
    8.8
    High

    CVE-2021-25318

    Last Modified: 21 Nov 2024

    A Incorrect Permission Assignment for Critical Resource vulnerability in Rancher allows users in the cluster to modify resources they should not have access to. This issue affects: Rancher versions prior to 2.5.9 ; Rancher versions prior to 2.4.16.

    Published: 15 Jul 2021
    8.8
    High

    CVE-2019-14841

    Last Modified: 13 May 2025

    A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attacker to gain admin privileges in the Business Central Console.

    Published: 15 Jul 2021
    5.3
    Medium

    CVE-2021-34429

    Last Modified: 21 Nov 2024

    For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5.

    Published: 15 Jul 2021
    8.8
    High

    CVE-2022-1227

    Last Modified: 21 Nov 2024

    A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.

    Published: 15 Jul 2021
    7.8
    High

    CVE-2020-25736

    Last Modified: 21 Nov 2024

    Acronis True Image 2019 update 1 through 2021 update 1 on macOS allows local privilege escalation due to an insecure XPC service configuration.

    Published: 15 Jul 2021
    3.1
    Low

    CVE-2021-25740

    Last Modified: 1 Jun 2026

    A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.

    Published: 15 Jul 2021
    7.5
    High

    CVE-2020-36420

    Last Modified: 21 Nov 2024

    Polipo through 1.1.1, when NDEBUG is omitted, allows denial of service via a reachable assertion during parsing of a malformed Range header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 14 Jul 2021
    9.8
    Critical

    CVE-2020-24133

    Last Modified: 21 Nov 2024

    A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute arbitrary code or carry out denial of service (DOS) attacks.

    Published: 14 Jul 2021
    9
    Critical

    CVE-2021-35211

    Last Modified: 27 Oct 2025

    Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. SolarWinds Serv-U Managed File Transfer and Serv-U Secure FTP for Windows before 15.2.3 HF2 are affected by this vulnerability.

    Published: 14 Jul 2021
    6.5
    Medium

    CVE-2021-22867

    Last Modified: 21 Nov 2024

    A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to read files on the GitHub Enterprise Server instance. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.1.3 and was fixed in 3.1.3, 3.0.11, and 2.22.17. This vulnerability was reported via the GitHub Bug Bounty program.

    Published: 14 Jul 2021
    7.8
    High

    CVE-2020-29157

    Last Modified: 21 Nov 2024

    An issue in RAONWIZ K Editor v2018.0.0.10 allows attackers to perform a DLL hijacking attack when the service or system is restarted.

    Published: 14 Jul 2021
    9.8
    Critical

    CVE-2020-18155

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in Subrion CMS v4.2.1 in the search page if a website uses a PDO connection.

    Published: 14 Jul 2021
    4.6
    Medium

    CVE-2021-34174

    Last Modified: 21 Nov 2024

    A vulnerability exists in Broadcom BCM4352 and BCM43684 chips. Any wireless router using BCM4352 and BCM43684 will be affected, such as ASUS AX6100. An attacker may cause a Denial of Service (DoS) to any device connected to BCM4352 or BCM43684 routers via an association or reassociation frame.

    Published: 14 Jul 2021
    7.5
    High

    CVE-2021-34173

    Last Modified: 21 Nov 2024

    An attacker can cause a Denial of Service and kernel panic in v4.2 and earlier versions of Espressif esp32 via a malformed beacon csa frame. The device requires a reboot to recover.

    Published: 14 Jul 2021