CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2019-25049

    Last Modified: 21 Nov 2024

    LibreSSL 2.9.1 through 3.2.1 has an out-of-bounds read in asn1_item_print_ctx (called from asn1_template_print_ctx).

    Published: 1 Jul 2021
    7.1
    High

    CVE-2019-25048

    Last Modified: 21 Nov 2024

    LibreSSL 2.9.1 through 3.2.1 has a heap-based buffer over-read in do_print_ex (called from asn1_item_print_ctx and ASN1_item_print).

    Published: 1 Jul 2021
    8.8
    High

    CVE-2020-36407

    Last Modified: 21 Nov 2024

    libavif 0.8.0 and 0.8.1 has an out-of-bounds write in avifDecoderDataFillImageGrid.

    Published: 1 Jul 2021
    8.8
    High

    CVE-2020-36406

    Last Modified: 21 Nov 2024

    uWebSockets 18.11.0 and 18.12.0 has a stack-based buffer overflow in uWS::TopicTree::trimTree (called from uWS::TopicTree::unsubscribeAll). NOTE: the vendor's position is that this is "a minor issue or not even an issue at all" because the developer of an application (that uses uWebSockets) should not be allowing the large number of triggered topics to accumulate

    Published: 1 Jul 2021
    7.8
    High

    CVE-2020-36405

    Last Modified: 21 Nov 2024

    Keystone Engine 0.9.2 has a use-after-free in llvm_ks::X86Operand::getToken.

    Published: 1 Jul 2021
    7.8
    High

    CVE-2020-36404

    Last Modified: 21 Nov 2024

    Keystone Engine 0.9.2 has an invalid free in llvm_ks::SmallVectorImpl<llvm_ks::MCFixup>::~SmallVectorImpl.

    Published: 1 Jul 2021
    8.8
    High

    CVE-2020-36403

    Last Modified: 21 Nov 2024

    HTSlib through 1.10.2 allows out-of-bounds write access in vcf_parse_format (called from vcf_parse and vcf_read).

    Published: 1 Jul 2021
    7.8
    High

    CVE-2020-36402

    Last Modified: 21 Nov 2024

    Solidity 0.7.5 has a stack-use-after-return issue in smtutil::CHCSmtLib2Interface::querySolver. NOTE: c39a5e2b7a3fabbf687f53a2823fc087be6c1a7e is cited in the OSV "fixed" field but does not have a code change.

    Published: 1 Jul 2021
    7.8
    High

    CVE-2020-36401

    Last Modified: 21 Nov 2024

    mruby 2.1.2 has a double free in mrb_default_allocf (called from mrb_free and obj_free).

    Published: 1 Jul 2021
    7.8
    High

    CVE-2021-36089

    Last Modified: 21 Nov 2024

    Grok 7.6.6 through 9.2.0 has a heap-based buffer overflow in grk::FileFormatDecompress::apply_palette_clr (called from grk::FileFormatDecompress::applyColour).

    Published: 1 Jul 2021
    9.8
    Critical

    CVE-2021-36088

    Last Modified: 21 Nov 2024

    Fluent Bit (aka fluent-bit) 1.7.0 through 1.7.4 has a double free in flb_free (called from flb_parser_json_do and flb_parser_do).

    Published: 1 Jul 2021
    5.5
    Medium

    CVE-2021-36083

    Last Modified: 21 Nov 2024

    KDE KImageFormats 5.70.0 through 5.81.0 has a stack-based buffer overflow in XCFImageFormat::loadTileRLE.

    Published: 1 Jul 2021
    8.8
    High

    CVE-2021-36082

    Last Modified: 21 Nov 2024

    ntop nDPI 3.4 has a stack-based buffer overflow in processClientServerHello.

    Published: 1 Jul 2021
    7.8
    High

    CVE-2021-36081

    Last Modified: 14 Sept 2026

    Tesseract OCR 5.0.0-alpha-20201231 has a one_ell_conflict use-after-free during a strpbrk call.

    Published: 1 Jul 2021
    8.8
    High

    CVE-2021-36080

    Last Modified: 21 Nov 2024

    GNU LibreDWG 0.12.3.4163 through 0.12.3.4191 has a double-free in bit_chain_free (called from dwg_encode_MTEXT and dwg_encode_add_object).

    Published: 1 Jul 2021
    9.8
    Critical

    CVE-2021-28804

    Last Modified: 21 Nov 2024

    A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.1.1540 build 20210107. QNAP Systems Inc. QuTS hero versions prior to h4.5.1.1582 build 20210217.

    Published: 1 Jul 2021
    5.4
    Medium

    CVE-2021-28803

    Last Modified: 21 Nov 2024

    This issue affects: QNAP Systems Inc. Q'center versions prior to 1.11.1004.

    Published: 1 Jul 2021
    9.8
    Critical

    CVE-2021-28802

    Last Modified: 21 Nov 2024

    A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.1.1540 build 20210107. QNAP Systems Inc. QuTS hero versions prior to h4.5.1.1582 build 20210217.

    Published: 1 Jul 2021
    6.1
    Medium

    CVE-2020-36196

    Last Modified: 21 Nov 2024

    A stored XSS vulnerability has been reported to affect QNAP NAS running QuLog Center. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Systems Inc. QuLog Center versions prior to 1.2.0.

    Published: 1 Jul 2021
    6.1
    Medium

    CVE-2020-36194

    Last Modified: 21 Nov 2024

    An XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.2.1566 Build 20210202. QNAP Systems Inc. QuTS hero versions prior to h4.5.2.1638 build 20210414. This issue does not affect: QNAP Systems Inc. QTS 4.5.3.

    Published: 1 Jul 2021
    7.5
    High

    CVE-2022-27381

    Last Modified: 21 Nov 2024

    An issue in the component Field::set_default of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

    Published: 1 Jul 2021
    9.8
    Critical

    CVE-2020-36400

    Last Modified: 21 Nov 2024

    ZeroMQ libzmq 4.3.3 has a heap-based buffer overflow in zmq::tcp_read, a different vulnerability than CVE-2021-20235.

    Published: 1 Jul 2021
    4.3
    Medium

    CVE-2021-21705

    Last Modified: 21 Nov 2024

    In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality via filter_var() function with FILTER_VALIDATE_URL parameter, an URL with invalid password field can be accepted as valid. This can lead to the code incorrectly parsing the URL and potentially leading to other security implications - like contacting a wrong server or making a wrong access decision.

    Published: 1 Jul 2021
    5.3
    Medium

    CVE-2021-22918

    Last Modified: 30 Apr 2025

    Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whether it is beyond pe, with the latter holding a pointer to the end of the buffer. This can lead to information disclosures or crashes. This function can be triggered via uv_getaddrinfo().

    Published: 1 Jul 2021
    5
    Medium

    CVE-2021-21704

    Last Modified: 21 Nov 2024

    In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server could cause crashes in various database functions, such as getAttribute(), execute(), fetch() and others by returning invalid response data that is not parsed correctly by the driver. This can result in crashes, denial of service or potentially memory corruption.

    Published: 1 Jul 2021
    9.8
    Critical

    CVE-2021-22345

    Last Modified: 21 Nov 2024

    There is an Input Verification Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause out-of-bounds memory write.

    Published: 30 Jun 2021
    5.3
    Medium

    CVE-2021-22346

    Last Modified: 21 Nov 2024

    There is an Improper Permission Management Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may lead to the disclosure of user habits.

    Published: 30 Jun 2021
    9.8
    Critical

    CVE-2021-22348

    Last Modified: 21 Nov 2024

    There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause code to execute.

    Published: 30 Jun 2021
    7.5
    High

    CVE-2021-22349

    Last Modified: 21 Nov 2024

    There is an Input Verification Vulnerability in Huawei Smartphone. Successful exploitation of insufficient input verification may cause the system to restart.

    Published: 30 Jun 2021
    7.8
    High

    CVE-2021-22352

    Last Modified: 21 Nov 2024

    There is a Configuration Defect Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may allow attackers to hijack the device and forge UIs to induce users to execute malicious commands.

    Published: 30 Jun 2021
    8.1
    High

    CVE-2021-22351

    Last Modified: 21 Nov 2024

    There is a Credentials Management Errors Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may induce users to grant permissions on modifying items in the configuration table,causing system exceptions.

    Published: 30 Jun 2021
    7.5
    High

    CVE-2021-22350

    Last Modified: 21 Nov 2024

    There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause the device to crash and restart.

    Published: 30 Jun 2021
    5.9
    Medium

    CVE-2021-34075

    Last Modified: 21 Nov 2024

    In Artica Pandora FMS <=754 in the File Manager component, there is sensitive information exposed on the client side which attackers can access.

    Published: 30 Jun 2021
    9.8
    Critical

    CVE-2021-22367

    Last Modified: 21 Nov 2024

    There is a Key Management Errors Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may lead to authentication bypass.

    Published: 30 Jun 2021
    7.5
    High

    CVE-2021-32736

    Last Modified: 21 Nov 2024

    think-helper defines a set of helper functions for ThinkJS. In versions of think-helper prior to 1.1.3, the software receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype. The vulnerability is patched in version 1.1.3.

    Published: 30 Jun 2021
    7.5
    High

    CVE-2021-22368

    Last Modified: 21 Nov 2024

    There is a Permission Control Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect normal use of the device.

    Published: 30 Jun 2021
    9.1
    Critical

    CVE-2021-22354

    Last Modified: 21 Nov 2024

    There is an Information Disclosure Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause out-of-bounds read.

    Published: 30 Jun 2021
    7.5
    High

    CVE-2021-22353

    Last Modified: 21 Nov 2024

    There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause the kernel to restart.

    Published: 30 Jun 2021
    4.3
    Medium

    CVE-2021-21676

    Last Modified: 21 Nov 2024

    Jenkins requests-plugin Plugin 2.2.7 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to send test emails to an attacker-specified email address.

    Published: 30 Jun 2021
    6.5
    Medium

    CVE-2021-21675

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins requests-plugin Plugin 2.2.12 and earlier allows attackers to create requests and/or have administrators apply pending requests.

    Published: 30 Jun 2021
    4.3
    Medium

    CVE-2021-21674

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins requests-plugin Plugin 2.2.6 and earlier allows attackers with Overall/Read permission to view the list of pending requests.

    Published: 30 Jun 2021
    6.1
    Medium

    CVE-2021-21673

    Last Modified: 21 Nov 2024

    Jenkins CAS Plugin 1.6.0 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.

    Published: 30 Jun 2021
    4.3
    Medium

    CVE-2021-21672

    Last Modified: 21 Nov 2024

    Jenkins Selenium HTML report Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

    Published: 30 Jun 2021
    7.5
    High

    CVE-2021-22371

    Last Modified: 21 Nov 2024

    There is an Improper Permission Management Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 30 Jun 2021
    9.8
    Critical

    CVE-2021-22323

    Last Modified: 21 Nov 2024

    There is an Integer Overflow Vulnerability in Huawei Smartphone. Successful exploitation of these vulnerabilities may escalate the permission to that of the root user.

    Published: 30 Jun 2021
    8.1
    High

    CVE-2021-22369

    Last Modified: 21 Nov 2024

    There is a Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability in Huawei Smartphone. Successful exploitation of these vulnerabilities may escalate the permission to that of the root user.

    Published: 30 Jun 2021
    7.5
    High

    CVE-2021-22374

    Last Modified: 21 Nov 2024

    There is an Improper Validation of Array Index Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause stability risks.

    Published: 30 Jun 2021
    9.8
    Critical

    CVE-2021-35973

    Last Modified: 21 Nov 2024

    NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, allowing an unauthenticated attacker to invoke any action by adding the &currentsetting.htm substring to the HTTP query, a related issue to CVE-2020-27866. This directly allows the attacker to change the web UI password, and eventually to enable debug mode (telnetd) and gain a shell on the device as the admin limited-user account (however, escalation to root is simple because of weak permissions on the /etc/ directory).

    Published: 30 Jun 2021
    9.8
    Critical

    CVE-2021-35971

    Last Modified: 21 Nov 2024

    Veeam Backup and Replication 10 before 10.0.1.4854 P20210609 and 11 before 11.0.0.837 P20210507 mishandles deserialization during Microsoft .NET remoting.

    Published: 30 Jun 2021
    7.5
    High

    CVE-2021-35970

    Last Modified: 21 Nov 2024

    Talk 4 in Coral before 4.12.1 allows remote attackers to discover e-mail addresses and other sensitive information via GraphQL because permission checks use an incorrect data type.

    Published: 30 Jun 2021