CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2020-18671

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4 via smtp config in /installer/test.php.

    Published: 24 Jun 2021
    7.8
    High

    CVE-2021-32491

    Last Modified: 21 Nov 2024

    A flaw was found in djvulibre-3.5.28 and earlier. An integer overflow in function render() in tools/ddjvu via crafted djvu file may lead to application crash and other consequences.

    Published: 24 Jun 2021
    5.4
    Medium

    CVE-2020-18670

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via database host and user in /installer/test.php.

    Published: 24 Jun 2021
    7.8
    High

    CVE-2021-3500

    Last Modified: 21 Nov 2024

    A flaw was found in djvulibre-3.5.28 and earlier. A Stack overflow in function DJVU::DjVuDocument::get_djvu_file() via crafted djvu file may lead to application crash and other consequences.

    Published: 24 Jun 2021
    7.8
    High

    CVE-2021-33002

    Last Modified: 21 Nov 2024

    Opening a maliciously crafted project file may cause an out-of-bounds write, which may allow an attacker to execute arbitrary code. User interaction is require on the WebAccess HMI Designer (versions 2.1.9.95 and prior).

    Published: 24 Jun 2021
    5.4
    Medium

    CVE-2020-18668

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerabililty in WebPort <=1.19.1 via the description parameter to script/listcalls.

    Published: 24 Jun 2021
    7.8
    High

    CVE-2021-33004

    Last Modified: 21 Nov 2024

    The affected product is vulnerable to memory corruption condition due to lack of proper validation of user supplied files, which may allow an attacker to execute arbitrary code. User interaction is required on the WebAccess HMI Designer (versions 2.1.9.95 and prior).

    Published: 24 Jun 2021
    7.8
    High

    CVE-2021-33000

    Last Modified: 21 Nov 2024

    Parsing a maliciously crafted project file may cause a heap-based buffer overflow, which may allow an attacker to perform arbitrary code execution. User interaction is required on the WebAccess HMI Designer (versions 2.1.9.95 and prior).

    Published: 24 Jun 2021
    7.2
    High

    CVE-2021-21574

    Last Modified: 21 Nov 2024

    Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions.

    Published: 24 Jun 2021
    7.2
    High

    CVE-2021-21573

    Last Modified: 21 Nov 2024

    Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions.

    Published: 24 Jun 2021
    7.2
    High

    CVE-2021-21572

    Last Modified: 21 Nov 2024

    Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions.

    Published: 24 Jun 2021
    5.9
    Medium

    CVE-2021-21571

    Last Modified: 21 Nov 2024

    Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability using a person-in-the-middle attack which may lead to a denial of service and payload tampering.

    Published: 24 Jun 2021
    9.8
    Critical

    CVE-2021-32708

    Last Modified: 21 Nov 2024

    Flysystem is an open source file storage library for PHP. The whitespace normalisation using in 1.x and 2.x removes any unicode whitespace. Under certain specific conditions this could potentially allow a malicious user to execute code remotely. The conditions are: A user is allowed to supply the path or filename of an uploaded file, the supplied path or filename is not checked against unicode chars, the supplied pathname checked against an extension deny-list, not an allow-list, the supplied path or filename contains a unicode whitespace char in the extension, the uploaded file is stored in a directory that allows PHP code to be executed. Given these conditions are met a user can upload and execute arbitrary code on the system under attack. The unicode whitespace removal has been replaced with a rejection (exception). For 1.x users, upgrade to 1.1.4. For 2.x users, upgrade to 2.1.1.

    Published: 24 Jun 2021
    8.5
    High

    CVE-2021-32704

    Last Modified: 21 Nov 2024

    DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection security vulnerability has been found in specific versions of DHIS2. This vulnerability affects the /api/trackedEntityInstances API endpoint in DHIS2 versions 2.34.4, 2.35.2, 2.35.3, 2.35.4, and 2.36.0. Earlier versions, such as 2.34.3 and 2.35.1 and all versions 2.33 and older are unaffected. The system is vulnerable to attack only from users that are logged in to DHIS2, and there is no known way of exploiting the vulnerability without first being logged in as a DHIS2 user. A successful exploit of this vulnerability could allow the malicious user to read, edit and delete data in the DHIS2 instance. There are no known exploits of the security vulnerabilities addressed by these patch releases. However, we strongly recommend that all DHIS2 implementations using versions 2.34, 2.35 and 2.36 install these patches as soon as possible. There is no straightforward known workaround for DHIS2 instances using the Tracker functionality other than upgrading the affected DHIS2 server to one of the patches in which this vulnerability has been fixed. For implementations which do NOT use Tracker functionality, it may be possible to block all network access to POST to the /api/trackedEntityInstance endpoint as a temporary workaround while waiting to upgrade.

    Published: 24 Jun 2021
    9.8
    Critical

    CVE-2020-18667

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in WebPort <=1.19.1 via the new connection, parameter name in type-conn.

    Published: 24 Jun 2021
    —
    Unknown

    CVE-2020-18666

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-18664. Reason: This candidate is a duplicate of CVE-2020-18664. Notes: All CVE users should reference CVE-2020-18664 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 24 Jun 2021
    5.3
    Medium

    CVE-2020-18665

    Last Modified: 21 Nov 2024

    Directory Traversal vulnerability in WebPort <=1.19.1 in tags of system settings.

    Published: 24 Jun 2021
    5.4
    Medium

    CVE-2020-18664

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in WebPort <=1.19.1via the connection name parameter in type-conn.

    Published: 24 Jun 2021
    9.8
    Critical

    CVE-2020-21784

    Last Modified: 21 Nov 2024

    phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php.

    Published: 24 Jun 2021
    8.8
    High

    CVE-2020-21785

    Last Modified: 21 Nov 2024

    In IBOS 4.5.4 Open, the database backup has Command Injection Vulnerability.

    Published: 24 Jun 2021
    9.8
    Critical

    CVE-2020-21786

    Last Modified: 21 Nov 2024

    In IBOS 4.5.4 Open, Arbitrary File Inclusion causes getshell via /system/modules/dashboard/controllers/CronController.php.

    Published: 24 Jun 2021
    6.1
    Medium

    CVE-2020-21783

    Last Modified: 21 Nov 2024

    In IBOS 4.5.4 the email function has a cross site scripting (XSS) vulnerability in emailbody[content] parameter.

    Published: 24 Jun 2021
    9.8
    Critical

    CVE-2021-31649

    Last Modified: 21 Nov 2024

    In applications using jfinal 4.9.08 and below, there is a deserialization vulnerability when using redis,may be vulnerable to remote code execute

    Published: 24 Jun 2021
    6.1
    Medium

    CVE-2020-18663

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the act parameter in bbs/move_update.php.

    Published: 24 Jun 2021
    9.8
    Critical

    CVE-2021-33346

    Last Modified: 21 Nov 2024

    There is an arbitrary password modification vulnerability in a D-LINK DSL-2888A router product. An attacker can use this vulnerability to modify the password of the admin user without authorization.

    Published: 24 Jun 2021
    9.8
    Critical

    CVE-2020-18662

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.

    Published: 24 Jun 2021
    6.1
    Medium

    CVE-2021-23398

    Last Modified: 21 Nov 2024

    All versions of package react-bootstrap-table are vulnerable to Cross-site Scripting (XSS) via the dataFormat parameter. The problem is triggered when an invalid React element is returned, leading to dangerouslySetInnerHTML being used, which does not sanitize the output.

    Published: 24 Jun 2021
    6.1
    Medium

    CVE-2020-18661

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the url parameter to bbs/login.php.

    Published: 24 Jun 2021
    9.8
    Critical

    CVE-2020-21787

    Last Modified: 21 Nov 2024

    CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php.

    Published: 24 Jun 2021
    4.3
    Medium

    CVE-2020-21788

    Last Modified: 21 Nov 2024

    In CRMEB 3.1.0+ strict domain name filtering leads to SSRF(Server-Side Request Forgery). The vulnerable code is in file /crmeb/app/admin/controller/store/CopyTaobao.php.

    Published: 24 Jun 2021
    6.1
    Medium

    CVE-2021-33348

    Last Modified: 21 Nov 2024

    An issue was discovered in JFinal framework v4.9.10 and below. The "set" method of the "Controller" class of jfinal framework is not strictly filtered, which will lead to XSS vulnerabilities in some cases.

    Published: 24 Jun 2021
    5.3
    Medium

    CVE-2021-27659

    Last Modified: 21 Nov 2024

    exacqVision Web Service 21.03 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that is served to other users.

    Published: 24 Jun 2021
    4.3
    Medium

    CVE-2021-27658

    Last Modified: 21 Nov 2024

    exacqVision Enterprise Manager 20.12 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that is served to other users.

    Published: 24 Jun 2021
    6.5
    Medium

    CVE-2021-23996

    Last Modified: 21 Nov 2024

    By utilizing 3D CSS in conjunction with Javascript, content could have been rendered outside the webpage's viewport, resulting in a spoofing attack that could have been used for phishing or other attacks on a user. This vulnerability affects Firefox < 88.

    Published: 24 Jun 2021
    8.8
    High

    CVE-2021-23997

    Last Modified: 21 Nov 2024

    Due to unexpected data type conversions, a use-after-free could have occurred when interacting with the font cache. We presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox < 88.

    Published: 24 Jun 2021
    3.1
    Low

    CVE-2021-24000

    Last Modified: 21 Nov 2024

    A race condition with requestPointerLock() and setTimeout() could have resulted in a user interacting with one tab when they believed they were on a separate tab. In conjunction with certain elements (such as &lt;input type="file"&gt;) this could have led to an attack where a user was confused about the origin of the webpage and potentially disclosed information they did not intend to. This vulnerability affects Firefox < 88.

    Published: 24 Jun 2021
    4.3
    Medium

    CVE-2021-24001

    Last Modified: 21 Nov 2024

    A compromised content process could have performed session history manipulations it should not have been able to due to testing infrastructure that was not restricted to testing-only configurations. This vulnerability affects Firefox < 88.

    Published: 24 Jun 2021
    6.1
    Medium

    CVE-2021-29944

    Last Modified: 21 Nov 2024

    Lack of escaping allowed HTML injection when a webpage was viewed in Reader View. While a Content Security Policy prevents direct code execution, HTML injection is still possible. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 88.

    Published: 24 Jun 2021
    8.8
    High

    CVE-2021-29947

    Last Modified: 21 Nov 2024

    Mozilla developers and community members reported memory safety bugs present in Firefox 87. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 88.

    Published: 24 Jun 2021
    9.8
    Critical

    CVE-2021-29954

    Last Modified: 21 Nov 2024

    Proxy functionality built into Hubs Cloud’s Reticulum software allowed access to internal URLs, including the metadata service. This vulnerability affects Hubs Cloud < mozillareality/reticulum/1.0.1/20210428201255.

    Published: 24 Jun 2021
    5.3
    Medium

    CVE-2021-29955

    Last Modified: 21 Nov 2024

    A transient execution vulnerability, named Floating Point Value Injection (FPVI) allowed an attacker to leak arbitrary memory addresses and may have also enabled JIT type confusion attacks. (A related vulnerability, Speculative Code Store Bypass (SCSB), did not affect Firefox.). This vulnerability affects Firefox ESR < 78.9 and Firefox < 87.

    Published: 24 Jun 2021
    4.3
    Medium

    CVE-2021-29958

    Last Modified: 21 Nov 2024

    When a download was initiated, the client did not check whether it was in normal or private browsing mode, which led to private mode cookies being shared in normal browsing mode. This vulnerability affects Firefox for iOS < 34.

    Published: 24 Jun 2021
    4.3
    Medium

    CVE-2021-29959

    Last Modified: 21 Nov 2024

    When a user has already allowed a website to access microphone and camera, disabling camera sharing would not fully prevent the website from re-enabling it without an additional prompt. This was only possible if the website kept recording with the microphone until re-enabling the camera. This vulnerability affects Firefox < 89.

    Published: 24 Jun 2021
    4.3
    Medium

    CVE-2021-29960

    Last Modified: 21 Nov 2024

    Firefox used to cache the last filename used for printing a file. When generating a filename for printing, Firefox usually suggests the web page title. The caching and suggestion techniques combined may have lead to the title of a website visited during private browsing mode being stored on disk. This vulnerability affects Firefox < 89.

    Published: 24 Jun 2021
    4.3
    Medium

    CVE-2021-29961

    Last Modified: 21 Nov 2024

    When styling and rendering an oversized `<select>` element, Firefox did not apply correct clipping which allowed an attacker to paint over the user interface. This vulnerability affects Firefox < 89.

    Published: 24 Jun 2021
    4.3
    Medium

    CVE-2021-29962

    Last Modified: 21 Nov 2024

    Firefox for Android would become unstable and hard-to-recover when a website opened too many popups. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.

    Published: 24 Jun 2021
    4.3
    Medium

    CVE-2021-29963

    Last Modified: 21 Nov 2024

    Address bar search suggestions in private browsing mode were re-using session data from normal mode. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.

    Published: 24 Jun 2021
    5.3
    Medium

    CVE-2021-29965

    Last Modified: 21 Nov 2024

    A malicious website that causes an HTTP Authentication dialog to be spawned could trick the built-in password manager to suggest passwords for the currently active website instead of the website that triggered the dialog. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.

    Published: 24 Jun 2021
    8.8
    High

    CVE-2021-29966

    Last Modified: 21 Nov 2024

    Mozilla developers reported memory safety bugs present in Firefox 88. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 89.

    Published: 24 Jun 2021
    8.1
    High

    CVE-2021-29968

    Last Modified: 21 Nov 2024

    When drawing text onto a canvas with WebRender disabled, an out of bounds read could occur. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.0.1.

    Published: 24 Jun 2021