CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-3044

    Last Modified: 21 Nov 2024

    An improper authorization vulnerability in Palo Alto Networks Cortex XSOAR enables a remote unauthenticated attacker with network access to the Cortex XSOAR server to perform unauthorized actions through the REST API. This issue impacts: Cortex XSOAR 6.1.0 builds later than 1016923 and earlier than 1271064; Cortex XSOAR 6.2.0 builds earlier than 1271065. This issue does not impact Cortex XSOAR 5.5.0, Cortex XSOAR 6.0.0, Cortex XSOAR 6.0.1, or Cortex XSOAR 6.0.2 versions. All Cortex XSOAR instances hosted by Palo Alto Networks are upgraded to resolve this vulnerability. No additional action is required for these instances.

    Published: 22 Jun 2021
    6.1
    Medium

    CVE-2020-18654

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in Wuzhi CMS v4.1.0 allows remote attackers to execute arbitrary code via the "Title" parameter in the component "/coreframe/app/guestbook/myissue.php".

    Published: 22 Jun 2021
    6.5
    Medium

    CVE-2020-15732

    Last Modified: 21 Nov 2024

    Improper Certificate Validation vulnerability in the Online Threat Prevention module as used in Bitdefender Total Security allows an attacker to potentially bypass HTTP Strict Transport Security (HSTS) checks. This issue affects: Bitdefender Total Security versions prior to 25.0.7.29. Bitdefender Internet Security versions prior to 25.0.7.29. Bitdefender Antivirus Plus versions prior to 25.0.7.29.

    Published: 22 Jun 2021
    8.8
    High

    CVE-2020-18648

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) in JuQingCMS v1.0 allows remote attackers to gain local privileges via the component "JuQingCMS_v1.0/admin/index.php?c=administrator&a=add".

    Published: 22 Jun 2021
    7.5
    High

    CVE-2020-18647

    Last Modified: 21 Nov 2024

    Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonecms/vendor".

    Published: 22 Jun 2021
    7.5
    High

    CVE-2020-18646

    Last Modified: 21 Nov 2024

    Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/public/index.php".

    Published: 22 Jun 2021
    7.5
    High

    CVE-2020-22176

    Last Modified: 21 Nov 2024

    PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerability in multiple areas. Remote unauthenticated users can exploit the vulnerability to obtain user sensitive information.

    Published: 22 Jun 2021
    7.5
    High

    CVE-2020-22170

    Last Modified: 21 Nov 2024

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

    Published: 22 Jun 2021
    7.5
    High

    CVE-2020-22164

    Last Modified: 21 Nov 2024

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\check_availability.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

    Published: 22 Jun 2021
    7.5
    High

    CVE-2020-22165

    Last Modified: 21 Nov 2024

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

    Published: 22 Jun 2021
    7.5
    High

    CVE-2020-22166

    Last Modified: 21 Nov 2024

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\forgot-password.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

    Published: 22 Jun 2021
    5.4
    Medium

    CVE-2020-22167

    Last Modified: 21 Nov 2024

    PHPGurukul Hospital Management System in PHP v4.0 has a Persistent Cross-Site Scripting vulnerability in \hms\admin\appointment-history.php. Remote registered users can exploit the vulnerability to obtain user cookie data.

    Published: 22 Jun 2021
    7.5
    High

    CVE-2020-22168

    Last Modified: 21 Nov 2024

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\change-emaild.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

    Published: 22 Jun 2021
    7.5
    High

    CVE-2020-22169

    Last Modified: 21 Nov 2024

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\appointment-history.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

    Published: 22 Jun 2021
    7.5
    High

    CVE-2020-22171

    Last Modified: 21 Nov 2024

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\registration.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

    Published: 22 Jun 2021
    7.5
    High

    CVE-2020-22172

    Last Modified: 21 Nov 2024

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

    Published: 22 Jun 2021
    7.5
    High

    CVE-2020-22173

    Last Modified: 21 Nov 2024

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\edit-profile.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

    Published: 22 Jun 2021
    7.5
    High

    CVE-2020-22174

    Last Modified: 21 Nov 2024

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\book-appointment.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

    Published: 22 Jun 2021
    7.5
    High

    CVE-2020-22175

    Last Modified: 21 Nov 2024

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\admin\betweendates-detailsreports.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

    Published: 22 Jun 2021
    7.5
    High

    CVE-2010-4816

    Last Modified: 21 Nov 2024

    It was found in FreeBSD 8.0, 6.3 and 4.9, and OpenBSD 4.6 that a null pointer dereference in ftpd/popen.c may lead to remote denial of service of the ftpd service.

    Published: 22 Jun 2021
    6.1
    Medium

    CVE-2021-35206

    Last Modified: 21 Nov 2024

    Gitpod before 0.6.0 allows unvalidated redirects.

    Published: 22 Jun 2021
    6.1
    Medium

    CVE-2010-4266

    Last Modified: 21 Nov 2024

    It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher.

    Published: 22 Jun 2021
    6.1
    Medium

    CVE-2010-4264

    Last Modified: 21 Nov 2024

    It was found in vanilla forums before 2.0.10 a cross-site scripting vulnerability where a filename could contain arbitrary code to execute on the client side.

    Published: 22 Jun 2021
    6.1
    Medium

    CVE-2021-35046

    Last Modified: 21 Nov 2024

    A session fixation vulnerability was discovered in Ice Hrm 29.0.0 OS which allows an attacker to hijack a valid user session via a crafted session cookie.

    Published: 22 Jun 2021
    6.1
    Medium

    CVE-2021-35045

    Last Modified: 21 Nov 2024

    Cross site scripting (XSS) vulnerability in Ice Hrm 29.0.0.OS, allows attackers to execute arbitrary code via the parameters to the /app/ endpoint.

    Published: 22 Jun 2021
    8.8
    High

    CVE-2021-34244

    Last Modified: 21 Nov 2024

    A cross site request forgery (CSRF) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to create new admin accounts or change users' passwords.

    Published: 22 Jun 2021
    5.4
    Medium

    CVE-2021-34243

    Last Modified: 21 Nov 2024

    A stored cross site scripting (XSS) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to execute arbitrary web scripts or HTML via a crafted file uploaded into the Document Management tab. The exploit is triggered when a user visits the upload location of the crafted file.

    Published: 22 Jun 2021
    —
    Unknown

    CVE-2010-3446

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 22 Jun 2021
    5.9
    Medium

    CVE-2010-3300

    Last Modified: 21 Nov 2024

    It was found that all OWASP ESAPI for Java up to version 2.0 RC2 are vulnerable to padding oracle attacks.

    Published: 22 Jun 2021
    —
    Unknown

    CVE-2010-2804

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 22 Jun 2021
    7.8
    High

    CVE-2010-2525

    Last Modified: 21 Nov 2024

    A flaw was discovered in gfs2 file system’s handling of acls (access control lists). An unprivileged local attacker could exploit this flaw to gain access or execute any file stored in the gfs2 file system.

    Published: 22 Jun 2021
    7.8
    High

    CVE-2021-0608

    Last Modified: 21 Nov 2024

    In handleAppLaunch of AppLaunchActivity.java, there is a possible arbitrary activity launch due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-174870704

    Published: 22 Jun 2021
    7.8
    High

    CVE-2021-0607

    Last Modified: 21 Nov 2024

    In iaxxx_calc_i2s_div of iaxxx-codec.c, there is a possible hardware port write with user controlled data due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-180950209

    Published: 22 Jun 2021
    6.5
    Medium

    CVE-2021-0551

    Last Modified: 21 Nov 2024

    In bind of MediaControlPanel.java, there is a possible way to lock up the system UI using a malicious media file due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-180518039

    Published: 22 Jun 2021
    5.5
    Medium

    CVE-2021-0552

    Last Modified: 21 Nov 2024

    In getEndItemSliceAction of MediaOutputSlice.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-175124820

    Published: 22 Jun 2021
    4.4
    Medium

    CVE-2021-0549

    Last Modified: 21 Nov 2024

    In sspRequestCallback of BondStateMachine.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-183961896

    Published: 22 Jun 2021
    5.5
    Medium

    CVE-2021-0542

    Last Modified: 21 Nov 2024

    In updateNotification of BeamTransferManager.java, there is a missing permission check. This could lead to local information disclosure of paired Bluetooth addresses with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-168712890

    Published: 22 Jun 2021
    4.4
    Medium

    CVE-2021-0541

    Last Modified: 21 Nov 2024

    In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the NFC server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169258455

    Published: 22 Jun 2021
    7.3
    High

    CVE-2021-0553

    Last Modified: 21 Nov 2024

    In onBindViewHolder of AppSwitchPreference.java, there is a possible bypass of device admin setttings due to unclear UI. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169936038

    Published: 22 Jun 2021
    7.8
    High

    CVE-2021-0550

    Last Modified: 21 Nov 2024

    In onLoadFailed of AnnotateActivity.java, there is a possible way to gain WRITE_EXTERNAL_STORAGE permissions without user consent due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-179688673

    Published: 22 Jun 2021
    7.8
    High

    CVE-2021-0548

    Last Modified: 21 Nov 2024

    In rw_i93_send_to_lower of rw_i93.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157650357

    Published: 22 Jun 2021
    7.8
    High

    CVE-2021-0547

    Last Modified: 21 Nov 2024

    In onReceive of NetInitiatedActivity.java, there is a possible way to supply an attacker-controlled value to a GPS HAL handler due to a missing permission check. This could lead to local escalation of privilege that may result in undefined behavior in some HAL implementations with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174151048

    Published: 22 Jun 2021
    6.7
    Medium

    CVE-2021-0546

    Last Modified: 21 Nov 2024

    In phNxpNciHal_print_res_status of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169258733

    Published: 22 Jun 2021
    6.7
    Medium

    CVE-2021-0545

    Last Modified: 21 Nov 2024

    In phNxpNciHal_print_res_status of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the NFC server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169258884

    Published: 22 Jun 2021
    6.7
    Medium

    CVE-2021-0544

    Last Modified: 21 Nov 2024

    In phNxpNciHal_print_res_status of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169257710

    Published: 22 Jun 2021
    6.7
    Medium

    CVE-2021-0543

    Last Modified: 21 Nov 2024

    In phNxpNciHal_process_ext_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169258743

    Published: 22 Jun 2021
    6.7
    Medium

    CVE-2021-0540

    Last Modified: 21 Nov 2024

    In halWrapperDataCallback of hal_wrapper.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169328517

    Published: 22 Jun 2021
    7.8
    High

    CVE-2021-0539

    Last Modified: 21 Nov 2024

    In archiveStoredConversation of MmsService.java, there is a possible way to archive message conversation without user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-180419673

    Published: 22 Jun 2021
    7.3
    High

    CVE-2021-0538

    Last Modified: 21 Nov 2024

    In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible exit of emergency callback mode due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-178821491

    Published: 22 Jun 2021
    7.3
    High

    CVE-2021-0537

    Last Modified: 21 Nov 2024

    In onCreate of WiFiInstaller.java, there is a possible way to install a malicious Hotspot 2.0 configuration due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-176756141

    Published: 22 Jun 2021