CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2019-25047

    Last Modified: 21 Nov 2024

    Greenbone Security Assistant (GSA) before 8.0.2 and Greenbone OS (GOS) before 5.0.10 allow XSS during 404 URL handling in gsad.

    Published: 21 Jun 2021
    9.8
    Critical

    CVE-2018-25016

    Last Modified: 21 Nov 2024

    Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection.

    Published: 21 Jun 2021
    8.8
    High

    CVE-2020-22390

    Last Modified: 21 Nov 2024

    Akaunting <= 2.0.9 is vulnerable to CSV injection in the Item name field, export function. Attackers can inject arbitrary code into the name parameter and perform code execution when the crafted file is opened.

    Published: 21 Jun 2021
    —
    Unknown

    CVE-2007-1857

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 21 Jun 2021
    —
    Unknown

    CVE-2006-1053

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 21 Jun 2021
    —
    Unknown

    CVE-2006-0849

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 21 Jun 2021
    —
    Unknown

    CVE-2006-0740

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 21 Jun 2021
    —
    Unknown

    CVE-2006-0017

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 21 Jun 2021
    —
    Unknown

    CVE-2006-0016

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 21 Jun 2021
    —
    Unknown

    CVE-2019-7002

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 21 Jun 2021
    —
    Unknown

    CVE-2020-7031

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 21 Jun 2021
    6.1
    Medium

    CVE-2021-28833

    Last Modified: 21 Nov 2024

    Increments Qiita::Markdown before 0.34.0 allows XSS via a crafted gist link, a different vulnerability than CVE-2021-28796.

    Published: 21 Jun 2021
    4.3
    Medium

    CVE-2021-28684

    Last Modified: 21 Nov 2024

    The XML parser used in ConeXware PowerArchiver before 20.10.02 allows processing of external entities, which might lead to exfiltration of local files over the network (via an XXE attack).

    Published: 21 Jun 2021
    7.8
    High

    CVE-2021-29337

    Last Modified: 21 Nov 2024

    MODAPI.sys in MSI Dragon Center 2.0.104.0 allows low-privileged users to access kernel memory and potentially escalate privileges via a crafted IOCTL 0x9c406104 call. This IOCTL provides the MmMapIoSpace feature for mapping physical memory.

    Published: 21 Jun 2021
    3.5
    Low

    CVE-2021-33572

    Last Modified: 21 Nov 2024

    A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Linux Security whereby the FSAVD component used in certain F-Secure products can crash while scanning larger packages/fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine.

    Published: 21 Jun 2021
    8.8
    High

    CVE-2021-31769

    Last Modified: 21 Nov 2024

    MyQ Server in MyQ X Smart before 8.2 allows remote code execution by unprivileged users because administrative session data can be read in the %PROGRAMFILES%\MyQ\PHP\Sessions directory. The "Select server file" feature is only intended for administrators but actually does not require authorization. An attacker can inject arbitrary OS commands (such as commands to create new .php files) via the Task Scheduler component.

    Published: 21 Jun 2021
    7.5
    High

    CVE-2020-20474

    Last Modified: 21 Nov 2024

    White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the default_task_edituser.php files failing to filter the csa_to_user parameter. Remote attackers can exploit the vulnerability to obtain database sensitive information.

    Published: 21 Jun 2021
    7.5
    High

    CVE-2020-20473

    Last Modified: 21 Nov 2024

    White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the control_task.php, control_project.php, default_user.php files failing to filter the sort parameter. Remote attackers can exploit the vulnerability to obtain database sensitive information.

    Published: 21 Jun 2021
    5.3
    Medium

    CVE-2020-20472

    Last Modified: 21 Nov 2024

    White Shark System (WSS) 1.3.2 has a sensitive information disclosure vulnerability. The if_get_addbook.php file does not have an authentication operation. Remote attackers can obtain username information for all users of the current site.

    Published: 21 Jun 2021
    8.8
    High

    CVE-2020-20471

    Last Modified: 21 Nov 2024

    White Shark System (WSS) 1.3.2 has an unauthorized access vulnerability in default_user_edit.php, remote attackers can exploit this vulnerability to escalate to admin privileges.

    Published: 21 Jun 2021
    5.3
    Medium

    CVE-2020-20470

    Last Modified: 21 Nov 2024

    White Shark System (WSS) 1.3.2 has web site physical path leakage vulnerability.

    Published: 21 Jun 2021
    7.5
    High

    CVE-2020-20469

    Last Modified: 21 Nov 2024

    White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the log_edit.php files failing to filter the csa_to_user parameter, remote attackers can exploit the vulnerability to obtain database sensitive information.

    Published: 21 Jun 2021
    6.5
    Medium

    CVE-2020-20468

    Last Modified: 21 Nov 2024

    White Shark System (WSS) 1.3.2 is vulnerable to CSRF. Attackers can use the user_edit_password.php file to modify the user password.

    Published: 21 Jun 2021
    6.5
    Medium

    CVE-2020-20467

    Last Modified: 21 Nov 2024

    White Shark System (WSS) 1.3.2 is vulnerable to sensitive information disclosure via default_task_add.php, remote attackers can exploit the vulnerability to create a task.

    Published: 21 Jun 2021
    9.8
    Critical

    CVE-2020-20466

    Last Modified: 21 Nov 2024

    White Shark System (WSS) 1.3.2 is vulnerable to unauthorized access via user_edit_password.php, remote attackers can modify the password of any user.

    Published: 21 Jun 2021
    6.1
    Medium

    CVE-2021-3623

    Last Modified: 21 Nov 2024

    A flaw was found in libtpms. The flaw can be triggered by specially-crafted TPM 2 command packets containing illegal values and may lead to an out-of-bounds access when the volatile state of the TPM 2 is marshalled/written or unmarshalled/read. The highest threat from this vulnerability is to system availability.

    Published: 21 Jun 2021
    4.3
    Medium

    CVE-2020-28200

    Last Modified: 21 Nov 2024

    The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with a complex regular expression for the regex extension.

    Published: 21 Jun 2021
    7.5
    High

    CVE-2021-29059

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in IS-SVG version 2.1.0 to 4.2.2 and below where a Regular Expression Denial of Service (ReDOS) occurs if the application is provided and checks a crafted invalid SVG string.

    Published: 21 Jun 2021
    5.9
    Medium

    CVE-2021-39365

    Last Modified: 21 Nov 2024

    In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

    Published: 21 Jun 2021
    5.3
    Medium

    CVE-2021-29060

    Last Modified: 21 Nov 2024

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Color-String version 1.5.5 and below which occurs when the application is provided and checks a crafted invalid HWB string.

    Published: 21 Jun 2021
    7.5
    High

    CVE-2021-29157

    Last Modified: 21 Nov 2024

    Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location. This occurs during use of local JWT validation with the posix fs driver.

    Published: 21 Jun 2021
    9.8
    Critical

    CVE-2021-24370

    Last Modified: 21 Nov 2024

    The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.

    Published: 21 Jun 2021
    7.5
    High

    CVE-2021-29063

    Last Modified: 21 Nov 2024

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Mpmath v1.0.0 through v1.2.1 when the mpmathify function is called.

    Published: 21 Jun 2021
    4.7
    Medium

    CVE-2021-33624

    Last Modified: 11 Nov 2025

    In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., because of type confusion) and consequently an unprivileged BPF program can read arbitrary memory locations via a side-channel attack, aka CID-9183671af6db.

    Published: 21 Jun 2021
    4.8
    Medium

    CVE-2021-33515

    Last Modified: 21 Nov 2024

    The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.

    Published: 21 Jun 2021
    6.1
    Medium

    CVE-2021-24368

    Last Modified: 21 Nov 2024

    The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or escape its result_id parameter when displaying an existing quiz result page, leading to a reflected Cross-Site Scripting issue. This could allow for privilege escalation by inducing a logged in admin to open a malicious link

    Published: 20 Jun 2021
    7.8
    High

    CVE-2021-3612

    Last Modified: 21 Nov 2024

    An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or possibly escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

    Published: 20 Jun 2021
    3.1
    Low

    CVE-2021-32719

    Last Modified: 21 Nov 2024

    RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper <script> tag sanitization. This potentially allows for JavaScript code execution in the context of the page. The user must be signed in and have elevated permissions (manage federation upstreams and policies) for this to occur. The vulnerability is patched in RabbitMQ 3.8.18. As a workaround, disable the `rabbitmq_federation_management` plugin and use [CLI tools](https://www.rabbitmq.com/cli.html) instead.

    Published: 19 Jun 2021
    7
    High

    CVE-2021-3609

    Last Modified: 21 Nov 2024

    .A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege escalation to root.

    Published: 19 Jun 2021
    7.5
    High

    CVE-2021-31660

    Last Modified: 21 Nov 2024

    RIOT-OS 2021.01 before commit 85da504d2dc30188b89f44c3276fc5a25b31251f contains a buffer overflow which could allow attackers to obtain sensitive information.

    Published: 18 Jun 2021
    9.8
    Critical

    CVE-2021-31272

    Last Modified: 21 Nov 2024

    SerenityOS before commit 3844e8569689dd476064a0759d704bc64fb3ca2c contains a directory traversal vulnerability in tar/unzip that may lead to command execution or privilege escalation.

    Published: 18 Jun 2021
    7.5
    High

    CVE-2021-31661

    Last Modified: 21 Nov 2024

    RIOT-OS 2021.01 before commit 609c9ada34da5546cffb632a98b7ba157c112658 contains a buffer overflow that could allow attackers to obtain sensitive information.

    Published: 18 Jun 2021
    7.5
    High

    CVE-2021-31662

    Last Modified: 21 Nov 2024

    RIOT-OS 2021.01 before commit 07f1254d8537497552e7dce80364aaead9266bbe contains a buffer overflow which could allow attackers to obtain sensitive information.

    Published: 18 Jun 2021
    7.5
    High

    CVE-2021-31663

    Last Modified: 21 Nov 2024

    RIOT-OS 2021.01 before commit bc59d60be60dfc0a05def57d74985371e4f22d79 contains a buffer overflow which could allow attackers to obtain sensitive information.

    Published: 18 Jun 2021
    7.5
    High

    CVE-2021-31664

    Last Modified: 21 Nov 2024

    RIOT-OS 2021.01 before commit 44741ff99f7a71df45420635b238b9c22093647a contains a buffer overflow which could allow attackers to obtain sensitive information.

    Published: 18 Jun 2021
    7.5
    High

    CVE-2021-33185

    Last Modified: 21 Nov 2024

    SerenityOS contains a buffer overflow in the set_range test in TestBitmap which could allow attackers to obtain sensitive information.

    Published: 18 Jun 2021
    7.5
    High

    CVE-2021-33186

    Last Modified: 21 Nov 2024

    SerenityOS in test-crypto.cpp contains a stack buffer overflow which could allow attackers to obtain sensitive information.

    Published: 18 Jun 2021
    8.2
    High

    CVE-2021-21410

    Last Modified: 21 Nov 2024

    Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An out-of-bounds read can be triggered by 6LoWPAN packets sent to devices running Contiki-NG 4.6 and prior. The IPv6 header decompression function (<code>uncompress_hdr_iphc</code>) does not perform proper boundary checks when reading from the packet buffer. Hence, it is possible to construct a compressed 6LoWPAN packet that will read more bytes than what is available from the packet buffer. As of time of publication, there is not a release with a patch available. Users can apply the patch for this vulnerability out-of-band as a workaround.

    Published: 18 Jun 2021
    8.2
    High

    CVE-2021-21257

    Last Modified: 21 Nov 2024

    Contiki-NG is an open-source, cross-platform operating system for internet of things devices. The RPL-Classic and RPL-Lite implementations in the Contiki-NG operating system versions prior to 4.6 do not validate the address pointer in the RPL source routing header This makes it possible for an attacker to cause out-of-bounds writes with packets injected into the network stack. Specifically, the problem lies in the rpl_ext_header_srh_update function in the two rpl-ext-header.c modules for RPL-Classic and RPL-Lite respectively. The addr_ptr variable is calculated using an unvalidated CMPR field value from the source routing header. An out-of-bounds write can be triggered on line 151 in os/net/routing/rpl-lite/rpl-ext-header.c and line 261 in os/net/routing/rpl-classic/rpl-ext-header.c, which contain the following memcpy call with addr_ptr as destination. The problem has been patched in Contiki-NG 4.6. Users can apply a patch out-of-band as a workaround.

    Published: 18 Jun 2021
    7.5
    High

    CVE-2021-21279

    Last Modified: 21 Nov 2024

    Contiki-NG is an open-source, cross-platform operating system for internet of things devices. In verions prior to 4.6, an attacker can perform a denial-of-service attack by triggering an infinite loop in the processing of IPv6 neighbor solicitation (NS) messages. This type of attack can effectively shut down the operation of the system because of the cooperative scheduling used for the main parts of Contiki-NG and its communication stack. The problem has been patched in Contiki-NG 4.6. Users can apply the patch for this vulnerability out-of-band as a workaround.

    Published: 18 Jun 2021