CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2020-22205

    Last Modified: 21 Nov 2024

    SQL Injection in ECShop 3.0 via the id parameter to admin/shophelp.php.

    Published: 16 Jun 2021
    9.8
    Critical

    CVE-2020-22204

    Last Modified: 21 Nov 2024

    SQL Injection in ECShop 2.7.6 via the goods_number parameter to flow.php. .

    Published: 16 Jun 2021
    9.8
    Critical

    CVE-2021-34813

    Last Modified: 21 Nov 2024

    Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup from the homeserver) because olm_pk_decrypt has a stack-based buffer overflow. Remote code execution might be possible for some nonstandard build configurations.

    Published: 16 Jun 2021
    9.8
    Critical

    CVE-2020-22203

    Last Modified: 21 Nov 2024

    SQL Injection in phpCMS 2008 sp4 via the genre parameter to yp/job.php.

    Published: 16 Jun 2021
    8.8
    High

    CVE-2020-22201

    Last Modified: 21 Nov 2024

    phpCMS 2008 sp4 allowas remote malicious users to execute arbitrary php commands via the pagesize parameter to yp/product.php.

    Published: 16 Jun 2021
    5.3
    Medium

    CVE-2020-22200

    Last Modified: 21 Nov 2024

    Directory Traversal vulnerability in phpCMS 9.1.13 via the q parameter to public_get_suggest_keyword.

    Published: 16 Jun 2021
    9.8
    Critical

    CVE-2020-22199

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in phpCMS 2007 SP6 build 0805 via the digg_mod parameter to digg_add.php.

    Published: 16 Jun 2021
    7.5
    High

    CVE-2021-29702

    Last Modified: 21 Nov 2024

    Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200658.

    Published: 16 Jun 2021
    4.4
    Medium

    CVE-2021-20567

    Last Modified: 21 Nov 2024

    IBM Resilient SOAR V38.0 could allow a local privileged attacker to obtain sensitive information due to improper or nonexisting encryption.IBM X-Force ID: 199239.

    Published: 16 Jun 2021
    7.5
    High

    CVE-2021-20566

    Last Modified: 21 Nov 2024

    IBM Resilient SOAR V38.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 199238.

    Published: 16 Jun 2021
    6.5
    Medium

    CVE-2021-20488

    Last Modified: 21 Nov 2024

    IBM Security Identity Manager 6.0.2 could allow an authenticated malicious user to change the passwords of other users in the Windows AD environment when IBM Security Identity Manager Windows Password Synch Plug-in is deployed and configured. IBM X-Force ID: 197789.

    Published: 16 Jun 2021
    6.5
    Medium

    CVE-2021-20483

    Last Modified: 21 Nov 2024

    IBM Security Identity Manager 6.0.2 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 197591.

    Published: 16 Jun 2021
    6.5
    Medium

    CVE-2020-35759

    Last Modified: 21 Nov 2024

    bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely).

    Published: 16 Jun 2021
    9.8
    Critical

    CVE-2020-35760

    Last Modified: 21 Nov 2024

    bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php files).

    Published: 16 Jun 2021
    5.4
    Medium

    CVE-2020-35761

    Last Modified: 21 Nov 2024

    bloofoxCMS 0.5.2.1 is infected with XSS that allows remote attackers to execute arbitrary JS/HTML Code.

    Published: 16 Jun 2021
    2.7
    Low

    CVE-2020-35762

    Last Modified: 21 Nov 2024

    bloofoxCMS 0.5.2.1 is infected with Path traversal in the 'fileurl' parameter that allows attackers to read local files.

    Published: 16 Jun 2021
    7.5
    High

    CVE-2020-24939

    Last Modified: 21 Nov 2024

    Prototype pollution in Stampit supermixer 1.0.3 allows an attacker to modify the prototype of a base object which can vary in severity depending on the implementation.

    Published: 16 Jun 2021
    7.2
    High

    CVE-2020-20444

    Last Modified: 21 Nov 2024

    Jact OpenClinic 0.8.20160412 allows the attacker to read server files after login to the the admin account by an infected 'file' GET parameter in '/shared/view_source.php' which "could" lead to RCE vulnerability .

    Published: 16 Jun 2021
    6.7
    Medium

    CVE-2020-27339

    Last Modified: 11 Aug 2026

    In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly validate the CommBuffer and CommBufferSize parameters, allowing callers to corrupt either the firmware or the OS memory. The fixed versions for this issue in the AhciBusDxe, IdeBusDxe, NvmExpressDxe, SdHostDriverDxe, and SdMmcDeviceDxe drivers are 05.16.25, 05.26.25, 05.35.25, 05.43.25, and 05.51.25 (for Kernel 5.1 through 5.5).

    Published: 16 Jun 2021
    9.8
    Critical

    CVE-2020-22198

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.

    Published: 16 Jun 2021
    7.8
    High

    CVE-2021-34803

    Last Modified: 21 Nov 2024

    TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations.

    Published: 16 Jun 2021
    9.8
    Critical

    CVE-2021-27610

    Last Modified: 21 Nov 2024

    SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about internal and external RFC user in consistent and distinguished format, which could lead to improper authentication and may be exploited by malicious users to obtain illegitimate access to the system.

    Published: 16 Jun 2021
    5.3
    Medium

    CVE-2021-34801

    Last Modified: 21 Nov 2024

    Valine 1.4.14 allows remote attackers to cause a denial of service (application outage) by supplying a ua (aka User-Agent) value that only specifies the product and version.

    Published: 16 Jun 2021
    7.2
    High

    CVE-2021-3584

    Last Modified: 21 Nov 2024

    A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to overwrite the defaults and perform command injection. The highest threat from this vulnerability is to confidentiality, integrity and availability of system. Fixed releases are 2.4.1, 2.5.1, 3.0.0.

    Published: 16 Jun 2021
    5.4
    Medium

    CVE-2021-21668

    Last Modified: 21 Nov 2024

    Jenkins Scriptler Plugin 3.1 and earlier does not escape script content, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Scriptler/Configure permission.

    Published: 16 Jun 2021
    5.4
    Medium

    CVE-2021-21667

    Last Modified: 21 Nov 2024

    Jenkins Scriptler Plugin 3.2 and earlier does not escape parameter names shown in job configuration forms, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Scriptler/Configure permission.

    Published: 16 Jun 2021
    6.5
    Medium

    CVE-2020-8299

    Last Modified: 21 Nov 2024

    Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WANOP Edition before 11.4.0, 11.3.2, 11.3.1a, 11.2.3a, 11.1.2c, 10.2.9a suffers from uncontrolled resource consumption by way of a network-based denial-of-service from within the same Layer 2 network segment. Note that the attacker must be in the same Layer 2 network segment as the vulnerable appliance.

    Published: 16 Jun 2021
    6.5
    Medium

    CVE-2020-8300

    Last Modified: 21 Nov 2024

    Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. Note that Citrix ADC or Citrix Gateway must be configured as a SAML SP or a SAML IdP for this to be possible.

    Published: 16 Jun 2021
    7.5
    High

    CVE-2021-22914

    Last Modified: 21 Nov 2024

    Citrix Cloud Connector before 6.31.0.62192 suffers from insecure storage of sensitive information due to sensitive information being stored in the Citrix Cloud Connector installation log files. Such information could be used by an malicious actor to access a Citrix Cloud environment. This issue affects all versions of Citrix Cloud Connector that were installed by passing secure client parameters for installation via the command line. The issue does not affect Citrix Cloud Connector if it was installed using the interactive installer or where a parameter file was used with the command-line installer.

    Published: 16 Jun 2021
    5.3
    Medium

    CVE-2021-31159

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732.

    Published: 16 Jun 2021
    5.9
    Medium

    CVE-2021-31857

    Last Modified: 21 Nov 2024

    In Zoho ManageEngine Password Manager Pro before 11.1 build 11104, attackers are able to retrieve credentials via a browser extension for non-website resource types.

    Published: 16 Jun 2021
    9.8
    Critical

    CVE-2021-32928

    Last Modified: 21 Nov 2024

    The Sentinel LDK Run-Time Environment installer (Versions 7.6 and prior) adds a firewall rule named “Sentinel License Manager” that allows incoming connections from private networks using TCP Port 1947. While uninstalling, the uninstaller fails to close Port 1947.

    Published: 16 Jun 2021
    7.8
    High

    CVE-2021-27483

    Last Modified: 21 Nov 2024

    ZOLL Defibrillator Dashboard, v prior to 2.2,The affected products contain insecure filesystem permissions that could allow a lower privilege user to escalate privileges to an administrative level user.

    Published: 16 Jun 2021
    7.5
    High

    CVE-2021-27485

    Last Modified: 21 Nov 2024

    ZOLL Defibrillator Dashboard, v prior to 2.2,The application allows users to store their passwords in a recoverable format, which could allow an attacker to retrieve the credentials from the web browser.

    Published: 16 Jun 2021
    5.4
    Medium

    CVE-2021-27479

    Last Modified: 21 Nov 2024

    ZOLL Defibrillator Dashboard, v prior to 2.2,The affected product’s web application could allow a low privilege user to inject parameters to contain malicious scripts to be executed by higher privilege users.

    Published: 16 Jun 2021
    5.5
    Medium

    CVE-2021-27487

    Last Modified: 21 Nov 2024

    ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products contain credentials stored in plaintext. This could allow an attacker to gain access to sensitive information.

    Published: 16 Jun 2021
    5.5
    Medium

    CVE-2021-27481

    Last Modified: 21 Nov 2024

    ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products utilize an encryption key in the data exchange process, which is hardcoded. This could allow an attacker to gain access to sensitive information.

    Published: 16 Jun 2021
    8.8
    High

    CVE-2021-27489

    Last Modified: 21 Nov 2024

    ZOLL Defibrillator Dashboard, v prior to 2.2, The web application allows a non-administrative user to upload a malicious file. This file could allow an attacker to remotely execute arbitrary commands.

    Published: 16 Jun 2021
    5.3
    Medium

    CVE-2021-34683

    Last Modified: 21 Nov 2024

    An issue was discovered in EXCELLENT INFOTEK CORPORATION (EIC) E-document System 3.0. A remote attacker can use kw/auth/bbs/asp/get_user_email_info_bbs.asp to obtain the contact information (name and e-mail address) of everyone in the entire organization. This information can allow remote attackers to perform social engineering or brute force attacks against the system login page.

    Published: 16 Jun 2021
    8.1
    High

    CVE-2021-32612

    Last Modified: 21 Nov 2024

    The VeryFitPro (com.veryfit2hr.second) application 3.2.8 for Android does all communication with the backend API over cleartext HTTP. This includes logins, registrations, and password change requests. This allows information theft and account takeover via network sniffing.

    Published: 16 Jun 2021
    4.6
    Medium

    CVE-2021-32033

    Last Modified: 21 Nov 2024

    Protectimus SLIM NFC 70 10.01 devices allow a Time Traveler attack in which attackers can predict TOTP passwords in certain situations. The time value used by the device can be set independently from the used seed value for generating time-based one-time passwords, without authentication. Thus, an attacker with short-time physical access to a device can set the internal real-time clock (RTC) to the future, generate one-time passwords, and reset the clock to the current time. This allows the generation of valid future time-based one-time passwords without having further access to the hardware token.

    Published: 16 Jun 2021
    6.5
    Medium

    CVE-2021-28979

    Last Modified: 21 Nov 2024

    SafeNet KeySecure Management Console 8.12.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked.

    Published: 16 Jun 2021
    7.5
    High

    CVE-2021-20094

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to crash the CodeMeter Runtime Server.

    Published: 16 Jun 2021
    9.1
    Critical

    CVE-2021-20093

    Last Modified: 21 Nov 2024

    A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to disclose heap memory contents or crash the CodeMeter Runtime Server.

    Published: 16 Jun 2021
    7.5
    High

    CVE-2021-21441

    Last Modified: 21 Nov 2024

    There is a XSS vulnerability in the ticket overview screens. It's possible to collect various information by having an e-mail shown in the overview screen. Attack can be performed by sending specially crafted e-mail to the system and it doesn't require any user intraction. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.26 and prior versions.

    Published: 16 Jun 2021
    9.8
    Critical

    CVE-2020-9493

    Last Modified: 21 Nov 2024

    A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution.

    Published: 16 Jun 2021
    6
    Medium

    CVE-2021-28815

    Last Modified: 21 Nov 2024

    Insecure storage of sensitive information has been reported to affect QNAP NAS running myQNAPcloud Link. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism. This issue affects: QNAP Systems Inc. myQNAPcloud Link versions prior to 2.2.21 on QTS 4.5.3; versions prior to 2.2.21 on QuTS hero h4.5.2; versions prior to 2.2.21 on QuTScloud c4.5.4.

    Published: 16 Jun 2021
    4.3
    Medium

    CVE-2021-3535

    Last Modified: 21 Nov 2024

    Rapid7 Nexpose is vulnerable to a non-persistent cross-site scripting vulnerability affecting the Security Console's Filtered Asset Search feature. A specific search criterion and operator combination in Filtered Asset Search could have allowed a user to pass code through the provided search field. This issue affects version 6.6.80 and prior, and is fixed in 6.6.81. If your Security Console currently falls on or within this affected version range, ensure that you update your Security Console to the latest version.

    Published: 16 Jun 2021
    9.8
    Critical

    CVE-2021-32685

    Last Modified: 21 Nov 2024

    tEnvoy contains the PGP, NaCl, and PBKDF2 in node.js and the browser (hashing, random, encryption, decryption, signatures, conversions), used by TogaTech.org. In versions prior to 7.0.3, the `verifyWithMessage` method of `tEnvoyNaClSigningKey` always returns `true` for any signature that has a SHA-512 hash matching the SHA-512 hash of the message even if the signature was invalid. This issue is patched in version 7.0.3. As a workaround: In `tenvoy.js` under the `verifyWithMessage` method definition within the `tEnvoyNaClSigningKey` class, ensure that the return statement call to `this.verify` ends in `.verified`.

    Published: 16 Jun 2021
    6.5
    Medium

    CVE-2021-32676

    Last Modified: 21 Nov 2024

    Nextcloud Talk is a fully on-premises audio/video and chat communication service. Password protected shared chats in Talk before version 9.0.10, 10.0.8 and 11.2.2 did not rotate the session cookie after a successful authentication event. It is recommended that the Nextcloud Talk App is upgraded to 9.0.10, 10.0.8 or 11.2.2. No workarounds for this vulnerability are known to exist.

    Published: 16 Jun 2021