CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2021-30526

    Last Modified: 21 Nov 2024

    Out of bounds write in TabStrip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.

    Published: 7 Jun 2021
    8.8
    High

    CVE-2021-30524

    Last Modified: 21 Nov 2024

    Use after free in TabStrip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

    Published: 7 Jun 2021
    8.8
    High

    CVE-2021-30525

    Last Modified: 21 Nov 2024

    Use after free in TabGroups in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

    Published: 7 Jun 2021
    8.8
    High

    CVE-2021-30523

    Last Modified: 21 Nov 2024

    Use after free in WebRTC in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted SCTP packet.

    Published: 7 Jun 2021
    8.8
    High

    CVE-2021-30521

    Last Modified: 21 Nov 2024

    Heap buffer overflow in Autofill in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.

    Published: 7 Jun 2021
    8.8
    High

    CVE-2021-30522

    Last Modified: 21 Nov 2024

    Use after free in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 7 Jun 2021
    5.3
    Medium

    CVE-2021-29621

    Last Modified: 7 Mar 2025

    Flask-AppBuilder is a development framework, built on top of Flask. User enumeration in database authentication in Flask-AppBuilder <= 3.2.3. Allows for a non authenticated user to enumerate existing accounts by timing the response time from the server when you are logging in. Upgrade to version 3.3.0 or higher to resolve.

    Published: 7 Jun 2021
    6.1
    Medium

    CVE-2020-18268

    Last Modified: 21 Nov 2024

    Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect" parameter in the component "zb_system/cmd.php."

    Published: 7 Jun 2021
    8.8
    High

    CVE-2020-18265

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary code via the component "Simple-Log/admin/admin.php?act=act_add_member".

    Published: 7 Jun 2021
    8.8
    High

    CVE-2020-18264

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary code via the component "Simple-Log/admin/admin.php?act=act_edit_member".

    Published: 7 Jun 2021
    5.3
    Medium

    CVE-2021-33896

    Last Modified: 21 Nov 2024

    Dino before 0.1.2 and 0.2.x before 0.2.1 allows Directory Traversal (only for creation of new files) via URI-encoded path separators.

    Published: 7 Jun 2021
    8.8
    High

    CVE-2021-20517

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server Network Deployment 8.5 and 9.0 could allow a remote authenticated attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to read and delete arbitrary files on the system. IBM X-Force ID: 198435.

    Published: 7 Jun 2021
    5.3
    Medium

    CVE-2020-5008

    Last Modified: 21 Nov 2024

    IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.14 stores sensitive information in GET request parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 193033.

    Published: 7 Jun 2021
    9.8
    Critical

    CVE-2021-20699

    Last Modified: 8 Dec 2025

    Sharp NEC Displays ((UN462A R1.300 and prior to it, UN462VA R1.300 and prior to it, UN492S R1.300 and prior to it, UN492VS R1.300 and prior to it, UN552A R1.300 and prior to it, UN552S R1.300 and prior to it, UN552VS R1.300 and prior to it, UN552 R1.300 and prior to it, UN552V R1.300 and prior to it, UX552S R1.300 and prior to it, UX552 R1.300 and prior to it, V864Q R2.000 and prior to it, C861Q R2.000 and prior to it, P754Q R2.000 and prior to it, V754Q R2.000 and prior to it, C751Q R2.000 and prior to it, V984Q R2.000 and prior to it, C981Q R2.000 and prior to it, P654Q R2.000 and prior to it, V654Q R2.000 and prior to it, C651Q R2.000 and prior to it, V554Q R2.000 and prior to it, P404 R3.200 and prior to it, P484 R3.200 and prior to it, P554 R3.200 and prior to it, V404 R3.200 and prior to it, V484 R3.200 and prior to it, V554 R3.200 and prior to it, V404-T R3.200 and prior to it, V484-T R3.200 and prior to it, V554-T R3.200 and prior to it, C501 R2.000 and prior to it, C551 R2.000 and prior to it, C431 R2.000 and prior to it) allows an attacker a buffer overflow and to execute remote code by sending long parameters that contains specific characters in http request.

    Published: 7 Jun 2021
    9.8
    Critical

    CVE-2021-20698

    Last Modified: 8 Dec 2025

    Sharp NEC Displays (UN462A R1.300 and prior to it, UN462VA R1.300 and prior to it, UN492S R1.300 and prior to it, UN492VS R1.300 and prior to it, UN552A R1.300 and prior to it, UN552S R1.300 and prior to it, UN552VS R1.300 and prior to it, UN552 R1.300 and prior to it, UN552V R1.300 and prior to it, UX552S R1.300 and prior to it, UX552 R1.300 and prior to it, V864Q R2.000 and prior to it, C861Q R2.000 and prior to it, P754Q R2.000 and prior to it, V754Q R2.000 and prior to it, C751Q R2.000 and prior to it, V984Q R2.000 and prior to it, C981Q R2.000 and prior to it, P654Q R2.000 and prior to it, V654Q R2.000 and prior to it, C651Q R2.000 and prior to it, V554Q R2.000 and prior to it, P404 R3.200 and prior to it, P484 R3.200 and prior to it, P554 R3.200 and prior to it, V404 R3.200 and prior to it, V484 R3.200 and prior to it, V554 R3.200 and prior to it, V404-T R3.200 and prior to it, V484-T R3.200 and prior to it, V554-T R3.200 and prior to it, C501 R2.000 and prior to it, C551 R2.000 and prior to it, C431 R2.000 and prior to it) allows an attacker to obtain root privileges and execute remote code by sending unintended parameters that contain specific characters in http request.

    Published: 7 Jun 2021
    5.3
    Medium

    CVE-2021-29099

    Last Modified: 10 Apr 2025

    A SQL injection vulnerability exists in some configurations of ArcGIS Server versions 10.8.1 and earlier. Specially crafted web requests can expose information that is not intended to be disclosed (not customer datasets). Web Services that use file based data sources (file Geodatabase or Shape Files or tile cached services) are unaffected by this issue.

    Published: 7 Jun 2021
    6.1
    Medium

    CVE-2021-33904

    Last Modified: 21 Nov 2024

    In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS. NOTE: The vendor states "there are configurable security flags and we are unable to reproduce them with the available information.

    Published: 7 Jun 2021
    7.5
    High

    CVE-2021-24340

    Last Modified: 21 Nov 2024

    The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been accessible to administrator only, was also available to any visitor, including unauthenticated ones.

    Published: 7 Jun 2021
    6.1
    Medium

    CVE-2021-24342

    Last Modified: 21 Nov 2024

    The JNews WordPress theme before 8.0.6 did not sanitise the cat_id parameter in the POST request /?ajax-request=jnews (with action=jnews_build_mega_category_*), leading to a Reflected Cross-Site Scripting (XSS) issue.

    Published: 7 Jun 2021
    4.8
    Medium

    CVE-2021-24343

    Last Modified: 21 Nov 2024

    The iFlyChat WordPress plugin before 4.7.0 does not sanitise its APP ID setting before outputting it back in the page, leading to an authenticated Stored Cross-Site Scripting issue

    Published: 7 Jun 2021
    4.8
    Medium

    CVE-2021-24344

    Last Modified: 21 Nov 2024

    The Easy Preloader WordPress plugin through 1.0.0 does not sanitise its setting fields, leading to authenticated (admin+) Stored Cross-Site scripting issues

    Published: 7 Jun 2021
    8.8
    High

    CVE-2021-24337

    Last Modified: 21 Nov 2024

    The id GET parameter of one of the Video Embed WordPress plugin through 1.0's page (available via forced browsing) is not sanitised, validated or escaped before being used in a SQL statement, allowing low privilege users, such as subscribers, to perform SQL injection.

    Published: 7 Jun 2021
    7.2
    High

    CVE-2021-24336

    Last Modified: 21 Nov 2024

    The FlightLog WordPress plugin through 3.0.2 does not sanitise, validate or escape various POST parameters before using them a SQL statement, leading to SQL injections exploitable by editor and administrator users

    Published: 7 Jun 2021
    6.1
    Medium

    CVE-2020-36383

    Last Modified: 21 Nov 2024

    PageLayer before 1.3.5 allows reflected XSS via the font-size parameter.

    Published: 7 Jun 2021
    6.1
    Medium

    CVE-2020-36384

    Last Modified: 21 Nov 2024

    PageLayer before 1.3.5 allows reflected XSS via color settings.

    Published: 7 Jun 2021
    5.4
    Medium

    CVE-2021-28382

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious user details from AD.

    Published: 7 Jun 2021
    6.1
    Medium

    CVE-2020-26885

    Last Modified: 21 Nov 2024

    An issue was discovered in 2sic 2sxc before 11.22. A XSS vulnerability in the sxcver parameter of dnn/ui.html allows an attacker to craft a malicious URL that executes a JavaScript payload in a victim's browser.

    Published: 7 Jun 2021
    7.8
    High

    CVE-2020-36385

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.10. drivers/infiniband/core/ucma.c has a use-after-free because the ctx is reached via the ctx_list in some ucma_migrate_id situations where ucma_close is called, aka CID-f5449e74802c.

    Published: 7 Jun 2021
    —
    Unknown

    CVE-2021-34064

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-33563. Reason: This candidate is a duplicate of CVE-2021-33563. Notes: All CVE users should reference CVE-2021-33563 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 7 Jun 2021
    —
    Unknown

    CVE-2021-34248

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-25905. Reason: This candidate is a duplicate of CVE-2020-25905. Notes: All CVE users should reference CVE-2020-25905 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 7 Jun 2021
    —
    Unknown

    CVE-2021-34250

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2021-33396. Reason: This record is a duplicate of CVE-2021-33396. Notes: All CVE users should reference CVE-2021-33396 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.

    Published: 7 Jun 2021
    7.5
    High

    CVE-2021-3580

    Last Modified: 21 Nov 2024

    A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.

    Published: 7 Jun 2021
    5.5
    Medium

    CVE-2020-13938

    Last Modified: 21 Nov 2024

    Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows

    Published: 7 Jun 2021
    8.8
    High

    CVE-2021-30528

    Last Modified: 21 Nov 2024

    Use after free in WebAuthentication in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker who had compromised the renderer process of a user who had saved a credit card in their Google account to potentially exploit heap corruption via a crafted HTML page.

    Published: 7 Jun 2021
    7.8
    High

    CVE-2021-0512

    Last Modified: 21 Nov 2024

    In __hidinput_change_resolution_multipliers of hid-input.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-173843328References: Upstream kernel

    Published: 7 Jun 2021
    8.1
    High

    CVE-2021-33898

    Last Modified: 21 Nov 2024

    In Invoice Ninja before 4.4.0, there is an unsafe call to unserialize() in app/Ninja/Repositories/AccountRepository.php that may allow an attacker to deserialize arbitrary PHP classes. In certain contexts, this can result in remote code execution. The attacker's input must be hosted at http://www.geoplugin.net (cleartext HTTP), and thus a successful attack requires spoofing that site or obtaining control of it.

    Published: 6 Jun 2021
    8.1
    High

    CVE-2021-33879

    Last Modified: 21 Nov 2024

    Tencent GameLoop before 4.1.21.90 downloaded updates over an insecure HTTP connection. A malicious attacker in an MITM position could spoof the contents of an XML document describing an update package, replacing a download URL with one pointing to an arbitrary Windows executable. Because the only integrity check would be a comparison of the downloaded file's MD5 checksum to the one contained within the XML document, the downloaded executable would then be executed on the victim's machine.

    Published: 6 Jun 2021
    4.2
    Medium

    CVE-2021-33881

    Last Modified: 21 Nov 2024

    On NXP MIFARE Ultralight and NTAG cards, an attacker can interrupt a write operation (aka conduct a "tear off" attack) over RFID to bypass a Monotonic Counter protection mechanism. The impact depends on how the anti tear-off feature is used in specific applications such as public transportation, physical access control, etc.

    Published: 6 Jun 2021
    5.9
    Medium

    CVE-2021-33880

    Last Modified: 21 Nov 2024

    The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack.

    Published: 6 Jun 2021
    7.5
    High

    CVE-2021-31701

    Last Modified: 21 Nov 2024

    Mintty before 3.4.7 mishandles Bracketed Paste Mode.

    Published: 6 Jun 2021
    9.8
    Critical

    CVE-2021-32198

    Last Modified: 21 Nov 2024

    EmTec ZOC through 8.02.4 allows remote servers to cause a denial of service (Windows GUI hang) by telling the ZOC window to change its title repeatedly at high speed, which results in many SetWindowTextA or SetWindowTextW calls. In other words, it does not implement a usleep or similar delay upon processing a title change.

    Published: 6 Jun 2021
    8.1
    High

    CVE-2021-32641

    Last Modified: 21 Nov 2024

    auth0-lock is Auth0's signin solution. Versions of nauth0-lock before and including `11.30.0` are vulnerable to reflected XSS. An attacker can execute arbitrary code when the library's `flashMessage` feature is utilized and user input or data from URL parameters is incorporated into the `flashMessage` or the library's `languageDictionary` feature is utilized and user input or data from URL parameters is incorporated into the `languageDictionary`. The vulnerability is patched in version 11.30.1.

    Published: 4 Jun 2021
    6.5
    Medium

    CVE-2021-31249

    Last Modified: 21 Nov 2024

    A CRLF injection vulnerability was found on BF-430, BF-431, and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack of validation on the parameter redirect= available on multiple CGI components.

    Published: 4 Jun 2021
    5.4
    Medium

    CVE-2021-31250

    Last Modified: 21 Nov 2024

    Multiple storage XSS vulnerabilities were discovered on BF-430, BF-431 and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack of sanitization of the input on the components man.cgi, if.cgi, dhcpc.cgi, ppp.cgi.

    Published: 4 Jun 2021
    9.8
    Critical

    CVE-2021-31251

    Last Modified: 21 Nov 2024

    An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by supplying a specially malformed request and an attacker may force the remote telnet server to believe that the user has already authenticated.

    Published: 4 Jun 2021
    6.1
    Medium

    CVE-2021-31252

    Last Modified: 21 Nov 2024

    An open redirect vulnerability exists in BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, and SEMAC devices from CHIYU Technology that can be exploited by sending a link that has a specially crafted URL to convince the user to click on it.

    Published: 4 Jun 2021
    6.8
    Medium

    CVE-2021-26928

    Last Modified: 21 Nov 2024

    BIRD through 2.0.7 does not provide functionality for password authentication of BGP peers. Because of this, products that use BIRD (which may, for example, include Tigera products in some configurations, as well as products of other vendors) may have been susceptible to route redirection for Denial of Service and/or Information Disclosure. NOTE: a researcher has asserted that the behavior is within Tigera’s area of responsibility; however, Tigera disagrees

    Published: 4 Jun 2021
    7.5
    High

    CVE-2021-29500

    Last Modified: 21 Nov 2024

    bubble fireworks is an open source java package relating to Spring Framework. In bubble fireworks before version 2021.BUILD-SNAPSHOT there is a vulnerability in which the package did not properly verify the signature of JSON Web Tokens. This allows to forgery of valid JWTs.

    Published: 4 Jun 2021
    7.5
    High

    CVE-2020-29321

    Last Modified: 21 Nov 2024

    The D-Link router DIR-868L 3.01 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.

    Published: 4 Jun 2021
    7.5
    High

    CVE-2020-29324

    Last Modified: 21 Nov 2024

    The DLink Router DIR-895L MFC v1.21b05 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.

    Published: 4 Jun 2021