CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-31618

    Last Modified: 21 Nov 2024

    Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server and used for the HTTP/1 protocol as well. On violation of these restrictions and HTTP response is sent to the client with a status code indicating why the request was rejected. This rejection response was not fully initialised in the HTTP/2 protocol handler if the offending header was the very first one received or appeared in a a footer. This led to a NULL pointer dereference on initialised memory, crashing reliably the child process. Since such a triggering HTTP/2 request is easy to craft and submit, this can be exploited to DoS the server. This issue affected mod_http2 1.15.17 and Apache HTTP Server version 2.4.47 only. Apache HTTP Server 2.4.47 was never released.

    Published: 4 Jun 2021
    9.8
    Critical

    CVE-2021-26691

    Last Modified: 21 Nov 2024

    In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow

    Published: 4 Jun 2021
    7.3
    High

    CVE-2020-35452

    Last Modified: 21 Nov 2024

    Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation option might make it possible, with limited consequences anyway due to the size (a single byte) and the value (zero byte) of the overflow

    Published: 4 Jun 2021
    7.5
    High

    CVE-2021-33838

    Last Modified: 21 Nov 2024

    Luca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because requests related to Check-In State occur shortly after requests for Phone Number Registration.

    Published: 3 Jun 2021
    7.5
    High

    CVE-2021-33839

    Last Modified: 21 Nov 2024

    Luca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because the QR code of a Public Location can be intentionally confused with the QR code of a Private Meeting.

    Published: 3 Jun 2021
    7.5
    High

    CVE-2021-33840

    Last Modified: 21 Nov 2024

    The server in Luca through 1.1.14 allows remote attackers to cause a denial of service (insertion of many fake records related to COVID-19) because Phone Number data lacks a digital signature.

    Published: 3 Jun 2021
    7.5
    High

    CVE-2020-36009

    Last Modified: 21 Nov 2024

    OBottle 2.0 in \c\g.php contains an arbitrary file download vulnerability.

    Published: 3 Jun 2021
    8.1
    High

    CVE-2020-36008

    Last Modified: 21 Nov 2024

    OBottle 2.0 in \c\t.php contains an arbitrary file write vulnerability.

    Published: 3 Jun 2021
    6.1
    Medium

    CVE-2020-36007

    Last Modified: 21 Nov 2024

    AppCMS 2.0.101 in /admin/template/tpl_app.php has a cross site scripting attack vulnerability which allows the attacker to obtain sensitive information of other users.

    Published: 3 Jun 2021
    6.5
    Medium

    CVE-2020-36006

    Last Modified: 21 Nov 2024

    AppCMS 2.0.101 in /admin/info.php has an arbitrary file deletion vulnerability which allows attackers to delete arbitrary files on the site.

    Published: 3 Jun 2021
    6.5
    Medium

    CVE-2020-36005

    Last Modified: 21 Nov 2024

    AppCMS 2.0.101 in /admin/app.php has an arbitrary file deletion vulnerability which allows attackers to delete arbitrary files on the site.

    Published: 3 Jun 2021
    6.5
    Medium

    CVE-2020-36004

    Last Modified: 21 Nov 2024

    AppCMS 2.0.101 in /admin/download_frame.php has a SQL injection vulnerability which allows attackers to obtain sensitive database information.

    Published: 3 Jun 2021
    6.5
    Medium

    CVE-2021-32662

    Last Modified: 21 Nov 2024

    Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In `@backstage/techdocs-common` versions prior to 0.6.3, a malicious actor could read sensitive files from the environment where TechDocs documentation is built and published by setting a particular path for `docs_dir` in `mkdocs.yml`. These files would then be available over the TechDocs backend API. This vulnerability is mitigated by the fact that an attacker would need access to modify the `mkdocs.yml` in the documentation source code, and would also need access to the TechDocs backend API. The vulnerability is patched in the `0.6.3` release of `@backstage/techdocs-common`.

    Published: 3 Jun 2021
    6.5
    Medium

    CVE-2021-32666

    Last Modified: 21 Nov 2024

    wire-ios is the iOS version of Wire, an open-source secure messaging app. In wire-ios versions 3.8.0 and prior, a vulnerability exists that can cause a denial of service between users. If a user has an invalid assetID for their profile picture and it contains the " character, it will cause the iOS client to crash. The vulnerability is patched in wire-ios version 3.8.1.

    Published: 3 Jun 2021
    8.8
    High

    CVE-2021-32665

    Last Modified: 21 Nov 2024

    wire-ios is the iOS version of Wire, an open-source secure messaging app. wire-ios versions 3.8.0 and earlier have a bug in which a conversation could be incorrectly set to "unverified. This occurs when: - Self user is added to a new conversation - Self user is added to an existing conversation - All the participants in the conversation were previously marked as verified. The vulnerability is patched in wire-ios version 3.8.1. As a workaround, one can unverify & verify a device in the conversation.

    Published: 3 Jun 2021
    7.5
    High

    CVE-2020-35970

    Last Modified: 21 Nov 2024

    An issue was discovered in YzmCMS 5.8. There is a SSRF vulnerability in the background collection management that allows arbitrary file read.

    Published: 3 Jun 2021
    5.4
    Medium

    CVE-2020-35971

    Last Modified: 21 Nov 2024

    A storage XSS vulnerability is found in YzmCMS v5.8, which can be used by attackers to inject JS code and attack malicious XSS on the /admin/system_manage/user_config_edit.html page.

    Published: 3 Jun 2021
    4.3
    Medium

    CVE-2020-35972

    Last Modified: 21 Nov 2024

    An issue was discovered in YzmCMS V5.8. There is a CSRF vulnerability that can add member user accounts via member/member/add.html.

    Published: 3 Jun 2021
    5.4
    Medium

    CVE-2020-35973

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms2020. There is a XSS vulnerability that can insert and execute JS code arbitrarily via /user/manage.php.

    Published: 3 Jun 2021
    9.8
    Critical

    CVE-2021-25947

    Last Modified: 21 Nov 2024

    Prototype pollution vulnerability in 'nestie' versions 0.0.0 through 1.0.0 allows an attacker to cause a denial of service and may lead to remote code execution.

    Published: 3 Jun 2021
    7.4
    High

    CVE-2021-22334

    Last Modified: 21 Nov 2024

    There is an Improper Access Control vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause app redirections.

    Published: 3 Jun 2021
    7.8
    High

    CVE-2021-22335

    Last Modified: 21 Nov 2024

    There is a Memory Buffer Improper Operation Limit vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause exceptions in image processing.

    Published: 3 Jun 2021
    5.3
    Medium

    CVE-2021-22337

    Last Modified: 21 Nov 2024

    There is an Information Disclosure vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause leaking of user click data.

    Published: 3 Jun 2021
    9.8
    Critical

    CVE-2021-22333

    Last Modified: 21 Nov 2024

    There is an Improper Validation of Array Index vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause code to execute, thus obtaining system permissions.

    Published: 3 Jun 2021
    6.8
    Medium

    CVE-2021-32661

    Last Modified: 21 Nov 2024

    Backstage is an open platform for building developer portals. In versions of Backstage's Techdocs Plugin (`@backstage/plugin-techdocs`) prior to 0.9.5, a malicious internal actor can potentially upload documentation content with malicious scripts by embedding the script within an `object` element. This may give access to sensitive data when other users visit that same documentation page. The ability to upload malicious content may be limited by internal code review processes, unless the chosen TechDocs deployment method is to use an object store and the actor has access to upload files directly to that store. The vulnerability is patched in the `0.9.5` release of `@backstage/plugin-techdocs`.

    Published: 3 Jun 2021
    6.8
    Medium

    CVE-2021-32660

    Last Modified: 21 Nov 2024

    Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In versions of `@backstage/tehdocs-common` prior to 0.6.4, a malicious internal actor is able to upload documentation content with malicious scripts. These scripts would normally be sanitized by the TechDocs frontend, but by tricking a user to visit the content via the TechDocs API, the content sanitazion will be bypassed. If the TechDocs API is hosted on the same origin as the Backstage app or other backend plugins, this may give access to sensitive data. The ability to upload malicious content may be limited by internal code review processes, unless the chosen TechDocs deployment method is to use an object store and the actor has access to upload files directly to that store. The vulnerability is patched in the `0.6.4` release of `@backstage/techdocs-common`.

    Published: 3 Jun 2021
    7.5
    High

    CVE-2021-22336

    Last Modified: 21 Nov 2024

    There is an Improper Control of Generation of Code vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause denial of security services on a rooted device.

    Published: 3 Jun 2021
    7.5
    High

    CVE-2021-22324

    Last Modified: 21 Nov 2024

    There is a Credentials Management Errors vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may impair data confidentiality.

    Published: 3 Jun 2021
    5.3
    Medium

    CVE-2021-22325

    Last Modified: 21 Nov 2024

    There is an Information Disclosure vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may result in video streams being intercepted during transmission.

    Published: 3 Jun 2021
    7.5
    High

    CVE-2021-22322

    Last Modified: 21 Nov 2024

    There is a Missing Authentication for Critical Function vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may impair data confidentiality.

    Published: 3 Jun 2021
    6.8
    Medium

    CVE-2021-22316

    Last Modified: 21 Nov 2024

    There is a Missing Authentication for Critical Function vulnerability in Huawei Smartphone. Attackers with physical access to the device can thereby exploit this vulnerability. A successful exploitation of this vulnerability can compromise the device's data security and functional availability.

    Published: 3 Jun 2021
    7.5
    High

    CVE-2021-22317

    Last Modified: 21 Nov 2024

    There is an Information Disclosure vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may impair data confidentiality.

    Published: 3 Jun 2021
    7.5
    High

    CVE-2021-22313

    Last Modified: 21 Nov 2024

    There is a Security Function vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may impair data confidentiality.

    Published: 3 Jun 2021
    3.3
    Low

    CVE-2021-22308

    Last Modified: 21 Nov 2024

    There is a Business Logic Errors vulnerability in Huawei Smartphone. The malicious apps installed on the device can keep taking screenshots in the background. This issue does not cause system errors, but may cause personal information leakage.

    Published: 3 Jun 2021
    7.5
    High

    CVE-2021-20380

    Last Modified: 21 Nov 2024

    IBM QRadar Advisor With Watson App 1.1 through 2.5 as used on IBM QRadar SIEM 7.4 could allow a remote user to obtain sensitive information from HTTP requests that could aid in further attacks against the system. IBM X-Force ID: 195712.

    Published: 3 Jun 2021
    4.8
    Medium

    CVE-2020-21003

    Last Modified: 21 Nov 2024

    Pbootcms v2.0.3 is vulnerable to Cross Site Scripting (XSS) via admin.php.

    Published: 3 Jun 2021
    6.5
    Medium

    CVE-2020-21005

    Last Modified: 21 Nov 2024

    WellCMS 2.0 beta3 is vulnerable to File Upload. A user can log in to the CMS background and upload a picture. Because the upload file type is controllable, the user can modify the upload file type to get webshell.

    Published: 3 Jun 2021
    7.5
    High

    CVE-2021-32926

    Last Modified: 4 Jun 2026

    When an authenticated password change request takes place, this vulnerability could allow the attacker to intercept the message that includes the legitimate, new password hash and replace it with an illegitimate hash. The user would no longer be able to authenticate to the controller (Micro800: All versions, MicroLogix 1400: Version 21 and later) causing a denial-of-service condition

    Published: 3 Jun 2021
    9.8
    Critical

    CVE-2021-33806

    Last Modified: 21 Nov 2024

    The BDew BdLib library before 1.16.1.7 for Minecraft allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObject as part of its use of Java serialization.

    Published: 3 Jun 2021
    7.5
    High

    CVE-2021-28848

    Last Modified: 21 Nov 2024

    Mintty before 3.4.5 allows remote servers to cause a denial of service (Windows GUI hang) by telling the Mintty window to change its title repeatedly at high speed, which results in many SetWindowTextA or SetWindowTextW calls. In other words, it does not implement a usleep or similar delay upon processing a title change.

    Published: 3 Jun 2021
    6.1
    Medium

    CVE-2021-26584

    Last Modified: 21 Nov 2024

    A security vulnerability in HPE OneView for VMware vCenter (OV4VC) could be exploited remotely to allow Cross-Site Scripting. HPE has released the following software update to resolve the vulnerability in HPE OneView for VMware vCenter (OV4VC).

    Published: 3 Jun 2021
    7.5
    High

    CVE-2021-28847

    Last Modified: 21 Nov 2024

    MobaXterm before 21.0 allows remote servers to cause a denial of service (Windows GUI hang) via tab title change requests that are sent repeatedly at high speed, which results in many SetWindowTextA or SetWindowTextW calls.

    Published: 3 Jun 2021
    7.8
    High

    CVE-2021-32460

    Last Modified: 21 Nov 2024

    The Trend Micro Maximum Security 2021 (v17) consumer product is vulnerable to an improper access control vulnerability in the installer which could allow a local attacker to escalate privileges on a target machine. Please note than an attacker must already have local user privileges and access on the machine to exploit this vulnerability.

    Published: 3 Jun 2021
    7.8
    High

    CVE-2021-24023

    Last Modified: 21 Nov 2024

    An improper input validation in FortiAI v1.4.0 and earlier may allow an authenticated user to gain system shell access via a malicious payload in the "diagnose" command.

    Published: 3 Jun 2021
    6.7
    Medium

    CVE-2021-22130

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow vulnerability in FortiProxy physical appliance CLI 2.0.0 to 2.0.1, 1.2.0 to 1.2.9, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 may allow an authenticated, remote attacker to perform a Denial of Service attack by running the `diagnose sys cpuset` with a large cpuset mask value. Fortinet is not aware of any successful exploitation of this vulnerability that would lead to code execution.

    Published: 3 Jun 2021
    5.9
    Medium

    CVE-2021-31830

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to embed JavaScript code when configuring the name of a database to be monitored. This would be triggered when any authorized user logs into the DBSec interface and opens the properties configuration page for this database.

    Published: 3 Jun 2021
    4.9
    Medium

    CVE-2021-31831

    Last Modified: 21 Nov 2024

    Incorrect access to deleted scripts vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authenticated attacker to gain access to signed SQL scripts which have been marked as deleted or expired within the administrative console. This access was only available through the REST API.

    Published: 3 Jun 2021
    7.8
    High

    CVE-2021-3560

    Last Modified: 6 Nov 2025

    It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 3 Jun 2021
    7.8
    High

    CVE-2021-3551

    Last Modified: 21 Nov 2024

    A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin password and gain admin privileges to the Dogtag CA manager. The highest threat from this vulnerability is to confidentiality.

    Published: 3 Jun 2021
    8.8
    High

    CVE-2021-28812

    Last Modified: 21 Nov 2024

    A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Video Station versions prior to 5.5.4 on QTS 4.5.2; versions prior to 5.5.4 on QuTS hero h4.5.2; versions prior to 5.5.4 on QuTScloud c4.5.4. This issue does not affect: QNAP Systems Inc. Video Station on QTS 4.3.6; on QTS 4.3.3.

    Published: 3 Jun 2021