CVE Feed

    Dashboard / CVE

    7.7
    High

    CVE-2021-28807

    Last Modified: 21 Nov 2024

    A post-authentication reflected XSS vulnerability has been reported to affect QNAP NAS running Q’center. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already fixed this vulnerability in the following versions of Q’center: QTS 4.5.3: Q’center v1.12.1012 and later QTS 4.3.6: Q’center v1.10.1004 and later QTS 4.3.3: Q’center v1.10.1004 and later QuTS hero h4.5.2: Q’center v1.12.1012 and later QuTScloud c4.5.4: Q’center v1.12.1012 and later

    Published: 3 Jun 2021
    5.7
    Medium

    CVE-2021-28806

    Last Modified: 21 Nov 2024

    A DOM-based XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.3.1652 Build 20210428. QNAP Systems Inc. QuTS hero versions prior to h4.5.2.1638 Build 20210414. QNAP Systems Inc. QuTScloud versions prior to c4.5.5.1656 Build 20210503. This issue does not affect: QNAP Systems Inc. QTS 4.3.6; 4.3.3.

    Published: 3 Jun 2021
    —
    Unknown

    CVE-2021-33805

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-10906. Reason: This candidate is a duplicate of CVE-2018-10906. Notes: All CVE users should reference CVE-2018-10906 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 3 Jun 2021
    7.4
    High

    CVE-2021-32923

    Last Modified: 21 Nov 2024

    HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.

    Published: 3 Jun 2021
    8.8
    High

    CVE-2021-33815

    Last Modified: 21 Nov 2024

    dwa_uncompress in libavcodec/exr.c in FFmpeg 4.4 allows an out-of-bounds array access because dc_count is not strictly checked.

    Published: 3 Jun 2021
    7.5
    High

    CVE-2021-22222

    Last Modified: 21 Nov 2024

    Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet injection or crafted capture file

    Published: 3 Jun 2021
    9.8
    Critical

    CVE-2020-35442

    Last Modified: 21 Nov 2024

    FDCMS (also known as Fangfa Content Management System) 4.0 allows remote attackers to get a webshell in the background via Front/lib/Action/FindexAction.class.php.

    Published: 2 Jun 2021
    9.8
    Critical

    CVE-2020-35441

    Last Modified: 21 Nov 2024

    FDCMS (aka Fangfa Content Management System) 4.0 contains a front-end SQL injection via Admin/Lib/Action/FloginAction.class.php.

    Published: 2 Jun 2021
    5.4
    Medium

    CVE-2021-29670

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199408.

    Published: 2 Jun 2021
    5.4
    Medium

    CVE-2021-29668

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199406.

    Published: 2 Jun 2021
    6.5
    Medium

    CVE-2021-20371

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195516.

    Published: 2 Jun 2021
    5.4
    Medium

    CVE-2021-20348

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-ForceID: 194597.

    Published: 2 Jun 2021
    5.4
    Medium

    CVE-2021-20347

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194596.

    Published: 2 Jun 2021
    5.4
    Medium

    CVE-2021-20346

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194595.

    Published: 2 Jun 2021
    5.4
    Medium

    CVE-2021-20345

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194594.

    Published: 2 Jun 2021
    5.4
    Medium

    CVE-2021-20343

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194593.

    Published: 2 Jun 2021
    5.4
    Medium

    CVE-2021-20338

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194449.

    Published: 2 Jun 2021
    5.4
    Medium

    CVE-2020-5030

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 193737.

    Published: 2 Jun 2021
    5.4
    Medium

    CVE-2020-4977

    Last Modified: 21 Nov 2024

    IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192470.

    Published: 2 Jun 2021
    6.5
    Medium

    CVE-2020-4732

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due to lack of security restrictions. IBM X-Force ID: 188126.

    Published: 2 Jun 2021
    8.8
    High

    CVE-2020-4495

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a specially-crafted request to the REST API, an attacker could exploit this vulnerability to bypass access restrictions, and execute arbitrary actions with administrative privileges. IBM X-Force ID: 182114.

    Published: 2 Jun 2021
    6.5
    Medium

    CVE-2020-22056

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the config_input function in af_acrossover.c.

    Published: 2 Jun 2021
    6.5
    Medium

    CVE-2020-22054

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_dict_set function in dict.c.

    Published: 2 Jun 2021
    7.5
    High

    CVE-2020-25362

    Last Modified: 21 Nov 2024

    The id paramater in Online Shopping Alphaware 1.0 has been discovered to be vulnerable to an Error-Based blind SQL injection in the /alphaware/details.php path. This allows an attacker to retrieve all databases.

    Published: 2 Jun 2021
    7.5
    High

    CVE-2020-24862

    Last Modified: 21 Nov 2024

    The catID parameter in Pharmacy Medical Store and Sale Point v1.0 has been found to be vulnerable to a Time-Based blind SQL injection via the /medical/inventories.php path which allows attackers to retrieve all databases.

    Published: 2 Jun 2021
    6.5
    Medium

    CVE-2020-22051

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the filter_frame function in vf_tile.c.

    Published: 2 Jun 2021
    6.5
    Medium

    CVE-2020-22049

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the wtvfile_open_sector function in wtvdec.c.

    Published: 2 Jun 2021
    6.5
    Medium

    CVE-2020-22048

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_frame_pool_get function in framepool.c.

    Published: 2 Jun 2021
    6.5
    Medium

    CVE-2020-22046

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the avpriv_float_dsp_allocl function in libavutil/float_dsp.c.

    Published: 2 Jun 2021
    3.2
    Low

    CVE-2021-23896

    Last Modified: 21 Nov 2024

    Cleartext Transmission of Sensitive Information vulnerability in the administrator interface of McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to view the unencrypted password of the McAfee Insights Server used to pass data to the Insights Server. This user is restricted to only have access to DBSec data in the Insights Server.

    Published: 2 Jun 2021
    9
    Critical

    CVE-2021-23895

    Last Modified: 21 Nov 2024

    Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authenticated attacker to create a reverse shell with administrator privileges on the DBSec server via carefully constructed Java serialized object sent to the DBSec server.

    Published: 2 Jun 2021
    9.6
    Critical

    CVE-2021-23894

    Last Modified: 21 Nov 2024

    Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote unauthenticated attacker to create a reverse shell with administrator privileges on the DBSec server via carefully constructed Java serialized object sent to the DBSec server.

    Published: 2 Jun 2021
    6.5
    Medium

    CVE-2021-24012

    Last Modified: 21 Nov 2024

    An improper following of a certificate's chain of trust vulnerability in FortiGate versions 6.4.0 to 6.4.4 may allow an LDAP user to connect to SSLVPN with any certificate that is signed by a trusted Certificate Authority.

    Published: 2 Jun 2021
    —
    Unknown

    CVE-2021-26940

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-33500. Reason: This candidate is a reservation duplicate of CVE-2021-33500. Notes: All CVE users should reference CVE-2021-33500 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 2 Jun 2021
    4.3
    Medium

    CVE-2020-6641

    Last Modified: 21 Nov 2024

    Two authorization bypass through user-controlled key vulnerabilities in the Fortinet FortiPresence 2.1.0 administration interface may allow an attacker to gain access to some user data via portal manager or portal users parameters.

    Published: 2 Jun 2021
    9.8
    Critical

    CVE-2021-29089

    Last Modified: 21 Nov 2024

    Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in thumbnail component in Synology Photo Station before 6.8.14-3500 allows remote attackers users to execute arbitrary SQL commands via unspecified vectors.

    Published: 2 Jun 2021
    7.2
    High

    CVE-2021-29090

    Last Modified: 21 Nov 2024

    Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in PHP component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to execute arbitrary SQL command via unspecified vectors.

    Published: 2 Jun 2021
    7.7
    High

    CVE-2021-29091

    Last Modified: 21 Nov 2024

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to write arbitrary files via unspecified vectors.

    Published: 2 Jun 2021
    7.5
    High

    CVE-2021-33560

    Last Modified: 3 Dec 2025

    Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.

    Published: 2 Jun 2021
    6.5
    Medium

    CVE-2021-31855

    Last Modified: 21 Nov 2024

    KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g., an IMAP server) causes KMail to upload the decrypted content of the message to the remote server. With a crafted message, a user could be tricked into decrypting an encrypted message and then deleting an attachment attached to this message. If the attacker has access to the messages stored on the email server, then the attacker could read the decrypted content of the encrypted message. This occurs in ViewerPrivate::deleteAttachment in messageviewer/src/viewer/viewer_p.cpp.

    Published: 2 Jun 2021
    9.8
    Critical

    CVE-2021-30474

    Last Modified: 21 Nov 2024

    aom_dsp/grain_table.c in libaom in AOMedia before 2021-03-30 has a use-after-free.

    Published: 2 Jun 2021
    4.9
    Medium

    CVE-2021-33203

    Last Modified: 21 Nov 2024

    Django before 2.2.24, 3.x before 3.1.12, and 3.2.x before 3.2.4 has a potential directory traversal via django.contrib.admindocs. Staff members could use the TemplateDetailView view to check the existence of arbitrary files. Additionally, if (and only if) the default admindocs templates have been customized by application developers to also show file contents, then not only the existence but also the file contents would have been exposed. In other words, there is directory traversal outside of the template root directories.

    Published: 2 Jun 2021
    7.5
    High

    CVE-2021-33571

    Last Modified: 21 Nov 2024

    In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit leading zero characters in octal literals. This may allow a bypass of access control that is based on IP addresses. (validate_ipv4_address and validate_ipv46_address are unaffected with Python 3.9.5+..) .

    Published: 2 Jun 2021
    4.3
    Medium

    CVE-2021-32657

    Last Modified: 21 Nov 2024

    Nextcloud Server is a Nextcloud package that handles data storage. In versions of Nextcloud Server prior to 10.0.11, 20.0.10, and 21.0.2, a malicious user may be able to break the user administration page. This would disallow administrators to administrate users on the Nextcloud instance. The vulnerability is fixed in versions 19.0.11, 20.0.10, and 21.0.2. As a workaround, administrators can use the OCC command line tool to administrate the Nextcloud users.

    Published: 1 Jun 2021
    8.6
    High

    CVE-2021-32656

    Last Modified: 21 Nov 2024

    Nextcloud Server is a Nextcloud package that handles data storage. A vulnerability in federated share exists in versions prior to 19.0.11, 20.0.10, and 21.0.2. An attacker can gain access to basic information about users of a server by accessing a public link that a legitimate server user added as a federated share. This happens because Nextcloud supports sharing registered users with other Nextcloud servers, which can be done automatically when selecting the "Add server automatically once a federated share was created successfully" setting. The vulnerability is patched in versions 19.0.11, 20.0.10, and 21.0.2 As a workaround, disable "Add server automatically once a federated share was created successfully" in the Nextcloud settings.

    Published: 1 Jun 2021
    3.5
    Low

    CVE-2021-32655

    Last Modified: 21 Nov 2024

    Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.11, 20.0.10, and 21.0.2, an attacker is able to convert a Files Drop link to a federated share. This causes an issue on the UI side of the sharing user. When the sharing user opens the sharing panel and tries to remove the "Create" privileges of this unexpected share, Nextcloud server would silently grant the share read privileges. The vulnerability is patched in versions 19.0.11, 20.0.10 and 21.0.2. No workarounds are known to exist.

    Published: 1 Jun 2021
    8.1
    High

    CVE-2021-32654

    Last Modified: 21 Nov 2024

    Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.11, 20.0.10, and 21.0.2, an attacker is able to receive write/read privileges on any Federated File Share. Since public links can be added as federated file share, this can also be exploited on any public link. Users can upgrade to patched versions (19.0.11, 20.0.10 or 21.0.2) or, as a workaround, disable federated file sharing.

    Published: 1 Jun 2021
    6.5
    Medium

    CVE-2020-22044

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the url_open_dyn_buf_internal function in libavformat/aviobuf.c.

    Published: 1 Jun 2021
    7.6
    High

    CVE-2021-22123

    Last Modified: 21 Nov 2024

    An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x, 5.9.x may allow a remote authenticated attacker to execute arbitrary commands on the system via the SAML server configuration page.

    Published: 1 Jun 2021
    6.5
    Medium

    CVE-2020-22043

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak at the fifo_alloc_common function in libavutil/fifo.c.

    Published: 1 Jun 2021