CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2021-22705

    Last Modified: 21 Nov 2024

    Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service or unauthorized access to system information when interacting directly with a driver installed by Vijeo Designer or EcoStruxure Machine Expert

    Published: 26 May 2021
    7.5
    High

    CVE-2021-22699

    Last Modified: 21 Nov 2024

    Improper Input Validation vulnerability exists in Modicon M241/M251 logic controllers firmware prior to V5.1.9.1 that could cause denial of service when specific crafted requests are sent to the controller over HTTP.

    Published: 26 May 2021
    6.5
    Medium

    CVE-2020-22019

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in FFmpeg 4.2 at convolution_y_10bit in libavfilter/vf_vmafmotion.c, which could let a remote malicious user cause a Denial of Service.

    Published: 26 May 2021
    6.5
    Medium

    CVE-2020-22020

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in FFmpeg 4.2 in the build_diff_map function in libavfilter/vf_fieldmatch.c, which could let a remote malicious user cause a Denial of Service.

    Published: 26 May 2021
    8.8
    High

    CVE-2018-16494

    Last Modified: 21 Nov 2024

    In VOS and overly permissive "umask" may allow for authorized users of the server to gain unauthorized access through insecure file permissions that can result in an arbitrary read, write, or execution of newly created files and directories. Insecure umask setting was present throughout the Versa servers.

    Published: 26 May 2021
    8.8
    High

    CVE-2018-16495

    Last Modified: 21 Nov 2024

    In VOS user session identifier (authentication token) is issued to the browser prior to authentication but is not changed after the user successfully logs into the application. Failing to issue a new session ID following a successful login introduces the possibility for an attacker to set up a trap session on the device the victim is likely to login with.

    Published: 26 May 2021
    5.3
    Medium

    CVE-2018-16496

    Last Modified: 21 Nov 2024

    In Versa Director, the un-authentication request found.

    Published: 26 May 2021
    7.8
    High

    CVE-2018-16497

    Last Modified: 31 Aug 2026

    In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server. If the job is run as the user root, there is a potential privilege escalation vulnerability. In this case, the job runs a script as root that is writable by users who are members of the versa group.

    Published: 26 May 2021
    5.5
    Medium

    CVE-2018-16498

    Last Modified: 21 Nov 2024

    In Versa Director, the unencrypted backup files stored on the Versa deployment contain credentials stored within configuration files. These credentials are for various application components such as SNMP, and SSL and Trust keystores.

    Published: 26 May 2021
    5.9
    Medium

    CVE-2018-16499

    Last Modified: 21 Nov 2024

    In VOS compromised, an attacker at network endpoints can possibly view communications between an unsuspecting user and the service using man-in-the-middle attacks. Usage of unapproved SSH encryption protocols or cipher suites also violates the Data Protection TSR (Technical Security Requirements).

    Published: 26 May 2021
    5.5
    Medium

    CVE-2019-25030

    Last Modified: 21 Nov 2024

    In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or key derivation function prior to storage. Popular hashing algorithms based on the Merkle-Damgardconstruction (such as MD5 and SHA-1) alone are insufficient in thwarting password cracking. Attackers can generate and use precomputed hashes for all possible password character combinations (commonly referred to as "rainbow tables") relatively quickly. The use of adaptive hashing algorithms such asscryptorbcryptor Key-Derivation Functions (i.e.PBKDF2) to hash passwords make generation of such rainbow tables computationally infeasible.

    Published: 26 May 2021
    9.8
    Critical

    CVE-2019-25029

    Last Modified: 31 Aug 2026

    In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are possible when an application passes unsafe user supplied data (forms, cookies, HTTP headers etc.) to a system shell. In this attack, the attacker-supplied operating system commands are usually executed with the privileges of the vulnerable application. Command injection attacks are possible largely due to insufficient input validation.

    Published: 26 May 2021
    7.8
    High

    CVE-2020-15076

    Last Modified: 21 Nov 2024

    Private Tunnel installer for macOS version 3.0.1 and older versions may corrupt system critical files it should not have access via symlinks in /tmp.

    Published: 26 May 2021
    9.8
    Critical

    CVE-2021-33470

    Last Modified: 21 Nov 2024

    COVID19 Testing Management System 1.0 is vulnerable to SQL Injection via the admin panel.

    Published: 26 May 2021
    4.8
    Medium

    CVE-2021-33469

    Last Modified: 21 Nov 2024

    COVID19 Testing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the "Admin name" parameter.

    Published: 26 May 2021
    8.8
    High

    CVE-2020-22015

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in FFmpeg 4.2 in mov_write_video_tag due to the out of bounds in libavformat/movenc.c, which could let a remote malicious user obtain sensitive information, cause a Denial of Service, or execute arbitrary code.

    Published: 26 May 2021
    8.2
    High

    CVE-2021-20492

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 197793.

    Published: 26 May 2021
    9.1
    Critical

    CVE-2021-20487

    Last Modified: 21 Nov 2024

    IBM Power9 Self Boot Engine(SBE) could allow a privileged user to inject malicious code and compromise the integrity of the host firmware bypassing the host firmware signature verification process.

    Published: 26 May 2021
    6.5
    Medium

    CVE-2021-20486

    Last Modified: 21 Nov 2024

    IBM Cloud Pak for Data 3.0 could allow an authenticated user to obtain sensitive information when installed with additional plugins. IBM X-Force ID: 197668.

    Published: 26 May 2021
    7.8
    High

    CVE-2019-4588

    Last Modified: 21 Nov 2024

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to execute arbitrary code and conduct DLL hijacking attacks.

    Published: 26 May 2021
    6.1
    Medium

    CVE-2020-18221

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in Typora v0.9.65 and earlier allows remote attackers to execute arbitrary code by injecting commands during block rendering of a mathematical formula.

    Published: 26 May 2021
    7.5
    High

    CVE-2021-33506

    Last Modified: 21 Nov 2024

    jitsi-meet-prosody in Jitsi Meet before 2.0.5963-1 does not ensure that restrict_room_creation is set by default. This can allow an attacker to circumvent conference moderation.

    Published: 26 May 2021
    8.8
    High

    CVE-2020-24020

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in FFMpeg 4.2.3 in dnn_execute_layer_pad in libavfilter/dnn/dnn_backend_native_layer_pad.c due to a call to memcpy without length checks, which could let a remote malicious user execute arbitrary code.

    Published: 26 May 2021
    9.8
    Critical

    CVE-2021-21986

    Last Modified: 21 Nov 2024

    The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Lifecycle Manager, and VMware Cloud Director Availability plug-ins. A malicious actor with network access to port 443 on vCenter Server may perform actions allowed by the impacted plug-ins without authentication.

    Published: 26 May 2021
    9.8
    Critical

    CVE-2021-21985

    Last Modified: 30 Oct 2025

    The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.

    Published: 26 May 2021
    7.5
    High

    CVE-2021-33038

    Last Modified: 21 Nov 2024

    An issue was discovered in management/commands/hyperkitty_import.py in HyperKitty through 1.3.4. When importing a private mailing list's archives, these archives are publicly visible for the duration of the import. For example, sensitive information might be available on the web for an hour during a large migration from Mailman 2 to Mailman 3.

    Published: 26 May 2021
    7.8
    High

    CVE-2021-32457

    Last Modified: 21 Nov 2024

    Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vulnerability which could allow an attacker to issue a specially crafted iotcl to escalate privileges on affected devices. An attacker must first obtain the ability to execute low-privileged code on the target device in order to exploit this vulnerability.

    Published: 26 May 2021
    9.8
    Critical

    CVE-2021-22160

    Last Modified: 21 Nov 2024

    If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if the algorithm of the presented token is set to "none". This allows an attacker to connect to Pulsar instances as any user (incl. admins).

    Published: 26 May 2021
    8.8
    High

    CVE-2020-26677

    Last Modified: 21 Nov 2024

    Any user logged in to a vFairs 3.3 virtual conference or event can perform SQL injection with a malicious query to the API.

    Published: 26 May 2021
    5.4
    Medium

    CVE-2020-26680

    Last Modified: 21 Nov 2024

    In vFairs 3.3, any user logged in to a vFairs virtual conference or event can modify any other users profile information to include a cross-site scripting payload. The user data stored by the database includes HTML tags that are intentionally rendered out onto the page, and this can be abused to perform XSS attacks.

    Published: 26 May 2021
    4.3
    Medium

    CVE-2020-26679

    Last Modified: 21 Nov 2024

    vFairs 3.3 is affected by Insecure Permissions. Any user logged in to a vFairs virtual conference or event can modify any other users profile information or profile picture. After receiving any user's unique identification number and their own, an HTTP POST request can be made update their profile description or supply a new profile image. This can lead to potential cross-site scripting attacks on any user, or upload malicious PHP webshells as "profile pictures." The user IDs can be easily determined by other responses from the API for an event or chat room.

    Published: 26 May 2021
    8.8
    High

    CVE-2020-26678

    Last Modified: 21 Nov 2024

    vFairs 3.3 is affected by Remote Code Execution. Any user logged in to a vFairs virtual conference or event can abuse the functionality to upload a profile picture in order to place a malicious PHP file on the server and gain code execution.

    Published: 26 May 2021
    6.5
    Medium

    CVE-2021-26034

    Last Modified: 25 Feb 2026

    An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in data download endpoints in com_banners and com_sysinfo.

    Published: 26 May 2021
    6.5
    Medium

    CVE-2021-26033

    Last Modified: 25 Feb 2026

    An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in the AJAX reordering endpoint.

    Published: 26 May 2021
    6.1
    Medium

    CVE-2021-26032

    Last Modified: 25 Feb 2026

    An issue was discovered in Joomla! 3.0.0 through 3.9.26. HTML was missing in the executable block list of MediaHelper::canUpload, leading to XSS attack vectors.

    Published: 26 May 2021
    5.4
    Medium

    CVE-2021-27676

    Last Modified: 21 Nov 2024

    Centreon version 20.10.2 is affected by a cross-site scripting (XSS) vulnerability. The dep_description (Dependency Description) and dep_name (Dependency Name) parameters are vulnerable to stored XSS. A user has to log in and go to the Configuration > Notifications > Hosts page.

    Published: 26 May 2021
    5.1
    Medium

    CVE-2021-29253

    Last Modified: 21 Nov 2024

    The Tableau integration in RSA Archer 6.4 P1 (6.4.0.1) through 6.9 P2 (6.9.0.2) is affected by an insecure credential storage vulnerability. An malicious attacker with access to the Tableau workbook file may obtain access to credential information to use it in further attacks.

    Published: 26 May 2021
    5.4
    Medium

    CVE-2021-29252

    Last Modified: 21 Nov 2024

    RSA Archer before 6.9 SP1 P1 (6.9.1.1) contains a stored XSS vulnerability. A remote authenticated malicious Archer user with access to modify link name fields could potentially exploit this vulnerability to execute code in a victim's browser.

    Published: 26 May 2021
    5.3
    Medium

    CVE-2021-22897

    Last Modified: 28 May 2026

    curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The selected cipher set was stored in a single "static" variable in the library, which has the surprising side-effect that if an application sets up multiple concurrent transfers, the last one that sets the ciphers will accidentally control the set used by all transfers. In a worst-case scenario, this weakens transport security significantly.

    Published: 26 May 2021
    7.8
    High

    CVE-2021-30498

    Last Modified: 3 Nov 2025

    A flaw was found in libcaca. A heap buffer overflow in export.c in function export_tga might lead to memory corruption and other potential consequences.

    Published: 26 May 2021
    7.8
    High

    CVE-2021-33200

    Last Modified: 21 Nov 2024

    kernel/bpf/verifier.c in the Linux kernel through 5.12.7 enforces incorrect limits for pointer arithmetic operations, aka CID-bb01a1bba579. This can be abused to perform out-of-bounds reads and writes in kernel memory, leading to local privilege escalation to root. In particular, there is a corner case where the off reg causes a masking direction change, which then results in an incorrect final aux->alu_limit.

    Published: 26 May 2021
    8.1
    High

    CVE-2021-22901

    Last Modified: 21 Nov 2024

    curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstances to potentially reach remote code execution in the client. When libcurl at run-time sets up support for TLS 1.3 session tickets on a connection using OpenSSL, it stores pointers to the transfer in-memory object for later retrieval when a session ticket arrives. If the connection is used by multiple transfers (like with a reused HTTP/1.1 connection or multiplexed HTTP/2 connection) that first transfer object might be freed before the new session is established on that connection and then the function will access a memory buffer that might be freed. When using that memory, libcurl might even call a function pointer in the object, making it possible for a remote code execution if the server could somehow manage to get crafted memory content into the correct place in memory.

    Published: 26 May 2021
    9.8
    Critical

    CVE-2021-22737

    Last Modified: 21 Nov 2024

    Insufficiently Protected Credentials vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cause unauthorized access of when credentials are discovered after a brute force attack.

    Published: 26 May 2021
    5.3
    Medium

    CVE-2021-23425

    Last Modified: 21 Nov 2024

    All versions of package trim-off-newlines are vulnerable to Regular Expression Denial of Service (ReDoS) via string processing.

    Published: 26 May 2021
    7.4
    High

    CVE-2021-25217

    Last Modified: 21 Nov 2024

    In ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16, ISC DHCP 4.4.0 -> 4.4.2 (Other branches of ISC DHCP (i.e., releases in the 4.0.x series or lower and releases in the 4.3.x series) are beyond their End-of-Life (EOL) and no longer supported by ISC. From inspection it is clear that the defect is also present in releases from those series, but they have not been officially tested for the vulnerability), The outcome of encountering the defect while reading a lease that will trigger it varies, according to: the component being affected (i.e., dhclient or dhcpd) whether the package was built as a 32-bit or 64-bit binary whether the compiler flag -fstack-protection-strong was used when compiling In dhclient, ISC has not successfully reproduced the error on a 64-bit system. However, on a 32-bit system it is possible to cause dhclient to crash when reading an improper lease, which could cause network connectivity problems for an affected system due to the absence of a running DHCP client process. In dhcpd, when run in DHCPv4 or DHCPv6 mode: if the dhcpd server binary was built for a 32-bit architecture AND the -fstack-protection-strong flag was specified to the compiler, dhcpd may exit while parsing a lease file containing an objectionable lease, resulting in lack of service to clients. Additionally, the offending lease and the lease immediately following it in the lease database may be improperly deleted. if the dhcpd server binary was built for a 64-bit architecture OR if the -fstack-protection-strong compiler flag was NOT specified, the crash will not occur, but it is possible for the offending lease and the lease which immediately followed it to be improperly deleted.

    Published: 26 May 2021
    9.8
    Critical

    CVE-2021-25945

    Last Modified: 21 Nov 2024

    Prototype pollution vulnerability in 'js-extend' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.

    Published: 26 May 2021
    9.8
    Critical

    CVE-2021-31917

    Last Modified: 21 Nov 2024

    A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authentication on all REST endpoints when DIGEST is used as the authentication method. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 26 May 2021
    3.1
    Low

    CVE-2021-22898

    Last Modified: 16 Apr 2026

    curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol.

    Published: 26 May 2021
    6.8
    Medium

    CVE-2021-31924

    Last Modified: 21 Nov 2024

    Yubico pam-u2f before 1.1.1 has a logic issue that, depending on the pam-u2f configuration and the application used, could lead to a local PIN bypass. This issue does not allow user presence (touch) or cryptographic signature verification to be bypassed, so an attacker would still need to physically possess and interact with the YubiKey or another enrolled authenticator. If pam-u2f is configured to require PIN authentication, and the application using pam-u2f allows the user to submit NULL as the PIN, pam-u2f will attempt to perform a FIDO2 authentication without PIN. If this authentication is successful, the PIN requirement is bypassed.

    Published: 25 May 2021
    9.8
    Critical

    CVE-2021-33575

    Last Modified: 21 Nov 2024

    The Pixar ruby-jss gem before 1.6.0 allows remote attackers to execute arbitrary code because of the Plist gem's documented behavior of using Marshal.load during XML document processing.

    Published: 25 May 2021