CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2020-26555

    Last Modified: 4 Nov 2025

    Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing without knowledge of the PIN.

    Published: 24 May 2021
    8.8
    High

    CVE-2020-26559

    Last Modified: 4 Nov 2025

    Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the provisioning protocol) to identify the AuthValue used given the Provisioner’s public key, and the confirmation number and nonce provided by the provisioning device. This could permit a device without the AuthValue to complete provisioning without brute-forcing the AuthValue.

    Published: 24 May 2021
    4.2
    Medium

    CVE-2020-26558

    Last Modified: 4 Nov 2025

    Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the authentication evidence of the initiating device, potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session. The attack methodology determines the Passkey value one bit at a time.

    Published: 24 May 2021
    7.5
    High

    CVE-2020-26556

    Last Modified: 21 Nov 2024

    Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack on an insufficiently random AuthValue before the provisioning procedure times out, to complete authentication by leveraging Malleable Commitment.

    Published: 24 May 2021
    9.8
    Critical

    CVE-2021-29300

    Last Modified: 21 Nov 2024

    The @ronomon/opened library before 1.5.2 is vulnerable to a command injection vulnerability which would allow a remote attacker to execute commands on the system if the library was used with untrusted input.

    Published: 24 May 2021
    7.2
    High

    CVE-2021-32629

    Last Modified: 21 Nov 2024

    Cranelift is an open-source code generator maintained by Bytecode Alliance. It translates a target-independent intermediate representation into executable machine code. There is a bug in 0.73 of the Cranelift x64 backend that can create a scenario that could result in a potential sandbox escape in a Wasm program. This bug was introduced in the new backend on 2020-09-08 and first included in a release on 2020-09-30, but the new backend was not the default prior to 0.73. The recently-released version 0.73 with default settings, and prior versions with an explicit build flag to select the new backend, are vulnerable. The bug in question performs a sign-extend instead of a zero-extend on a value loaded from the stack, under a specific set of circumstances. If those circumstances occur, the bug could allow access to memory addresses upto 2GiB before the start of the Wasm program heap. If the heap bound is larger than 2GiB, then it would be possible to read memory from a computable range dependent on the size of the heaps bound. The impact of this bug is highly dependent on heap implementation, specifically: * if the heap has bounds checks, and * does not rely exclusively on guard pages, and * the heap bound is 2GiB or smaller * then this bug cannot be used to reach memory from another Wasm program heap. The impact of the vulnerability is mitigated if there is no memory mapped in the range accessible using this bug, for example, if there is a 2 GiB guard region before the Wasm program heap. The bug in question performs a sign-extend instead of a zero-extend on a value loaded from the stack, when the register allocator reloads a spilled integer value narrower than 64 bits. This interacts poorly with another optimization: the instruction selector elides a 32-to-64-bit zero-extend operator when we know that an instruction producing a 32-bit value actually zeros the upper 32 bits of its destination register. Hence, we rely on these zeroed bits, but the type of the value is still i32, and the spill/reload reconstitutes those bits as the sign extension of the i32’s MSB. The issue would thus occur when: * An i32 value in a Wasm program is greater than or equal to 0x8000_0000; * The value is spilled and reloaded by the register allocator due to high register pressure in the program between the value’s definition and its use; * The value is produced by an instruction that we know to be “special” in that it zeroes the upper 32 bits of its destination: add, sub, mul, and, or; * The value is then zero-extended to 64 bits in the Wasm program; * The resulting 64-bit value is used. Under these circumstances there is a potential sandbox escape when the i32 value is a pointer. The usual code emitted for heap accesses zero-extends the Wasm heap address, adds it to a 64-bit heap base, and accesses the resulting address. If the zero-extend becomes a sign-extend, the program could reach backward and access memory up to 2GiB before the start of its heap. In addition to assessing the nature of the code generation bug in Cranelift, we have also determined that under specific circumstances, both Lucet and Wasmtime using this version of Cranelift may be exploitable. See referenced GitHub Advisory for more details.

    Published: 24 May 2021
    9.8
    Critical

    CVE-2019-12348

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 2019. SQL Injection exists in user/ztconfig.php via the daohang or img POST parameter.

    Published: 24 May 2021
    7.2
    High

    CVE-2021-20557

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 199184.

    Published: 24 May 2021
    5.3
    Medium

    CVE-2021-20428

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196315.

    Published: 24 May 2021
    9.8
    Critical

    CVE-2021-20426

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196313.

    Published: 24 May 2021
    7.5
    High

    CVE-2021-20419

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196280.

    Published: 24 May 2021
    7.8
    High

    CVE-2021-20389

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.2 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 195770.

    Published: 24 May 2021
    6.1
    Medium

    CVE-2021-20386

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195767.

    Published: 24 May 2021
    7.2
    High

    CVE-2021-20385

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 195766.

    Published: 24 May 2021
    8.8
    High

    CVE-2020-4990

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 192710.

    Published: 24 May 2021
    6.4
    Medium

    CVE-2021-3485

    Last Modified: 21 Nov 2024

    An Improper Input Validation vulnerability in the Product Update feature of Bitdefender Endpoint Security Tools for Linux allows a man-in-the-middle attacker to abuse the DownloadFile function of the Product Update to achieve remote code execution. This issue affects: Bitdefender Endpoint Security Tools for Linux versions prior to 6.2.21.155.

    Published: 24 May 2021
    6.5
    Medium

    CVE-2020-25408

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) vulnerability exists in ProjectWorlds College Management System Php 1.0 that allows a remote attacker to modify, delete, or make a new entry of the student, faculty, teacher, subject, scores, location, and article data.

    Published: 24 May 2021
    6.5
    Medium

    CVE-2020-28911

    Last Modified: 21 Nov 2024

    Incorrect Access Control in Nagios Fusion 4.1.8 and earlier allows low-privileged authenticated users to extract passwords used to manage fused servers via the test_server command in ajaxhelper.php.

    Published: 24 May 2021
    9.8
    Critical

    CVE-2020-28910

    Last Modified: 21 Nov 2024

    Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of symlinks, which are mishandled in getprofile.sh.

    Published: 24 May 2021
    8.8
    High

    CVE-2020-28909

    Last Modified: 21 Nov 2024

    Incorrect File Permissions in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root via modification of scripts. Low-privileges users are able to modify files that can be executed by sudo.

    Published: 24 May 2021
    9.8
    Critical

    CVE-2020-28908

    Last Modified: 21 Nov 2024

    Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to nagios.

    Published: 24 May 2021
    9.8
    Critical

    CVE-2020-28907

    Last Modified: 21 Nov 2024

    Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to download of an untrusted update package in upgrade_to_latest.sh.

    Published: 24 May 2021
    8.8
    High

    CVE-2020-28906

    Last Modified: 21 Nov 2024

    Incorrect File Permissions in Nagios XI 5.7.5 and earlier and Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root. Low-privileged users are able to modify files that are included (aka sourced) by scripts executed by root.

    Published: 24 May 2021
    8.8
    High

    CVE-2020-28905

    Last Modified: 21 Nov 2024

    Improper Input Validation in Nagios Fusion 4.1.8 and earlier allows an authenticated attacker to execute remote code via table pagination.

    Published: 24 May 2021
    9.8
    Critical

    CVE-2020-28904

    Last Modified: 21 Nov 2024

    Execution with Unnecessary Privileges in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation as nagios via installation of a malicious component containing PHP code.

    Published: 24 May 2021
    6.1
    Medium

    CVE-2020-28903

    Last Modified: 21 Nov 2024

    Improper input validation in Nagios Fusion 4.1.8 and earlier allows a remote attacker with control over a fused server to inject arbitrary HTML, aka XSS.

    Published: 24 May 2021
    9.8
    Critical

    CVE-2020-28902

    Last Modified: 21 Nov 2024

    Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmd_subsys.php.

    Published: 24 May 2021
    9.8
    Critical

    CVE-2020-28901

    Last Modified: 21 Nov 2024

    Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vectors related to corrupt component installation in cmd_subsys.php.

    Published: 24 May 2021
    9.8
    Critical

    CVE-2020-28900

    Last Modified: 21 Nov 2024

    Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_to_latest.sh.

    Published: 24 May 2021
    9.8
    Critical

    CVE-2021-32075

    Last Modified: 21 Nov 2024

    Re-Logic Terraria before 1.4.2.3 performs Insecure Deserialization.

    Published: 24 May 2021
    6.1
    Medium

    CVE-2020-26006

    Last Modified: 21 Nov 2024

    Project Worlds Online Examination System 1.0 is affected by Cross Site Scripting (XSS) via account.php.

    Published: 24 May 2021
    6.5
    Medium

    CVE-2020-25411

    Last Modified: 21 Nov 2024

    Projectworlds Online Examination System 1.0 is vulnerable to CSRF, which allows a remote attacker to delete the existing user.

    Published: 24 May 2021
    9.8
    Critical

    CVE-2020-25409

    Last Modified: 21 Nov 2024

    Projectsworlds College Management System Php 1.0 is vulnerable to SQL injection issues over multiple parameters.

    Published: 24 May 2021
    6.5
    Medium

    CVE-2021-21989

    Last Modified: 21 Nov 2024

    VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (TTC Parser). A malicious actor with access to a virtual machine or remote desktop may be able to exploit these issues leading to information disclosure from the TPView process running on the system where Workstation or Horizon Client for Windows is installed.

    Published: 24 May 2021
    6.5
    Medium

    CVE-2021-21988

    Last Modified: 21 Nov 2024

    VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (JPEG2000 Parser). A malicious actor with access to a virtual machine or remote desktop may be able to exploit these issues leading to information disclosure from the TPView process running on the system where Workstation or Horizon Client for Windows is installed.

    Published: 24 May 2021
    6.5
    Medium

    CVE-2021-21987

    Last Modified: 21 Nov 2024

    VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (TTC Parser). A malicious actor with access to a virtual machine or remote desktop may be able to exploit these issues leading to information disclosure from the TPView process running on the system where Workstation or Horizon Client for Windows is installed.

    Published: 24 May 2021
    9.1
    Critical

    CVE-2021-21001

    Last Modified: 15 Aug 2025

    On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges.

    Published: 24 May 2021
    5.3
    Medium

    CVE-2021-21000

    Last Modified: 15 Aug 2025

    On WAGO PFC200 devices in different firmware versions with special crafted packets an attacker with network access to the device could cause a denial of service for the login service of the runtime.

    Published: 24 May 2021
    5.4
    Medium

    CVE-2021-24306

    Last Modified: 21 Nov 2024

    The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not properly sanitise, validate or encode the query string when generating a link to edit user's own profile, leading to an authenticated reflected Cross-Site Scripting issue. Knowledge of the targeted username is required to exploit this, and attackers would then need to make the related logged in user open a malicious link.

    Published: 24 May 2021
    8.8
    High

    CVE-2021-24307

    Last Modified: 21 Nov 2024

    The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticated users with "aioseo_tools_settings" privilege (most of the time admin) to execute arbitrary code on the underlying host. Users can restore plugin's configuration by uploading a backup .ini file in the section "Tool > Import/Export". However, the plugin attempts to unserialize values of the .ini file. Moreover, the plugin embeds Monolog library which can be used to craft a gadget chain and thus trigger system command execution.

    Published: 24 May 2021
    5.4
    Medium

    CVE-2021-24308

    Last Modified: 21 Nov 2024

    The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.1 is not properly sanitised when output in the About section of the profile page, leading to a stored Cross-Site Scripting issue. This could allow low privilege users (such as students) to elevate their privilege via an XSS attack when an admin will view their profile.

    Published: 24 May 2021
    4.8
    Medium

    CVE-2021-24332

    Last Modified: 21 Nov 2024

    The Autoptimize WordPress plugin before 2.8.4 was missing proper escaping and sanitisation in some of its settings, allowing high privilege users to set XSS payloads in them, leading to stored Cross-Site Scripting issues

    Published: 24 May 2021
    6.1
    Medium

    CVE-2021-24300

    Last Modified: 21 Nov 2024

    The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-Site Scripting issue

    Published: 24 May 2021
    6.1
    Medium

    CVE-2021-24297

    Last Modified: 21 Nov 2024

    The Goto WordPress theme before 2.1 did not properly sanitize the formvalue JSON POST parameter in its tl_filter AJAX action, leading to an unauthenticated Reflected Cross-site Scripting (XSS) vulnerability.

    Published: 24 May 2021
    6.1
    Medium

    CVE-2021-24298

    Last Modified: 21 Nov 2024

    The method and share GET parameters of the Giveaway pages were not sanitised, validated or escaped before being output back in the pages, thus leading to reflected XSS

    Published: 24 May 2021
    5.4
    Medium

    CVE-2021-24301

    Last Modified: 21 Nov 2024

    The Hotjar Connecticator WordPress plugin through 1.1.1 is vulnerable to Stored Cross-Site Scripting (XSS) in the 'hotjar script' textarea. The request did include a CSRF nonce that was properly verified by the server and this vulnerability could only be exploited by administrator users.

    Published: 24 May 2021
    5.4
    Medium

    CVE-2021-24302

    Last Modified: 21 Nov 2024

    The Hana Flv Player WordPress plugin through 3.1.3 is vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) vulnerability within the 'Default Skin' field.

    Published: 24 May 2021
    6.1
    Medium

    CVE-2021-24305

    Last Modified: 21 Nov 2024

    The Target First WordPress Plugin v2.0, also previously known as Watcheezy, suffers from a critical unauthenticated stored XSS vulnerability. An attacker could change the licence key value through a POST on any URL with the 'weeWzKey' parameter that will be save as the 'weeID option and is not sanitized.

    Published: 24 May 2021
    4.8
    Medium

    CVE-2021-24296

    Last Modified: 21 Nov 2024

    The WP Customer Reviews WordPress plugin before 3.5.6 did not sanitise some of its settings, allowing high privilege users such as administrators to set XSS payloads in them which will then be triggered in pages where reviews are enabled

    Published: 24 May 2021
    6.1
    Medium

    CVE-2021-24294

    Last Modified: 21 Nov 2024

    The dsgvoaio_write_log AJAX action of the DSGVO All in one for WP WordPress plugin before 4.0 did not sanitise or escape some POST parameter submitted before outputting them in the Log page in the administrator dashboard (wp-admin/admin.php?page=dsgvoaiofree-show-log). This could allow unauthenticated attackers to gain unauthorised access by using an XSS payload to create a rogue administrator account, which will be trigged when an administrator will view the logs.

    Published: 24 May 2021