CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2021-29659

    Last Modified: 31 Mar 2025

    ownCloud 10.7 has an incorrect access control vulnerability, leading to remote information disclosure. Due to a bug in the related API endpoint, the attacker can enumerate all users in a single request by entering three whitespaces. Secondary, the retrieval of all users on a large instance could cause higher than average load on the instance.

    Published: 20 May 2021
    7.5
    High

    CVE-2021-27461

    Last Modified: 21 Nov 2024

    A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected webserver applications allow access to stored data that can be obtained by using specially crafted URLs.

    Published: 20 May 2021
    9.8
    Critical

    CVE-2021-27459

    Last Modified: 21 Nov 2024

    A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The webserver of the affected products allows unvalidated files to be uploaded, which an attacker could utilize to execute arbitrary code.

    Published: 20 May 2021
    7.5
    High

    CVE-2021-27457

    Last Modified: 21 Nov 2024

    A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected products utilize a weak encryption algorithm for storage of sensitive data, which may allow an attacker to more easily obtain credentials used for access.

    Published: 20 May 2021
    6.1
    Medium

    CVE-2021-27467

    Last Modified: 21 Nov 2024

    A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected product’s web interface allows an attacker to route click or keystroke to another page provided by the attacker to gain unauthorized access to sensitive information.

    Published: 20 May 2021
    6.1
    Medium

    CVE-2021-27465

    Last Modified: 21 Nov 2024

    A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected applications do not validate webpage input, which could allow an attacker to inject arbitrary HTML code into a webpage. This would allow an attacker to modify the page and display incorrect or undesirable data.

    Published: 20 May 2021
    5.3
    Medium

    CVE-2021-27463

    Last Modified: 21 Nov 2024

    A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected applications utilize persistent cookies where the session cookie attribute is not properly invalidated, allowing an attacker to intercept the cookies and gain access to sensitive information.

    Published: 20 May 2021
    9.8
    Critical

    CVE-2021-20721

    Last Modified: 21 Nov 2024

    KonaWiki2 versions prior to 2.2.4 allows a remote attacker to upload arbitrary files via unspecified vectors. If the file contains PHP scripts, arbitrary code may be executed.

    Published: 20 May 2021
    9.8
    Critical

    CVE-2021-20720

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in the KonaWiki2 versions prior to 2.2.4 allows remote attackers to execute arbitrary SQL commands and to obtain/alter the information stored in the database via unspecified vectors.

    Published: 20 May 2021
    6.8
    Medium

    CVE-2021-20719

    Last Modified: 21 Nov 2024

    RFNTPS firmware versions System_01000004 and earlier, and Web_01000004 and earlier allow an attacker on the same network segment to execute arbitrary OS commands with a root privilege via unspecified vectors.

    Published: 20 May 2021
    7.7
    High

    CVE-2021-23386

    Last Modified: 21 Nov 2024

    This affects the package dns-packet before 5.2.2. It creates buffers with allocUnsafe and does not always fill them before forming network packets. This can expose internal application memory over unencrypted network when querying crafted invalid domain names.

    Published: 20 May 2021
    —
    Unknown

    CVE-2021-33235

    Last Modified: 6 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-34035. Reason: This candidate is a duplicate of CVE-2022-34035. Notes: All CVE users should reference CVE-2022-34035 instead of this candidate.

    Published: 20 May 2021
    —
    Unknown

    CVE-2021-33236

    Last Modified: 6 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-34033. Reason: This candidate is a duplicate of CVE-2022-34033. Notes: All CVE users should reference CVE-2022-34033 instead of this candidate.

    Published: 20 May 2021
    5.9
    Medium

    CVE-2020-15522

    Last Modified: 17 Jul 2025

    Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.

    Published: 20 May 2021
    7.5
    High

    CVE-2021-33194

    Last Modified: 21 Nov 2024

    golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows attackers to cause a denial of service (infinite loop) via crafted ParseFragment input.

    Published: 20 May 2021
    7.5
    High

    CVE-2021-29625

    Last Modified: 21 Nov 2024

    Adminer is open-source database management software. A cross-site scripting vulnerability in Adminer versions 4.6.1 to 4.8.0 affects users of MySQL, MariaDB, PgSQL and SQLite. XSS is in most cases prevented by strict CSP in all modern browsers. The only exception is when Adminer is using a `pdo_` extension to communicate with the database (it is used if the native extensions are not enabled). In browsers without CSP, Adminer versions 4.6.1 to 4.8.0 are affected. The vulnerability is patched in version 4.8.1. As workarounds, one can use a browser supporting strict CSP or enable the native PHP extensions (e.g. `mysqli`) or disable displaying PHP errors (`display_errors`).

    Published: 19 May 2021
    6.5
    Medium

    CVE-2021-29624

    Last Modified: 21 Nov 2024

    fastify-csrf is an open-source plugin helps developers protect their Fastify server against CSRF attacks. Versions of fastify-csrf prior to 3.1.0 have a "double submit" mechanism using cookies with an application deployed across multiple subdomains, e.g. "heroku"-style platform as a service. Version 3.1.0 of the fastify-csrf fixes it. the vulnerability. The user of the module would need to supply a `userInfo` when generating the CSRF token to fully implement the protection on their end. This is needed only for applications hosted on different subdomains.

    Published: 19 May 2021
    8.1
    High

    CVE-2021-29503

    Last Modified: 21 Nov 2024

    HedgeDoc is a platform to write and share markdown. HedgeDoc before version 1.8.2 is vulnerable to a cross-site scripting attack using the YAML-metadata of a note. An attacker with write access to a note can embed HTML tags in the Open Graph metadata section of the note, resulting in the frontend rendering the script tag as part of the `<head>` section. Unless your instance prevents guests from editing notes, this vulnerability allows unauthenticated attackers to inject JavaScript into notes that allow guest edits. If your instance prevents guests from editing notes, this vulnerability allows authenticated attackers to inject JavaScript into any note pages they have write-access to. This vulnerability is patched in version 1.8.2. As a workaround, one can disable guest edits until the next update.

    Published: 19 May 2021
    5.3
    Medium

    CVE-2021-20529

    Last Modified: 21 Nov 2024

    IBM Control Center 6.2.0.0 could allow a user to obtain sensitive version information that could be used in further attacks against the system. IBM X-Force ID: 198763.

    Published: 19 May 2021
    5.4
    Medium

    CVE-2021-20528

    Last Modified: 21 Nov 2024

    IBM Control Center 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198761.

    Published: 19 May 2021
    5.4
    Medium

    CVE-2021-20374

    Last Modified: 21 Nov 2024

    IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195522.

    Published: 19 May 2021
    3.3
    Low

    CVE-2020-4765

    Last Modified: 21 Nov 2024

    IBM Cloud Pak for Multicloud Management prior to 2.3 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 188902.

    Published: 19 May 2021
    4.3
    Medium

    CVE-2020-4646

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5, 6.0.0.0 through 6.0.3.3, and 6.1.0.0 through 6.1.0.2 could allow an authenticated user to view pages they shoiuld not have access to due to improper authorization control.

    Published: 19 May 2021
    5.9
    Medium

    CVE-2021-27924

    Last Modified: 21 Nov 2024

    An issue was discovered in Couchbase Server 6.x through 6.6.1. The Couchbase Server UI is insecurely logging session cookies in the logs. This allows for the impersonation of a user if the log files are obtained by an attacker before a session cookie expires.

    Published: 19 May 2021
    6.1
    Medium

    CVE-2020-36365

    Last Modified: 21 Nov 2024

    Smartstore (aka SmartStoreNET) before 4.1.0 allows CommonController.ClearCache, ClearDatabaseCache, RestartApplication, and ScheduleTaskController.Edit open redirect.

    Published: 19 May 2021
    4.4
    Medium

    CVE-2021-27925

    Last Modified: 21 Nov 2024

    An issue was discovered in Couchbase Server 6.5.x and 6.6.x through 6.6.1. When using the View Engine and Auditing is enabled, a crash condition can (depending on a race condition) cause an internal user with administrator privileges, @ns_server, to have its credentials leaked in cleartext in the ns_server.info.log file.

    Published: 19 May 2021
    9.1
    Critical

    CVE-2020-36364

    Last Modified: 21 Nov 2024

    An issue was discovered in Smartstore (aka SmartStoreNET) before 4.1.0. Administration/Controllers/ImportController.cs allows path traversal (for copy and delete actions) in the ImportController.Create method via a TempFileName field.

    Published: 19 May 2021
    7.5
    High

    CVE-2021-25644

    Last Modified: 21 Nov 2024

    An issue was discovered in Couchbase Server 5.x and 6.x through 6.6.1 and 7.0.0 Beta. Incorrect commands to the REST API can result in leaked authentication information being stored in cleartext in the debug.log and info.log files, and is also shown in the UI visible to administrators.

    Published: 19 May 2021
    6.5
    Medium

    CVE-2021-31158

    Last Modified: 21 Nov 2024

    In the Query Engine in Couchbase Server 6.5.x and 6.6.x through 6.6.1, Common Table Expression queries were not correctly checking the user's permissions, allowing read-access to resources beyond what those users were explicitly allowed to access.

    Published: 19 May 2021
    9.8
    Critical

    CVE-2021-33204

    Last Modified: 21 Nov 2024

    In the pg_partman (aka PG Partition Manager) extension before 4.5.1 for PostgreSQL, arbitrary code execution can be achieved via SECURITY DEFINER functions because an explicit search_path is not set.

    Published: 19 May 2021
    6.1
    Medium

    CVE-2021-31930

    Last Modified: 21 Nov 2024

    Persistent cross-site scripting (XSS) in the web interface of Concerto through 2.3.6 allows an unauthenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into the First Name or Last Name parameter upon registration. When a privileged user attempts to delete the account, the XSS payload will be executed.

    Published: 19 May 2021
    8.8
    High

    CVE-2017-17677

    Last Modified: 21 Nov 2024

    BMC Remedy 9.1SP3 is affected by authenticated code execution. Authenticated users that have the right to create reports can use BIRT templates to run code.

    Published: 19 May 2021
    5.3
    Medium

    CVE-2017-17675

    Last Modified: 21 Nov 2024

    BMC Remedy Mid Tier 9.1SP3 is affected by log hijacking. Remote logging can be accessed by unauthenticated users, allowing for an attacker to hijack the system logs. This data can include user names and HTTP data.

    Published: 19 May 2021
    6.1
    Medium

    CVE-2017-17678

    Last Modified: 21 Nov 2024

    BMC Remedy Mid Tier 9.1SP3 is affected by cross-site scripting (XSS). A DOM-based cross-site scripting vulnerability was discovered in a legacy utility.

    Published: 19 May 2021
    9.8
    Critical

    CVE-2017-17674

    Last Modified: 21 Nov 2024

    BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port scanning, Server Side Request Forgery (SSRF), or remote code execution (RCE).

    Published: 19 May 2021
    6.5
    Medium

    CVE-2020-20266

    Last Modified: 21 Nov 2024

    Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/dot1x process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

    Published: 19 May 2021
    6.5
    Medium

    CVE-2020-20264

    Last Modified: 21 Nov 2024

    Mikrotik RouterOs before 6.47 (stable tree) in the /ram/pckg/advanced-tools/nova/bin/netwatch process. An authenticated remote attacker can cause a Denial of Service due to a divide by zero error.

    Published: 19 May 2021
    4.9
    Medium

    CVE-2021-21733

    Last Modified: 21 Nov 2024

    The management system of ZXCDN is impacted by the information leak vulnerability. Attackers can make further analysis according to the information returned by the program, and then obtain some sensitive information. This affects ZXCDN V7.01 all versions up to IAMV7.01.01.02.

    Published: 19 May 2021
    7.5
    High

    CVE-2021-21732

    Last Modified: 21 Nov 2024

    A mobile phone of ZTE is impacted by improper access control vulnerability. Due to improper permission settings, third-party applications can read some files in the proc file system without authorization. Attackers could exploit this vulnerability to obtain sensitive information. This affects Axon 11 5G ZTE/CN_P725A12/P725A12:10/QKQ1.200816.002/20201116.175317:user/release-keys.

    Published: 19 May 2021
    7.5
    High

    CVE-2021-20589

    Last Modified: 21 Nov 2024

    Buffer access with incorrect length value vulnerability in GOT2000 series GT27 model communication driver versions 01.19.000 through 01.38.000, GT25 model communication driver versions 01.19.000 through 01.38.000, GT23 model communication driver versions 01.19.000 through 01.38.000 and GT21 model communication driver versions 01.21.000 through 01.39.000, GOT SIMPLE series GS21 model communication driver versions 01.21.000 through 01.39.000, GT SoftGOT2000 versions 1.170C through 1.250L and Tension Controller LE7-40GU-L Screen package data for MODBUS/TCP V1.00 allows a remote unauthenticated attacker to stop the communication function of the products via specially crafted packets.

    Published: 19 May 2021
    8.5
    High

    CVE-2021-30465

    Last Modified: 21 Nov 2024

    runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on a race condition.

    Published: 19 May 2021
    5.5
    Medium

    CVE-2021-33452

    Last Modified: 21 Nov 2024

    An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_malloc() in nasmlib/alloc.c.

    Published: 19 May 2021
    0
    Low

    CVE-2021-3558

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 19 May 2021
    5.3
    Medium

    CVE-2021-41495

    Last Modified: 21 Nov 2024

    Null Pointer Dereference vulnerability exists in numpy.sort in NumPy &lt and 1.19 in the PyArray_DescrNew function due to missing return-value validation, which allows attackers to conduct DoS attacks by repetitively creating sort arrays. NOTE: While correct that validation is missing, an error can only occur due to an exhaustion of memory. If the user can exhaust memory, they are already privileged. Further, it should be practically impossible to construct an attack which can target the memory exhaustion to occur at exactly this place

    Published: 19 May 2021
    5.5
    Medium

    CVE-2021-33450

    Last Modified: 21 Nov 2024

    An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_calloc() in nasmlib/alloc.c.

    Published: 19 May 2021
    6.5
    Medium

    CVE-2021-3557

    Last Modified: 21 Nov 2024

    A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created ServiceAccount argocd-argocd-server, the unprivileged user is able to read all resources of the cluster including all secrets which might enable privilege escalations. The highest threat from this vulnerability is to data confidentiality.

    Published: 19 May 2021
    5.5
    Medium

    CVE-2021-31315

    Last Modified: 21 Nov 2024

    Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the blit function of their custom fork of the rlottie library. A remote attacker might be able to access Telegram's stack memory out-of-bounds on a victim device via a malicious animated sticker.

    Published: 18 May 2021
    9.8
    Critical

    CVE-2021-31316

    Last Modified: 21 Nov 2024

    The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.

    Published: 18 May 2021
    5.5
    Medium

    CVE-2021-31317

    Last Modified: 21 Nov 2024

    Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the VDasher constructor of their custom fork of the rlottie library. A remote attacker might be able to access Telegram's heap memory out-of-bounds on a victim device via a malicious animated sticker.

    Published: 18 May 2021
    5.5
    Medium

    CVE-2021-31318

    Last Modified: 21 Nov 2024

    Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the LOTCompLayerItem::LOTCompLayerItem function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-bounds on a victim device via a malicious animated sticker.

    Published: 18 May 2021