CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2021-31319

    Last Modified: 21 Nov 2024

    Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by an Integer Overflow in the LOTGradient::populate function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-bounds on a victim device via a malicious animated sticker.

    Published: 18 May 2021
    7.1
    High

    CVE-2021-31320

    Last Modified: 21 Nov 2024

    Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the VGradientCache::generateGradientColorTable function of their custom fork of the rlottie library. A remote attacker might be able to overwrite heap memory out-of-bounds on a victim device via a malicious animated sticker.

    Published: 18 May 2021
    7.1
    High

    CVE-2021-31321

    Last Modified: 21 Nov 2024

    Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the gray_split_cubic function of their custom fork of the rlottie library. A remote attacker might be able to overwrite Telegram's stack memory out-of-bounds on a victim device via a malicious animated sticker.

    Published: 18 May 2021
    5.5
    Medium

    CVE-2021-31322

    Last Modified: 21 Nov 2024

    Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LOTGradient::populate function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-bounds on a victim device via a malicious animated sticker.

    Published: 18 May 2021
    5.5
    Medium

    CVE-2021-31323

    Last Modified: 21 Nov 2024

    Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LottieParserImpl::parseDashProperty function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-bounds on a victim device via a malicious animated sticker.

    Published: 18 May 2021
    9.8
    Critical

    CVE-2021-31324

    Last Modified: 21 Nov 2024

    The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.

    Published: 18 May 2021
    5.4
    Medium

    CVE-2020-19924

    Last Modified: 21 Nov 2024

    In Boostnote 0.12.1, exporting to PDF contains opportunities for XSS attacks.

    Published: 18 May 2021
    6.5
    Medium

    CVE-2020-20245

    Last Modified: 21 Nov 2024

    Mikrotik RouterOs stable 6.46.3 suffers from a memory corruption vulnerability in the log process. An authenticated remote attacker can cause a Denial of Service due to improper memory access.

    Published: 18 May 2021
    6.5
    Medium

    CVE-2020-20246

    Last Modified: 21 Nov 2024

    Mikrotik RouterOs stable 6.46.3 suffers from a memory corruption vulnerability in the mactel process. An authenticated remote attacker can cause a Denial of Service due to improper memory access.

    Published: 18 May 2021
    6.5
    Medium

    CVE-2020-20227

    Last Modified: 21 Nov 2024

    Mikrotik RouterOs stable 6.47 suffers from a memory corruption vulnerability in the /nova/bin/diskd process. An authenticated remote attacker can cause a Denial of Service due to invalid memory access.

    Published: 18 May 2021
    6.5
    Medium

    CVE-2020-20220

    Last Modified: 21 Nov 2024

    Mikrotik RouterOs prior to stable 6.47 suffers from a memory corruption vulnerability in the /nova/bin/bfd process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

    Published: 18 May 2021
    6.5
    Medium

    CVE-2020-20237

    Last Modified: 21 Nov 2024

    Mikrotik RouterOs 6.46.3 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. An authenticated remote attacker can cause a Denial of Service due to improper memory access.

    Published: 18 May 2021
    6.5
    Medium

    CVE-2020-20236

    Last Modified: 21 Nov 2024

    Mikrotik RouterOs 6.46.3 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. An authenticated remote attacker can cause a Denial of Service due to improper memory access.

    Published: 18 May 2021
    6.5
    Medium

    CVE-2020-20222

    Last Modified: 21 Nov 2024

    Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

    Published: 18 May 2021
    6.5
    Medium

    CVE-2020-20214

    Last Modified: 21 Nov 2024

    Mikrotik RouterOs 6.44.6 (long-term tree) suffers from an assertion failure vulnerability in the btest process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.

    Published: 18 May 2021
    9.8
    Critical

    CVE-2020-18178

    Last Modified: 21 Nov 2024

    Path Traversal in HongCMS v4.0.0 allows remote attackers to view, edit, and delete arbitrary files via a crafted POST request to the component "/hcms/admin/index.php/language/ajax."

    Published: 18 May 2021
    9.8
    Critical

    CVE-2021-32305

    Last Modified: 21 Nov 2024

    WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter.

    Published: 18 May 2021
    9.8
    Critical

    CVE-2020-20951

    Last Modified: 21 Nov 2024

    In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.

    Published: 18 May 2021
    4.3
    Medium

    CVE-2020-24740

    Last Modified: 21 Nov 2024

    An issue was discovered in Pluck 4.7.10-dev2. There is a CSRF vulnerability that can editpage via a /admin.php?action=editpage

    Published: 18 May 2021
    5.5
    Medium

    CVE-2020-23861

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow vulnerability exists in LibreDWG 0.10.1 via the read_system_page function at libredwg-0.10.1/src/decode_r2007.c:666:5, which causes a denial of service by submitting a dwg file.

    Published: 18 May 2021
    7.8
    High

    CVE-2021-32238

    Last Modified: 21 Nov 2024

    Epic Games / Psyonix Rocket League <=1.95 is affected by Buffer Overflow. Stack-based buffer overflow occurs when Rocket League handles UPK object files that can result in code execution and denial of service scenario.

    Published: 18 May 2021
    5.5
    Medium

    CVE-2020-23856

    Last Modified: 21 Nov 2024

    Use-after-Free vulnerability in cflow 1.6 in the void call(char *name, int line) function at src/parser.c, which could cause a denial of service via the pointer variable caller->callee.

    Published: 18 May 2021
    6.1
    Medium

    CVE-2020-24026

    Last Modified: 21 Nov 2024

    TinyShop, a free and open source mall based on RageFrame2, has a stored XSS vulnerability that affects version 1.2.0. TinyShop allows XSS via the explain_first and again_explain parameters of the /evaluate/index.php page. The vulnerability may be exploited remotely, resulting in cross-site scripting (XSS) or information disclosure.

    Published: 18 May 2021
    5.5
    Medium

    CVE-2020-23852

    Last Modified: 21 Nov 2024

    A heap based buffer overflow vulnerability exists in ffjpeg through 2020-07-02 in the jfif_decode(void *ctxt, BMP *pb) function at ffjpeg/src/jfif.c (line 544 & line 545), which could cause a denial of service by submitting a malicious jpeg image.

    Published: 18 May 2021
    5.5
    Medium

    CVE-2020-23851

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow vulnerability exists in ffjpeg through 2020-07-02 in the jfif_decode(void *ctxt, BMP *pb) function at ffjpeg/src/jfif.c:513:28, which could cause a denial of service by submitting a malicious jpeg image.

    Published: 18 May 2021
    6.5
    Medium

    CVE-2020-20254

    Last Modified: 21 Nov 2024

    Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/lcdstat process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

    Published: 18 May 2021
    6.5
    Medium

    CVE-2020-20253

    Last Modified: 21 Nov 2024

    Mikrotik RouterOs before 6.47 (stable tree) suffers from a divison by zero vulnerability in the /nova/bin/lcdstat process. An authenticated remote attacker can cause a Denial of Service due to a divide by zero error.

    Published: 18 May 2021
    7.8
    High

    CVE-2021-30145

    Last Modified: 21 Nov 2024

    A format string vulnerability in mpv through 0.33.0 allows user-assisted remote attackers to achieve code execution via a crafted m3u playlist file.

    Published: 18 May 2021
    7.8
    High

    CVE-2021-22117

    Last Modified: 2 Apr 2025

    RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins.

    Published: 18 May 2021
    7.5
    High

    CVE-2002-2438

    Last Modified: 20 Nov 2024

    TCP firewalls could be circumvented by sending a SYN Packets with other flags (like e.g. RST flag) set, which was not correctly discarded by the Linux TCP stack after firewalling.

    Published: 18 May 2021
    4
    Medium

    CVE-2020-15279

    Last Modified: 21 Nov 2024

    An Improper Access Control vulnerability in the logging component of Bitdefender Endpoint Security Tools for Windows versions prior to 6.6.23.320 allows a regular user to learn the scanning exclusion paths. This issue was discovered during external security research.

    Published: 18 May 2021
    7.8
    High

    CVE-2021-3423

    Last Modified: 21 Nov 2024

    Uncontrolled Search Path Element vulnerability in the openssl component as used in Bitdefender GravityZone Business Security allows an attacker to load a third party DLL to elevate privileges. This issue affects Bitdefender GravityZone Business Security versions prior to 6.6.23.329.

    Published: 18 May 2021
    8.8
    High

    CVE-2021-31827

    Last Modified: 21 Nov 2024

    In Progress MOVEit Transfer before 2021.0 (13.0), a SQL injection vulnerability has been found in the MOVEit Transfer web app that could allow an authenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or destroy database elements. This is in MOVEit.DMZ.WebApp in SILHuman.vb.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33167

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33165

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33163

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33160

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33156

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33154

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33151

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33152

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33153

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33148

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33144

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33143

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33140

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33138

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33136

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33134

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33133

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021