CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2021-33131

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33132

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33125

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33127

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33121

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33116

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33112

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33111

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33109

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33102

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33099

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33100

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33084

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33085

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33072

    Last Modified: 4 Sept 2025

    This is unused.

    Published: 18 May 2021
    8.7
    High

    CVE-2021-22543

    Last Modified: 21 Nov 2024

    An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed while still accessible by the VMM and guest. This allows users with the ability to start and control a VM to read/write random pages of memory and can result in local privilege escalation.

    Published: 18 May 2021
    2.7
    Low

    CVE-2021-25737

    Last Modified: 21 Nov 2024

    A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or link-local range, but the same validation was not performed on EndpointSlice IPs.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33065

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33066

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33067

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

    Published: 18 May 2021
    —
    Unknown

    CVE-2021-33070

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

    Published: 18 May 2021
    5.5
    Medium

    CVE-2021-3585

    Last Modified: 21 Nov 2024

    A flaw was found in openstack-tripleo-heat-templates. Plain passwords from RHSM exist in the logs during OSP13 deployment with subscription-manager.

    Published: 18 May 2021
    5.5
    Medium

    CVE-2021-3798

    Last Modified: 21 Nov 2024

    A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is created via C_CreateObject, nor when C_DeriveKey is used with ECDH public data. This may allow a malicious user to extract the private key by performing an invalid curve attack.

    Published: 18 May 2021
    9.8
    Critical

    CVE-2021-31535

    Last Modified: 21 Nov 2024

    LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code. The libX11 XLookupColor request (intended for server-side color lookup) contains a flaw allowing a client to send color-name requests with a name longer than the maximum size allowed by the protocol (and also longer than the maximum packet size for normal-sized packets). The user-controlled data exceeding the maximum size is then interpreted by the server as additional X protocol requests and executed, e.g., to disable X server authorization completely. For example, if the victim encounters malicious terminal control sequences for color codes, then the attacker may be able to take full control of the running graphical session.

    Published: 18 May 2021
    7.3
    High

    CVE-2021-33195

    Last Modified: 21 Nov 2024

    Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers, and thus a return value may contain an unsafe injection (e.g., XSS) that does not conform to the RFC1035 format.

    Published: 18 May 2021
    6.5
    Medium

    CVE-2021-29622

    Last Modified: 21 Nov 2024

    Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seamless transition, the URL's prefixed by /new redirect to /. Due to a bug in the code, it is possible for an attacker to craft an URL that can redirect to any other URL, in the /new endpoint. If a user visits a prometheus server with a specially crafted address, they can be redirected to an arbitrary URL. The issue was patched in the 2.26.1 and 2.27.1 releases. In 2.28.0, the /new endpoint will be removed completely. The workaround is to disable access to /new via a reverse proxy in front of Prometheus.

    Published: 18 May 2021
    8.8
    High

    CVE-2020-21831

    Last Modified: 21 Nov 2024

    A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_handles ../../src/decode.c:2637.

    Published: 17 May 2021
    8.8
    High

    CVE-2020-21844

    Last Modified: 21 Nov 2024

    GNU LibreDWG 0.10 is affected by: memcpy-param-overlap. The impact is: execute arbitrary code (remote). The component is: read_2004_section_header ../../src/decode.c:2580.

    Published: 17 May 2021
    7.8
    High

    CVE-2020-24755

    Last Modified: 21 Nov 2024

    In Ubiquiti UniFi Video v3.10.13, when the executable starts, its first library validation is in the current directory. This allows the impersonation and modification of the library to execute code on the system. This was tested in (Windows 7 x64/Windows 10 x64).

    Published: 17 May 2021
    8.8
    High

    CVE-2020-21843

    Last Modified: 21 Nov 2024

    A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_read_RC ../../src/bits.c:318.

    Published: 17 May 2021
    8.8
    High

    CVE-2020-18198

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete specific images via the component " /admin.php?action=images."

    Published: 17 May 2021
    8.8
    High

    CVE-2020-18195

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete a specific article via the component " /admin.php?action=page."

    Published: 17 May 2021
    6.1
    Medium

    CVE-2020-18194

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in emlog v6.0.0 allows remote attackers to execute arbitrary code by adding a crafted script as a link to a new blog post.

    Published: 17 May 2021
    8.8
    High

    CVE-2020-21842

    Last Modified: 21 Nov 2024

    A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_revhistory ../../src/decode.c:3051.

    Published: 17 May 2021
    8.8
    High

    CVE-2020-21841

    Last Modified: 21 Nov 2024

    A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_read_B ../../src/bits.c:135.

    Published: 17 May 2021
    8.8
    High

    CVE-2020-21840

    Last Modified: 21 Nov 2024

    A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_search_sentinel ../../src/bits.c:1985.

    Published: 17 May 2021
    6.5
    Medium

    CVE-2020-21839

    Last Modified: 21 Nov 2024

    An issue was discovered in GNU LibreDWG 0.10. Crafted input will lead to an memory leak in dwg_decode_eed ../../src/decode.c:3638.

    Published: 17 May 2021
    8.8
    High

    CVE-2020-21838

    Last Modified: 21 Nov 2024

    A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via: read_2004_section_appinfo ../../src/decode.c:2842.

    Published: 17 May 2021
    8.8
    High

    CVE-2020-21836

    Last Modified: 21 Nov 2024

    A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_preview ../../src/decode.c:3175.

    Published: 17 May 2021
    6.5
    Medium

    CVE-2020-21835

    Last Modified: 21 Nov 2024

    A null pointer deference issue exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2337.

    Published: 17 May 2021
    6.5
    Medium

    CVE-2020-21834

    Last Modified: 21 Nov 2024

    A null pointer deference issue exists in GNU LibreDWG 0.10 via get_bmp ../../programs/dwgbmp.c:164.

    Published: 17 May 2021
    8.8
    High

    CVE-2020-21833

    Last Modified: 21 Nov 2024

    A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via: read_2004_section_classes ../../src/decode.c:2440.

    Published: 17 May 2021
    8.8
    High

    CVE-2020-21832

    Last Modified: 21 Nov 2024

    A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2417.

    Published: 17 May 2021
    8.8
    High

    CVE-2020-21830

    Last Modified: 21 Nov 2024

    A heap based buffer overflow vulneraibility exists in GNU LibreDWG 0.10 via bit_calc_CRC ../../src/bits.c:2213.

    Published: 17 May 2021
    7.8
    High

    CVE-2020-21827

    Last Modified: 21 Nov 2024

    A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2379.

    Published: 17 May 2021
    4.2
    Medium

    CVE-2021-32622

    Last Modified: 21 Nov 2024

    Matrix-React-SDK is a react-based SDK for inserting a Matrix chat/voip client into a web page. Before version 3.21.0, when uploading a file, the local file preview can lead to execution of scripts embedded in the uploaded file. This can only occur after several user interactions to open the preview in a separate tab. This only impacts the local user while in the process of uploading. It cannot be exploited remotely or by other users. This vulnerability is patched in version 3.21.0.

    Published: 17 May 2021
    6.1
    Medium

    CVE-2020-29205

    Last Modified: 21 Nov 2024

    XSS in signup form in Project Worlds Online Examination System 1.0 allows remote attacker to inject arbitrary code via the name field

    Published: 17 May 2021
    8.8
    High

    CVE-2020-21819

    Last Modified: 21 Nov 2024

    A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641via htmlescape ../../programs/escape.c:51.

    Published: 17 May 2021
    8.8
    High

    CVE-2020-21818

    Last Modified: 21 Nov 2024

    A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:48.

    Published: 17 May 2021
    6.5
    Medium

    CVE-2020-21817

    Last Modified: 21 Nov 2024

    A null pointer dereference issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:29. which causes a denial of service (application crash).

    Published: 17 May 2021