CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2020-21815

    Last Modified: 21 Nov 2024

    A null pointer deference issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2SVG.c:114, which causes a denial of service (application crash).

    Published: 17 May 2021
    5.4
    Medium

    CVE-2020-24993

    Last Modified: 21 Nov 2024

    There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when visitors access the article module.

    Published: 17 May 2021
    5.4
    Medium

    CVE-2020-24992

    Last Modified: 21 Nov 2024

    There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when an administrator accesses the content management module.

    Published: 17 May 2021
    8.8
    High

    CVE-2020-21816

    Last Modified: 21 Nov 2024

    A heab based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:46.

    Published: 17 May 2021
    8.8
    High

    CVE-2020-21814

    Last Modified: 21 Nov 2024

    A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlwescape ../../programs/escape.c:97.

    Published: 17 May 2021
    3.1
    Low

    CVE-2021-32618

    Last Modified: 21 Nov 2024

    The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is an independently maintained version of Flask-Security based on the 3.0.0 version of Flask-Security. All versions of Flask-Security-Too allow redirects after many successful views (e.g. /login) by honoring the ?next query param. There is code in FS to validate that the url specified in the next parameter is either relative OR has the same netloc (network location) as the requesting URL. This check utilizes Pythons urlsplit library. However many browsers are very lenient on the kind of URL they accept and 'fill in the blanks' when presented with a possibly incomplete URL. As a concrete example - setting http://login?next=\\\github.com will pass FS's relative URL check however many browsers will gladly convert this to http://github.com. Thus an attacker could send such a link to an unwitting user, using a legitimate site and have it redirect to whatever site they want. This is considered a low severity due to the fact that if Werkzeug is used (which is very common with Flask applications) as the WSGI layer, it by default ALWAYS ensures that the Location header is absolute - thus making this attack vector mute. It is possible for application writers to modify this default behavior by setting the 'autocorrect_location_header=False`.

    Published: 17 May 2021
    7.8
    High

    CVE-2020-21813

    Last Modified: 21 Nov 2024

    A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2SVG.c:114.

    Published: 17 May 2021
    6.5
    Medium

    CVE-2021-32456

    Last Modified: 21 Nov 2024

    SITEL CAP/PRX firmware version 5.2.01 allows an attacker with access to the local network of the device to obtain the authentication passwords by analysing the network traffic.

    Published: 17 May 2021
    5.4
    Medium

    CVE-2021-23384

    Last Modified: 21 Nov 2024

    The package koa-remove-trailing-slashes before 2.0.2 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as https://example.com//attacker.example/). The vulnerable code is in index.js::removeTrailingSlashes(), as the web server uses relative URLs instead of absolute URLs.

    Published: 17 May 2021
    9.6
    Critical

    CVE-2021-32454

    Last Modified: 21 Nov 2024

    SITEL CAP/PRX firmware version 5.2.01 makes use of a hardcoded password. An attacker with access to the device could modify these credentials, leaving the administrators of the device without access.

    Published: 17 May 2021
    7.5
    High

    CVE-2021-29747

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain highly sensitive information due to a vulnerability in the authentication mechanism. IBM X-Force ID: 201775.

    Published: 17 May 2021
    9.1
    Critical

    CVE-2020-4670

    Last Modified: 21 Nov 2024

    IBM Planning Analytics Local 2.0 connects to a Redis server. The Redis server, an in-memory data structure store, running on the remote host is not protected by password authentication. A remote attacker can exploit this to gain unauthorized access to the server. IBM X-Force ID: 186401.

    Published: 17 May 2021
    9.1
    Critical

    CVE-2020-4669

    Last Modified: 21 Nov 2024

    IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain unauthorized access to the database. IBM X-Force ID: 184600.

    Published: 17 May 2021
    6.7
    Medium

    CVE-2021-25264

    Last Modified: 21 Nov 2024

    In multiple versions of Sophos Endpoint products for MacOS, a local attacker could execute arbitrary code with administrator privileges.

    Published: 17 May 2021
    5.3
    Medium

    CVE-2020-13667

    Last Modified: 21 Nov 2024

    Access bypass vulnerability in of Drupal Core Workspaces allows an attacker to access data without correct permissions. The Workspaces module doesn't sufficiently check access permissions when switching workspaces, leading to an access bypass vulnerability. An attacker might be able to see content before the site owner intends people to see the content. This vulnerability is mitigated by the fact that sites are only vulnerable if they have installed the experimental Workspaces module. This issue affects Drupal Core8.8.X versions prior to 8.8.10; 8.9.X versions prior to 8.9.6; 9.0.X versions prior to 9.0.6.

    Published: 17 May 2021
    5.4
    Medium

    CVE-2021-24326

    Last Modified: 21 Nov 2024

    The tab parameter of the settings page of the All 404 Redirect to Homepage WordPress plugin before 1.21 was vulnerable to an authenticated reflected Cross-Site Scripting (XSS) issue as user input was not properly sanitised before being output in an attribute.

    Published: 17 May 2021
    6.1
    Medium

    CVE-2021-24325

    Last Modified: 21 Nov 2024

    The tab parameter of the settings page of the 404 SEO Redirection WordPress plugin through 1.3 is vulnerable to a reflected Cross-Site Scripting (XSS) issue as user input is not properly sanitised or escaped before being output in an attribute.

    Published: 17 May 2021
    4.8
    Medium

    CVE-2021-24327

    Last Modified: 21 Nov 2024

    The SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 6.4 did not sanitise the Redirect From and Redirect To fields when creating a new redirect in the dashboard, allowing high privilege users (even with the unfiltered_html disabled) to set XSS payloads

    Published: 17 May 2021
    6.1
    Medium

    CVE-2021-24299

    Last Modified: 21 Nov 2024

    The ReDi Restaurant Reservation WordPress plugin before 21.0426 provides the functionality to let users make restaurant reservations. These reservations are stored and can be listed on an 'Upcoming' page provided by the plugin. An unauthenticated user can fill in the form to make a restaurant reservation. The form to make a restaurant reservation field called 'Comment' does not use proper input validation and can be used to store XSS payloads. The XSS payloads will be executed when the plugin user goes to the 'Upcoming' page, which is an external website https://upcoming.reservationdiary.eu/ loaded in an iframe, and the stored reservation with XSS payload is loaded.

    Published: 17 May 2021
    4.8
    Medium

    CVE-2021-24315

    Last Modified: 21 Nov 2024

    The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.4 did not sanitise or escape the Background Image field of its Stripe Checkout Setting and Logo field in its Email settings, leading to authenticated (admin+) Stored XSS issues.

    Published: 17 May 2021
    6.1
    Medium

    CVE-2021-24290

    Last Modified: 21 Nov 2024

    There are several endpoints in the Store Locator Plus for WordPress plugin through 5.5.15 that could allow unauthenticated attackers the ability to inject malicious JavaScript into pages.

    Published: 17 May 2021
    5.4
    Medium

    CVE-2021-24292

    Last Modified: 21 Nov 2024

    The Happy Addons for Elementor WordPress plugin before 2.24.0, Happy Addons Pro for Elementor WordPress plugin before 1.17.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method: The “Card” widget accepts a “title_tag” parameter. Although the element control lists a fixed set of possible html tags, it is possible to send a ‘save_builder’ request with the “heading_tag” set to “script”, and the actual “title” parameter set to JavaScript to be executed within the script tags added by the “heading_tag” parameter.

    Published: 17 May 2021
    7.5
    High

    CVE-2021-24295

    Last Modified: 21 Nov 2024

    It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib/Cleantalk/ApbctWP/Firewall/SFW.php included a vulnerable query that could be injected via the User-Agent Header by manipulating the cookies set by the Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.153.4, sending an initial request to obtain a ct_sfw_pass_key cookie and then manually setting a separate ct_sfw_passed cookie and disallowing it from being reset.

    Published: 17 May 2021
    9.8
    Critical

    CVE-2021-24314

    Last Modified: 21 Nov 2024

    The Goto WordPress theme before 2.1 did not sanitise, validate of escape the keywords GET parameter from its listing page before using it in a SQL statement, leading to an Unauthenticated SQL injection issue

    Published: 17 May 2021
    6.5
    Medium

    CVE-2021-24324

    Last Modified: 21 Nov 2024

    The 404 SEO Redirection WordPress plugin through 1.3 is lacking CSRF checks in all its settings, allowing attackers to make a logged in user change the plugin's settings. Due to the lack of sanitisation and escaping in some fields, it could also lead to Stored Cross-Site Scripting issues

    Published: 17 May 2021
    4.8
    Medium

    CVE-2021-24323

    Last Modified: 21 Nov 2024

    When taxes are enabled, the "Additional tax classes" field was not properly sanitised or escaped before being output back in the admin dashboard, allowing high privilege users such as admin to use XSS payloads even when the unfiltered_html is disabled

    Published: 17 May 2021
    6.1
    Medium

    CVE-2021-24288

    Last Modified: 21 Nov 2024

    When subscribing using AcyMailing, the 'redirect' parameter isn't properly sanitized. Turning the request from POST to GET, an attacker can craft a link containing a potentially malicious landing page and send it to the victim.

    Published: 17 May 2021
    8.8
    High

    CVE-2021-24289

    Last Modified: 21 Nov 2024

    There is functionality in the Store Locator Plus for WordPress plugin through 5.5.14 that made it possible for authenticated users to update their user meta data to become an administrator on any site using the plugin.

    Published: 17 May 2021
    6.5
    Medium

    CVE-2021-32453

    Last Modified: 21 Nov 2024

    SITEL CAP/PRX firmware version 5.2.01 allows an attacker with access to the local network, to access via HTTP to the internal configuration database of the device without any authentication. An attacker could exploit this vulnerability in order to obtain information about the device´s configuration.

    Published: 17 May 2021
    6.8
    Medium

    CVE-2021-32455

    Last Modified: 21 Nov 2024

    SITEL CAP/PRX firmware version 5.2.01, allows an attacker with access to the device´s network to cause a denial of service condition on the device. An attacker could exploit this vulnerability by sending HTTP requests massively.

    Published: 17 May 2021
    6.1
    Medium

    CVE-2021-33041

    Last Modified: 21 Nov 2024

    vmd through 1.34.0 allows 'div class="markdown-body"' XSS, as demonstrated by Electron remote code execution via require('child_process').execSync('calc.exe') on Windows and a similar attack on macOS.

    Published: 17 May 2021
    6.1
    Medium

    CVE-2019-14827

    Last Modified: 21 Nov 2024

    A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive rendering from contexts. Mustache helper tags that were included in template contexts were not being escaped before that context was injected into another Mustache helper, which could result in script injection in some templates. This affects versions 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions.

    Published: 17 May 2021
    9.8
    Critical

    CVE-2021-27734

    Last Modified: 21 Nov 2024

    Hirschmann HiOS 07.1.01, 07.1.02, and 08.1.00 through 08.5.xx and HiSecOS 03.3.00 through 03.5.01 allow remote attackers to change the credentials of existing users.

    Published: 17 May 2021
    8.8
    High

    CVE-2021-32403

    Last Modified: 21 Nov 2024

    Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of security mechanisms for token protection and unsafe inputs and modules.

    Published: 17 May 2021
    8.8
    High

    CVE-2021-32402

    Last Modified: 21 Nov 2024

    Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of validation and insecure configurations in inputs and modules.

    Published: 17 May 2021
    5.9
    Medium

    CVE-2021-27342

    Last Modified: 21 Nov 2024

    An authentication brute-force protection mechanism bypass in telnetd in D-Link Router model DIR-842 firmware version 3.0.2 allows a remote attacker to circumvent the anti-brute-force cool-down delay period via a timing-based side-channel attack

    Published: 17 May 2021
    7.8
    High

    CVE-2021-31728

    Last Modified: 21 Nov 2024

    Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 allows a non-privileged process to open a handle to \.\ZemanaAntiMalware, register itself with the driver by sending IOCTL 0x80002010, allocate executable memory using a flaw in IOCTL 0x80002040, install a hook with IOCTL 0x80002044 and execute the executable memory using this hook with IOCTL 0x80002014 or 0x80002018, this exposes ring 0 code execution in the context of the driver allowing the non-privileged process to elevate privileges.

    Published: 17 May 2021
    7.8
    High

    CVE-2021-31727

    Last Modified: 21 Nov 2024

    Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 where IOCTL's 0x80002014, 0x80002018 expose unrestricted disk read/write capabilities respectively. A non-privileged process can open a handle to \.\ZemanaAntiMalware, register with the driver using IOCTL 0x80002010 and send these IOCTL's to escalate privileges by overwriting the boot sector or overwriting critical code in the pagefile.

    Published: 17 May 2021
    6.5
    Medium

    CVE-2007-5967

    Last Modified: 21 Nov 2024

    A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user approval.

    Published: 17 May 2021
    4.3
    Medium

    CVE-2021-29052

    Last Modified: 21 Nov 2024

    The Data Engine module in Liferay Portal 7.3.0 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 does not check permissions in DataDefinitionResourceImpl.getSiteDataDefinitionByContentTypeByDataDefinitionKey, which allows remote authenticated users to view DDMStructures via GET API calls.

    Published: 17 May 2021
    6.1
    Medium

    CVE-2021-29048

    Last Modified: 13 May 2025

    Cross-site scripting (XSS) vulnerability in the Layout module's page administration page in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.2 before fix pack 11 and 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_layout_admin_web_portlet_GroupPagesPortlet_name parameter.

    Published: 17 May 2021
    6.1
    Medium

    CVE-2021-29051

    Last Modified: 13 May 2025

    Cross-site scripting (XSS) vulnerability in the Asset module's Asset Publisher app in Liferay Portal 7.2.1 through 7.3.5, and Liferay DXP 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_XXXXXXXXXXXX_assetEntryId parameter.

    Published: 17 May 2021
    6.1
    Medium

    CVE-2021-29044

    Last Modified: 13 May 2025

    Cross-site scripting (XSS) vulnerability in the Site module's membership request administration pages in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_site_my_sites_web_portlet_MySitesPortlet_comments parameter.

    Published: 17 May 2021
    5.9
    Medium

    CVE-2021-29043

    Last Modified: 13 May 2025

    The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 does not obfuscate the S3 store's proxy password, which allows attackers to steal the proxy password via man-in-the-middle attacks or shoulder surfing.

    Published: 17 May 2021
    8.8
    High

    CVE-2021-29053

    Last Modified: 21 Nov 2024

    Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1 allow remote authenticated users to execute arbitrary SQL commands via the classPKField parameter to (1) CommerceChannelRelFinder.countByC_C, or (2) CommerceChannelRelFinder.findByC_C.

    Published: 17 May 2021
    6.1
    Medium

    CVE-2021-29046

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the Asset module's category selector input field in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_asset_categories_admin_web_portlet_AssetCategoriesAdminPortlet_title parameter.

    Published: 17 May 2021
    6.1
    Medium

    CVE-2021-29045

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the Redirect module's redirection administration page in Liferay Portal 7.3.2 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_redirect_web_internal_portlet_RedirectPortlet_destinationURL parameter.

    Published: 17 May 2021
    5.3
    Medium

    CVE-2021-29023

    Last Modified: 29 Jul 2026

    InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable.

    Published: 17 May 2021
    8
    High

    CVE-2021-4157

    Last Modified: 21 Nov 2024

    An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users use mirroring (replication of files with NFS). A user, having access to the NFS mount, could potentially use this flaw to crash the system or escalate privileges on the system.

    Published: 17 May 2021
    4.3
    Medium

    CVE-2021-29956

    Last Modified: 21 Nov 2024

    OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were stored unencrypted on the user's local disk. The master password protection was inactive for those keys. Version 78.10.2 will restore the protection mechanism for newly imported keys, and will automatically protect keys that had been imported using affected Thunderbird versions. This vulnerability affects Thunderbird < 78.10.2.

    Published: 17 May 2021