CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2021-21652

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins Xray - Test Management for Jira Plugin 2.4.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 11 May 2021
    4.3
    Medium

    CVE-2021-21653

    Last Modified: 21 Nov 2024

    Jenkins Xray - Test Management for Jira Plugin 2.4.0 and earlier does not perform a permission check in an HTTP endpoint, allowing with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

    Published: 11 May 2021
    4.3
    Medium

    CVE-2021-21651

    Last Modified: 21 Nov 2024

    Jenkins S3 publisher Plugin 0.11.6 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to obtain the list of configured profiles.

    Published: 11 May 2021
    5.4
    Medium

    CVE-2021-21649

    Last Modified: 21 Nov 2024

    Jenkins Dashboard View Plugin 2.15 and earlier does not escape URLs referenced in Image Dashboard Portlets, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Configure permission.

    Published: 11 May 2021
    4.3
    Medium

    CVE-2021-21650

    Last Modified: 21 Nov 2024

    Jenkins S3 publisher Plugin 0.11.6 and earlier does not perform Run/Artifacts permission checks in various HTTP endpoints and API models, allowing attackers with Item/Read permission to obtain information about artifacts uploaded to S3, if the optional Run/Artifacts permission is enabled.

    Published: 11 May 2021
    6.1
    Medium

    CVE-2021-31537

    Last Modified: 21 Nov 2024

    SIS SIS-REWE Go before 7.7 SP17 allows XSS: rewe/prod/web/index.php (affected parameters are config, version, win, db, pwd, and user) and /rewe/prod/web/rewe_go_check.php (version and all other parameters).

    Published: 11 May 2021
    6.1
    Medium

    CVE-2021-32561

    Last Modified: 21 Nov 2024

    OctoPrint before 1.6.0 allows XSS because API error messages include the values of input parameters.

    Published: 11 May 2021
    6.5
    Medium

    CVE-2021-32560

    Last Modified: 21 Nov 2024

    The Logging subsystem in OctoPrint before 1.6.0 has incorrect access control because it attempts to manage files that are not *.log files.

    Published: 11 May 2021
    6.1
    Medium

    CVE-2021-21990

    Last Modified: 21 Nov 2024

    VMware Workspace one UEM console (2102 prior to 21.2.0.8, 2101 prior to 21.1.0.14, 2011 prior to 20.11.0.27, 2010 prior to 20.10.0.16,2008 prior to 20.8.0.28, 2007 prior to 20.7.0.14,2006 prior to 20.6.0.19, 2005 prior to 20.5.0.46, 2004 prior to 20.4.0.21, 2003 prior to 20.3.0.23, 2001 prior to 20.1.0.32, 1912 prior to 19.12.0.24) contain a cross-site scripting vulnerability. VMware Workspace ONE UEM console does not validate incoming requests during device enrollment after leading to rendering of unsanitized input on the user device in response.

    Published: 11 May 2021
    6.1
    Medium

    CVE-2020-35438

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in the kk Star Ratings plugin before 4.1.5.

    Published: 11 May 2021
    9.8
    Critical

    CVE-2021-31897

    Last Modified: 21 Nov 2024

    In JetBrains WebStorm before 2021.1, code execution without user confirmation was possible for untrusted projects.

    Published: 11 May 2021
    7.5
    High

    CVE-2021-31898

    Last Modified: 21 Nov 2024

    In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS.

    Published: 11 May 2021
    7.5
    High

    CVE-2021-30482

    Last Modified: 21 Nov 2024

    In JetBrains UpSource before 2020.1.1883, application passwords were not revoked correctly

    Published: 11 May 2021
    9.8
    Critical

    CVE-2021-31915

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible.

    Published: 11 May 2021
    9.8
    Critical

    CVE-2021-31914

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was possible.

    Published: 11 May 2021
    7.5
    High

    CVE-2021-31913

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2020.2.3, insufficient checks of the redirect_uri were made during GitHub SSO token exchange.

    Published: 11 May 2021
    8.8
    High

    CVE-2021-31912

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset.

    Published: 11 May 2021
    6.1
    Medium

    CVE-2021-31911

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2020.2.3, reflected XSS was possible on several pages.

    Published: 11 May 2021
    7.5
    High

    CVE-2021-31910

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2020.2.3, information disclosure via SSRF was possible.

    Published: 11 May 2021
    5.4
    Medium

    CVE-2021-31908

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2020.2.3, stored XSS was possible on several pages.

    Published: 11 May 2021
    9.8
    Critical

    CVE-2021-31909

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2020.2.3, argument injection leading to remote code execution was possible.

    Published: 11 May 2021
    5.4
    Medium

    CVE-2021-3315

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2020.2.2, stored XSS on a tests page was possible.

    Published: 11 May 2021
    5.3
    Medium

    CVE-2021-31907

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2020.2.2, permission checks for changing TeamCity plugins were implemented improperly.

    Published: 11 May 2021
    2.7
    Low

    CVE-2021-31906

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2020.2.2, audit logs were not sufficient when an administrator uploaded a file.

    Published: 11 May 2021
    3.3
    Low

    CVE-2021-26309

    Last Modified: 21 Nov 2024

    Information disclosure in the TeamCity plugin for IntelliJ before 2020.2.2.85899 was possible because a local temporary file had Insecure Permissions.

    Published: 11 May 2021
    7.5
    High

    CVE-2021-26310

    Last Modified: 21 Nov 2024

    In the TeamCity IntelliJ plugin before 2020.2.2.85899, DoS was possible.

    Published: 11 May 2021
    6.1
    Medium

    CVE-2021-31904

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2020.2.2, XSS was potentially possible on the test history page.

    Published: 11 May 2021
    7.8
    High

    CVE-2021-30005

    Last Modified: 21 Nov 2024

    In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.

    Published: 11 May 2021
    7.5
    High

    CVE-2021-31905

    Last Modified: 21 Nov 2024

    In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible.

    Published: 11 May 2021
    7.5
    High

    CVE-2021-31902

    Last Modified: 21 Nov 2024

    In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly.

    Published: 11 May 2021
    6.1
    Medium

    CVE-2021-31903

    Last Modified: 21 Nov 2024

    In JetBrains YouTrack before 2021.1.9819, a pull request's title was sanitized insufficiently, leading to XSS.

    Published: 11 May 2021
    5.4
    Medium

    CVE-2021-27733

    Last Modified: 21 Nov 2024

    In JetBrains YouTrack before 2020.6.6441, stored XSS was possible via an issue attachment.

    Published: 11 May 2021
    7.5
    High

    CVE-2021-31901

    Last Modified: 21 Nov 2024

    In JetBrains Hub before 2021.1.13079, two-factor authentication wasn't enabled properly for the All Users group.

    Published: 11 May 2021
    7.5
    High

    CVE-2021-30504

    Last Modified: 21 Nov 2024

    In JetBrains IntelliJ IDEA before 2021.1, DoS was possible because of unbounded resource allocation.

    Published: 11 May 2021
    7.8
    High

    CVE-2021-29263

    Last Modified: 21 Nov 2024

    In JetBrains IntelliJ IDEA 2020.3.3, local code execution was possible because of insufficient checks when getting the project from VCS.

    Published: 11 May 2021
    7.5
    High

    CVE-2021-30006

    Last Modified: 21 Nov 2024

    In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure.

    Published: 11 May 2021
    5.3
    Medium

    CVE-2021-31900

    Last Modified: 21 Nov 2024

    In JetBrains Code With Me bundled to the compatible IDE versions before 2021.1, a client could open a browser on a host.

    Published: 11 May 2021
    8.8
    High

    CVE-2021-31899

    Last Modified: 21 Nov 2024

    In JetBrains Code With Me bundled to the compatible IDEs before version 2021.1, the client could execute code in read-only mode.

    Published: 11 May 2021
    8.8
    High

    CVE-2020-27246

    Last Modified: 21 Nov 2024

    An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoComment parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 11 May 2021
    8.8
    High

    CVE-2020-27245

    Last Modified: 21 Nov 2024

    An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoBuyer parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 11 May 2021
    8.8
    High

    CVE-2020-27244

    Last Modified: 21 Nov 2024

    An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoCode parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 11 May 2021
    8.8
    High

    CVE-2020-27243

    Last Modified: 21 Nov 2024

    An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoService parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 11 May 2021
    8.8
    High

    CVE-2020-27242

    Last Modified: 21 Nov 2024

    An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoLocation parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 11 May 2021
    5.4
    Medium

    CVE-2021-32544

    Last Modified: 21 Nov 2024

    Special characters of IGT search function in igt+ are not filtered in specific fields, which allow remote authenticated attackers can inject malicious JavaScript and carry out DOM-based XSS (Cross-site scripting) attacks.

    Published: 11 May 2021
    5.4
    Medium

    CVE-2021-30174

    Last Modified: 21 Nov 2024

    RiyaLab CloudISO event item is added, special characters in specific field of time management page are not properly filtered, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks.

    Published: 11 May 2021
    5.3
    Medium

    CVE-2020-26146

    Last Modified: 2 Jun 2026

    An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. Note that WEP is vulnerable to this attack by design.

    Published: 11 May 2021
    5.4
    Medium

    CVE-2020-26147

    Last Modified: 14 Apr 2026

    An issue was discovered in the Linux kernel 5.8.9. The WEP, WPA, WPA2, and WPA3 implementations reassemble fragments even though some of them were sent in plaintext. This vulnerability can be abused to inject packets and/or exfiltrate selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used.

    Published: 11 May 2021
    6.5
    Medium

    CVE-2020-26145

    Last Modified: 14 Apr 2026

    An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept second (or subsequent) broadcast fragments even when sent in plaintext and process them as full unfragmented frames. An adversary can abuse this to inject arbitrary network packets independent of the network configuration.

    Published: 11 May 2021
    6.5
    Medium

    CVE-2020-26144

    Last Modified: 14 Apr 2026

    An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) header for EAPOL. An adversary can abuse this to inject arbitrary network packets independent of the network configuration.

    Published: 11 May 2021
    6.5
    Medium

    CVE-2020-26143

    Last Modified: 14 Apr 2026

    An issue was discovered in the ALFA Windows 10 driver 1030.36.604 for AWUS036ACH. The WEP, WPA, WPA2, and WPA3 implementations accept fragmented plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration.

    Published: 11 May 2021