CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-2021-30171

    Last Modified: 21 Nov 2024

    Special characters of ERP POS news page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks, additionally access and manipulate customer’s information.

    Published: 7 May 2021
    4.6
    Medium

    CVE-2021-30170

    Last Modified: 21 Nov 2024

    Special characters of ERP POS customer profile page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks, additionally access and manipulate customer’s information.

    Published: 7 May 2021
    8.4
    High

    CVE-2021-1927

    Last Modified: 21 Nov 2024

    Possible use after free due to lack of null check while memory is being freed in FastRPC driver in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 7 May 2021
    7.8
    High

    CVE-2021-1915

    Last Modified: 21 Nov 2024

    Buffer overflow can occur due to improper validation of NDP application information length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 7 May 2021
    7.5
    High

    CVE-2021-1925

    Last Modified: 21 Nov 2024

    Possible denial of service scenario due to improper handling of group management action frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 7 May 2021
    7.3
    High

    CVE-2021-1910

    Last Modified: 21 Nov 2024

    Double free in video due to lack of input buffer length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 7 May 2021
    6.2
    Medium

    CVE-2021-1906

    Last Modified: 28 Oct 2025

    Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 7 May 2021
    8.4
    High

    CVE-2021-1905

    Last Modified: 28 Oct 2025

    Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 7 May 2021
    6.8
    Medium

    CVE-2021-1895

    Last Modified: 21 Nov 2024

    Possible integer overflow due to improper length check while flashing an image in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music

    Published: 7 May 2021
    6.8
    Medium

    CVE-2020-11295

    Last Modified: 21 Nov 2024

    Use after free in camera If the threadmanager is being cleaned up while the worker thread is processing objects in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 7 May 2021
    8.4
    High

    CVE-2021-1891

    Last Modified: 21 Nov 2024

    A possible use-after-free occurrence in audio driver can happen when pointers are not properly handled in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 7 May 2021
    5.9
    Medium

    CVE-2020-11294

    Last Modified: 21 Nov 2024

    Out of bound write in logger due to prefix size is not validated while prepended to logging string in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 7 May 2021
    7.8
    High

    CVE-2020-11289

    Last Modified: 21 Nov 2024

    Out of bound write can occur in TZ command handler due to lack of validation of command ID in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 7 May 2021
    5.1
    Medium

    CVE-2020-11293

    Last Modified: 21 Nov 2024

    Out of bound read can happen in Widevine TA while copying data to buffer from user data due to lack of check of buffer length received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 7 May 2021
    7.8
    High

    CVE-2020-11288

    Last Modified: 21 Nov 2024

    Out of bound write can occur in playready while processing command due to lack of input validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

    Published: 7 May 2021
    8.2
    High

    CVE-2020-11285

    Last Modified: 21 Nov 2024

    Buffer over-read while unpacking the RTCP packet we may read extra byte if wrong length is provided in RTCP packets in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 7 May 2021
    8.4
    High

    CVE-2020-11284

    Last Modified: 21 Nov 2024

    Locked memory can be unlocked and modified by non secure boot loader through improper system call sequence making the memory region untrusted source of input for secure boot loader in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

    Published: 7 May 2021
    7.5
    High

    CVE-2020-11279

    Last Modified: 21 Nov 2024

    Memory corruption while processing crafted SDES packets due to improper length check in sdes packets recieved in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 7 May 2021
    7.5
    High

    CVE-2020-11273

    Last Modified: 21 Nov 2024

    Histogram type KPI was teardown with the assumption of the existence of histogram binning info and will lead to null pointer access when histogram binning info is missing due to lack of null check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile

    Published: 7 May 2021
    7.5
    High

    CVE-2020-11274

    Last Modified: 21 Nov 2024

    Denial of service in MODEM due to assert to the invalid configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 7 May 2021
    7.5
    High

    CVE-2020-11268

    Last Modified: 21 Nov 2024

    Potential UE reset while decoding a crafted Sib1 or SIB1 that schedules unsupported SIBs and can lead to denial of service in Snapdragon Auto, Snapdragon Mobile

    Published: 7 May 2021
    6.2
    Medium

    CVE-2020-11254

    Last Modified: 21 Nov 2024

    Memory corruption during buffer allocation due to dereferencing session ctx pointer without checking if pointer is valid in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile

    Published: 7 May 2021
    4.3
    Medium

    CVE-2020-29445

    Last Modified: 12 Feb 2025

    Affected versions of Confluence Server before 7.4.8, and versions from 7.5.0 before 7.11.0 allow attackers to identify internal hosts and ports via a blind server-side request forgery vulnerability in Team Calendars parameters.

    Published: 7 May 2021
    5.4
    Medium

    CVE-2020-29444

    Last Modified: 12 Feb 2025

    Affected versions of Team Calendar in Confluence Server before 7.11.0 allow attackers to inject arbitrary HTML or Javascript via a Cross Site Scripting Vulnerability in admin global setting parameters.

    Published: 7 May 2021
    7.5
    High

    CVE-2021-32074

    Last Modified: 21 Nov 2024

    HashiCorp vault-action (aka Vault GitHub Action) before 2.2.0 allows attackers to obtain sensitive information from log files because a multi-line secret was not correctly registered with GitHub Actions for log masking.

    Published: 7 May 2021
    9.8
    Critical

    CVE-2021-32090

    Last Modified: 21 Nov 2024

    The dashboard component of StackLift LocalStack 0.12.6 allows attackers to inject arbitrary shell commands via the functionName parameter.

    Published: 7 May 2021
    6.1
    Medium

    CVE-2021-32091

    Last Modified: 21 Nov 2024

    A Cross-site scripting (XSS) vulnerability exists in StackLift LocalStack 0.12.6.

    Published: 7 May 2021
    6.1
    Medium

    CVE-2021-32092

    Last Modified: 21 Nov 2024

    A Cross-site scripting (XSS) vulnerability in the DocumentAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows remote attackers to inject arbitrary web script or HTML via the uuid parameter.

    Published: 7 May 2021
    6.5
    Medium

    CVE-2021-32093

    Last Modified: 21 Nov 2024

    The ConfigFileAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to read arbitrary files via the ConfigName parameter.

    Published: 7 May 2021
    8.8
    High

    CVE-2021-32094

    Last Modified: 21 Nov 2024

    U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to upload arbitrary files.

    Published: 7 May 2021
    8.1
    High

    CVE-2021-32095

    Last Modified: 21 Nov 2024

    U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to delete arbitrary files.

    Published: 7 May 2021
    8.8
    High

    CVE-2021-32096

    Last Modified: 21 Nov 2024

    The ConsoleAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows a CSRF attack that results in injecting arbitrary Ruby code (for an eval call) via the CONSOLE_COMMAND_STRING parameter.

    Published: 7 May 2021
    9.8
    Critical

    CVE-2021-32098

    Last Modified: 21 Nov 2024

    Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.

    Published: 7 May 2021
    9.8
    Critical

    CVE-2021-32099

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileged session via the /include/chart_generator.php session_id parameter, leading to a login bypass.

    Published: 7 May 2021
    6.5
    Medium

    CVE-2021-32100

    Last Modified: 21 Nov 2024

    A remote file inclusion vulnerability exists in Artica Pandora FMS 742, exploitable by the lowest privileged user.

    Published: 7 May 2021
    8.2
    High

    CVE-2021-32101

    Last Modified: 21 Nov 2024

    The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/_machine_config.php. To exploit the vulnerability, an unauthenticated attacker can register an account, bypassing the permission check of this portal's API. Then, the attacker can then manipulate and read data of every registered patient.

    Published: 7 May 2021
    8.8
    High

    CVE-2021-32102

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists (with user privileges) in library/custom_template/ajax_code.php in OpenEMR 5.0.2.1.

    Published: 7 May 2021
    4.8
    Medium

    CVE-2021-32103

    Last Modified: 21 Nov 2024

    A Stored XSS vulnerability in interface/usergroup/usergroup_admin.php in OpenEMR before 5.0.2.1 allows a admin authenticated user to inject arbitrary web script or HTML via the lname parameter.

    Published: 7 May 2021
    8.8
    High

    CVE-2021-32104

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists (with user privileges) in interface/forms/eye_mag/save.php in OpenEMR 5.0.2.1.

    Published: 7 May 2021
    7.5
    High

    CVE-2021-23424

    Last Modified: 21 Nov 2024

    This affects all versions of package ansi-html. If an attacker provides a malicious string, it will get stuck processing the input for an extremely long time.

    Published: 7 May 2021
    5.3
    Medium

    CVE-2021-33430

    Last Modified: 21 Nov 2024

    A Buffer Overflow vulnerability exists in NumPy 1.9.x in the PyArray_NewFromDescr_int function of ctors.c when specifying arrays of large dimensions (over 32) from Python code, which could let a malicious user cause a Denial of Service. NOTE: The vendor does not agree this is a vulneraility; In (very limited) circumstances a user may be able provoke the buffer overflow, the user is most likely already privileged to at least provoke denial of service by exhausting memory. Triggering this further requires the use of uncommon API (complicated structured dtypes), which is very unlikely to be available to an unprivileged user

    Published: 7 May 2021
    7.5
    High

    CVE-2021-32077

    Last Modified: 21 Nov 2024

    Primary Source Verification in VerityStream MSOW Solutions before 3.1.1 allows an anonymous internet user to discover Social Security Number (SSN) values via a brute-force attack on a (sometimes hidden) search field, because the last four SSN digits are part of the supported combination of search selectors. This discloses doctors' and nurses' social security numbers and PII.

    Published: 6 May 2021
    8.8
    High

    CVE-2020-23264

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) in Fork-CMS before 5.8.2 allow remote attackers to hijack the authentication of logged administrators.

    Published: 6 May 2021
    6.1
    Medium

    CVE-2020-23263

    Last Modified: 21 Nov 2024

    Persistent Cross-site scripting vulnerability on Fork CMS version 5.8.2 allows remote attackers to inject arbitrary Javascript code via the "navigation_title" parameter and the "title" parameter in /private/en/pages/add.

    Published: 6 May 2021
    4.6
    Medium

    CVE-2021-27941

    Last Modified: 21 Nov 2024

    Unconstrained Web access to the device's private encryption key in the QR code pairing mode in the eWeLink mobile application (through 4.9.2 on Android and through 4.9.1 on iOS) allows a physically proximate attacker to eavesdrop on Wi-Fi credentials and other sensitive information by monitoring the Wi-Fi spectrum during a device pairing process.

    Published: 6 May 2021
    9.8
    Critical

    CVE-2021-29203

    Last Modified: 21 Nov 2024

    A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software, prior to version 1.22. The vulnerability could be remotely exploited to bypass remote authentication leading to execution of arbitrary commands, gaining privileged access, causing denial of service, and changing the configuration. HPE has released a software update to resolve the vulnerability in the HPE Edgeline Infrastructure Manager.

    Published: 6 May 2021
    9.8
    Critical

    CVE-2021-31737

    Last Modified: 21 Nov 2024

    emlog v5.3.1 and emlog v6.0.0 have a Remote Code Execution vulnerability due to upload of database backup file in admin/data.php.

    Published: 6 May 2021
    6.5
    Medium

    CVE-2021-29493

    Last Modified: 21 Nov 2024

    Kennnyshiwa-cogs contains cogs for Red Discordbot. An RCE exploit has been found in the Tickets module of kennnyshiwa-cogs. This exploit allows discord users to craft a message that can reveal sensitive and harmful information. Users can upgrade to version 5a84d60018468e5c0346f7ee74b2b4650a6dade7 to receive a patch or, as a workaround, unload tickets to render the exploit unusable.

    Published: 6 May 2021
    7.1
    High

    CVE-2022-0850

    Last Modified: 21 Nov 2024

    A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace.

    Published: 6 May 2021
    7.5
    High

    CVE-2021-28665

    Last Modified: 21 Nov 2024

    Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can lead to excessive consumption of memory and CPU resources, and possibly a denial of service.

    Published: 6 May 2021