CVE Feed

    Dashboard / CVE

    4.9
    Medium

    CVE-2020-4993

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.3 and 7.4 when decompressing or verifying signature of zip files processes data in a way that may be vulnerable to path traversal attacks. IBM X-Force ID: 192905.

    Published: 5 May 2021
    9.8
    Critical

    CVE-2020-4979

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.3 and 7.4 is vulnerable to insecure inter-deployment communication. An attacker that is able to comprimise or spoof traffic between hosts may be able to execute arbitrary commands. IBM X-Force D: 192538.

    Published: 5 May 2021
    7.8
    High

    CVE-2020-4932

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.3 and 7.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 191748.

    Published: 5 May 2021
    5.4
    Medium

    CVE-2020-4929

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191706.

    Published: 5 May 2021
    6.5
    Medium

    CVE-2020-4883

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.3 and 7.4 could disclose sensitive information about other domains which could be used in further attacks against the system. IBM X-Force ID: 190907.

    Published: 5 May 2021
    7.6
    High

    CVE-2021-29489

    Last Modified: 21 Nov 2024

    Highcharts JS is a JavaScript charting library based on SVG. In Highcharts versions 8 and earlier, the chart options structure was not systematically filtered for XSS vectors. The potential impact was that content from untrusted sources could execute code in the end user's browser. The vulnerability is patched in version 9. As a workaround, implementers who are not able to upgrade may apply DOMPurify recursively to the options structure to filter out malicious markup.

    Published: 5 May 2021
    7.8
    High

    CVE-2021-29100

    Last Modified: 10 Apr 2025

    A path traversal vulnerability exists in Esri ArcGIS Earth versions 1.11.0 and below which allows arbitrary file creation on an affected system through crafted input. An attacker could exploit this vulnerability to gain arbitrary code execution under security context of the user running ArcGIS Earth by inducing the user to upload a crafted file to an affected system.

    Published: 5 May 2021
    7.5
    High

    CVE-2021-31518

    Last Modified: 21 Nov 2024

    Trend Micro Home Network Security 6.5.599 and earlier is vulnerable to a file-parsing vulnerability which could allow an attacker to exploit the vulnerability and cause a denial-of-service to the device. This vulnerability is similar, but not identical to CVE-2021-31517.

    Published: 5 May 2021
    7.5
    High

    CVE-2021-31517

    Last Modified: 21 Nov 2024

    Trend Micro Home Network Security 6.5.599 and earlier is vulnerable to a file-parsing vulnerability which could allow an attacker to exploit the vulnerability and cause a denial-of-service to the device. This vulnerability is similar, but not identical to CVE-2021-31518.

    Published: 5 May 2021
    8.8
    High

    CVE-2020-13664

    Last Modified: 21 Nov 2024

    Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an administrator into visiting a malicious site that could result in creating a carefully named directory on the file system. With this directory in place, an attacker could attempt to brute force a remote code execution vulnerability. Windows servers are most likely to be affected. This issue affects: Drupal Drupal Core 8.8.x versions prior to 8.8.8; 8.9.x versions prior to 8.9.1; 9.0.1 versions prior to 9.0.1.

    Published: 5 May 2021
    6.1
    Medium

    CVE-2020-13662

    Last Modified: 21 Nov 2024

    Open Redirect vulnerability in Drupal Core allows a user to be tricked into visiting a specially crafted link which would redirect them to an arbitrary external URL. This issue affects: Drupal Drupal Core 7 version 7.70 and prior versions.

    Published: 5 May 2021
    9.8
    Critical

    CVE-2020-13665

    Last Modified: 21 Nov 2024

    Access bypass vulnerability in Drupal Core allows JSON:API when JSON:API is in read/write mode. Only sites that have the read_only set to FALSE under jsonapi.settings config are vulnerable. This issue affects: Drupal Drupal Core 8.8.x versions prior to 8.8.8; 8.9.x versions prior to 8.9.1; 9.0.x versions prior to 9.0.1.

    Published: 5 May 2021
    6.1
    Medium

    CVE-2020-13666

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Drupal Core. Drupal AJAX API does not disable JSONP by default, allowing for an XSS attack. This issue affects: Drupal Drupal Core 7.x versions prior to 7.73; 8.8.x versions prior to 8.8.10; 8.9.x versions prior to 8.9.6; 9.0.x versions prior to 9.0.6.

    Published: 5 May 2021
    10
    Critical

    CVE-2016-20010

    Last Modified: 21 Nov 2024

    EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving boolval, which is unavailable before PHP 5.5.

    Published: 5 May 2021
    5.4
    Medium

    CVE-2021-29250

    Last Modified: 21 Nov 2024

    BTCPay Server through 1.0.7.0 suffers from a Stored Cross Site Scripting (XSS) vulnerability within the POS Add Products functionality. This enables cookie stealing.

    Published: 5 May 2021
    5.3
    Medium

    CVE-2021-29248

    Last Modified: 21 Nov 2024

    BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the Secure flag for a cookie.

    Published: 5 May 2021
    5.3
    Medium

    CVE-2021-29247

    Last Modified: 21 Nov 2024

    BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the HTTPOnly flag for a cookie.

    Published: 5 May 2021
    6.7
    Medium

    CVE-2021-29246

    Last Modified: 21 Nov 2024

    BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achieve code execution. The attacker must craft a malicious plugin file with special characters to upload the file outside of the restricted directory.

    Published: 5 May 2021
    5.3
    Medium

    CVE-2021-29245

    Last Modified: 21 Nov 2024

    BTCPay Server through 1.0.7.0 uses a weak method Next to produce pseudo-random values to generate a legacy API key.

    Published: 5 May 2021
    9.8
    Critical

    CVE-2021-31800

    Last Modified: 21 Nov 2024

    Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a running smbserver instance can list and write to arbitrary files via ../ directory traversal. This could potentially be abused to achieve arbitrary code execution by replacing /etc/shadow or an SSH authorized key.

    Published: 5 May 2021
    7.8
    High

    CVE-2021-25319

    Last Modified: 21 Nov 2024

    A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to escalate to root. This issue affects: openSUSE Factory virtualbox version 6.1.20-1.1 and prior versions.

    Published: 5 May 2021
    9.1
    Critical

    CVE-2020-36333

    Last Modified: 21 Nov 2024

    themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook.

    Published: 5 May 2021
    8.8
    High

    CVE-2020-36334

    Last Modified: 21 Nov 2024

    themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database.

    Published: 5 May 2021
    4.8
    Medium

    CVE-2020-22428

    Last Modified: 21 Nov 2024

    SolarWinds Serv-U before 15.1.6 Hotfix 3 is affected by Cross Site Scripting (XSS) via a directory name (entered by an admin) containing a JavaScript payload.

    Published: 5 May 2021
    6.1
    Medium

    CVE-2021-25179

    Last Modified: 21 Nov 2024

    SolarWinds Serv-U before 15.2 is affected by Cross Site Scripting (XSS) via the HTTP Host header.

    Published: 5 May 2021
    7.5
    High

    CVE-2021-22902

    Last Modified: 21 Nov 2024

    The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible denial of service vulnerability in the Mime type parser of Action Dispatch. Carefully crafted Accept headers can cause the mime type parser in Action Dispatch to do catastrophic backtracking in the regular expression engine.

    Published: 5 May 2021
    6.1
    Medium

    CVE-2021-22903

    Last Modified: 21 Nov 2024

    The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vulnerability. Specially crafted Host headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. This is similar to CVE-2021-22881. Strings in config.hosts that do not have a leading dot are converted to regular expressions without proper escaping. This causes, for example, `config.hosts << "sub.example.com"` to permit a request with a Host header value of `sub-example.com`.

    Published: 5 May 2021
    6.1
    Medium

    CVE-2021-29953

    Last Modified: 21 Nov 2024

    A malicious webpage could have forced a Firefox for Android user into executing attacker-controlled JavaScript in the context of another domain, resulting in a Universal Cross-Site Scripting vulnerability. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected. Further details are being temporarily withheld to allow users an opportunity to update.*. This vulnerability affects Firefox < 88.0.1 and Firefox for Android < 88.1.3.

    Published: 5 May 2021
    7.5
    High

    CVE-2021-22885

    Last Modified: 21 Nov 2024

    A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input.

    Published: 5 May 2021
    7.5
    High

    CVE-2021-22904

    Last Modified: 21 Nov 2024

    The actionpack ruby gem before 6.1.3.2, 6.0.3.7, 5.2.4.6, 5.2.6 suffers from a possible denial of service vulnerability in the Token Authentication logic in Action Controller due to a too permissive regular expression. Impacted code uses `authenticate_or_request_with_http_token` or `authenticate_with_http_token` for request authentication.

    Published: 5 May 2021
    7.5
    High

    CVE-2021-29952

    Last Modified: 21 Nov 2024

    When Web Render components were destructed, a race condition could have caused undefined behavior, and we presume that with enough effort may have been exploitable to run arbitrary code. This vulnerability affects Firefox < 88.0.1 and Firefox for Android < 88.1.3.

    Published: 5 May 2021
    9.1
    Critical

    CVE-2021-32055

    Last Modified: 21 Nov 2024

    Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c has an out-of-bounds read in situations where an IMAP sequence set ends with a comma. NOTE: the $imap_qresync setting for QRESYNC is not enabled by default.

    Published: 5 May 2021
    6.5
    Medium

    CVE-2021-26804

    Last Modified: 21 Nov 2024

    Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validation by changing any file extension to ".gif", then uploading it in the "Administration/ Parameters/ Images" section of the application.

    Published: 4 May 2021
    5.4
    Medium

    CVE-2020-4987

    Last Modified: 21 Nov 2024

    The IBM FlashSystem 900 user management GUI is vulnerable to stored cross-site scripting in code versions 1.5.2.8 and prior and 1.6.1.2 and prior. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 4 May 2021
    8.8
    High

    CVE-2020-21999

    Last Modified: 21 Nov 2024

    iWT Ltd FaceSentry Access Control System 6.4.8 suffers from an authenticated OS command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user via the 'strInIP' POST parameter in pingTest PHP script.

    Published: 4 May 2021
    8.8
    High

    CVE-2021-21551

    Last Modified: 28 Oct 2025

    Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.

    Published: 4 May 2021
    7.8
    High

    CVE-2020-27518

    Last Modified: 21 Nov 2024

    All versions of Windscribe VPN for Mac and Windows <= v2.02.10 contain a local privilege escalation vulnerability in the WindscribeService component. A low privilege user could leverage several openvpn options to execute code as root/SYSTEM.

    Published: 4 May 2021
    6.3
    Medium

    CVE-2021-22547

    Last Modified: 21 Nov 2024

    In IoT Devices SDK, there is an implementation of calloc() that doesn't have a length check. An attacker could pass in memory objects larger than the buffer and wrap around to have a smaller buffer than required, allowing the attacker access to the other parts of the heap. We recommend upgrading the Google Cloud IoT Device SDK for Embedded C used to 1.0.3 or greater.

    Published: 4 May 2021
    7.5
    High

    CVE-2021-3154

    Last Modified: 21 Nov 2024

    An issue was discovered in SolarWinds Serv-U before 15.2.2. Unauthenticated attackers can retrieve cleartext passwords via macro Injection. NOTE: this had a distinct fix relative to CVE-2020-35481.

    Published: 4 May 2021
    7.8
    High

    CVE-2021-29240

    Last Modified: 21 Nov 2024

    The Package Manager of CODESYS Development System 3 before 3.5.17.0 does not check the validity of packages before installation and may be used to install CODESYS packages with malicious content.

    Published: 4 May 2021
    7.5
    High

    CVE-2021-31164

    Last Modified: 21 Nov 2024

    Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements.

    Published: 4 May 2021
    7.5
    High

    CVE-2021-29478

    Last Modified: 21 Nov 2024

    Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Redis 6.2 before 6.2.3 could be exploited to corrupt the heap and potentially result with remote code execution. Redis 6.0 and earlier are not directly affected by this issue. The problem is fixed in version 6.2.3. An additional workaround to mitigate the problem without patching the `redis-server` executable is to prevent users from modifying the `set-max-intset-entries` configuration parameter. This can be done using ACL to restrict unprivileged users from using the `CONFIG SET` command.

    Published: 4 May 2021
    2.2
    Low

    CVE-2020-8562

    Last Modified: 1 Jun 2026

    As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Services, Pods, Nodes, or StorageClass service providers. As part of this mitigation Kubernetes does a DNS name resolution check and validates that response IPs are not in the link-local (169.254.0.0/16) or localhost (127.0.0.0/8) range. Kubernetes then performs a second DNS resolution without validation for the actual connection. If a non-standard DNS server returns different non-cached responses, a user may be able to bypass the proxy IP restriction and access private networks on the control plane.

    Published: 4 May 2021
    7.8
    High

    CVE-2021-23134

    Last Modified: 21 Nov 2024

    Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW capability.

    Published: 4 May 2021
    5.3
    Medium

    CVE-2021-23343

    Last Modified: 21 Nov 2024

    All versions of package path-parse are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, splitTailRe, and splitPathRe regular expressions. ReDoS exhibits polynomial worst-case time complexity.

    Published: 4 May 2021
    6.5
    Medium

    CVE-2021-3544

    Last Modified: 21 Nov 2024

    Several memory leaks were found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. They exist in contrib/vhost-user-gpu/vhost-user-gpu.c and contrib/vhost-user-gpu/virgl.c due to improper release of memory (i.e., free) after effective lifetime.

    Published: 4 May 2021
    7.5
    High

    CVE-2021-31542

    Last Modified: 21 Nov 2024

    In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names.

    Published: 4 May 2021
    6.5
    Medium

    CVE-2021-3545

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. The flaw exists in virgl_cmd_get_capset_info() in contrib/vhost-user-gpu/virgl.c and could occur due to the read of uninitialized memory. A malicious guest could exploit this issue to leak memory from the host.

    Published: 4 May 2021
    8.2
    High

    CVE-2021-3546

    Last Modified: 21 Nov 2024

    An out-of-bounds write vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. The flaw occurs while processing the 'VIRTIO_GPU_CMD_GET_CAPSET' command from the guest. It could allow a privileged guest user to crash the QEMU process on the host, resulting in a denial of service condition, or potential code execution with the privileges of the QEMU process.

    Published: 4 May 2021
    6.5
    Medium

    CVE-2021-29951

    Last Modified: 21 Nov 2024

    The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service. This could be used to prevent the browser update service from operating (if an attacker spammed the 'Stop' command); but also exposed attack surface in the maintenance service. *Note: This issue only affected Windows operating systems older than Win 10 build 1709. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.10.1, Firefox < 87, and Firefox ESR < 78.10.1.

    Published: 4 May 2021