CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-29145

    Last Modified: 21 Nov 2024

    A remote server side request forgery (SSRF) remote code execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager that address this security vulnerability.

    Published: 29 Apr 2021
    5.4
    Medium

    CVE-2021-29146

    Last Modified: 21 Nov 2024

    A remote cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager that address this security vulnerability.

    Published: 29 Apr 2021
    6.1
    Medium

    CVE-2021-29137

    Last Modified: 21 Nov 2024

    A remote URL redirection vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

    Published: 29 Apr 2021
    8.8
    High

    CVE-2021-25167

    Last Modified: 21 Nov 2024

    A remote unauthorized access vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

    Published: 29 Apr 2021
    8.8
    High

    CVE-2021-25166

    Last Modified: 21 Nov 2024

    A remote unauthorized access vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

    Published: 29 Apr 2021
    8.1
    High

    CVE-2021-25163

    Last Modified: 21 Nov 2024

    A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

    Published: 29 Apr 2021
    7.7
    High

    CVE-2021-21414

    Last Modified: 21 Nov 2024

    Prisma is an open source ORM for Node.js & TypeScript. As of today, we are not aware of any Prisma users or external consumers of the `@prisma/sdk` package who are affected by this security vulnerability. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. It only affects the `getPackedPackage` function and this function is not advertised and only used for tests & building our CLI, no malicious code was found after checking our codebase.

    Published: 29 Apr 2021
    6.5
    Medium

    CVE-2021-21391

    Last Modified: 21 Nov 2024

    CKEditor 5 provides a WYSIWYG editing solution. This CVE affects the following npm packages: ckeditor5-engine, ckeditor5-font, ckeditor5-image, ckeditor5-list, ckeditor5-markdown-gfm, ckeditor5-media-embed, ckeditor5-paste-from-office, and ckeditor5-widget. Following an internal audit, a regular expression denial of service (ReDoS) vulnerability has been discovered in multiple CKEditor 5 packages. The vulnerability allowed to abuse particular regular expressions, which could cause a significant performance drop resulting in a browser tab freeze. It affects all users using the CKEditor 5 packages listed above at version <= 26.0.0. The problem has been recognized and patched. The fix will be available in version 27.0.0.

    Published: 29 Apr 2021
    7.8
    High

    CVE-2021-31776

    Last Modified: 21 Nov 2024

    Aviatrix VPN Client before 2.14.14 on Windows has an unquoted search path that enables local privilege escalation to the SYSTEM user, if the machine is misconfigured to allow unprivileged users to write to directories that are supposed to be restricted to administrators.

    Published: 29 Apr 2021
    9.8
    Critical

    CVE-2021-20090

    Last Modified: 3 Nov 2025

    A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote attackers to bypass authentication.

    Published: 29 Apr 2021
    9.8
    Critical

    CVE-2021-31875

    Last Modified: 21 Nov 2024

    In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_json_parse, which can potentially lead to redirection of control flow. NOTE: the original reporter disputes the significance of this finding because "there isn’t very much of an opportunity to exploit this reliably for an information leak, so there isn’t any real security impact."

    Published: 29 Apr 2021
    7.5
    High

    CVE-2021-31918

    Last Modified: 21 Nov 2024

    A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update and creation. The highest threat from this vulnerability is to data confidentiality.

    Published: 29 Apr 2021
    7.5
    High

    CVE-2020-15225

    Last Modified: 21 Nov 2024

    django-filter is a generic system for filtering Django QuerySets based on user selections. In django-filter before version 2.4.0, automatically generated `NumberFilter` instances, whose value was later converted to an integer, were subject to potential DoS from maliciously input using exponential format with sufficiently large exponents. Version 2.4.0+ applies a `MaxValueValidator` with a a default `limit_value` of 1e50 to the form field used by `NumberFilter` instances. In addition, `NumberFilter` implements the new `get_max_validator()` which should return a configured validator instance to customise the limit, or else `None` to disable the additional validation. Users may manually apply an equivalent validator if they are not able to upgrade.

    Published: 29 Apr 2021
    3.3
    Low

    CVE-2021-25317

    Last Modified: 21 Nov 2024

    A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Leap 15.2, Factory allows local attackers with control of the lp users to create files as root with 0644 permissions without the ability to set the content. This issue affects: SUSE Linux Enterprise Server 11-SP4-LTSS cups versions prior to 1.3.9. SUSE Manager Server 4.0 cups versions prior to 2.2.7. SUSE OpenStack Cloud Crowbar 9 cups versions prior to 1.7.5. openSUSE Leap 15.2 cups versions prior to 2.2.7. openSUSE Factory cups version 2.3.3op2-2.1 and prior versions.

    Published: 29 Apr 2021
    6.8
    Medium

    CVE-2021-20254

    Last Modified: 21 Nov 2024

    A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negative cache entry had been added to the mapping cache. This could cause the calling code to return those values into the process token that stores the group membership for a user. The highest threat from this vulnerability is to data confidentiality and integrity.

    Published: 29 Apr 2021
    6.7
    Medium

    CVE-2021-3543

    Last Modified: 21 Nov 2024

    A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closures on the enclave file descriptor. A local user of a host machine could use this flaw to crash the system or escalate their privileges on the system.

    Published: 29 Apr 2021
    7.5
    High

    CVE-2020-7038

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in Management component of Avaya Equinox Conferencing that could potentially allow an unauthenticated, remote attacker to gain access to screen sharing and whiteboard sessions. The affected versions of Management component of Avaya Equinox Conferencing include all 3.x versions before 3.17. Avaya Equinox Conferencing is now offered as Avaya Meetings Server.

    Published: 28 Apr 2021
    8.1
    High

    CVE-2020-7037

    Last Modified: 21 Nov 2024

    An XML External Entities (XXE) vulnerability in Media Server component of Avaya Equinox Conferencing could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system or even potentially lead to a denial of service. The affected versions of Avaya Equinox Conferencing includes all 9.x versions before 9.1.11. Equinox Conferencing is now offered as Avaya Meetings Server.

    Published: 28 Apr 2021
    9.4
    Critical

    CVE-2021-29483

    Last Modified: 21 Nov 2024

    ManageWiki is an extension to the MediaWiki project. The 'wikiconfig' API leaked the value of private configuration variables set through the ManageWiki variable to all users. This has been patched by https://github.com/miraheze/ManageWiki/compare/99f3b2c8af18...befb83c66f5b.patch. If you are unable to patch set `$wgAPIListModules['wikiconfig'] = 'ApiQueryDisabled';` or remove private config as a workaround.

    Published: 28 Apr 2021
    6
    Medium

    CVE-2021-2321

    Last Modified: 21 Nov 2024

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).

    Published: 28 Apr 2021
    6.1
    Medium

    CVE-2020-22789

    Last Modified: 21 Nov 2024

    Unauthenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via the login page. The XSS is executed when an administrator accesses the logs.

    Published: 28 Apr 2021
    5.4
    Medium

    CVE-2020-22790

    Last Modified: 21 Nov 2024

    Authenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to execute codeby injecting arbitrary web script or HTML via modifying the name of the users. The XSS is executed when an administrator access the logs.

    Published: 28 Apr 2021
    7.5
    High

    CVE-2020-22781

    Last Modified: 21 Nov 2024

    In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denial of service (crash the instance).

    Published: 28 Apr 2021
    7.5
    High

    CVE-2020-22782

    Last Modified: 21 Nov 2024

    Etherpad < 1.8.3 is affected by a denial of service in the import functionality. Upload of binary file to the import endpoint would crash the instance.

    Published: 28 Apr 2021
    6.5
    Medium

    CVE-2020-22783

    Last Modified: 21 Nov 2024

    Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files. This affects every database backend supported by Etherpad.

    Published: 28 Apr 2021
    7.5
    High

    CVE-2020-22784

    Last Modified: 21 Nov 2024

    In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database records using UeberDB's MySQL connector could allow bypassing access controls enforced on key names.

    Published: 28 Apr 2021
    7.5
    High

    CVE-2020-22785

    Last Modified: 21 Nov 2024

    Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service. Aggressively targeting random pad import endpoints with empty data would flatten all pads due to lack of rate limiting and missing ownership check.

    Published: 28 Apr 2021
    8.1
    High

    CVE-2021-25165

    Last Modified: 21 Nov 2024

    A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

    Published: 28 Apr 2021
    6.5
    Medium

    CVE-2021-25164

    Last Modified: 21 Nov 2024

    A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

    Published: 28 Apr 2021
    7.2
    High

    CVE-2021-25152

    Last Modified: 21 Nov 2024

    A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

    Published: 28 Apr 2021
    8.1
    High

    CVE-2021-25153

    Last Modified: 21 Nov 2024

    A remote SQL injection vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

    Published: 28 Apr 2021
    7.5
    High

    CVE-2021-25154

    Last Modified: 21 Nov 2024

    A remote escalation of privilege vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

    Published: 28 Apr 2021
    8.8
    High

    CVE-2021-25151

    Last Modified: 21 Nov 2024

    A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

    Published: 28 Apr 2021
    6.1
    Medium

    CVE-2020-17999

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in MiniCMS v1.10 allows remote attackers to execute arbitrary code by injecting commands via a crafted HTTP request to the component "/mc-admin/post-edit.php".

    Published: 28 Apr 2021
    6.1
    Medium

    CVE-2020-18022

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in Qibosoft QiboCMS v7 and earlier allows remote attackers to execute arbitrary code or obtain sensitive information by injecting arbitrary commands in a HTTP request to the "ewebeditor\3.1.1\kindeditor.js" component.

    Published: 28 Apr 2021
    7.5
    High

    CVE-2020-21996

    Last Modified: 21 Nov 2024

    AVE DOMINAplus <=1.10.x suffers from an unauthenticated reboot command execution. Attackers can exploit this issue to cause a denial of service scenario.

    Published: 28 Apr 2021
    9.8
    Critical

    CVE-2020-21994

    Last Modified: 21 Nov 2024

    AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file '/xml/authClients.xml' and obtain administrative login information that allows for a successful authentication bypass attack.

    Published: 28 Apr 2021
    6.1
    Medium

    CVE-2020-21993

    Last Modified: 21 Nov 2024

    In WEMS Limited Enterprise Manager 2.58, input passed to the GET parameter 'email' is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML code in a user's browser session in context of an affected site.

    Published: 28 Apr 2021
    8.1
    High

    CVE-2021-25147

    Last Modified: 21 Nov 2024

    A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

    Published: 28 Apr 2021
    7.8
    High

    CVE-2020-7123

    Last Modified: 21 Nov 2024

    A local escalation of privilege vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager that address this security vulnerability.

    Published: 28 Apr 2021
    9.8
    Critical

    CVE-2020-21991

    Last Modified: 21 Nov 2024

    AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly calling the autologin GET parameter in changeparams.php script. Setting the autologin value to 1 allows an unauthenticated attacker to permanently disable the authentication security control and access the management interface with admin privileges without providing credentials.

    Published: 28 Apr 2021
    5.5
    Medium

    CVE-2021-3508

    Last Modified: 21 Nov 2024

    A flaw was found in PDFResurrect in version 0.22b. There is an infinite loop in get_xref_linear_skipped() in pdf.c via a crafted PDF file.

    Published: 28 Apr 2021
    5.4
    Medium

    CVE-2021-29388

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in SourceCodester Budget Management System 1.0 allows users to inject and store arbitrary JavaScript code in index.php via vulnerable field 'Budget Title'.

    Published: 28 Apr 2021
    7.5
    High

    CVE-2020-18019

    Last Modified: 21 Nov 2024

    SQL Injection in Xinhu OA System v1.8.3 allows remote attackers to obtain sensitive information by injecting arbitrary commands into the "typeid" variable of the "createfolderAjax" function in the "mode_worcAction.php" component.

    Published: 28 Apr 2021
    9.8
    Critical

    CVE-2020-18020

    Last Modified: 21 Nov 2024

    SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands into the "user_phone" parameter of a crafted HTTP request to the "admin.php" component.

    Published: 28 Apr 2021
    5.4
    Medium

    CVE-2021-29387

    Last Modified: 21 Nov 2024

    Multiple stored cross-site scripting (XSS) vulnerabilities in Sourcecodester Equipment Inventory System 1.0 allow remote attackers to inject arbitrary javascript via any "Add" sections, such as Add Item , Employee and Position or others in the Name Parameters.

    Published: 28 Apr 2021
    6.1
    Medium

    CVE-2021-29159

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability has been discovered in Nexus Repository Manager 3.x before 3.30.1. An attacker with a local account can create entities with crafted properties that, when viewed by an administrator, can execute arbitrary JavaScript in the context of the NXRM application.

    Published: 28 Apr 2021
    7.5
    High

    CVE-2021-22331

    Last Modified: 21 Nov 2024

    There is a JavaScript injection vulnerability in certain Huawei smartphones. A module does not verify some inputs sufficiently. Attackers can exploit this vulnerability by sending a malicious application request to launch JavaScript injection. This may compromise normal service. Affected product versions include HUAWEI P30 versions earlier than 10.1.0.165(C01E165R2P11), 11.0.0.118(C635E2R1P3), 11.0.0.120(C00E120R2P5), 11.0.0.138(C10E4R5P3), 11.0.0.138(C185E4R7P3), 11.0.0.138(C432E8R2P3), 11.0.0.138(C461E4R3P3), 11.0.0.138(C605E4R1P3), and 11.0.0.138(C636E4R3P3).

    Published: 28 Apr 2021
    7.5
    High

    CVE-2021-22332

    Last Modified: 21 Nov 2024

    There is a pointer double free vulnerability in some versions of CloudEngine 5800, CloudEngine 6800, CloudEngine 7800 and CloudEngine 12800. When a function is called, the same memory pointer is copied to two functional modules. Attackers can exploit this vulnerability by performing a malicious operation to cause the pointer double free. This may lead to module crash, compromising normal service.

    Published: 28 Apr 2021
    6.5
    Medium

    CVE-2021-22330

    Last Modified: 21 Nov 2024

    There is an out of bounds write vulnerability in Huawei Smartphone HUAWEI P30 versions 9.1.0.131(C00E130R1P21) when processing a message. An unauthenticated attacker can exploit this vulnerability by sending specific message to the target device. Due to insufficient validation of the input parameter, successful exploit can cause the process and the service to be abnormal.

    Published: 28 Apr 2021