CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2021-3451

    Last Modified: 21 Nov 2024

    A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow configuration files to be written to non-standard locations.

    Published: 27 Apr 2021
    7.8
    High

    CVE-2021-3464

    Last Modified: 21 Nov 2024

    A DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow privilege escalation.

    Published: 27 Apr 2021
    8.8
    High

    CVE-2021-28269

    Last Modified: 21 Nov 2024

    Soyal Technology 701Client 9.0.1 is vulnerable to Insecure permissions via client.exe binary with Authenticated Users group with Full permissions.

    Published: 27 Apr 2021
    9.8
    Critical

    CVE-2021-30642

    Last Modified: 21 Nov 2024

    An input validation flaw in the Symantec Security Analytics web UI 7.2 prior 7.2.7, 8.1, prior to 8.1.3-NSR3, 8.2, prior to 8.2.1-NSR2 or 8.2.2 allows a remote, unauthenticated attacker to execute arbitrary OS commands on the target with elevated privileges.

    Published: 27 Apr 2021
    8.8
    High

    CVE-2021-28271

    Last Modified: 21 Nov 2024

    Soyal Technologies SOYAL 701Server 9.0.1 suffers from an elevation of privileges vulnerability which can be used by an authenticated user to change the executable file with a binary choice. The vulnerability is due to improper permissions with the 'F' flag (Full) for 'Everyone'and 'Authenticated Users' group.

    Published: 27 Apr 2021
    7.8
    High

    CVE-2021-22664

    Last Modified: 21 Nov 2024

    CNCSoft-B Versions 1.0.0.3 and prior is vulnerable to an out-of-bounds write, which may allow an attacker to execute arbitrary code.

    Published: 27 Apr 2021
    7.8
    High

    CVE-2021-22660

    Last Modified: 21 Nov 2024

    CNCSoft-B Versions 1.0.0.3 and prior is vulnerable to an out-of-bounds read, which may allow an attacker to execute arbitrary code.

    Published: 27 Apr 2021
    9.8
    Critical

    CVE-2021-27480

    Last Modified: 21 Nov 2024

    Delta Industrial Automation COMMGR Versions 1.12 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute remote code.

    Published: 27 Apr 2021
    5.4
    Medium

    CVE-2020-35542

    Last Modified: 21 Nov 2024

    Unisys Data Exchange Management Studio through 5.0.34 doesn't sanitize the input to a HTML document field. This could be used for an XSS attack.

    Published: 27 Apr 2021
    6.1
    Medium

    CVE-2021-28125

    Last Modified: 21 Nov 2024

    Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener functionality would allow for a malicious user to create a short URL for a dashboard that could convince the user to click the link.

    Published: 27 Apr 2021
    7.5
    High

    CVE-2020-17517

    Last Modified: 21 Nov 2024

    The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default. The current security vulnerability allows access to keys and buckets through a curl command or an unauthenticated HTTP request. This enables unauthorized access to buckets and keys thereby exposing data to anonymous clients or users. This affected Apache Ozone prior to the 1.1.0 release.

    Published: 27 Apr 2021
    6.5
    Medium

    CVE-2021-20714

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in WP Fastest Cache versions prior to 0.9.1.7 allows a remote attacker with administrator privileges to delete arbitrary files on the server via unspecified vectors.

    Published: 27 Apr 2021
    4.3
    Medium

    CVE-2021-20715

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Hot Pepper Gourmet App for Android ver.4.111.0 and earlier, and for iOS ver.4.111.0 and earlier allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App.

    Published: 27 Apr 2021
    7.5
    High

    CVE-2021-31826

    Last Modified: 21 Nov 2024

    Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery feature. The flaw is exploitable (for a daemon crash) on systems not using this feature if a crafted cookie is supplied.

    Published: 27 Apr 2021
    7.5
    High

    CVE-2021-30165

    Last Modified: 21 Nov 2024

    The default administrator account & password of the EDIMAX wireless network camera is hard-coded. Remote attackers can disassemble firmware to obtain the privileged permission and further control the devices.

    Published: 27 Apr 2021
    5.3
    Medium

    CVE-2021-30635

    Last Modified: 21 Nov 2024

    Sonatype Nexus Repository Manager 3.x before 3.30.1 allows a remote attacker to get a list of files and directories that exist in a UI-related folder via directory traversal (no customer-specific data is exposed).

    Published: 27 Apr 2021
    7.5
    High

    CVE-2021-31671

    Last Modified: 21 Nov 2024

    pgsync before 0.6.7 is affected by Information Disclosure of sensitive information. Syncing the schema with the --schema-first and --schema-only options is mishandled. For example, the sslmode connection parameter may be lost, which means that SSL would not be used.

    Published: 27 Apr 2021
    4
    Medium

    CVE-2021-21429

    Last Modified: 21 Nov 2024

    OpenAPI Generator allows generation of API client libraries, server stubs, documentation and configuration automatically given an OpenAPI Spec. Using `File.createTempFile` in JDK will result in creating and using insecure temporary files that can leave application and system data vulnerable to attacks. OpenAPI Generator maven plug-in creates insecure temporary files during the process. The issue has been patched with `Files.createTempFile` and released in the v5.1.0 stable version.

    Published: 27 Apr 2021
    7.5
    High

    CVE-2021-22140

    Last Modified: 21 Nov 2024

    Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta feature. Using this vector, an attacker whose website is being crawled by App Search could craft a malicious sitemap.xml to traverse the filesystem of the host running the instance and obtain sensitive files.

    Published: 27 Apr 2021
    6.5
    Medium

    CVE-2021-22139

    Last Modified: 21 Nov 2024

    Kibana versions before 7.12.1 contain a denial of service vulnerability was found in the webhook actions due to a lack of timeout or a limit on the request size. An attacker with permissions to create webhook actions could drain the Kibana host connection pool, making Kibana unavailable for all other users.

    Published: 27 Apr 2021
    4.7
    Medium

    CVE-2021-29474

    Last Modified: 21 Nov 2024

    HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker can read arbitrary `.md` files from the server's filesystem due to an improper input validation, which results in the ability to perform a relative path traversal. To verify if you are affected, you can try to open the following URL: `http://localhost:3000/..%2F..%2FREADME#` (replace `http://localhost:3000` with your instance's base-URL e.g. `https://demo.hedgedoc.org/..%2F..%2FREADME#`). If you see a README page being rendered, you run an affected version. The attack works due the fact that the internal router passes the url-encoded alias to the `noteController.showNote`-function. This function passes the input directly to findNote() utility function, that will pass it on the the parseNoteId()-function, that tries to make sense out of the noteId/alias and check if a note already exists and if so, if a corresponding file on disk was updated. If no note exists the note creation-function is called, which pass this unvalidated alias, with a `.md` appended, into a path.join()-function which is read from the filesystem in the follow up routine and provides the pre-filled content of the new note. This allows an attacker to not only read arbitrary `.md` files from the filesystem, but also observes changes to them. The usefulness of this attack can be considered limited, since mainly markdown files are use the file-ending `.md` and all markdown files contained in the hedgedoc project, like the README, are public anyway. If other protections such as a chroot or container or proper file permissions are in place, this attack's usefulness is rather limited. On a reverse-proxy level one can force a URL-decode, which will prevent this attack because the router will not accept such a path.

    Published: 26 Apr 2021
    8.8
    High

    CVE-2021-22669

    Last Modified: 21 Nov 2024

    Incorrect permissions are set to default on the ‘Project Management’ page of WebAccess/SCADA portal of WebAccess/SCADA Versions 9.0.1 and prior, which may allow a low-privileged user to update an administrator’s password and login as an administrator to escalate privileges on the system.

    Published: 26 Apr 2021
    10
    Critical

    CVE-2021-29475

    Last Modified: 21 Nov 2024

    HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker is able to receive arbitrary files from the file system when exporting a note to PDF. Since the code injection has to take place as note content, there fore this exploit requires the attackers ability to modify a note. This will affect all instances, which have pdf export enabled. This issue has been fixed by https://github.com/hedgedoc/hedgedoc/commit/c1789474020a6d668d616464cb2da5e90e123f65 and is available in version 1.5.0. Starting the CodiMD/HedgeDoc instance with `CMD_ALLOW_PDF_EXPORT=false` or set `"allowPDFExport": false` in config.json can mitigate this issue for those who cannot upgrade. This exploit works because while PhantomJS doesn't actually render the `file:///` references to the PDF file itself, it still uses them internally, and exfiltration is possible, and easy through JavaScript rendering. The impact is pretty bad, as the attacker is able to read the CodiMD/HedgeDoc `config.json` file as well any other files on the filesystem. Even though the suggested Docker deploy option doesn't have many interesting files itself, the `config.json` still often contains sensitive information, database credentials, and maybe OAuth secrets among other things.

    Published: 26 Apr 2021
    9.8
    Critical

    CVE-2021-31646

    Last Modified: 21 Nov 2024

    Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote). The affected component is the file forgot_pwd.php - it uses a weak algorithm for the generation of password recovery tokens (the PHP uniqueid function), allowing a brute force attack.

    Published: 26 Apr 2021
    7.5
    High

    CVE-2021-31783

    Last Modified: 21 Nov 2024

    show_default.php in the LocalFilesEditor extension before 11.4.0.1 for Piwigo allows Local File Inclusion because the file parameter is not validated with a proper regular-expression check.

    Published: 26 Apr 2021
    7.8
    High

    CVE-2021-31784

    Last Modified: 21 Nov 2024

    An out-of-bounds write vulnerability exists in the file-reading procedure in Open Design Alliance Drawings SDK before 2021.6 on all supported by ODA platforms in static configuration. This can allow attackers to cause a crash, potentially enabling a denial of service attack (Crash, Exit, or Restart) or possible code execution.

    Published: 26 Apr 2021
    9.6
    Critical

    CVE-2021-21226

    Last Modified: 21 Nov 2024

    Use after free in navigation in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

    Published: 26 Apr 2021
    8.8
    High

    CVE-2021-21225

    Last Modified: 21 Nov 2024

    Out of bounds memory access in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Apr 2021
    8.8
    High

    CVE-2021-21224

    Last Modified: 24 Oct 2025

    Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

    Published: 26 Apr 2021
    9.6
    Critical

    CVE-2021-21223

    Last Modified: 21 Nov 2024

    Integer overflow in Mojo in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

    Published: 26 Apr 2021
    6.5
    Medium

    CVE-2021-21222

    Last Modified: 21 Nov 2024

    Heap buffer overflow in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.

    Published: 26 Apr 2021
    7.5
    High

    CVE-2021-29694

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 200258.

    Published: 26 Apr 2021
    7.8
    High

    CVE-2021-29672

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Client 8.1.0.0-8 through 1.11.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking when processing the current locale settings. A local attacker could overflow a buffer and execute arbitrary code on the system with elevated privileges or cause the application to crash. IBM X-Force ID: 199479

    Published: 26 Apr 2021
    5.5
    Medium

    CVE-2021-20546

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and cause the application to crash. IBM X-Force ID: 198934

    Published: 26 Apr 2021
    6.2
    Medium

    CVE-2021-20536

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Plus File Systems Agent 10.1.6 and 10.1.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 198836.

    Published: 26 Apr 2021
    7.8
    High

    CVE-2021-20532

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 could allow a local user to escalate their privileges to take full control of the system due to insecure directory permissions. IBM X-Force ID: 198811.

    Published: 26 Apr 2021
    6.5
    Medium

    CVE-2021-20432

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM X-Force ID: 196344.

    Published: 26 Apr 2021
    5.3
    Medium

    CVE-2020-4562

    Last Modified: 21 Nov 2024

    IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information by allowing cross-window communication with unrestricted target origin via documentation frames.

    Published: 26 Apr 2021
    6.5
    Medium

    CVE-2021-21221

    Last Modified: 21 Nov 2024

    Insufficient validation of untrusted input in Mojo in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.

    Published: 26 Apr 2021
    5.5
    Medium

    CVE-2021-21219

    Last Modified: 21 Nov 2024

    Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.

    Published: 26 Apr 2021
    5.5
    Medium

    CVE-2021-21217

    Last Modified: 21 Nov 2024

    Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.

    Published: 26 Apr 2021
    5.5
    Medium

    CVE-2021-21218

    Last Modified: 21 Nov 2024

    Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.

    Published: 26 Apr 2021
    6.5
    Medium

    CVE-2021-21216

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML page.

    Published: 26 Apr 2021
    8.8
    High

    CVE-2021-21214

    Last Modified: 21 Nov 2024

    Use after free in Network API in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension.

    Published: 26 Apr 2021
    6.5
    Medium

    CVE-2021-21215

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML page.

    Published: 26 Apr 2021
    8.8
    High

    CVE-2021-21213

    Last Modified: 21 Nov 2024

    Use after free in WebMIDI in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Apr 2021
    6.5
    Medium

    CVE-2021-21211

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 26 Apr 2021
    6.5
    Medium

    CVE-2021-21212

    Last Modified: 21 Nov 2024

    Incorrect security UI in Network Config UI in Google Chrome on ChromeOS prior to 90.0.4430.72 allowed a remote attacker to potentially compromise WiFi connection security via a malicious WAP.

    Published: 26 Apr 2021
    6.5
    Medium

    CVE-2021-21210

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Network in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially access local UDP ports via a crafted HTML page.

    Published: 26 Apr 2021
    6.5
    Medium

    CVE-2021-21208

    Last Modified: 21 Nov 2024

    Insufficient data validation in QR scanner in Google Chrome on iOS prior to 90.0.4430.72 allowed an attacker displaying a QR code to perform domain spoofing via a crafted QR code.

    Published: 26 Apr 2021