CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2021-21209

    Last Modified: 21 Nov 2024

    Inappropriate implementation in storage in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 26 Apr 2021
    8.6
    High

    CVE-2021-21207

    Last Modified: 21 Nov 2024

    Use after free in IndexedDB in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

    Published: 26 Apr 2021
    8.8
    High

    CVE-2021-21204

    Last Modified: 21 Nov 2024

    Use after free in Blink in Google Chrome on OS X prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Apr 2021
    8.1
    High

    CVE-2021-21205

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 26 Apr 2021
    8.8
    High

    CVE-2021-21203

    Last Modified: 21 Nov 2024

    Use after free in Blink in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Apr 2021
    8.6
    High

    CVE-2021-21202

    Last Modified: 21 Nov 2024

    Use after free in extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

    Published: 26 Apr 2021
    9.6
    Critical

    CVE-2021-21201

    Last Modified: 21 Nov 2024

    Use after free in permissions in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

    Published: 26 Apr 2021
    8.8
    High

    CVE-2021-21206

    Last Modified: 24 Oct 2025

    Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Apr 2021
    5.5
    Medium

    CVE-2021-27851

    Last Modified: 21 Nov 2024

    A security vulnerability that can lead to local privilege escalation has been found in ’guix-daemon’. It affects multi-user setups in which ’guix-daemon’ runs locally. The attack consists in having an unprivileged user spawn a build process, for instance with `guix build`, that makes its build directory world-writable. The user then creates a hardlink to a root-owned file such as /etc/shadow in that build directory. If the user passed the --keep-failed option and the build eventually fails, the daemon changes ownership of the whole build tree, including the hardlink, to the user. At that point, the user has write access to the target file. Versions after and including v0.11.0-3298-g2608e40988, and versions prior to v1.2.0-75109-g94f0312546 are vulnerable.

    Published: 26 Apr 2021
    5.3
    Medium

    CVE-2021-28399

    Last Modified: 21 Nov 2024

    OrangeHRM 4.7 allows an unauthenticated user to enumerate the valid username and email address via the forgot password function.

    Published: 26 Apr 2021
    9.8
    Critical

    CVE-2021-25839

    Last Modified: 21 Nov 2024

    A weak password requirement vulnerability exists in the Create New User function of MintHCM RELEASE 3.0.8, which could lead an attacker to easier password brute-forcing.

    Published: 26 Apr 2021
    6.1
    Medium

    CVE-2021-25838

    Last Modified: 21 Nov 2024

    The Import function in MintHCM RELEASE 3.0.8 allows an attacker to execute a cross-site scripting (XSS) payload in file-upload.

    Published: 26 Apr 2021
    7.5
    High

    CVE-2020-15078

    Last Modified: 21 Nov 2024

    OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.

    Published: 26 Apr 2021
    8.8
    High

    CVE-2021-31802

    Last Modified: 21 Nov 2024

    NETGEAR R7000 1.0.11.116 devices have a heap-based Buffer Overflow that is exploitable from the local network without authentication. The vulnerability exists within the handling of an HTTP request. An attacker can leverage this to execute code as root. The problem is that a user-provided length value is trusted during a backup.cgi file upload. The attacker must add a \n before the Content-Length header.

    Published: 26 Apr 2021
    6.1
    Medium

    CVE-2021-28079

    Last Modified: 21 Nov 2024

    Jamovi <=1.6.18 is affected by a cross-site scripting (XSS) vulnerability. The column-name is vulnerable to XSS in the ElectronJS Framework. An attacker can make a .omv (Jamovi) document containing a payload. When opened by victim, the payload is triggered.

    Published: 26 Apr 2021
    9.8
    Critical

    CVE-2021-26797

    Last Modified: 21 Nov 2024

    An access control vulnerability in Hame SD1 Wi-Fi firmware <=V.20140224154640 allows an attacker to get system administrator through an open Telnet service.

    Published: 26 Apr 2021
    9.8
    Critical

    CVE-2021-25928

    Last Modified: 30 Apr 2025

    Prototype pollution vulnerability in 'safe-obj' versions 1.0.0 through 1.0.2 allows an attacker to cause a denial of service and may lead to remote code execution.

    Published: 26 Apr 2021
    9.8
    Critical

    CVE-2021-25927

    Last Modified: 30 Apr 2025

    Prototype pollution vulnerability in 'safe-flat' versions 2.0.0 through 2.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.

    Published: 26 Apr 2021
    4.8
    Medium

    CVE-2021-23365

    Last Modified: 21 Nov 2024

    The package github.com/tyktechnologies/tyk-identity-broker before 1.1.1 are vulnerable to Authentication Bypass via the Go XML parser which can cause SAML authentication bypass. This is because the XML parser doesn’t guarantee integrity in the XML round-trip (encoding/decoding XML data).

    Published: 26 Apr 2021
    6.1
    Medium

    CVE-2021-31803

    Last Modified: 21 Nov 2024

    cPanel before 94.0.3 allows self-XSS via EasyApache 4 Save Profile (SEC-581).

    Published: 26 Apr 2021
    5.5
    Medium

    CVE-2021-31804

    Last Modified: 21 Nov 2024

    LeoCAD before 21.03 sometimes allows a use-after-free during the opening of a new document.

    Published: 26 Apr 2021
    9.8
    Critical

    CVE-2021-20711

    Last Modified: 21 Nov 2024

    Aterm WG2600HS firmware Ver1.5.1 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.

    Published: 26 Apr 2021
    5.3
    Medium

    CVE-2021-20712

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in NEC Aterm WG2600HS firmware Ver1.5.1 and earlier, and Aterm WX3000HP firmware Ver1.1.2 and earlier allows a device connected to the LAN side to be accessed from the WAN side due to the defect in the IPv6 firewall function.

    Published: 26 Apr 2021
    6.1
    Medium

    CVE-2021-20710

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Aterm WG2600HS firmware Ver1.5.1 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.

    Published: 26 Apr 2021
    7.2
    High

    CVE-2021-20708

    Last Modified: 21 Nov 2024

    NEC Aterm devices (Aterm WF1200CR firmware Ver1.3.2 and earlier, Aterm WG1200CR firmware Ver1.3.3 and earlier, and Aterm WG2600HS firmware Ver1.5.1 and earlier) allow authenticated attackers to execute arbitrary OS commands by sending a specially crafted request to a specific URL.

    Published: 26 Apr 2021
    7.2
    High

    CVE-2021-20709

    Last Modified: 21 Nov 2024

    Improper validation of integrity check value vulnerability in NEC Aterm WF1200CR firmware Ver1.3.2 and earlier, Aterm WG1200CR firmware Ver1.3.3 and earlier, and Aterm WG2600HS firmware Ver1.5.1 and earlier allows an attacker with an administrative privilege to execute arbitrary OS commands by sending a specially crafted request to a specific URL.

    Published: 26 Apr 2021
    9.8
    Critical

    CVE-2021-20697

    Last Modified: 21 Nov 2024

    Missing authentication for critical function in DAP-1880AC firmware version 1.21 and earlier allows a remote attacker to login to the device as an authenticated user without the access privilege via unspecified vectors.

    Published: 26 Apr 2021
    8.8
    High

    CVE-2021-20696

    Last Modified: 21 Nov 2024

    DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated attacker to execute arbitrary OS commands by sending a specially crafted request to a specific CGI program.

    Published: 26 Apr 2021
    8.8
    High

    CVE-2021-20695

    Last Modified: 21 Nov 2024

    Improper following of a certificate's chain of trust vulnerability in DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated attacker to gain root privileges via unspecified vectors.

    Published: 26 Apr 2021
    8.8
    High

    CVE-2021-20694

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated attacker to bypass access restriction and to start a telnet service via unspecified vectors.

    Published: 26 Apr 2021
    7.5
    High

    CVE-2021-20693

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Gurunavi App for Android ver.10.0.10 and earlier and for iOS ver.11.1.2 and earlier allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App.

    Published: 26 Apr 2021
    6.1
    Medium

    CVE-2021-20680

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in NEC Aterm devices (Aterm WG1900HP2 firmware Ver.1.3.1 and earlier, Aterm WG1900HP firmware Ver.2.5.1 and earlier, Aterm WG1800HP4 firmware Ver.1.3.1 and earlier, Aterm WG1800HP3 firmware Ver.1.5.1 and earlier, Aterm WG1200HS2 firmware Ver.2.5.0 and earlier, Aterm WG1200HP3 firmware Ver.1.3.1 and earlier, Aterm WG1200HP2 firmware Ver.2.5.0 and earlier, Aterm W1200EX firmware Ver.1.3.1 and earlier, Aterm W1200EX-MS firmware Ver.1.3.1 and earlier, Aterm WG1200HS firmware all versions Aterm WG1200HP firmware all versions Aterm WF800HP firmware all versions Aterm WF300HP2 firmware all versions Aterm WR8165N firmware all versions Aterm W500P firmware all versions, and Aterm W300P firmware all versions) allows remote attackers to inject arbitrary script or HTML via unspecified vectors.

    Published: 26 Apr 2021
    8.8
    High

    CVE-2021-21220

    Last Modified: 24 Oct 2025

    Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Apr 2021
    5.3
    Medium

    CVE-2021-23382

    Last Modified: 21 Nov 2024

    The package postcss before 8.2.13 are vulnerable to Regular Expression Denial of Service (ReDoS) via getAnnotationURL() and loadAnnotation() in lib/previous-map.js. The vulnerable regexes are caused mainly by the sub-pattern \/\*\s* sourceMappingURL=(.*).

    Published: 26 Apr 2021
    6.1
    Medium

    CVE-2020-13529

    Last Modified: 21 Nov 2024

    An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW and DCHP ACK packets to reconfigure the server.

    Published: 26 Apr 2021
    7.5
    High

    CVE-2021-3513

    Last Modified: 21 Nov 2024

    A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnerability is to confidentiality.

    Published: 26 Apr 2021
    7.1
    High

    CVE-2021-3561

    Last Modified: 21 Nov 2024

    An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() could allow an attacker to provide a crafted malicious input causing the application to either crash or in some cases cause memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.

    Published: 26 Apr 2021
    8.8
    High

    CVE-2021-31718

    Last Modified: 21 Nov 2024

    The server in npupnp before 4.1.4 is affected by DNS rebinding in the embedded web server (including UPnP SOAP and GENA endpoints), leading to remote code execution.

    Published: 25 Apr 2021
    8.8
    High

    CVE-2021-31762

    Last Modified: 21 Nov 2024

    Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse shell through Webmin's running process feature.

    Published: 25 Apr 2021
    9.6
    Critical

    CVE-2021-31761

    Last Modified: 21 Nov 2024

    Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process feature.

    Published: 25 Apr 2021
    8.8
    High

    CVE-2021-31760

    Last Modified: 21 Nov 2024

    Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to achieve Remote Command Execution (RCE) through Webmin's running process feature.

    Published: 25 Apr 2021
    9.8
    Critical

    CVE-2021-31726

    Last Modified: 21 Nov 2024

    Akuvox C315 115.116.2613 allows remote command Injection via the cfgd_server service. The attack vector is sending a payload to port 189 (default root 0.0.0.0).

    Published: 25 Apr 2021
    9.8
    Critical

    CVE-2021-30502

    Last Modified: 21 Nov 2024

    The unofficial vscode-ghc-simple (aka Simple Glasgow Haskell Compiler) extension before 0.2.3 for Visual Studio Code allows remote code execution via a crafted workspace configuration with replCommand.

    Published: 25 Apr 2021
    2.5
    Low

    CVE-2021-29473

    Last Modified: 21 Nov 2024

    Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as `insert`. The bug is fixed in version v0.27.4. Please see our security policy for information about Exiv2 security.

    Published: 25 Apr 2021
    5.4
    Medium

    CVE-2021-31712

    Last Modified: 21 Nov 2024

    react-draft-wysiwyg (aka React Draft Wysiwyg) before 1.14.6 allows a javascript: URi in a Link Target of the link decorator in decorators/Link/index.js when a draft is shared across users, leading to XSS.

    Published: 24 Apr 2021
    6.1
    Medium

    CVE-2021-31794

    Last Modified: 21 Nov 2024

    Settings.aspx?view=About in Directum 5.8.2 allows XSS via the HTTP User-Agent header.

    Published: 24 Apr 2021
    7
    High

    CVE-2021-31795

    Last Modified: 21 Nov 2024

    The PowerVR GPU kernel driver in pvrsrvkm.ko through 2021-04-24 for the Linux kernel, as used on Alcatel 1S phones, allows attackers to overwrite heap memory via PhysmemNewRamBackedPMR.

    Published: 24 Apr 2021
    7.5
    High

    CVE-2021-31598

    Last Modified: 21 Nov 2024

    An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_decode() performs incorrect memory handling while parsing crafted XML files, leading to a heap-based buffer overflow.

    Published: 24 Apr 2021
    5.7
    Medium

    CVE-2021-3572

    Last Modified: 25 Aug 2026

    A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

    Published: 24 Apr 2021
    7.5
    High

    CVE-2021-31791

    Last Modified: 21 Nov 2024

    In Hardware Sentry KM before 10.0.01 for BMC PATROL, a cleartext password may be discovered after a failure or timeout of a command.

    Published: 23 Apr 2021