CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2021-31254

    Last Modified: 21 Nov 2024

    Buffer overflow in the tenc_box_read function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file, related invalid IV sizes.

    Published: 19 Apr 2021
    5.5
    Medium

    CVE-2021-31262

    Last Modified: 21 Nov 2024

    The AV1_DuplicateConfig function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

    Published: 19 Apr 2021
    7.2
    High

    CVE-2021-20527

    Last Modified: 21 Nov 2024

    IBM Resilient SOAR V38.0 could allow a privileged user to create create malicious scripts that could be executed as another user. IBM X-Force ID: 198759.

    Published: 19 Apr 2021
    5.4
    Medium

    CVE-2020-28141

    Last Modified: 21 Nov 2024

    The messaging subsystem in the Online Discussion Forum 1.0 is vulnerable to XSS in the message body. An authenticated user can send messages to arbitrary users on the system that include javascript that will execute when viewing the messages page.

    Published: 19 Apr 2021
    7.8
    High

    CVE-2021-27031

    Last Modified: 21 Nov 2024

    A user may be tricked into opening a malicious FBX file which may exploit a use-after-free vulnerability in FBX's Review causing the application to reference a memory location controlled by an unauthorized third party, thereby running arbitrary code on the system.

    Published: 19 Apr 2021
    7.8
    High

    CVE-2021-27030

    Last Modified: 21 Nov 2024

    A user may be tricked into opening a malicious FBX file which may exploit a Directory Traversal Remote Code Execution vulnerability in FBX’s Review causing it to run arbitrary code on the system.

    Published: 19 Apr 2021
    5.5
    Medium

    CVE-2021-27029

    Last Modified: 21 Nov 2024

    The user may be tricked into opening a malicious FBX file which may exploit a Null Pointer Dereference vulnerability in FBX's Review version 1.5.0 and prior causing the application to crash leading to a denial of service.

    Published: 19 Apr 2021
    7.8
    High

    CVE-2021-27028

    Last Modified: 21 Nov 2024

    A Memory Corruption Vulnerability in Autodesk FBX Review version 1.5.0 and prior may lead to remote code execution through maliciously crafted DLL files.

    Published: 19 Apr 2021
    7.8
    High

    CVE-2021-27027

    Last Modified: 21 Nov 2024

    An Out-Of-Bounds Read Vulnerability in Autodesk FBX Review version 1.5.0 and prior may lead to code execution through maliciously crafted DLL files or information disclosure.

    Published: 19 Apr 2021
    7.8
    High

    CVE-2021-21981

    Last Modified: 13 Aug 2025

    VMware NSX-T contains a privilege escalation vulnerability due to an issue with RBAC (Role based access control) role assignment. Successful exploitation of this issue may allow attackers with local guest user account to assign privileges higher than their own permission level.

    Published: 19 Apr 2021
    8.1
    High

    CVE-2021-20992

    Last Modified: 21 Nov 2024

    In Fibaro Home Center 2 and Lite devices in all versions provide a web based management interface over unencrypted HTTP protocol. Communication between the user and the device can be eavesdropped to hijack sessions, tokens and passwords.

    Published: 19 Apr 2021
    9.8
    Critical

    CVE-2021-20991

    Last Modified: 21 Nov 2024

    In Fibaro Home Center 2 and Lite devices with firmware version 4.540 and older an authenticated user can run commands as root user using a command injection vulnerability.

    Published: 19 Apr 2021
    7.5
    High

    CVE-2021-20990

    Last Modified: 21 Nov 2024

    In Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older an internal management service is accessible on port 8000 and some API endpoints could be accessed without authentication to trigger a shutdown, a reboot or a reboot into recovery mode.

    Published: 19 Apr 2021
    5.9
    Medium

    CVE-2021-20989

    Last Modified: 21 Nov 2024

    Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older initiate SSH connections to the Fibaro cloud to provide remote access and remote support capabilities. This connection can be intercepted using DNS spoofing attack and a device initiated remote port-forward channel can be used to connect to the web management interface. Knowledge of authorization credentials to the management interface is required to perform any further actions.

    Published: 19 Apr 2021
    7.8
    High

    CVE-2020-7851

    Last Modified: 21 Nov 2024

    Innorix Web-Based File Transfer Solution versuibs prior to and including 9.2.18.385 contains a vulnerability that could allow remote files to be downloaded and executed by setting the arguments to the internal method. A remote attacker could induce a user to access a crafted web page, causing damage such as malicious code infection.

    Published: 19 Apr 2021
    6.5
    Medium

    CVE-2021-21070

    Last Modified: 23 Apr 2025

    Adobe Robohelp version 2020.0.3 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead to privilege escalation. An attacker with admin permissions to write to the file system could leverage this vulnerability to escalate privileges.

    Published: 19 Apr 2021
    6.1
    Medium

    CVE-2021-29399

    Last Modified: 21 Nov 2024

    XMB is vulnerable to cross-site scripting (XSS) due to inadequate filtering of BBCode input. This bug affects all versions of XMB. All XMB installations must be updated to versions 1.9.12.03 or 1.9.11.16.

    Published: 19 Apr 2021
    3.3
    Low

    CVE-2021-36087

    Last Modified: 3 Nov 2025

    The CIL compiler in SELinux 3.2 has a heap-based buffer over-read in ebitmap_match_any (called indirectly from cil_check_neverallow). This occurs because there is sometimes a lack of checks for invalid statements in an optional block.

    Published: 19 Apr 2021
    3.3
    Low

    CVE-2021-36086

    Last Modified: 24 Mar 2026

    The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set and cil_reset_classperms_list).

    Published: 19 Apr 2021
    3.3
    Low

    CVE-2021-36084

    Last Modified: 3 Nov 2025

    The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called from __cil_verify_classpermission and __cil_pre_verify_helper).

    Published: 19 Apr 2021
    8.8
    High

    CVE-2021-23999

    Last Modified: 21 Nov 2024

    If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges that should not be granted to web content. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.

    Published: 19 Apr 2021
    8.8
    High

    CVE-2021-23995

    Last Modified: 21 Nov 2024

    When Responsive Design Mode was enabled, it used references to objects that were previously freed. We presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.

    Published: 19 Apr 2021
    8.8
    High

    CVE-2021-23994

    Last Modified: 21 Nov 2024

    A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.

    Published: 19 Apr 2021
    6.5
    Medium

    CVE-2021-23998

    Last Modified: 21 Nov 2024

    Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.

    Published: 19 Apr 2021
    2.5
    Low

    CVE-2021-29948

    Last Modified: 21 Nov 2024

    Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replacing the file. This vulnerability affects Thunderbird < 78.10.

    Published: 19 Apr 2021
    8.8
    High

    CVE-2021-24002

    Last Modified: 21 Nov 2024

    When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and allowed arbitrary commands to be sent to the FTP server. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.

    Published: 19 Apr 2021
    6.5
    Medium

    CVE-2021-29945

    Last Modified: 21 Nov 2024

    The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read and result in a crash. *Note: This issue only affected x86-32 platforms. Other platforms are unaffected.*. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.

    Published: 19 Apr 2021
    8.8
    High

    CVE-2021-29946

    Last Modified: 21 Nov 2024

    Ports that were written as an integer overflow above the bounds of a 16-bit integer could have bypassed port blocking restrictions when used in the Alt-Svc header. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.

    Published: 19 Apr 2021
    6.1
    Medium

    CVE-2021-3507

    Last Modified: 21 Nov 2024

    A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers from the floppy drive to the guest system. A privileged guest user could use this flaw to crash the QEMU process on the host resulting in DoS scenario, or potential information leakage from the host memory.

    Published: 19 Apr 2021
    3.3
    Low

    CVE-2021-36085

    Last Modified: 3 Nov 2025

    The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called from __verify_map_perm_classperms and hashtab_map).

    Published: 19 Apr 2021
    7.3
    High

    CVE-2021-23379

    Last Modified: 21 Nov 2024

    This affects all versions of package portkiller. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

    Published: 18 Apr 2021
    5.6
    Medium

    CVE-2021-23380

    Last Modified: 21 Nov 2024

    This affects all versions of package roar-pidusage. If attacker-controlled user input is given to the stat function of this package on certain operating systems, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

    Published: 18 Apr 2021
    7.3
    High

    CVE-2021-23381

    Last Modified: 21 Nov 2024

    This affects all versions of package killing. If attacker-controlled user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

    Published: 18 Apr 2021
    7.3
    High

    CVE-2021-23374

    Last Modified: 21 Nov 2024

    This affects all versions of package ps-visitor. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

    Published: 18 Apr 2021
    7.3
    High

    CVE-2021-23375

    Last Modified: 21 Nov 2024

    This affects all versions of package psnode. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

    Published: 18 Apr 2021
    9.8
    Critical

    CVE-2021-23376

    Last Modified: 21 Nov 2024

    This affects all versions of package ffmpegdotjs. If attacker-controlled user input is given to the trimvideo function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

    Published: 18 Apr 2021
    9.8
    Critical

    CVE-2021-23377

    Last Modified: 21 Nov 2024

    This affects all versions of package onion-oled-js. If attacker-controlled user input is given to the scroll function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

    Published: 18 Apr 2021
    9.8
    Critical

    CVE-2021-23378

    Last Modified: 21 Nov 2024

    This affects all versions of package picotts. If attacker-controlled user input is given to the say function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

    Published: 18 Apr 2021
    6.7
    Medium

    CVE-2021-23133

    Last Modified: 21 Nov 2024

    A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)->sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CGROUP_INET_SOCK_CREATE is attached which denies creation of some SCTP socket.

    Published: 18 Apr 2021
    7.5
    High

    CVE-2022-0391

    Last Modified: 17 Dec 2025

    A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.

    Published: 18 Apr 2021
    5.3
    Medium

    CVE-2021-23413

    Last Modified: 21 Nov 2024

    This affects the package jszip before 3.7.0. Crafting a new zip file with filenames set to Object prototype values (e.g __proto__, toString, etc) results in a returned object with a modified prototype instance.

    Published: 18 Apr 2021
    7.8
    High

    CVE-2021-29457

    Last Modified: 21 Nov 2024

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A heap buffer overflow was found in Exiv2 versions v0.27.3 and earlier. The heap overflow is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to gain code execution, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when _writing_ the metadata, which is a less frequently used Exiv2 operation than _reading_ the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as `insert`. The bug is fixed in version v0.27.4.

    Published: 18 Apr 2021
    5.5
    Medium

    CVE-2021-29155

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 5.11.x. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory. Specifically, for sequences of pointer arithmetic operations, the pointer modification performed by the first operation is not correctly accounted for when restricting subsequent operations.

    Published: 18 Apr 2021
    5.5
    Medium

    CVE-2021-29458

    Last Modified: 21 Nov 2024

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as insert. The bug is fixed in version v0.27.4.

    Published: 18 Apr 2021
    9.8
    Critical

    CVE-2020-36195

    Last Modified: 21 Nov 2024

    An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information. QNAP has already fixed this vulnerability in the following versions of Multimedia Console and the Media Streaming add-on. QTS 4.3.3: Media Streaming add-on 430.1.8.10 and later QTS 4.3.6: Media Streaming add-on 430.1.8.8 and later QTS 4.4.x and later: Multimedia Console 1.3.4 and later We have also fixed this vulnerability in the following versions of QTS 4.3.3 and QTS 4.3.6, respectively: QTS 4.3.3.1624 Build 20210416 or later QTS 4.3.6.1620 Build 20210322 or later

    Published: 17 Apr 2021
    9.8
    Critical

    CVE-2020-2509

    Last Modified: 27 Oct 2025

    A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later QTS 4.5.1.1495 Build 20201123 and later QTS 4.3.6.1620 Build 20210322 and later QTS 4.3.4.1632 Build 20210324 and later QTS 4.3.3.1624 Build 20210416 and later QTS 4.2.6 Build 20210327 and later QuTS hero h4.5.1.1491 build 20201119 and later

    Published: 17 Apr 2021
    5.9
    Medium

    CVE-2021-29446

    Last Modified: 21 Nov 2024

    jose-node-cjs-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if either failed `JWEDecryptionFailed` would be thrown. But a possibly observable difference in timing when padding error would occur while decrypting the ciphertext makes a padding oracle and an adversary might be able to make use of that oracle to decrypt data without knowing the decryption key by issuing on average 128*b calls to the padding oracle (where b is the number of bytes in the ciphertext block). A patch was released which ensures the HMAC tag is verified before performing CBC decryption. The fixed versions are `>=3.11.4`. Users should upgrade to `^3.11.4`.

    Published: 16 Apr 2021
    5.9
    Medium

    CVE-2021-29445

    Last Modified: 21 Nov 2024

    jose-node-esm-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if either failed `JWEDecryptionFailed` would be thrown. But a possibly observable difference in timing when padding error would occur while decrypting the ciphertext makes a padding oracle and an adversary might be able to make use of that oracle to decrypt data without knowing the decryption key by issuing on average 128*b calls to the padding oracle (where b is the number of bytes in the ciphertext block). A patch was released which ensures the HMAC tag is verified before performing CBC decryption. The fixed versions are `>=3.11.4`. Users should upgrade to `^3.11.4`.

    Published: 16 Apr 2021
    5.9
    Medium

    CVE-2021-29444

    Last Modified: 21 Nov 2024

    jose-browser-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if either failed `JWEDecryptionFailed` would be thrown. But a possibly observable difference in timing when padding error would occur while decrypting the ciphertext makes a padding oracle and an adversary might be able to make use of that oracle to decrypt data without knowing the decryption key by issuing on average 128*b calls to the padding oracle (where b is the number of bytes in the ciphertext block). A patch was released which ensures the HMAC tag is verified before performing CBC decryption. The fixed versions are `>=3.11.4`. Users should upgrade to `^3.11.4`.

    Published: 16 Apr 2021
    9.1
    Critical

    CVE-2021-29451

    Last Modified: 21 Nov 2024

    Portofino is an open source web development framework. Portofino before version 5.2.1 did not properly verify the signature of JSON Web Tokens. This allows forging a valid JWT. The issue will be patched in the upcoming 5.2.1 release.

    Published: 16 Apr 2021