CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2021-21094

    Last Modified: 23 Apr 2025

    Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by an Out-of-bounds write vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Apr 2021
    8.1
    High

    CVE-2020-28593

    Last Modified: 21 Nov 2024

    A unauthenticated backdoor exists in the configuration server functionality of Cosori Smart 5.8-Quart Air Fryer CS158-AF 1.1.0. A specially crafted JSON object can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

    Published: 15 Apr 2021
    9.8
    Critical

    CVE-2020-28592

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow vulnerability exists in the configuration server functionality of the Cosori Smart 5.8-Quart Air Fryer CS158-AF 1.1.0. A specially crafted JSON object can lead to remote code execution. An attacker can send a malicious packet to trigger this vulnerability.

    Published: 15 Apr 2021
    9.8
    Critical

    CVE-2020-27239

    Last Modified: 21 Nov 2024

    An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The assetStatus parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 15 Apr 2021
    9.8
    Critical

    CVE-2020-27238

    Last Modified: 21 Nov 2024

    An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 15 Apr 2021
    9.8
    Critical

    CVE-2020-27237

    Last Modified: 21 Nov 2024

    An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter in the The nomenclature parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 15 Apr 2021
    6.5
    Medium

    CVE-2021-30209

    Last Modified: 21 Nov 2024

    Textpattern V4.8.4 contains an arbitrary file upload vulnerability where a plug-in can be loaded in the background without any security verification, which may lead to obtaining system permissions.

    Published: 15 Apr 2021
    6.7
    Medium

    CVE-2021-0488

    Last Modified: 21 Nov 2024

    In pb_write of pb_encode.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-178754781

    Published: 15 Apr 2021
    6.5
    Medium

    CVE-2021-27545

    Last Modified: 21 Nov 2024

    SQL Injection in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to obtain sensitive database information by injecting SQL commands into the "sername" parameter.

    Published: 15 Apr 2021
    4.8
    Medium

    CVE-2021-27544

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "sername" parameter.

    Published: 15 Apr 2021
    5.4
    Medium

    CVE-2021-27129

    Last Modified: 11 Nov 2025

    CASAP Automated Enrollment System version 1.0 contains a cross-site scripting (XSS) vulnerability through the Students > Edit > ROUTE parameter.

    Published: 15 Apr 2021
    4.9
    Medium

    CVE-2020-7270

    Last Modified: 21 Nov 2024

    Exposure of Sensitive Information in the web interface in McAfee Advanced Threat Defense (ATD) prior to 4.12.2 allows remote authenticated users to view sensitive unencrypted information via a carefully crafted HTTP request parameter. The risk is partially mitigated if your ATD instances are deployed as recommended with no direct access from the Internet to them.

    Published: 15 Apr 2021
    4.9
    Medium

    CVE-2020-7269

    Last Modified: 21 Nov 2024

    Exposure of Sensitive Information in the web interface in McAfee Advanced Threat Defense (ATD) prior to 4.12.2 allows remote authenticated users to view sensitive unencrypted information via a carefully crafted HTTP request parameter. The risk is partially mitigated if your ATD instances are deployed as recommended with no direct access from the Internet to them.

    Published: 15 Apr 2021
    7.8
    High

    CVE-2021-23887

    Last Modified: 21 Nov 2024

    Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attacker to write to arbitrary controlled kernel addresses. This is achieved by launching applications, suspending them, modifying the memory and restarting them when they are monitored by McAfee DLP through the hdlphook driver.

    Published: 15 Apr 2021
    5.5
    Medium

    CVE-2021-23886

    Last Modified: 21 Nov 2024

    Denial of Service vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attacker to cause a BSoD through suspending a process, modifying the processes memory and restarting it. This is triggered by the hdlphook driver reading invalid memory.

    Published: 15 Apr 2021
    4.8
    Medium

    CVE-2020-7308

    Last Modified: 21 Nov 2024

    Cleartext Transmission of Sensitive Information between McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update and McAfee Global Threat Intelligence (GTI) servers using DNS allows a remote attacker to view the requests from ENS and responses from GTI over DNS. By gaining control of an intermediate DNS server or altering the network DNS configuration, it is possible for an attacker to intercept requests and send their own responses.

    Published: 15 Apr 2021
    9.8
    Critical

    CVE-2021-27850

    Last Modified: 21 Nov 2024

    A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5, 5.5.0, 5.6.2 and 5.7.0. The vulnerability I have found is a bypass of the fix for CVE-2019-0195. Recap: Before the fix of CVE-2019-0195 it was possible to download arbitrary class files from the classpath by providing a crafted asset file URL. An attacker was able to download the file `AppModule.class` by requesting the URL `http://localhost:8080/assets/something/services/AppModule.class` which contains a HMAC secret key. The fix for that bug was a blacklist filter that checks if the URL ends with `.class`, `.properties` or `.xml`. Bypass: Unfortunately, the blacklist solution can simply be bypassed by appending a `/` at the end of the URL: `http://localhost:8080/assets/something/services/AppModule.class/` The slash is stripped after the blacklist check and the file `AppModule.class` is loaded into the response. This class usually contains the HMAC secret key which is used to sign serialized Java objects. With the knowledge of that key an attacker can sign a Java gadget chain that leads to RCE (e.g. CommonsBeanUtils1 from ysoserial). Solution for this vulnerability: * For Apache Tapestry 5.4.0 to 5.6.1, upgrade to 5.6.2 or later. * For Apache Tapestry 5.7.0, upgrade to 5.7.1 or later.

    Published: 15 Apr 2021
    4.3
    Medium

    CVE-2021-23884

    Last Modified: 21 Nov 2024

    Cleartext Transmission of Sensitive Information vulnerability in the ePO Extension of McAfee Content Security Reporter (CSR) prior to 2.8.0 allows an ePO administrator to view the unencrypted password of the McAfee Web Gateway (MWG) or the password of the McAfee Web Gateway Cloud Server (MWGCS) read only user used to retrieve log files for analysis in CSR.

    Published: 15 Apr 2021
    7.5
    High

    CVE-2021-28682

    Last Modified: 21 Nov 2024

    An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable integer overflow in which a very large grpc-timeout value leads to unexpected timeout calculations.

    Published: 15 Apr 2021
    7.5
    High

    CVE-2021-28683

    Last Modified: 21 Nov 2024

    An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable NULL pointer dereference and crash in TLS when an unknown TLS alert code is received.

    Published: 15 Apr 2021
    7.5
    High

    CVE-2021-29258

    Last Modified: 21 Nov 2024

    An issue was discovered in Envoy 1.14.0. There is a remotely exploitable crash for HTTP2 Metadata, because an empty METADATA map triggers a Reachable Assertion.

    Published: 15 Apr 2021
    6.5
    Medium

    CVE-2021-3524

    Last Modified: 21 Nov 2024

    A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. In addition, the prior bug fix for CVE-2020-10753 did not account for the use of \r as a header separator, thus a new flaw has been created.

    Published: 15 Apr 2021
    5.3
    Medium

    CVE-2021-30479

    Last Modified: 21 Nov 2024

    An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the all_public_streams API feature resulted in guest users being able to receive message traffic to public streams that should have been only accessible to members of the organization.

    Published: 14 Apr 2021
    4.3
    Medium

    CVE-2021-30478

    Last Modified: 21 Nov 2024

    An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the can_forge_sender permission (previously is_api_super_user) resulted in users with this permission being able to send messages appearing as if sent by a system bot, including to other organizations hosted by the same Zulip installation.

    Published: 14 Apr 2021
    3.7
    Low

    CVE-2021-26076

    Last Modified: 21 Nov 2024

    The jira.editor.user.mode cookie set by the Jira Editor Plugin in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before version 8.13.4, and from version 8.14.0 before version 8.15.0 allows remote anonymous attackers who can perform an attacker in the middle attack to learn which mode a user is editing in due to the cookie not being set with a secure attribute if Jira was configured to use https.

    Published: 14 Apr 2021
    4.3
    Medium

    CVE-2021-26075

    Last Modified: 21 Nov 2024

    The Jira importers plugin AttachTemporaryFile rest resource in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before 8.13.4, and from version 8.14.0 before 8.15.1 allowed remote authenticated attackers to obtain the full path of the Jira application data directory via an information disclosure vulnerability in the error message when presented with an invalid filename.

    Published: 14 Apr 2021
    6.1
    Medium

    CVE-2020-36288

    Last Modified: 21 Nov 2024

    The issue navigation and search view in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before version 8.13.4, and from version 8.14.0 before version 8.15.1 allows remote attackers to inject arbitrary HTML or JavaScript via a DOM Cross-Site Scripting (XSS) vulnerability caused by parameter pollution.

    Published: 14 Apr 2021
    4.3
    Medium

    CVE-2021-30477

    Last Modified: 21 Nov 2024

    An issue was discovered in Zulip Server before 3.4. A bug in the implementation of replies to messages sent by outgoing webhooks to private streams meant that an outgoing webhook bot could be used to send messages to private streams that the user was not intended to be able to send messages to.

    Published: 14 Apr 2021
    2.7
    Low

    CVE-2021-30487

    Last Modified: 21 Nov 2024

    In the topic moving API in Zulip Server 3.x before 3.4, organization administrators were able to move messages to streams in other organizations hosted by the same Zulip installation.

    Published: 14 Apr 2021
    7.2
    High

    CVE-2021-27183

    Last Modified: 21 Nov 2024

    An issue was discovered in MDaemon before 20.0.4. Administrators can use Remote Administration to exploit an Arbitrary File Write vulnerability. An attacker is able to create new files in any location of the filesystem, or he may be able to modify existing files. This vulnerability may directly lead to Remote Code Execution.

    Published: 14 Apr 2021
    8.8
    High

    CVE-2021-27182

    Last Modified: 21 Nov 2024

    An issue was discovered in MDaemon before 20.0.4. There is an IFRAME injection vulnerability in Webmail (aka WorldClient). It can be exploited via an email message. It allows an attacker to perform any action with the privileges of the attacked user.

    Published: 14 Apr 2021
    8.8
    High

    CVE-2021-27181

    Last Modified: 21 Nov 2024

    An issue was discovered in MDaemon before 20.0.4. Remote Administration allows an attacker to perform a fixation of the anti-CSRF token. In order to exploit this issue, the user has to click on a malicious URL provided by the attacker and successfully authenticate into the application. Having the value of the anti-CSRF token, the attacker may trick the user into visiting his malicious page and performing any request with the privileges of attacked user.

    Published: 14 Apr 2021
    6.1
    Medium

    CVE-2021-27180

    Last Modified: 21 Nov 2024

    An issue was discovered in MDaemon before 20.0.4. There is Reflected XSS in Webmail (aka WorldClient). It can be exploited via a GET request. It allows performing any action with the privileges of the attacked user.

    Published: 14 Apr 2021
    6.3
    Medium

    CVE-2021-29449

    Last Modified: 6 Apr 2026

    Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation vulnerabilities were discovered in version 5.2.4 of Pi-hole core. See the referenced GitHub security advisory for details.

    Published: 14 Apr 2021
    7.2
    High

    CVE-2021-28157

    Last Modified: 21 Nov 2024

    An SQL Injection issue in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows an administrative user to execute arbitrary SQL commands via a username in api/security/userinfo/delete.

    Published: 14 Apr 2021
    6.5
    Medium

    CVE-2021-28048

    Last Modified: 21 Nov 2024

    An overly permissive CORS policy in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 14 Apr 2021
    7.2
    High

    CVE-2021-29654

    Last Modified: 21 Nov 2024

    AjaxSearchPro before 4.20.8 allows Deserialization of Untrusted Data (in the import database feature of the administration panel), leading to Remote Code execution.

    Published: 14 Apr 2021
    5.3
    Medium

    CVE-2021-26031

    Last Modified: 25 Feb 2026

    An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate filters on module layout settings could lead to an LFI.

    Published: 14 Apr 2021
    6.1
    Medium

    CVE-2021-26030

    Last Modified: 25 Feb 2026

    An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate escaping allowed XSS attacks using the logo parameter of the default templates on error page

    Published: 14 Apr 2021
    9.8
    Critical

    CVE-2021-30459

    Last Modified: 21 Nov 2024

    A SQL Injection issue in the SQL Panel in Jazzband Django Debug Toolbar before 1.11.1, 2.x before 2.2.1, and 3.x before 3.2.1 allows attackers to execute SQL statements by changing the raw_sql input field of the SQL explain, analyze, or select form.

    Published: 14 Apr 2021
    7.5
    High

    CVE-2021-3017

    Last Modified: 21 Nov 2024

    The web interface on Intelbras WIN 300 and WRN 342 devices through 2021-01-04 allows remote attackers to discover credentials by reading the def_wirelesspassword line in the HTML source code.

    Published: 14 Apr 2021
    7.5
    High

    CVE-2021-28484

    Last Modified: 21 Nov 2024

    An issue was discovered in the /api/connector endpoint handler in Yubico yubihsm-connector before 3.0.1 (in YubiHSM SDK before 2021.04). The handler did not validate the length of the request, which can lead to a state where yubihsm-connector becomes stuck in a loop waiting for the YubiHSM to send it data, preventing any further operations until the yubihsm-connector is restarted. An attacker can send 0, 1, or 2 bytes to trigger this.

    Published: 14 Apr 2021
    9.8
    Critical

    CVE-2021-27710

    Last Modified: 21 Nov 2024

    Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs because the function executes glibc's system function with untrusted input. In the function, "ip" parameter is directly passed to the attacker, allowing them to control the "ip" field to attack the OS.

    Published: 14 Apr 2021
    5.4
    Medium

    CVE-2020-35660

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in Monica before 2.19.1 via the journal page.

    Published: 14 Apr 2021
    5.4
    Medium

    CVE-2020-28124

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in LavaLite 5.8.0 via the Address field.

    Published: 14 Apr 2021
    8.8
    High

    CVE-2021-28826

    Last Modified: 21 Nov 2024

    The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Bridge - Community Edition and TIBCO Messaging - Eclipse Mosquitto Distribution - Bridge - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from a lack of access restrictions on certain files and/or folders in the installation. Affected releases are TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Bridge - Community Edition: versions 1.3.0 and below and TIBCO Messaging - Eclipse Mosquitto Distribution - Bridge - Enterprise Edition: versions 1.3.0 and below.

    Published: 14 Apr 2021
    8.8
    High

    CVE-2021-28825

    Last Modified: 21 Nov 2024

    The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Community Edition and TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from a lack of access restrictions on certain files and/or folders in the installation. Affected releases are TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Community Edition: versions 1.3.0 and below and TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Enterprise Edition: versions 1.3.0 and below.

    Published: 14 Apr 2021
    5.3
    Medium

    CVE-2021-28060

    Last Modified: 21 Nov 2024

    A Server-Side Request Forgery (SSRF) vulnerability in Group Office 6.4.196 allows a remote attacker to forge GET requests to arbitrary URLs via the url parameter to group/api/upload.php.

    Published: 14 Apr 2021
    5.4
    Medium

    CVE-2020-35418

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in the contact page of Group Office CRM 6.4.196 by uploading a crafted svg file.

    Published: 14 Apr 2021
    6.1
    Medium

    CVE-2020-35419

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in Group Office CRM 6.4.196 via the SET_LANGUAGE parameter.

    Published: 14 Apr 2021