CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2021-24197

    Last Modified: 21 Nov 2024

    The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that visits the page where the table is published can tamper the parameters to access the data of another user that are present in the same table by taking over the user permissions on the table through formdata[wdt_ID] parameter. By exploiting this issue an attacker is able to access and manage the data of all users in the same table.

    Published: 12 Apr 2021
    5.4
    Medium

    CVE-2021-25925

    Last Modified: 30 Apr 2025

    in SiCKRAGE, versions 4.2.0 to 10.0.11.dev1 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly when processed by the server. Therefore, an attacker can inject arbitrary JavaScript code inside the application, and possibly steal a user’s sensitive information.

    Published: 12 Apr 2021
    6.1
    Medium

    CVE-2021-25926

    Last Modified: 30 Apr 2025

    In SiCKRAGE, versions 9.3.54.dev1 to 10.0.11.dev1 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validated properly in the `quicksearch` feature. Therefore, an attacker can steal a user's sessionID to masquerade as a victim user, to carry out any actions in the context of the user.

    Published: 12 Apr 2021
    9.8
    Critical

    CVE-2020-28872

    Last Modified: 21 Nov 2024

    An authorization bypass vulnerability in Monitorr v1.7.6m in Monitorr/assets/config/_installation/_register.php allows an unauthorized person to create valid credentials.

    Published: 12 Apr 2021
    7.5
    High

    CVE-2021-23370

    Last Modified: 21 Nov 2024

    This affects the package swiper before 6.5.1.

    Published: 12 Apr 2021
    7.5
    High

    CVE-2021-23371

    Last Modified: 21 Nov 2024

    This affects the package chrono-node before 2.2.4. It hangs on a date-like string with lots of embedded spaces.

    Published: 12 Apr 2021
    7.5
    High

    CVE-2020-24285

    Last Modified: 21 Nov 2024

    INTELBRAS TELEFONE IP TIP200 version 60.61.75.22 allows an attacker to obtain sensitive information through /cgi-bin/cgiServer.exx.

    Published: 12 Apr 2021
    6.1
    Medium

    CVE-2021-20208

    Last Modified: 21 Nov 2024

    A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity.

    Published: 12 Apr 2021
    8.8
    High

    CVE-2021-29379

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DIR-802 A1 devices through 1.00b05. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker can perform command injection by injecting a payload into the Search Target (ST) field of the SSDP M-SEARCH discover packet. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 12 Apr 2021
    9.8
    Critical

    CVE-2021-27905

    Last Modified: 21 Nov 2024

    The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate another ReplicationHandler on another Solr core to replicate index data into the local core. To prevent a SSRF vulnerability, Solr ought to check these parameters against a similar configuration it uses for the "shards" parameter. Prior to this bug getting fixed, it did not. This problem affects essentially all Solr versions prior to it getting fixed in 8.8.2.

    Published: 12 Apr 2021
    3.3
    Low

    CVE-2021-38209

    Last Modified: 21 Nov 2024

    net/netfilter/nf_conntrack_standalone.c in the Linux kernel before 5.12.2 allows observation of changes in any net namespace because these changes are leaked into all other net namespaces. This is related to the NF_SYSCTL_CT_MAX, NF_SYSCTL_CT_EXPECT_MAX, and NF_SYSCTL_CT_BUCKETS sysctls.

    Published: 12 Apr 2021
    5.3
    Medium

    CVE-2021-23368

    Last Modified: 21 Nov 2024

    The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.

    Published: 12 Apr 2021
    7.5
    High

    CVE-2021-29262

    Last Modified: 21 Nov 2024

    When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing security.json znode, if the optional read-only user is configured then Solr would not treat that node as a sensitive path and would allow it to be readable. Additionally, with any ZkACLProvider, if the security.json is already present, Solr will not automatically update the ACLs.

    Published: 12 Apr 2021
    5.6
    Medium

    CVE-2021-23369

    Last Modified: 21 Nov 2024

    The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

    Published: 12 Apr 2021
    5.6
    Medium

    CVE-2021-23383

    Last Modified: 21 Nov 2024

    The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.

    Published: 12 Apr 2021
    4.8
    Medium

    CVE-2021-29425

    Last Modified: 25 Aug 2026

    In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.

    Published: 12 Apr 2021
    9.1
    Critical

    CVE-2021-29943

    Last Modified: 21 Nov 2024

    When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests using server credentials instead of original client credentials. This would result in incorrect authorization resolution on the receiving hosts.

    Published: 12 Apr 2021
    4.2
    Medium

    CVE-2020-7924

    Last Modified: 21 Nov 2024

    Usage of specific command line parameter in MongoDB Tools which was originally intended to just skip hostname checks, may result in MongoDB skipping all certificate validation. This may result in accepting invalid certificates.This issue affects: MongoDB Inc. MongoDB Database Tools 3.6 versions later than 3.6.5; 3.6 versions prior to 3.6.21; 4.0 versions prior to 4.0.21; 4.2 versions prior to 4.2.11; 100 versions prior to 100.2.0. MongoDB Inc. Mongomirror 0 versions later than 0.6.0.

    Published: 12 Apr 2021
    4.8
    Medium

    CVE-2021-3536

    Last Modified: 21 Nov 2024

    A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality and Integrity.

    Published: 12 Apr 2021
    7.5
    High

    CVE-2015-20001

    Last Modified: 21 Nov 2024

    In the standard library in Rust before 1.2.0, BinaryHeap is not panic-safe. The binary heap is left in an inconsistent state when the comparison of generic elements inside sift_up or sift_down_range panics. This bug leads to a drop of zeroed memory as an arbitrary type, which can result in a memory safety violation.

    Published: 11 Apr 2021
    6.5
    Medium

    CVE-2021-30485

    Last Modified: 21 Nov 2024

    An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd(), while parsing a crafted XML file, performs incorrect memory handling, leading to a NULL pointer dereference while running strcmp() on a NULL pointer.

    Published: 11 Apr 2021
    8
    High

    CVE-2021-30481

    Last Modified: 3 Nov 2025

    Valve Steam before 2021-04-17, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because of a buffer overflow that occurs for a Steam invite after one click.

    Published: 10 Apr 2021
    9.8
    Critical

    CVE-2021-20020

    Last Modified: 21 Nov 2024

    A command execution vulnerability in SonicWall GMS 9.3 allows a remote unauthenticated attacker to locally escalate privilege to root.

    Published: 10 Apr 2021
    8.5
    High

    CVE-2021-30480

    Last Modified: 21 Nov 2024

    Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user interaction. An attacker must be within the same organization, or an external party who has been accepted as a contact. NOTE: this is specific to the Zoom Chat software, which is different from the chat feature of the Zoom Meetings and Zoom Video Webinars software.

    Published: 9 Apr 2021
    8.8
    High

    CVE-2021-21199

    Last Modified: 21 Nov 2024

    Use after free in Aura in Google Chrome on Linux prior to 89.0.4389.114 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

    Published: 9 Apr 2021
    7.4
    High

    CVE-2021-21198

    Last Modified: 21 Nov 2024

    Out of bounds read in IPC in Google Chrome prior to 89.0.4389.114 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

    Published: 9 Apr 2021
    8.8
    High

    CVE-2021-21197

    Last Modified: 21 Nov 2024

    Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 9 Apr 2021
    8.8
    High

    CVE-2021-21196

    Last Modified: 21 Nov 2024

    Heap buffer overflow in TabStrip in Google Chrome on Windows prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 9 Apr 2021
    8.8
    High

    CVE-2021-21194

    Last Modified: 21 Nov 2024

    Use after free in screen sharing in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 9 Apr 2021
    8.8
    High

    CVE-2021-21195

    Last Modified: 21 Nov 2024

    Use after free in V8 in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 9 Apr 2021
    7.5
    High

    CVE-2021-21432

    Last Modified: 21 Nov 2024

    Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. An authentication mechanism added in version 0.7.0 enables some malicious user to obtain secrets utilizing the injected credentials within the `~/.netrc` file. Refer to the referenced GitHub Security Advisory for complete details. This is fixed in version 0.7.5.

    Published: 9 Apr 2021
    9.9
    Critical

    CVE-2021-21433

    Last Modified: 21 Nov 2024

    Discord Recon Server is a bot that allows you to do your reconnaissance process from your Discord. Remote code execution in version 0.0.1 would allow remote users to execute commands on the server resulting in serious issues. This flaw is patched in 0.0.2.

    Published: 9 Apr 2021
    9.8
    Critical

    CVE-2020-23763

    Last Modified: 21 Nov 2024

    SQL injection in admin.php in Online Book Store 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication.

    Published: 9 Apr 2021
    7.2
    High

    CVE-2021-20022

    Last Modified: 10 Nov 2025

    SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.

    Published: 9 Apr 2021
    9.8
    Critical

    CVE-2021-20021

    Last Modified: 10 Nov 2025

    A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.

    Published: 9 Apr 2021
    7.8
    High

    CVE-2020-13532

    Last Modified: 21 Nov 2024

    A privilege escalation vulnerability exists in Dream Report 5 R20-2. In the default configuration, the Syncfusion Dashboard Service service binary can be replaced by attackers to escalate privileges to NT SYSTEM. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 9 Apr 2021
    5.4
    Medium

    CVE-2020-23762

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in the Larsens Calender plugin Version <= 1.2 for WordPress allows remote attackers to execute arbitrary web script via the "titel" column on the "Eintrage hinzufugen" tab.

    Published: 9 Apr 2021
    7.8
    High

    CVE-2020-13533

    Last Modified: 21 Nov 2024

    A privilege escalation vulnerability exists in Dream Report 5 R20-2. IIn the default configuration, the following registry keys, which reference binaries with weak permissions, can be abused by attackers to effectively ‘backdoor’ the installation files and escalate privileges when a new user logs in and uses the application.

    Published: 9 Apr 2021
    7.8
    High

    CVE-2020-13534

    Last Modified: 21 Nov 2024

    A privilege escalation vulnerability exists in Dream Report 5 R20-2. COM Class Identifiers (CLSID), installed by Dream Report 5 20-2, reference LocalServer32 and InprocServer32 with weak privileges which can lead to privilege escalation when used. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 9 Apr 2021
    6.1
    Medium

    CVE-2020-23761

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in subrion CMS Version <= 4.2.1 allows remote attackers to execute arbitrary web script via the "payment gateway" column on transactions tab.

    Published: 9 Apr 2021
    8.8
    High

    CVE-2020-13592

    Last Modified: 21 Nov 2024

    An exploitable SQL injection vulnerability exists in "global_lists/choices" page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability, this can be done either with administrator credentials or through cross-site request forgery.

    Published: 9 Apr 2021
    8.8
    High

    CVE-2020-13587

    Last Modified: 21 Nov 2024

    An exploitable SQL injection vulnerability exists in the "forms_fields_rules/rules" page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability, this can be done either with administrator credentials or through cross-site request forgery.

    Published: 9 Apr 2021
    8.8
    High

    CVE-2020-13591

    Last Modified: 21 Nov 2024

    An exploitable SQL injection vulnerability exists in the "access_rules/rules_form" page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability, this can be done either with administrator credentials or through cross-site request forgery.

    Published: 9 Apr 2021
    5.5
    Medium

    CVE-2021-25381

    Last Modified: 21 Nov 2024

    Using unsafe PendingIntent in Samsung Account in versions 10.8.0.4 in Android P(9.0) and below, and 12.1.1.3 in Android Q(10.0) and above allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.

    Published: 9 Apr 2021
    5.8
    Medium

    CVE-2021-25380

    Last Modified: 21 Nov 2024

    Improper handling of exceptional conditions in Bixby prior to version 3.0.53.02 allows attacker to execute the actions registered by the user.

    Published: 9 Apr 2021
    4
    Medium

    CVE-2021-25379

    Last Modified: 21 Nov 2024

    Intent redirection vulnerability in Gallery prior to version 5.4.16.1 allows attacker to execute privileged action.

    Published: 9 Apr 2021
    4.3
    Medium

    CVE-2021-25378

    Last Modified: 21 Nov 2024

    Improper access control of certain port in SmartThings prior to version 1.7.63.6 allows remote temporary denial of service.

    Published: 9 Apr 2021
    3.3
    Low

    CVE-2021-25377

    Last Modified: 21 Nov 2024

    Intent redirection in Samsung Experience Service versions 10.8.0.4 in Android P(9.0) below, and 12.2.0.5 in Android Q(10.0) above allows attacker to execute privileged action.

    Published: 9 Apr 2021
    3.1
    Low

    CVE-2021-25376

    Last Modified: 21 Nov 2024

    An improper synchronization logic in Samsung Email prior to version 6.1.41.0 can leak messages in certain mailbox in plain text when STARTTLS negotiation is failed.

    Published: 9 Apr 2021
    6.5
    Medium

    CVE-2021-25375

    Last Modified: 21 Nov 2024

    Using predictable index for attachments in Samsung Email prior to version 6.1.41.0 allows remote attackers to get attachments of another emails when users open the malicious attachment.

    Published: 9 Apr 2021