CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2016-8169

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 9 Apr 2021
    —
    Unknown

    CVE-2016-8170

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 9 Apr 2021
    —
    Unknown

    CVE-2016-8172

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 9 Apr 2021
    —
    Unknown

    CVE-2016-8173

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 9 Apr 2021
    —
    Unknown

    CVE-2016-8161

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 9 Apr 2021
    —
    Unknown

    CVE-2016-8162

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 9 Apr 2021
    7.6
    High

    CVE-2021-21431

    Last Modified: 21 Nov 2024

    sopel-channelmgnt is a channelmgnt plugin for sopel. In versions prior to 2.0.1, on some IRC servers, restrictions around the removal of the bot using the kick/kickban command could be bypassed when kicking multiple users at once. We also believe it may have been possible to remove users from other channels but due to the wonder that is IRC and following RfCs, We have no POC for that. Freenode is not affected. This is fixed in version 2.0.1. As a workaround, do not use this plugin on networks where TARGMAX > 1.

    Published: 9 Apr 2021
    7
    High

    CVE-2021-29221

    Last Modified: 21 Nov 2024

    A local privilege escalation vulnerability was discovered in Erlang/OTP prior to version 23.2.3. By adding files to an existing installation's directory, a local attacker could hijack accounts of other users running Erlang programs or possibly coerce a service running with "erlsrv.exe" to execute arbitrary code as Local System. This can occur only under specific conditions on Windows with unsafe filesystem permissions.

    Published: 9 Apr 2021
    8.8
    High

    CVE-2021-25328

    Last Modified: 21 Nov 2024

    Skyworth Digital Technology RN510 V.3.1.0.4 RN510 V.3.1.0.4 contains a buffer overflow vulnerability in /cgi-bin/app-staticIP.asp. An authenticated attacker can send a specially crafted request to endpoint which can lead to a denial of service (DoS) or possible code execution on the device.

    Published: 9 Apr 2021
    6.5
    Medium

    CVE-2021-25327

    Last Modified: 21 Nov 2024

    Skyworth Digital Technology RN510 V.3.1.0.4 contains a cross-site request forgery (CSRF) vulnerability in /cgi-bin/net-routeadd.asp and /cgi-bin/sec-urlfilter.asp. Missing CSRF protection in devices can lead to XSRF, as the above pages are vulnerable to cross-site scripting (XSS).

    Published: 9 Apr 2021
    5.4
    Medium

    CVE-2021-25326

    Last Modified: 21 Nov 2024

    Skyworth Digital Technology RN510 V.3.1.0.4 is affected by an incorrect access control vulnerability in/cgi-bin/test_version.asp. If Wi-Fi is connected but an unauthenticated user visits a URL, the SSID password and web UI password may be disclosed.

    Published: 9 Apr 2021
    8.8
    High

    CVE-2020-21884

    Last Modified: 4 Jul 2026

    Unibox SMB 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a cross-site request forgery (CSRF) vulnerability in /tools/network-trace, /list_users, /list_byod?usertype=raduser, /dhcp_leases, /go?rid=202 in which a specially crafted HTTP request may reconfigure the device.

    Published: 9 Apr 2021
    8.8
    High

    CVE-2020-21883

    Last Modified: 5 Jul 2026

    Unibox U-50 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a OS command injection vulnerability in /tools/ping, which can leads to complete device takeover.

    Published: 9 Apr 2021
    6.1
    Medium

    CVE-2021-30458

    Last Modified: 21 Nov 2024

    An issue was discovered in Wikimedia Parsoid before 0.11.1 and 0.12.x before 0.12.2. An attacker can send crafted wikitext that Utils/WTUtils.php will transform by using a <meta> tag, bypassing sanitization steps, and potentially allowing for XSS.

    Published: 9 Apr 2021
    5.3
    Medium

    CVE-2020-36287

    Last Modified: 21 Nov 2024

    The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to obtain gadget related settings via a missing permissions check.

    Published: 9 Apr 2021
    8
    High

    CVE-2021-29427

    Last Modified: 21 Nov 2024

    In Gradle from version 5.1 and before version 7.0 there is a vulnerability which can lead to information disclosure and/or dependency poisoning. Repository content filtering is a security control Gradle introduced to help users specify what repositories are used to resolve specific dependencies. This feature was introduced in the wake of the "A Confusing Dependency" blog post. In some cases, Gradle may ignore content filters and search all repositories for dependencies. This only occurs when repository content filtering is used from within a `pluginManagement` block in a settings file. This may change how dependencies are resolved for Gradle plugins and build scripts. For builds that are vulnerable, there are two risks: 1) Information disclosure: Gradle could make dependency requests to repositories outside your organization and leak internal package identifiers. 2) Dependency poisoning/Dependency confusion: Gradle could download a malicious binary from a repository outside your organization due to name squatting. For a full example and more details refer to the referenced GitHub Security Advisory. The problem has been patched and released with Gradle 7.0. Users relying on this feature should upgrade their build as soon as possible. As a workaround, users may use a company repository which has the right rules for fetching packages from public repositories, or use project level repository content filtering, inside `buildscript.repositories`. This option is available since Gradle 5.1 when the feature was introduced.

    Published: 9 Apr 2021
    8.8
    High

    CVE-2021-29428

    Last Modified: 21 Nov 2024

    In Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it. Gradle builds could be vulnerable to a local privilege escalation from an attacker quickly deleting and recreating files in the system temporary directory. This vulnerability impacted builds using precompiled script plugins written in Kotlin DSL and tests for Gradle plugins written using ProjectBuilder or TestKit. If you are on Windows or modern versions of macOS, you are not vulnerable. If you are on a Unix-like operating system with the "sticky" bit set on your system temporary directory, you are not vulnerable. The problem has been patched and released with Gradle 7.0. As a workaround, on Unix-like operating systems, ensure that the "sticky" bit is set. This only allows the original user (or root) to delete a file. If you are unable to change the permissions of the system temporary directory, you can move the Java temporary directory by setting the System Property `java.io.tmpdir`. The new path needs to limit permissions to the build user only. For additional details refer to the referenced GitHub Security Advisory.

    Published: 9 Apr 2021
    4.3
    Medium

    CVE-2021-3503

    Last Modified: 21 Nov 2024

    A flaw was found in Wildfly where insufficient RBAC restrictions may lead to expose metrics data. The highest threat from this vulnerability is to the confidentiality.

    Published: 9 Apr 2021
    4
    Medium

    CVE-2021-29429

    Last Modified: 21 Nov 2024

    In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downloaded by Gradle. Some builds could be vulnerable to a local information disclosure. Remote files accessed through TextResourceFactory are downloaded into the system temporary directory first. Sensitive information contained in these files can be exposed to other local users on the same system. If you do not use the `TextResourceFactory` API, you are not vulnerable. As of Gradle 7.0, uses of the system temporary directory have been moved to the Gradle User Home directory. By default, this directory is restricted to the user running the build. As a workaround, set a more restrictive umask that removes read access to other users. When files are created in the system temporary directory, they will not be accessible to other users. If you are unable to change your system's umask, you can move the Java temporary directory by setting the System Property `java.io.tmpdir`. The new path needs to limit permissions to the build user only.

    Published: 9 Apr 2021
    7.5
    High

    CVE-2020-6590

    Last Modified: 21 Nov 2024

    Forcepoint Web Security Content Gateway versions prior to 8.5.4 improperly process XML input, leading to information disclosure.

    Published: 8 Apr 2021
    6.5
    Medium

    CVE-2021-22512

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects version 6.7 and earlier versions. The vulnerability could allow form validation without permission checks.

    Published: 8 Apr 2021
    6.5
    Medium

    CVE-2021-22511

    Last Modified: 21 Nov 2024

    Improper Certificate Validation vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects version 6.7 and earlier versions. The vulnerability could allow unconditionally disabling of SSL/TLS certificates.

    Published: 8 Apr 2021
    6.1
    Medium

    CVE-2021-22510

    Last Modified: 21 Nov 2024

    Reflected XSS vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects all version 6.7 and earlier versions.

    Published: 8 Apr 2021
    6.5
    Medium

    CVE-2021-22513

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects version 6.7 and earlier versions. The vulnerability could allow access without permission checks.

    Published: 8 Apr 2021
    5.5
    Medium

    CVE-2020-14106

    Last Modified: 21 Nov 2024

    The application in the mobile phone can unauthorized access to the list of running processes in the mobile phone, Xiaomi Mobile Phone MIUI < 2021.01.26.

    Published: 8 Apr 2021
    5.5
    Medium

    CVE-2020-14103

    Last Modified: 21 Nov 2024

    The application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI < 2020.01.15.

    Published: 8 Apr 2021
    7.8
    High

    CVE-2021-3146

    Last Modified: 21 Nov 2024

    The Dolby Audio X2 (DAX2) API service before 0.8.8.90 on Windows allows local users to gain privileges.

    Published: 8 Apr 2021
    6.5
    Medium

    CVE-2021-22312

    Last Modified: 21 Nov 2024

    There is a memory leak vulnerability in some Huawei products. An authenticated remote attacker may exploit this vulnerability by sending specific message to the affected product. Due to not release the allocated memory properly, successful exploit may cause some service abnormal. Affected product include some versions of IPS Module, NGFW Module, Secospace USG6300, Secospace USG6500, Secospace USG6600 and USG9500.

    Published: 8 Apr 2021
    7.5
    High

    CVE-2020-14099

    Last Modified: 21 Nov 2024

    On Xiaomi router AX1800 rom version < 1.0.336 and RM1800 root version < 1.0.26, the encryption scheme for a user's backup files uses hard-coded keys, which can expose sensitive information such as a user's password.

    Published: 8 Apr 2021
    8.1
    High

    CVE-2020-14104

    Last Modified: 21 Nov 2024

    A RACE CONDITION on XQBACKUP causes a decompression path error on Xiaomi router AX3600 with ROM version =1.0.50.

    Published: 8 Apr 2021
    9.8
    Critical

    CVE-2021-22507

    Last Modified: 21 Nov 2024

    Authentication bypass vulnerability in Micro Focus Operations Bridge Manager affects versions 2019.05, 2019.11, 2020.05 and 2020.10. The vulnerability could allow remote attackers to bypass user authentication and get unauthorized access.

    Published: 8 Apr 2021
    6.5
    Medium

    CVE-2021-22115

    Last Modified: 21 Nov 2024

    Cloud Controller API versions prior to 1.106.0 logs service broker credentials if the default value of db logging config field is changed. CAPI database logs service broker password in plain text whenever a job to clean up orphaned items is run by Cloud Controller.

    Published: 8 Apr 2021
    7.5
    High

    CVE-2021-3328

    Last Modified: 21 Nov 2024

    An issue was discovered in Aprelium Abyss Web Server X1 2.12.1 and 2.14. A crafted HTTP request can lead to an out-of-bounds read that crashes the application.

    Published: 8 Apr 2021
    6.1
    Medium

    CVE-2021-27945

    Last Modified: 21 Nov 2024

    The Squirro Insights Engine was affected by a Reflected Cross-Site Scripting (XSS) vulnerability affecting versions 2.0.0 up to and including 3.2.4. An attacker can use the vulnerability to inject malicious JavaScript code into the application, which will execute within the browser of any user who views the relevant application content. The attacker-supplied code can perform a wide variety of actions, such as stealing victims' session tokens or login credentials, performing arbitrary actions on their behalf, and logging their keystrokes.

    Published: 8 Apr 2021
    7.5
    High

    CVE-2020-23539

    Last Modified: 21 Nov 2024

    An issue was discovered in Realtek rtl8723de BLE Stack <= 4.1 that allows remote attackers to cause a Denial of Service via the interval field to the CONNECT_REQ message.

    Published: 8 Apr 2021
    8.8
    High

    CVE-2021-27522

    Last Modified: 21 Nov 2024

    Learnsite 1.2.5.0 contains a remote privilege escalation vulnerability in /Manager/index.aspx through the JudgIsAdmin() function. By modifying the initial letter of the key of a user cookie, the key of the administrator cookie can be obtained.

    Published: 8 Apr 2021
    9.8
    Critical

    CVE-2020-23426

    Last Modified: 21 Nov 2024

    zzcms 201910 contains an access control vulnerability through escalation of privileges in /user/adv.php, which allows an attacker to modify data for further attacks such as CSRF.

    Published: 8 Apr 2021
    —
    Unknown

    CVE-2020-8629

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019

    Published: 8 Apr 2021
    —
    Unknown

    CVE-2020-8630

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019

    Published: 8 Apr 2021
    —
    Unknown

    CVE-2020-8627

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019

    Published: 8 Apr 2021
    —
    Unknown

    CVE-2020-8628

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019

    Published: 8 Apr 2021
    —
    Unknown

    CVE-2020-8626

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019

    Published: 8 Apr 2021
    7.2
    High

    CVE-2021-30462

    Last Modified: 21 Nov 2024

    VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not require a password to run /usr/local/vesta/bin scripts.

    Published: 8 Apr 2021
    7.8
    High

    CVE-2021-30463

    Last Modified: 21 Nov 2024

    VestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissions. After reading the RKEY value from user.conf under the /usr/local/vesta/data/users/admin directory, the admin password can be changed via a /reset/?action=confirm&user=admin&code= URI. This occurs because chmod is used unsafely.

    Published: 8 Apr 2021
    6.1
    Medium

    CVE-2021-28924

    Last Modified: 21 Nov 2024

    Self Authenticated XSS in Nagios Network Analyzer before 2.4.2 via the nagiosna/groups/queries page.

    Published: 8 Apr 2021
    9.8
    Critical

    CVE-2021-28925

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Nagios Network Analyzer before 2.4.3 via the o[col] parameter to api/checks/read/.

    Published: 8 Apr 2021
    6.5
    Medium

    CVE-2021-20480

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 197502.

    Published: 8 Apr 2021
    5.4
    Medium

    CVE-2021-30111

    Last Modified: 21 Nov 2024

    A stored XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in the event name and description fields. An attack can inject a JavaScript code that will be stored in the page. If any visitor sees the events, then the payload will be executed.

    Published: 8 Apr 2021
    6.5
    Medium

    CVE-2021-30112

    Last Modified: 21 Nov 2024

    Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a student_leave_application request through module/core/studentleaveapplication/create. The application fails to validate the CSRF token for a POST request using Guardian privilege.

    Published: 8 Apr 2021
    6.1
    Medium

    CVE-2021-30113

    Last Modified: 21 Nov 2024

    A blind XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in event name and description fields. An attacker can inject a JavaScript code that will be stored in the page. If any visitor sees the event, then the payload will be executed and sends the victim's information to the attacker website.

    Published: 8 Apr 2021