CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-24026

    Last Modified: 21 Nov 2024

    A missing bounds check within the audio decoding pipeline for WhatsApp calls in WhatsApp for Android prior to v2.21.3, WhatsApp Business for Android prior to v2.21.3, WhatsApp for iOS prior to v2.21.32, and WhatsApp Business for iOS prior to v2.21.32 could have allowed an out-of-bounds write.

    Published: 6 Apr 2021
    7.5
    High

    CVE-2021-24027

    Last Modified: 21 Nov 2024

    A cache configuration issue prior to WhatsApp for Android v2.21.4.18 and WhatsApp Business for Android v2.21.4.18 may have allowed a third party with access to the device’s external storage to read cached TLS material.

    Published: 6 Apr 2021
    5.5
    Medium

    CVE-2021-29136

    Last Modified: 21 Nov 2024

    Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbitrary host paths via a crafted image that causes symlink traversal when "umoci unpack" or "umoci raw unpack" is used.

    Published: 6 Apr 2021
    5.4
    Medium

    CVE-2021-30146

    Last Modified: 21 Nov 2024

    Seafile 7.0.5 (2019) allows Persistent XSS via the "share of library functionality."

    Published: 6 Apr 2021
    5.4
    Medium

    CVE-2021-30140

    Last Modified: 21 Nov 2024

    LiquidFiles 3.4.15 has stored XSS through the "send email" functionality when sending a file via email to an administrator. When a file has no extension and contains malicious HTML / JavaScript content (such as SVG with HTML content), the payload is executed upon a click. This is fixed in 3.5.

    Published: 6 Apr 2021
    5.9
    Medium

    CVE-2021-26833

    Last Modified: 21 Nov 2024

    Cleartext Storage in a File or on Disk in TimelyBills <= 1.7.0 for iOS and versions <= 1.21.115 for Android allows attacker who can locally read user's files obtain JWT tokens for user's account due to insufficient cache clearing mechanisms. A threat actor can obtain sensitive user data by decoding the tokens as JWT is signed and encoded, not encrypted.

    Published: 6 Apr 2021
    7.5
    High

    CVE-2020-36285

    Last Modified: 21 Nov 2024

    Union Pay up to 3.3.12, for iOS mobile apps, contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability, allows attackers to shop for free in merchants' websites and mobile apps, via a crafted authentication code (MAC) which is generated based on a secret key which is NULL.

    Published: 6 Apr 2021
    7.5
    High

    CVE-2020-36284

    Last Modified: 21 Nov 2024

    Union Pay up to 3.4.93.4.9, for android, contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability, allows attackers to shop for free in merchants' websites and mobile apps, via a crafted authentication code (MAC) which is generated based on a secret key which is NULL.

    Published: 6 Apr 2021
    7.5
    High

    CVE-2020-23533

    Last Modified: 21 Nov 2024

    Union Pay up to 1.2.0, for web based versions contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability, allows attackers to shop for free in merchants' websites and mobile apps, via a crafted authentication code (MAC) which is generated based on a secret key which is NULL.

    Published: 6 Apr 2021
    8.8
    High

    CVE-2021-28142

    Last Modified: 21 Nov 2024

    CITSmart before 9.1.2.28 mishandles the "filtro de autocomplete."

    Published: 6 Apr 2021
    6.5
    Medium

    CVE-2021-30046

    Last Modified: 21 Nov 2024

    VIGRA Computer Vision Library Version-1-11-1 contains a segmentation fault vulnerability in the impex.hxx read_image_band() function, in which a crafted file can cause a denial of service.

    Published: 6 Apr 2021
    9.1
    Critical

    CVE-2021-30045

    Last Modified: 21 Nov 2024

    SerenityOS 2021-03-27 contains a buffer overflow vulnerability in the EndOfCentralDirectory::read() function.

    Published: 6 Apr 2021
    7.8
    High

    CVE-2021-28874

    Last Modified: 21 Nov 2024

    SerenityOS fixed as of c9f25bca048443e317f1994ba9b106f2386688c3 contains a buffer overflow vulnerability in LibTextCode through opening a crafted file.

    Published: 6 Apr 2021
    7.5
    High

    CVE-2021-28075

    Last Modified: 21 Nov 2024

    iKuaiOS 3.4.8 Build 202012291059 has an arbitrary file download vulnerability, which can be exploited by attackers to obtain sensitive information.

    Published: 6 Apr 2021
    9.8
    Critical

    CVE-2021-27698

    Last Modified: 21 Nov 2024

    RIOT-OS 2021.01 contains a buffer overflow vulnerability in /sys/net/gnrc/routing/rpl/gnrc_rpl_control_messages.c through the _parse_options() function.

    Published: 6 Apr 2021
    9.8
    Critical

    CVE-2021-27697

    Last Modified: 21 Nov 2024

    RIOT-OS 2021.01 contains a buffer overflow vulnerability in sys/net/gnrc/routing/rpl/gnrc_rpl_validation.c through the gnrc_rpl_validation_options() function.

    Published: 6 Apr 2021
    9.8
    Critical

    CVE-2021-27357

    Last Modified: 21 Nov 2024

    RIOT-OS 2020.01 contains a buffer overflow vulnerability in /sys/net/gnrc/routing/rpl/gnrc_rpl_control_messages.c.

    Published: 6 Apr 2021
    7.5
    High

    CVE-2021-27343

    Last Modified: 21 Nov 2024

    SerenityOS Unspecified is affected by: Buffer Overflow. The impact is: obtain sensitive information (context-dependent). The component is: /Userland/Libraries/LibCrypto/ASN1/DER.h Crypto::der_decode_sequence() function. The attack vector is: Parsing RSA Key ASN.1.

    Published: 6 Apr 2021
    9.8
    Critical

    CVE-2021-28173

    Last Modified: 21 Nov 2024

    The file upload function of Vangene deltaFlow E-platform does not perform access controlled properly. Remote attackers can upload and execute arbitrary files without login.

    Published: 6 Apr 2021
    7.5
    High

    CVE-2021-28172

    Last Modified: 21 Nov 2024

    There is a Path Traversal vulnerability in the file download function of Vangene deltaFlow E-platform. Remote attackers can access credential data with this leakage.

    Published: 6 Apr 2021
    9.8
    Critical

    CVE-2021-28171

    Last Modified: 21 Nov 2024

    The Vangene deltaFlow E-platform does not take properly protective measures. Attackers can obtain privileged permissions remotely by tampering with users’ data in the Cookie.

    Published: 6 Apr 2021
    5.3
    Medium

    CVE-2021-28658

    Last Modified: 21 Nov 2024

    In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were not affected by this vulnerability.

    Published: 6 Apr 2021
    7.5
    High

    CVE-2021-30163

    Last Modified: 21 Nov 2024

    Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that have changes to project_id values.

    Published: 6 Apr 2021
    6.1
    Medium

    CVE-2020-36306

    Last Modified: 21 Nov 2024

    Redmine before 4.0.7 and 4.1.x before 4.1.1 has XSS via the back_url field.

    Published: 6 Apr 2021
    6.1
    Medium

    CVE-2020-36307

    Last Modified: 21 Nov 2024

    Redmine before 4.0.7 and 4.1.x before 4.1.1 has stored XSS via textile inline links.

    Published: 6 Apr 2021
    5.3
    Medium

    CVE-2020-36308

    Last Modified: 21 Nov 2024

    Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading time entries.

    Published: 6 Apr 2021
    5.3
    Medium

    CVE-2019-25026

    Last Modified: 21 Nov 2024

    Redmine before 3.4.13 and 4.x before 4.0.6 mishandles markup data during Textile formatting.

    Published: 6 Apr 2021
    9.8
    Critical

    CVE-2021-30164

    Last Modified: 21 Nov 2024

    Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues API.

    Published: 6 Apr 2021
    5.5
    Medium

    CVE-2021-30161

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 11 software. Attackers can bypass the lockscreen protection mechanism after an incoming call has been terminated. The LG ID is LVE-SMP-210002 (April 2021).

    Published: 6 Apr 2021
    7.1
    High

    CVE-2021-30162

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 4.4 through 11 software. Attackers can leverage ISMS services to bypass access control on specific content providers. The LG ID is LVE-SMP-210003 (April 2021).

    Published: 6 Apr 2021
    9.8
    Critical

    CVE-2021-30149

    Last Modified: 21 Nov 2024

    Composr 10.0.36 allows upload and execution of PHP files.

    Published: 6 Apr 2021
    6.1
    Medium

    CVE-2021-30150

    Last Modified: 21 Nov 2024

    Composr 10.0.36 allows XSS in an XML script.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28209

    Last Modified: 21 Nov 2024

    The specific function in ASUS BMC’s firmware Web management page (Delete video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28208

    Last Modified: 21 Nov 2024

    The specific function in ASUS BMC’s firmware Web management page (Get video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28207

    Last Modified: 21 Nov 2024

    The specific function in ASUS BMC’s firmware Web management page (Get Help file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28206

    Last Modified: 21 Nov 2024

    The specific function in ASUS BMC’s firmware Web management page (Record video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28205

    Last Modified: 21 Nov 2024

    The specific function in ASUS BMC’s firmware Web management page (Delete SOL video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.

    Published: 6 Apr 2021
    7.2
    High

    CVE-2021-28204

    Last Modified: 21 Nov 2024

    The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can launch command injection to execute command arbitrary.

    Published: 6 Apr 2021
    7.2
    High

    CVE-2021-28203

    Last Modified: 21 Nov 2024

    The Web Set Media Image function in ASUS BMC’s firmware Web management page does not filter the specific parameter. As obtaining the administrator permission, remote attackers can launch command injection to execute command arbitrary.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28202

    Last Modified: 21 Nov 2024

    The Service configuration-2 function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28201

    Last Modified: 21 Nov 2024

    The Service configuration-1 function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28200

    Last Modified: 21 Nov 2024

    The CD media configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28199

    Last Modified: 21 Nov 2024

    The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28198

    Last Modified: 21 Nov 2024

    The Firmware protocol configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28197

    Last Modified: 21 Nov 2024

    The Active Directory configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28196

    Last Modified: 21 Nov 2024

    The specific function in ASUS BMC’s firmware Web management page (Generate SSL certificate function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28195

    Last Modified: 21 Nov 2024

    The Radius configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28194

    Last Modified: 21 Nov 2024

    The specific function in ASUS BMC’s firmware Web management page (Remote image configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28193

    Last Modified: 21 Nov 2024

    The SMTP configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28192

    Last Modified: 21 Nov 2024

    The specific function in ASUS BMC’s firmware Web management page (Remote video storage function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021