CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2021-29011

    Last Modified: 21 Nov 2024

    DMA Softlab Radius Manager 4.4.0 is affected by Cross Site Scripting (XSS) via the description, name, or address field (under admin.php).

    Published: 2 Apr 2021
    9.8
    Critical

    CVE-2021-29012

    Last Modified: 21 Nov 2024

    DMA Softlab Radius Manager 4.4.0 assigns the same session cookie to every admin session. The cookie is valid when the admin is logged in, but is invalid (temporarily) during times when the admin is logged out. In other words, the cookie is functionally equivalent to a static password, and thus provides permanent access if stolen.

    Published: 2 Apr 2021
    6.1
    Medium

    CVE-2021-25894

    Last Modified: 21 Nov 2024

    Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the /magnoliaPublic/travel/members/login.html mgnlUserId parameter.

    Published: 2 Apr 2021
    5.4
    Medium

    CVE-2021-25893

    Last Modified: 21 Nov 2024

    Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the setText parameter of /magnoliaAuthor/.magnolia/.

    Published: 2 Apr 2021
    9.8
    Critical

    CVE-2021-30000

    Last Modified: 21 Nov 2024

    An issue was discovered in LATRIX 0.6.0. SQL injection in the txtaccesscode parameter of inandout.php leads to information disclosure and code execution.

    Published: 2 Apr 2021
    4.8
    Medium

    CVE-2021-30003

    Last Modified: 21 Nov 2024

    An issue was discovered on Nokia G-120W-F 3FE46606AGAB91 devices. There is Stored XSS in the administrative interface via urlfilter.cgi?add url_address.

    Published: 2 Apr 2021
    6.2
    Medium

    CVE-2021-30002

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.11.3 when a webcam device exists. video_usercopy in drivers/media/v4l2-core/v4l2-ioctl.c has a memory leak for large arguments, aka CID-fb18802a338b.

    Published: 2 Apr 2021
    7.5
    High

    CVE-2021-22696

    Last Modified: 13 Feb 2025

    CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR)). Instead of sending a JWT token as a "request" parameter, the spec also supports specifying a URI from which to retrieve a JWT token from via the "request_uri" parameter. CXF was not validating the "request_uri" parameter (apart from ensuring it uses "https) and was making a REST request to the parameter in the request to retrieve a token. This means that CXF was vulnerable to DDos attacks on the authorization server, as specified in section 10.4.1 of the spec. This issue affects Apache CXF versions prior to 3.4.3; Apache CXF versions prior to 3.3.10.

    Published: 2 Apr 2021
    8.1
    High

    CVE-2021-21421

    Last Modified: 21 Nov 2024

    node-etsy-client is a NodeJs Etsy ReST API Client. Applications that are using node-etsy-client and reporting client error to the end user will offer api key value too This is fixed in node-etsy-client v0.3.0 and later.

    Published: 1 Apr 2021
    5.4
    Medium

    CVE-2021-23922

    Last Modified: 21 Nov 2024

    An issue was discovered in Devolutions Remote Desktop Manager before 2020.2.12. There is a cross-site scripting (XSS) vulnerability in webviews.

    Published: 1 Apr 2021
    6.1
    Medium

    CVE-2021-23925

    Last Modified: 21 Nov 2024

    An issue was discovered in Devolutions Server before 2020.3. There is a cross-site scripting (XSS) vulnerability in entries of type Document.

    Published: 1 Apr 2021
    7.5
    High

    CVE-2021-23924

    Last Modified: 21 Nov 2024

    An issue was discovered in Devolutions Server before 2020.3. There is an exposure of sensitive information in diagnostic files.

    Published: 1 Apr 2021
    9.1
    Critical

    CVE-2021-23921

    Last Modified: 21 Nov 2024

    An issue was discovered in Devolutions Server before 2020.3. There is broken access control on Password List entry elements.

    Published: 1 Apr 2021
    8.1
    High

    CVE-2021-23923

    Last Modified: 21 Nov 2024

    An issue was discovered in Devolutions Server before 2020.3. There is Broken Authentication with Windows domain users.

    Published: 1 Apr 2021
    7.5
    High

    CVE-2021-21420

    Last Modified: 21 Nov 2024

    vscode-stripe is an extension for Visual Studio Code. A vulnerability in Stripe for Visual Studio Code extension exists when it loads an untrusted source-code repository containing malicious settings. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. The update addresses the vulnerability by modifying the way the extension validates its settings.

    Published: 1 Apr 2021
    3.7
    Low

    CVE-2021-21416

    Last Modified: 21 Nov 2024

    django-registration is a user registration package for Django. The django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data, with the result that sensitive data could be included in error reports rather than removed automatically by Django. Triggering this requires: A site is using django-registration < 3.1.2, The site has detailed error reports (such as Django's emailed error reports to site staff/developers) enabled and a server-side error (HTTP 5xx) occurs during an attempt by a user to register an account. Under these conditions, recipients of the detailed error report will see all submitted data from the account-registration attempt, which may include the user's proposed credentials (such as a password).

    Published: 1 Apr 2021
    5.4
    Medium

    CVE-2021-28047

    Last Modified: 21 Nov 2024

    Cross-Site Scripting (XSS) in Administrative Reports in Devolutions Remote Desktop Manager before 2021.1 allows remote authenticated users to inject arbitrary web script or HTML via multiple input fields.

    Published: 1 Apr 2021
    6.5
    Medium

    CVE-2021-28970

    Last Modified: 21 Nov 2024

    eMPS 9.0.1.923211 on the Central Management of FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the job_id parameter to the email search feature. According to the vendor, the issue is fixed in 9.0.3.

    Published: 1 Apr 2021
    6.5
    Medium

    CVE-2021-28969

    Last Modified: 21 Nov 2024

    eMPS 9.0.1.923211 on FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the sort_by parameter to the email search feature. According to the vendor, the issue is fixed in 9.0.3. NOTE: this is different from CVE-2020-25034 and affects newer versions of the software.

    Published: 1 Apr 2021
    5.4
    Medium

    CVE-2020-19619

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the signature field to /settings/profile.

    Published: 1 Apr 2021
    5.4
    Medium

    CVE-2020-19618

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post content field to /post/editing.

    Published: 1 Apr 2021
    5.4
    Medium

    CVE-2020-19617

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the nickname field to /settings/profile.

    Published: 1 Apr 2021
    5.4
    Medium

    CVE-2020-19616

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post header field to /post/editing.

    Published: 1 Apr 2021
    7.5
    High

    CVE-2020-19613

    Last Modified: 21 Nov 2024

    Server Side Request Forgery (SSRF) vulnerability in saveUrlAs function in ImagesService.java in sunkaifei FlyCMS version 20190503.

    Published: 1 Apr 2021
    9.1
    Critical

    CVE-2021-21982

    Last Modified: 21 Nov 2024

    VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a malicious actor with network access to the administrative interface of the VMware Carbon Black Cloud Workload appliance to obtain a valid authentication token. Successful exploitation of this issue would result in the attacker being able to view and alter administrative configuration settings.

    Published: 1 Apr 2021
    6.5
    Medium

    CVE-2021-26581

    Last Modified: 21 Nov 2024

    A potential security vulnerability has been identified in HPE Superdome Flex server. A denial of service attack can be remotely exploited leaving hung connections to the BMC web interface. The monarch BMC must be rebooted to recover from this situation. Other BMC management is not impacted. HPE has made the following software update to resolve the vulnerability in HPE Superdome Flex Server: Superdome Flex Server Firmware 3.30.142 or later.

    Published: 1 Apr 2021
    6.1
    Medium

    CVE-2021-26580

    Last Modified: 21 Nov 2024

    A potential security vulnerability has been identified in HPE iLO Amplifier Pack. The vulnerability could be remotely exploited to allow Cross-Site Scripting (XSS). HPE has provided the following software update to resolve the vulnerability in HPE iLO Amplifier Pack: HPE iLO Amplifier Pack 1.95 or later.

    Published: 1 Apr 2021
    6.6
    Medium

    CVE-2021-27653

    Last Modified: 21 Nov 2024

    Misconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data exposure.

    Published: 1 Apr 2021
    4.3
    Medium

    CVE-2021-26072

    Last Modified: 21 Nov 2024

    The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SSRF) vulnerability.

    Published: 1 Apr 2021
    9.1
    Critical

    CVE-2021-20078

    Last Modified: 21 Nov 2024

    Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway component. This allows a remote attacker to remotely delete any directory or directories on the OS.

    Published: 1 Apr 2021
    5.5
    Medium

    CVE-2021-26718

    Last Modified: 21 Nov 2024

    KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus protection.

    Published: 1 Apr 2021
    8.8
    High

    CVE-2021-25924

    Last Modified: 21 Nov 2024

    In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backup` endpoint. An attacker can trick a victim to click on a malicious link which could change backup configurations or execute system commands in the post_backup_script field.

    Published: 1 Apr 2021
    5.5
    Medium

    CVE-2020-9148

    Last Modified: 21 Nov 2024

    An application bypass mechanism vulnerability exists in a component interface of Huawei Smartphone. Local attackers can exploit this vulnerability to delete user SMS messages.

    Published: 1 Apr 2021
    5.5
    Medium

    CVE-2020-9149

    Last Modified: 21 Nov 2024

    An application error verification vulnerability exists in a component interface of Huawei Smartphone. Local attackers can exploit this vulnerability to modify and delete user SMS messages.

    Published: 1 Apr 2021
    5.5
    Medium

    CVE-2020-9146

    Last Modified: 21 Nov 2024

    A memory buffer error vulnerability exists in a component interface of Huawei Smartphone. Local attackers can exploit this vulnerability to cause memory leakage and doS attacks by carefully constructing attack scenarios.

    Published: 1 Apr 2021
    7.8
    High

    CVE-2020-9147

    Last Modified: 21 Nov 2024

    A memory buffer error vulnerability exists in a component interface of Huawei Smartphone. Local attackers may exploit this vulnerability by carefully constructing attack scenarios to cause out-of-bounds read.

    Published: 1 Apr 2021
    8.6
    High

    CVE-2021-22195

    Last Modified: 21 Nov 2024

    Client side code execution in gitlab-vscode-extension v3.15.0 and earlier allows attacker to execute code on user system

    Published: 1 Apr 2021
    4.3
    Medium

    CVE-2021-22177

    Last Modified: 21 Nov 2024

    Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike the server resource utilization via gitlab-shell command.

    Published: 1 Apr 2021
    6.5
    Medium

    CVE-2021-28546

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are missing support for an integrity check. An unauthenticated attacker could leverage this vulnerability to modify content in a certified PDF without invalidating the certification. Exploitation of this issue requires user interaction in that a victim must open the tampered file.

    Published: 1 Apr 2021
    8.1
    High

    CVE-2021-28545

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are missing support for an integrity check. An unauthenticated attacker would have the ability to completely manipulate data in a certified PDF without invalidating the original certification. Exploitation of this issue requires user interaction in that a victim must open the tampered file.

    Published: 1 Apr 2021
    7.2
    High

    CVE-2021-29083

    Last Modified: 14 Jan 2025

    Improper neutralization of special elements used in an OS command in SYNO.Core.Network.PPPoE in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote authenticated users to execute arbitrary code via realname parameter.

    Published: 1 Apr 2021
    6.5
    Medium

    CVE-2021-29251

    Last Modified: 21 Nov 2024

    BTCPay Server before 1.0.7.1 mishandles the policy setting in which users can register (in Server Settings > Policies). This affects Docker use cases in which a mail server is configured.

    Published: 1 Apr 2021
    7.5
    High

    CVE-2021-29929

    Last Modified: 21 Nov 2024

    An issue was discovered in the endian_trait crate through 2021-01-04 for Rust. A double drop can occur when a user-provided Endian impl panics.

    Published: 1 Apr 2021
    7.5
    High

    CVE-2021-29930

    Last Modified: 21 Nov 2024

    An issue was discovered in the arenavec crate through 2021-01-12 for Rust. A drop of uninitialized memory can sometimes occur upon a panic in T::default().

    Published: 1 Apr 2021
    7.5
    High

    CVE-2021-29931

    Last Modified: 21 Nov 2024

    An issue was discovered in the arenavec crate through 2021-01-12 for Rust. A double drop can sometimes occur upon a panic in T::drop().

    Published: 1 Apr 2021
    7.5
    High

    CVE-2021-29932

    Last Modified: 21 Nov 2024

    An issue was discovered in the parse_duration crate through 2021-03-18 for Rust. It allows attackers to cause a denial of service (CPU and memory consumption) via a duration string with a large exponent.

    Published: 1 Apr 2021
    7.5
    High

    CVE-2021-29933

    Last Modified: 21 Nov 2024

    An issue was discovered in the insert_many crate through 2021-01-26 for Rust. Elements may be dropped twice if a .next() method panics.

    Published: 1 Apr 2021
    7.3
    High

    CVE-2021-29934

    Last Modified: 21 Nov 2024

    An issue was discovered in PartialReader in the uu_od crate before 0.0.4 for Rust. Attackers can read the contents of uninitialized memory locations via a user-provided Read operation.

    Published: 1 Apr 2021
    7.3
    High

    CVE-2021-29935

    Last Modified: 21 Nov 2024

    An issue was discovered in the rocket crate before 0.4.7 for Rust. uri::Formatter can have a use-after-free if a user-provided function panics.

    Published: 1 Apr 2021
    9.8
    Critical

    CVE-2021-29936

    Last Modified: 21 Nov 2024

    An issue was discovered in the adtensor crate through 2021-01-11 for Rust. There is a drop of uninitialized memory via the FromIterator implementation for Vector and Matrix.

    Published: 1 Apr 2021