CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-22991

    Last Modified: 27 Oct 2025

    On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traffic Management Microkernel (TMM) URI normalization, which may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may theoretically allow bypass of URL based access control or remote code execution (RCE). Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

    Published: 31 Mar 2021
    8.8
    High

    CVE-2021-29658

    Last Modified: 21 Nov 2024

    The unofficial vscode-rufo extension before 0.0.4 for Visual Studio Code allows attackers to execute arbitrary binaries if the user opens a crafted workspace folder.

    Published: 31 Mar 2021
    9.1
    Critical

    CVE-2021-22989

    Last Modified: 21 Nov 2024

    On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, when running in Appliance mode with Advanced WAF or BIG-IP ASM provisioned, the TMUI, also referred to as the Configuration utility, has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

    Published: 31 Mar 2021
    9.8
    Critical

    CVE-2021-22992

    Last Modified: 21 Nov 2024

    On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, a malicious HTTP response to an Advanced WAF/BIG-IP ASM virtual server with Login Page configured in its policy may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may allow remote code execution (RCE), leading to complete system compromise. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

    Published: 31 Mar 2021
    7.5
    High

    CVE-2021-22995

    Last Modified: 21 Nov 2024

    On all 7.x and 6.x versions (fixed in 8.0.0), BIG-IQ high availability (HA) when using a Quorum device for automatic failover does not implement any form of authentication with the Corosync daemon. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

    Published: 31 Mar 2021
    7.2
    High

    CVE-2021-22990

    Last Modified: 21 Nov 2024

    On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, on systems with Advanced WAF or BIG-IP ASM provisioned, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

    Published: 31 Mar 2021
    9.9
    Critical

    CVE-2021-22987

    Last Modified: 21 Nov 2024

    On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3 when running in Appliance mode, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

    Published: 31 Mar 2021
    6.3
    Medium

    CVE-2021-23348

    Last Modified: 21 Nov 2024

    This affects the package portprocesses before 1.0.5. If (attacker-controlled) user input is given to the killProcess function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

    Published: 31 Mar 2021
    9.8
    Critical

    CVE-2021-22986

    Last Modified: 27 Oct 2025

    On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

    Published: 31 Mar 2021
    8.8
    High

    CVE-2021-22988

    Last Modified: 21 Nov 2024

    On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, TMUI, also referred to as the Configuration utility, has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

    Published: 31 Mar 2021
    8.8
    High

    CVE-2021-21782

    Last Modified: 21 Nov 2024

    An out-of-bounds write vulnerability exists in the SGI format buffer size processing functionality of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 31 Mar 2021
    8.8
    High

    CVE-2021-21776

    Last Modified: 21 Nov 2024

    An out-of-bounds write vulnerability exists in the SGI Format Buffer Size Processing functionality of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 31 Mar 2021
    7.8
    High

    CVE-2021-21773

    Last Modified: 21 Nov 2024

    An out-of-bounds write vulnerability exists in the TIFF header count-processing functionality of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 31 Mar 2021
    6.5
    Medium

    CVE-2021-23983

    Last Modified: 21 Nov 2024

    By causing a transition on a parent node by removing a CSS rule, an invalid property for a marker could have been applied, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 87.

    Published: 31 Mar 2021
    6.5
    Medium

    CVE-2021-23985

    Last Modified: 21 Nov 2024

    If an attacker is able to alter specific about:config values (for example malware running on the user's computer), the Devtools remote debugging feature could have been enabled in a way that was unnoticable to the user. This would have allowed a remote attacker (able to make a direct network connection to the victim) to monitor the user's browsing activity and (plaintext) network traffic. This was addressed by providing a visual cue when Devtools has an open network socket. This vulnerability affects Firefox < 87.

    Published: 31 Mar 2021
    6.5
    Medium

    CVE-2021-23986

    Last Modified: 21 Nov 2024

    A malicious extension with the 'search' permission could have installed a new search engine whose favicon referenced a cross-origin URL. The response to this cross-origin request could have been read by the extension, allowing a same-origin policy bypass by the extension, which should not have cross-origin permissions. This cross-origin request was made without cookies, so the sensitive information disclosed by the violation was limited to local-network resources or resources that perform IP-based authentication. This vulnerability affects Firefox < 87.

    Published: 31 Mar 2021
    8.8
    High

    CVE-2021-23988

    Last Modified: 21 Nov 2024

    Mozilla developers reported memory safety bugs present in Firefox 86. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 87.

    Published: 31 Mar 2021
    7.5
    High

    CVE-2021-28245

    Last Modified: 21 Nov 2024

    PbootCMS 3.0.4 contains a SQL injection vulnerability through index.php via the search parameter that can reveal sensitive information through adding an admin account.

    Published: 31 Mar 2021
    7.2
    High

    CVE-2020-28173

    Last Modified: 21 Nov 2024

    Simple College Website 1.0 allows a user to conduct remote code execution via /alumni/admin/ajax.php?action=save_settings when uploading a malicious file using the image upload functionality, which is stored in /alumni/admin/assets/uploads/.

    Published: 31 Mar 2021
    9.8
    Critical

    CVE-2020-28172

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in Simple College Website 1.0 allows remote unauthenticated attackers to bypass the admin authentication mechanism in college_website/admin/ajax.php?action=login, thus gaining access to the website administrative panel.

    Published: 31 Mar 2021
    5.3
    Medium

    CVE-2021-22876

    Last Modified: 9 Jun 2025

    curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request.

    Published: 31 Mar 2021
    3.7
    Low

    CVE-2021-22890

    Last Modified: 9 Jun 2025

    curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confuse session tickets arriving from the HTTPS proxy but work as if they arrived from the remote server and then wrongly "short-cut" the host handshake. When confusing the tickets, a HTTPS proxy can trick libcurl to use the wrong session ticket resume for the host and thereby circumvent the server TLS certificate check and make a MITM attack to be possible to perform unnoticed. Note that such a malicious HTTPS proxy needs to provide a certificate that curl will accept for the MITMed server for an attack to work - unless curl has been told to ignore the server certificate check.

    Published: 31 Mar 2021
    7.4
    High

    CVE-2021-29657

    Last Modified: 21 Nov 2024

    arch/x86/kvm/svm/nested.c in the Linux kernel before 5.11.12 has a use-after-free in which an AMD KVM guest can bypass access control on host OS MSRs when there are nested guests, aka CID-a58d9166a756. This occurs because of a TOCTOU race condition associated with a VMCB12 double fetch in nested_svm_vmrun.

    Published: 31 Mar 2021
    8
    High

    CVE-2021-21413

    Last Modified: 21 Nov 2024

    isolated-vm is a library for nodejs which gives you access to v8's Isolate interface. Versions of isolated-vm before v4.0.0 have API pitfalls which may make it easy for implementers to expose supposed secure isolates to the permissions of the main nodejs isolate. Reference objects allow access to the underlying reference's full prototype chain. In an environment where the implementer has exposed a Reference instance to an attacker they would be able to use it to acquire a Reference to the nodejs context's Function object. Similar application-specific attacks could be possible by modifying the local prototype of other API objects. Access to NativeModule objects could allow an attacker to load and run native code from anywhere on the filesystem. If combined with, for example, a file upload API this would allow for arbitrary code execution. This is addressed in v4.0.0 through a series of related changes.

    Published: 30 Mar 2021
    7.8
    High

    CVE-2020-24995

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in sniff_channel_order function in aacdec_template.c in ffmpeg 3.1.2, allows attackers to execute arbitrary code (local).

    Published: 30 Mar 2021
    9.8
    Critical

    CVE-2020-24391

    Last Modified: 21 Nov 2024

    mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this may overlap CVE-2019-10769.

    Published: 30 Mar 2021
    5.3
    Medium

    CVE-2021-29642

    Last Modified: 21 Nov 2024

    GistPad before 0.2.7 allows a crafted workspace folder to change the URL for the Gist API, which leads to leakage of GitHub access tokens.

    Published: 30 Mar 2021
    6.4
    Medium

    CVE-2021-21412

    Last Modified: 21 Nov 2024

    Potential for arbitrary code execution in npm package @thi.ng/egf `#gpg`-tagged property values (only if `decrypt: true` option is enabled). PR with patch has been submitted and will has been released as of v0.4.0 By default the EGF parse functions do NOT attempt to decrypt values (since GPG only available in non-browser env). However, if GPG encrypted values are used/required: 1. Perform a regex search for `#gpg`-tagged values in the EGF source file/string and check for backtick (\`) chars in the encrypted value string 2. Replace/remove them or skip parsing if present.

    Published: 30 Mar 2021
    5.5
    Medium

    CVE-2021-26579

    Last Modified: 21 Nov 2024

    A security vulnerability in HPE Unified Data Management (UDM) could allow the local disclosure of privileged information (CWE-321: Use of Hard-coded Cryptographic Key in a product). HPE has provided updates to versions 1.2009.0 and 1.2101.0 of HPE Unified Data Management (UDM). Version 1.2103.0 of HPE Unified Data Management (UDM) removes all hard-coded cryptographic keys.

    Published: 30 Mar 2021
    —
    Unknown

    CVE-2021-29640

    Last Modified: 15 Feb 2024

    This candidate was in a CNA pool that was not assigned to any issues during 2021.

    Published: 30 Mar 2021
    —
    Unknown

    CVE-2021-29639

    Last Modified: 15 Feb 2024

    This candidate was in a CNA pool that was not assigned to any issues during 2021.

    Published: 30 Mar 2021
    —
    Unknown

    CVE-2021-29634

    Last Modified: 15 Feb 2024

    This candidate was in a CNA pool that was not assigned to any issues during 2021.

    Published: 30 Mar 2021
    —
    Unknown

    CVE-2021-29635

    Last Modified: 15 Feb 2024

    This candidate was in a CNA pool that was not assigned to any issues during 2021.

    Published: 30 Mar 2021
    —
    Unknown

    CVE-2021-29636

    Last Modified: 15 Feb 2024

    This candidate was in a CNA pool that was not assigned to any issues during 2021.

    Published: 30 Mar 2021
    —
    Unknown

    CVE-2021-29637

    Last Modified: 15 Feb 2024

    This candidate was in a CNA pool that was not assigned to any issues during 2021.

    Published: 30 Mar 2021
    —
    Unknown

    CVE-2021-29638

    Last Modified: 15 Feb 2024

    This candidate was in a CNA pool that was not assigned to any issues during 2021.

    Published: 30 Mar 2021
    —
    Unknown

    CVE-2021-29633

    Last Modified: 15 Feb 2024

    This candidate was in a CNA pool that was not assigned to any issues during 2021.

    Published: 30 Mar 2021
    5.4
    Medium

    CVE-2021-20520

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198572.

    Published: 30 Mar 2021
    5.4
    Medium

    CVE-2021-20518

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198437.

    Published: 30 Mar 2021
    5.4
    Medium

    CVE-2021-20506

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198231.

    Published: 30 Mar 2021
    5.4
    Medium

    CVE-2021-20504

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198231.

    Published: 30 Mar 2021
    5.4
    Medium

    CVE-2021-20503

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198182.

    Published: 30 Mar 2021
    7.1
    High

    CVE-2021-20502

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation Products are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 198059.

    Published: 30 Mar 2021
    5.4
    Medium

    CVE-2021-20447

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 196623.

    Published: 30 Mar 2021
    5.4
    Medium

    CVE-2021-20352

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194710.

    Published: 30 Mar 2021
    7.1
    High

    CVE-2021-20482

    Last Modified: 21 Nov 2024

    IBM Cloud Pak for Automation 20.0.2 and 20.0.3 IF002 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 197504.

    Published: 30 Mar 2021
    5.5
    Medium

    CVE-2020-4944

    Last Modified: 21 Nov 2024

    IBM UrbanCode Deploy (UCD) 7.0.3.0, 7.0.4.0, 7.0.5.3, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2, stores keystore passwords in plain text after a manual edit, which can be read by a local user. IBM X-Force ID: 191944.

    Published: 30 Mar 2021
    5.5
    Medium

    CVE-2020-4884

    Last Modified: 21 Nov 2024

    IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 190908.

    Published: 30 Mar 2021
    5.4
    Medium

    CVE-2020-4848

    Last Modified: 21 Nov 2024

    IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 could allow an authenticated user to initiate a plugin or compare process resources that they should not have access to. IBM X-Force ID: 190293.

    Published: 30 Mar 2021
    5.4
    Medium

    CVE-2021-21398

    Last Modified: 21 Nov 2024

    PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.7.3, an attacker can inject HTML when the Grid Column Type DataColumn is badly used. The problem is fixed in 1.7.7.3

    Published: 30 Mar 2021