CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2021-21389

    Last Modified: 21 Nov 2024

    BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2.1 it's possible for a non-privileged, regular user to obtain administrator rights by exploiting an issue in the REST API members endpoint. The vulnerability has been fixed in BuddyPress 7.2.1. Existing installations of the plugin should be updated to this version to mitigate the issue.

    Published: 26 Mar 2021
    6.1
    Medium

    CVE-2021-21333

    Last Modified: 21 Nov 2024

    Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.27.0, the notification emails sent for notifications for missed messages or for an expiring account are subject to HTML injection. In the case of the notification for missed messages, this could allow an attacker to insert forged content into the email. The account expiry feature is not enabled by default and the HTML injection is not controllable by an attacker. This is fixed in version 1.27.0.

    Published: 26 Mar 2021
    6.9
    Medium

    CVE-2021-21332

    Last Modified: 21 Nov 2024

    Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.27.0, the password reset endpoint served via Synapse was vulnerable to cross-site scripting (XSS) attacks. The impact depends on the configuration of the domain that Synapse is deployed on, but may allow access to cookies and other browser data, CSRF vulnerabilities, and access to other resources served on the same domain or parent domains. This is fixed in version 1.27.0.

    Published: 26 Mar 2021
    6.2
    Medium

    CVE-2021-22184

    Last Modified: 21 Nov 2024

    An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to see sensitive information that wasn't properly redacted.

    Published: 26 Mar 2021
    4.3
    Medium

    CVE-2021-22180

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab affecting all versions starting from 13.4. Improper access control allows unauthorized users to access details on analytic pages.

    Published: 26 Mar 2021
    5.7
    Medium

    CVE-2021-22194

    Last Modified: 21 Nov 2024

    In all versions of GitLab, marshalled session keys were being stored in Redis.

    Published: 26 Mar 2021
    4.3
    Medium

    CVE-2021-22172

    Last Modified: 21 Nov 2024

    Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccessible on the releases page

    Published: 26 Mar 2021
    6.1
    Medium

    CVE-2021-25372

    Last Modified: 14 Jan 2026

    An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.

    Published: 26 Mar 2021
    6.1
    Medium

    CVE-2021-25371

    Last Modified: 30 Oct 2025

    A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.

    Published: 26 Mar 2021
    6.1
    Medium

    CVE-2021-25370

    Last Modified: 14 Jan 2026

    An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic.

    Published: 26 Mar 2021
    6.2
    Medium

    CVE-2021-25369

    Last Modified: 30 Oct 2025

    An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.

    Published: 26 Mar 2021
    6.1
    Medium

    CVE-2021-22886

    Last Modified: 21 Nov 2024

    Rocket.Chat before 3.11, 3.10.5, 3.9.7, 3.8.8 is vulnerable to persistent cross-site scripting (XSS) using nested markdown tags allowing a remote attacker to inject arbitrary JavaScript in a message. This flaw leads to arbitrary file read and RCE on Rocket.Chat desktop app.

    Published: 26 Mar 2021
    7.5
    High

    CVE-2021-29255

    Last Modified: 21 Nov 2024

    MicroSeven MYM71080i-B 2.0.5 through 2.0.20 devices send admin credentials in cleartext to pnp.microseven.com TCP port 7007. An attacker on the same network as the device can capture these credentials.

    Published: 26 Mar 2021
    7.5
    High

    CVE-2021-21403

    Last Modified: 21 Nov 2024

    In github.com/kongchuanhujiao/server before version 1.3.21 there is an authentication Bypass by Primary Weakness vulnerability. All users are impacted. This is fixed in version 1.3.21.

    Published: 26 Mar 2021
    8.8
    High

    CVE-2020-28695

    Last Modified: 21 Nov 2024

    Askey Fiber Router RTF3505VW-N1 BR_SV_g000_R3505VWN1001_s32_7 devices allow Remote Code Execution and retrieval of admin credentials to log into the Dashboard or login via SSH, leading to code execution as root.

    Published: 26 Mar 2021
    6.6
    Medium

    CVE-2021-20285

    Last Modified: 11 Apr 2025

    A flaw was found in upx canPack in p_lx_elf.cpp in UPX 3.96. This flaw allows attackers to cause a denial of service (SEGV or buffer overflow and application crash) or possibly have unspecified other impacts via a crafted ELF. The highest threat from this vulnerability is to system availability.

    Published: 26 Mar 2021
    6.1
    Medium

    CVE-2021-1629

    Last Modified: 21 Nov 2024

    Tableau Server fails to validate certain URLs that are embedded in emails sent to Tableau Server users.

    Published: 26 Mar 2021
    9.8
    Critical

    CVE-2021-1628

    Last Modified: 21 Nov 2024

    MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Affected versions: Mule 4.x runtime released before February 2, 2021.

    Published: 26 Mar 2021
    9.8
    Critical

    CVE-2021-1627

    Last Modified: 21 Nov 2024

    MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. This affects: Mule 3.8.x,3.9.x,4.x runtime released before February 2, 2021.

    Published: 26 Mar 2021
    9.8
    Critical

    CVE-2021-1626

    Last Modified: 21 Nov 2024

    MuleSoft is aware of a Remote Code Execution vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Versions affected: Mule 4.1.x and 4.2.x runtime released before February 2, 2021.

    Published: 26 Mar 2021
    4.8
    Medium

    CVE-2020-35856

    Last Modified: 21 Nov 2024

    SolarWinds Orion Platform before 2020.2.5 allows stored XSS attacks by an administrator on the Customize View page.

    Published: 26 Mar 2021
    4.8
    Medium

    CVE-2021-3109

    Last Modified: 21 Nov 2024

    The custom menu item options page in SolarWinds Orion Platform before 2020.2.5 allows Reverse Tabnabbing in the context of an administrator account.

    Published: 26 Mar 2021
    9.8
    Critical

    CVE-2020-19625

    Last Modified: 21 Nov 2024

    Remote Code Execution Vulnerability in tests/support/stores/test_grid_filter.php in oria gridx 1.3, allows remote attackers to execute arbitrary code, via crafted value to the $query parameter.

    Published: 26 Mar 2021
    5.4
    Medium

    CVE-2020-19626

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or HTML, via /admin/settings/sites/new.

    Published: 26 Mar 2021
    6.1
    Medium

    CVE-2020-25840

    Last Modified: 21 Nov 2024

    Cross-Site scripting vulnerability in Micro Focus Access Manager product, affects all version prior to version 5.0. The vulnerability could cause configuration destruction.

    Published: 26 Mar 2021
    7.5
    High

    CVE-2021-22506

    Last Modified: 27 Oct 2025

    Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage.

    Published: 26 Mar 2021
    6.1
    Medium

    CVE-2021-3275

    Last Modified: 21 Nov 2024

    Unauthenticated stored cross-site scripting (XSS) exists in multiple TP-Link products including WIFI Routers (Wireless AC routers), Access Points, ADSL + DSL Gateways and Routers, which affects TD-W9977v1, TL-WA801NDv5, TL-WA801Nv6, TL-WA802Nv5, and Archer C3150v2 devices through the improper validation of the hostname. Some of the pages including dhcp.htm, networkMap.htm, dhcpClient.htm, qsEdit.htm, and qsReview.htm and use this vulnerable hostname function (setDefaultHostname()) without sanitization.

    Published: 26 Mar 2021
    6.5
    Medium

    CVE-2021-23890

    Last Modified: 21 Nov 2024

    Information leak vulnerability in the Agent Handler of McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows an unauthenticated user to download McAfee product packages (specifically McAfee Agent) available in ePO repository and install them on their own machines to have it managed and then in turn get policy details from the ePO server. This can only happen when the ePO Agent Handler is installed in a Demilitarized Zone (DMZ) to service machines not connected to the network through a VPN.

    Published: 26 Mar 2021
    6.3
    Medium

    CVE-2021-23888

    Last Modified: 21 Nov 2024

    Unvalidated client-side URL redirect vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 could cause an authenticated ePO user to load an untrusted site in an ePO iframe which could steal information from the authenticated user.

    Published: 26 Mar 2021
    3.5
    Low

    CVE-2021-23889

    Last Modified: 21 Nov 2024

    Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows ePO administrators to inject arbitrary web script or HTML via multiple parameters where the administrator's entries were not correctly sanitized.

    Published: 26 Mar 2021
    5.4
    Medium

    CVE-2021-20683

    Last Modified: 21 Nov 2024

    Improper neutralization of JavaScript input in the blog article editing function of baserCMS versions prior to 4.4.5 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors.

    Published: 26 Mar 2021
    7.2
    High

    CVE-2021-20682

    Last Modified: 21 Nov 2024

    baserCMS versions prior to 4.4.5 allows a remote attacker with an administrative privilege to execute arbitrary OS commands via unspecified vectors.

    Published: 26 Mar 2021
    5.4
    Medium

    CVE-2021-20681

    Last Modified: 21 Nov 2024

    Improper neutralization of JavaScript input in the page editing function of baserCMS versions prior to 4.4.5 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors.

    Published: 26 Mar 2021
    3.1
    Low

    CVE-2021-20677

    Last Modified: 21 Nov 2024

    UNIVERGE Aspire series PBX (UNIVERGE Aspire WX from 1.00 to 3.51, UNIVERGE Aspire UX from 1.00 to 9.70, UNIVERGE SV9100 from 1.00 to 10.70, and SL2100 from 1.00 to 3.00) allows a remote authenticated attacker to cause system down and a denial of service (DoS) condition by sending a specially crafted command.

    Published: 26 Mar 2021
    7.8
    High

    CVE-2021-28250

    Last Modified: 21 Nov 2024

    CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a setuid (and/or setgid) file. When a component is run as an argument of the runpicEhealth executable, the script code will be executed as the ehealth user. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 26 Mar 2021
    7.5
    High

    CVE-2021-28248

    Last Modified: 21 Nov 2024

    CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is able to perform an arbitrary number of /web/frames/ authentication attempts using different passwords, and eventually gain access to a targeted account, NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 26 Mar 2021
    8.8
    High

    CVE-2021-28249

    Last Modified: 21 Nov 2024

    CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. To exploit the vulnerability, the ehealth user must create a malicious library in the writable RPATH, to be dynamically linked when the FtpCollector executable is run. The code in the library will be executed as the root user. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 26 Mar 2021
    5.4
    Medium

    CVE-2021-28247

    Last Modified: 21 Nov 2024

    CA eHealth Performance Manager through 6.3.2.12 is affected by Cross Site Scripting (XSS). The impact is: An authenticated remote user is able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and perform a Reflected Cross-Site Scripting attack against the platform users. The affected endpoints are: cgi/nhWeb with the parameter report, aviewbin/filtermibobjects.pl with the parameter namefilter, and aviewbin/query.pl with the parameters System, SystemText, Group, and GroupText. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 26 Mar 2021
    7.8
    High

    CVE-2021-28246

    Last Modified: 21 Nov 2024

    CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. A regular user must create a malicious library in the writable RPATH, to be dynamically linked when the emtgtctl2 executable is run. The code in the library will be executed as the ehealth user. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 26 Mar 2021
    7.5
    High

    CVE-2020-28346

    Last Modified: 21 Nov 2024

    ACRN through 2.2 has a devicemodel/hw/pci/virtio/virtio.c NULL Pointer Dereference.

    Published: 26 Mar 2021
    6.5
    Medium

    CVE-2021-3153

    Last Modified: 21 Nov 2024

    HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users within an organization to have two-factor authentication enabled. Fixed in v202103-1.

    Published: 26 Mar 2021
    6.5
    Medium

    CVE-2021-3027

    Last Modified: 21 Nov 2024

    app/views_mod/user/user.py in LibrIT PaSSHport through 2.5 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided search filter because user input gets no sanitization.

    Published: 26 Mar 2021
    6.1
    Medium

    CVE-2020-23517

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Aryanic HighMail (High CMS) versions 2020 and before allows remote attackers to inject arbitrary web script or HTML, via 'user' to LoginForm.

    Published: 26 Mar 2021
    5.4
    Medium

    CVE-2021-3469

    Last Modified: 21 Nov 2024

    Foreman versions before 2.3.4 and before 2.4.0 is affected by an improper authorization handling flaw. An authenticated attacker can impersonate the foreman-proxy if product enable the Puppet Certificate authority (CA) to sign certificate requests that have subject alternative names (SANs). Foreman do not enable SANs by default and `allow-authorization-extensions` is set to `false` unless user change `/etc/puppetlabs/puppetserver/conf.d/ca.conf` configuration explicitly.

    Published: 26 Mar 2021
    7.5
    High

    CVE-2021-3119

    Last Modified: 21 Nov 2024

    Zetetic SQLCipher 4.x before 4.4.3 has a NULL pointer dereferencing issue related to sqlcipher_export in crypto.c and sqlite3StrICmp in sqlite3.c. This may allow an attacker to perform a remote denial of service attack. For example, an SQL injection can be used to execute the crafted SQL command sequence, which causes a segmentation fault.

    Published: 25 Mar 2021
    9.8
    Critical

    CVE-2021-27372

    Last Modified: 21 Nov 2024

    Realtek xPON RTL9601D SDK 1.9 stores passwords in plaintext which may allow attackers to possibly gain access to the device with root permissions via the build-in network monitoring tool and execute arbitrary commands.

    Published: 25 Mar 2021
    7.8
    High

    CVE-2021-29098

    Last Modified: 5 May 2025

    Multiple uninitialized pointer vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) and ArcGIS Pro 2.7 (and earlier) allow an unauthenticated attacker to achieve arbitrary code execution in the context of the current user.

    Published: 25 Mar 2021
    7.8
    High

    CVE-2021-29097

    Last Modified: 21 Nov 2024

    Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) and ArcGIS Pro 2.7 (and earlier) allow an unauthenticated attacker to achieve arbitrary code execution in the context of the current user.

    Published: 25 Mar 2021
    6.8
    Medium

    CVE-2021-29095

    Last Modified: 21 Nov 2024

    Multiple uninitialized pointer vulnerabilities when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticated attacker with specialized permissions to achieve arbitrary code execution in the context of the service account.

    Published: 25 Mar 2021
    6.8
    Medium

    CVE-2021-29094

    Last Modified: 21 Nov 2024

    Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticated attacker with specialized permissions to achieve arbitrary code execution in the context of the service account.

    Published: 25 Mar 2021