CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2021-29093

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticated attacker with specialized permissions to achieve arbitrary code execution in the context of the service account.

    Published: 25 Mar 2021
    7.5
    High

    CVE-2020-10579

    Last Modified: 21 Nov 2024

    A directory traversal on the /admin/sysmon.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to list the content of arbitrary server directories accessible to the user running the application.

    Published: 25 Mar 2021
    8.8
    High

    CVE-2020-10580

    Last Modified: 21 Nov 2024

    A command injection on the /admin/broadcast.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers to execute arbitrary PHP code on the server as the user running the application.

    Published: 25 Mar 2021
    7.5
    High

    CVE-2020-10581

    Last Modified: 21 Nov 2024

    Multiple session validity check issues in several administration functionalities of Invigo Automatic Device Management (ADM) through 5.0 allow remote attackers to read potentially sensitive data hosted by the application.

    Published: 25 Mar 2021
    9.8
    Critical

    CVE-2020-10582

    Last Modified: 21 Nov 2024

    A SQL injection on the /admin/display_errors.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to execute arbitrary SQL requests (including data reading and modification) on the database.

    Published: 25 Mar 2021
    8.8
    High

    CVE-2020-10583

    Last Modified: 21 Nov 2024

    The /admin/admapi.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers to execute arbitrary OS commands on the server as the user running the application.

    Published: 25 Mar 2021
    7.5
    High

    CVE-2020-10584

    Last Modified: 21 Nov 2024

    A directory traversal on the /admin/search_by.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to read arbitrary server files accessible to the user running the application.

    Published: 25 Mar 2021
    6.1
    Medium

    CVE-2021-22889

    Last Modified: 21 Nov 2024

    Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `statsBreakdown` parameter of stats.php (and possibly other scripts) due to single quotes not being escaped. An attacker could trick a user with access to the user interface of a Revive Adserver instance into clicking on a specifically crafted URL and pressing a certain key combination to execute injected JavaScript code.

    Published: 25 Mar 2021
    6.1
    Medium

    CVE-2021-22888

    Last Modified: 21 Nov 2024

    Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `status` parameter of campaign-zone-zones.php. An attacker could trick a user with access to the user interface of a Revive Adserver instance into clicking on a specifically crafted URL and execute injected JavaScript code.

    Published: 25 Mar 2021
    7.8
    High

    CVE-2021-27448

    Last Modified: 21 Nov 2024

    A miscommunication in the file system allows adversaries with access to the MU320E to escalate privileges on the MU320E (all firmware versions prior to v04A00.1).

    Published: 25 Mar 2021
    7.8
    High

    CVE-2021-27454

    Last Modified: 21 Nov 2024

    The software performs an operation at a privilege level higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses on the Reason DR60 (all firmware versions prior to 02A04.1).

    Published: 25 Mar 2021
    7.8
    High

    CVE-2021-27450

    Last Modified: 21 Nov 2024

    SSH server configuration file does not implement some best practices. This could lead to a weakening of the SSH protocol strength, which could lead to additional misconfiguration or be leveraged as part of a larger attack on the MU320E (all firmware versions prior to v04A00.1).

    Published: 25 Mar 2021
    9.8
    Critical

    CVE-2021-27440

    Last Modified: 21 Nov 2024

    The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components on the Reason DR60 (all firmware versions prior to 02A04.1).

    Published: 25 Mar 2021
    8.8
    High

    CVE-2021-27438

    Last Modified: 21 Nov 2024

    The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components on the Reason DR60 (all firmware versions prior to 02A04.1).

    Published: 25 Mar 2021
    7.8
    High

    CVE-2021-27452

    Last Modified: 21 Nov 2024

    The software contains a hard-coded password that could allow an attacker to take control of the merging unit using these hard-coded credentials on the MU320E (all firmware versions prior to v04A00.1).

    Published: 25 Mar 2021
    4.8
    Medium

    CVE-2021-29010

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in the "report_type" parameter.

    Published: 25 Mar 2021
    4.8
    Medium

    CVE-2021-29009

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in the "type" parameter.

    Published: 25 Mar 2021
    4.8
    Medium

    CVE-2021-29008

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via webmaster-tools.php in the "to_time" parameter.

    Published: 25 Mar 2021
    7.5
    High

    CVE-2021-20217

    Last Modified: 21 Nov 2024

    A flaw was found in Privoxy in versions before 3.0.31. An assertion failure triggered by a crafted CGI request may lead to denial of service. The highest threat from this vulnerability is to system availability.

    Published: 25 Mar 2021
    7.5
    High

    CVE-2021-20216

    Last Modified: 21 Nov 2024

    A flaw was found in Privoxy in versions before 3.0.31. A memory leak that occurs when decompression fails unexpectedly may lead to a denial of service. The highest threat from this vulnerability is to system availability.

    Published: 25 Mar 2021
    7.5
    High

    CVE-2021-20215

    Last Modified: 21 Nov 2024

    A flaw was found in Privoxy in versions before 3.0.29. Memory leaks in the show-status CGI handler when memory allocations fail can lead to a system crash.

    Published: 25 Mar 2021
    7.5
    High

    CVE-2021-20214

    Last Modified: 21 Nov 2024

    A flaw was found in Privoxy in versions before 3.0.29. Memory leaks in the client-tags CGI handler when client tags are configured and memory allocations fail can lead to a system crash.

    Published: 25 Mar 2021
    7.5
    High

    CVE-2021-20213

    Last Modified: 21 Nov 2024

    A flaw was found in Privoxy in versions before 3.0.29. Dereference of a NULL-pointer that could result in a crash if accept-intercepted-requests was enabled, Privoxy failed to get the request destination from the Host header and a memory allocation failed.

    Published: 25 Mar 2021
    7.5
    High

    CVE-2021-20212

    Last Modified: 21 Nov 2024

    A flaw was found in Privoxy in versions before 3.0.29. Memory leak if multiple filters are executed and the last one is skipped due to a pcre error leading to a system crash.

    Published: 25 Mar 2021
    7.5
    High

    CVE-2021-20211

    Last Modified: 21 Nov 2024

    A flaw was found in Privoxy in versions before 3.0.29. Memory leak when client tags are active can cause a system crash.

    Published: 25 Mar 2021
    7.5
    High

    CVE-2021-20210

    Last Modified: 21 Nov 2024

    A flaw was found in Privoxy in versions before 3.0.29. Memory leak in the show-status CGI handler when no filter files are configured can lead to a system crash.

    Published: 25 Mar 2021
    7.5
    High

    CVE-2020-35502

    Last Modified: 21 Nov 2024

    A flaw was found in Privoxy in versions before 3.0.29. Memory leaks when a response is buffered and the buffer limit is reached or Privoxy is running out of memory can lead to a system crash.

    Published: 25 Mar 2021
    5.4
    Medium

    CVE-2021-26596

    Last Modified: 21 Nov 2024

    An issue was discovered in Nokia NetAct 18A. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims. Here, the /netact/sct filename parameter is used.

    Published: 25 Mar 2021
    6.5
    Medium

    CVE-2021-26597

    Last Modified: 21 Nov 2024

    An issue was discovered in Nokia NetAct 18A. A remote user, authenticated to the NOKIA NetAct Web Page, can visit the Site Configuration Tool web site section and arbitrarily upload potentially dangerous files without restrictions via the /netact/sct dir parameter in conjunction with the operation=upload value.

    Published: 25 Mar 2021
    7.8
    High

    CVE-2021-29096

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) and ArcGIS Pro 2.7 (and earlier) allows an unauthenticated attacker to achieve arbitrary code execution in the context of the current user.

    Published: 25 Mar 2021
    5.9
    Medium

    CVE-2021-27195

    Last Modified: 21 Nov 2024

    Improper Authorization vulnerability in Netop Vision Pro up to and including to 9.7.1 allows an attacker to replay network traffic.

    Published: 25 Mar 2021
    8.8
    High

    CVE-2021-27194

    Last Modified: 21 Nov 2024

    Cleartext transmission of sensitive information in Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to gather credentials including Windows login usernames and passwords.

    Published: 25 Mar 2021
    9.8
    Critical

    CVE-2021-27193

    Last Modified: 21 Nov 2024

    Incorrect default permissions vulnerability in the API of Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to read and write files on the remote machine with system privileges resulting in a privilege escalation.

    Published: 25 Mar 2021
    7.8
    High

    CVE-2021-27192

    Last Modified: 21 Nov 2024

    Local privilege escalation vulnerability in Windows clients of Netop Vision Pro up to and including 9.7.1 allows a local user to gain administrator privileges whilst using the clients.

    Published: 25 Mar 2021
    3.3
    Low

    CVE-2021-25368

    Last Modified: 21 Nov 2024

    Hijacking vulnerability in Samsung Cloud prior to version 4.7.0.3 allows attackers to intercept when the provider is executed.

    Published: 25 Mar 2021
    3.7
    Low

    CVE-2021-25367

    Last Modified: 21 Nov 2024

    Path Traversal vulnerability in Samsung Notes prior to version 4.2.00.22 allows attackers to access local files without permission.

    Published: 25 Mar 2021
    3.2
    Low

    CVE-2021-25366

    Last Modified: 21 Nov 2024

    Improper access control in Samsung Internet prior to version 13.2.1.70 allows physically proximate attackers to bypass the secret mode's authentication.

    Published: 25 Mar 2021
    5.5
    Medium

    CVE-2021-25355

    Last Modified: 21 Nov 2024

    Using unsafe PendingIntent in Samsung Notes prior to version 4.2.00.22 allows local attackers unauthorized action without permission via hijacking the PendingIntent.

    Published: 25 Mar 2021
    3.3
    Low

    CVE-2021-25354

    Last Modified: 21 Nov 2024

    Improper input check in Samsung Internet prior to version 13.2.1.46 allows attackers to launch non-exported activity in Samsung Browser via malicious deeplink.

    Published: 25 Mar 2021
    5.5
    Medium

    CVE-2021-25353

    Last Modified: 21 Nov 2024

    Using empty PendingIntent in Galaxy Themes prior to version 5.2.00.1215 allows local attackers to read/write private file directories of Galaxy Themes application without permission via hijacking the PendingIntent.

    Published: 25 Mar 2021
    5.5
    Medium

    CVE-2021-25352

    Last Modified: 21 Nov 2024

    Using PendingIntent with implicit intent in Bixby Voice prior to version 3.0.52.14 allows attackers to execute privileged action by hijacking and modifying the intent.

    Published: 25 Mar 2021
    3.2
    Low

    CVE-2021-25351

    Last Modified: 21 Nov 2024

    Improper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1.1.3 allows physically proximate attackers to log out user account on device without user password.

    Published: 25 Mar 2021
    2
    Low

    CVE-2021-25350

    Last Modified: 21 Nov 2024

    Information Exposure vulnerability in Samsung Account prior to version 12.1.1.3 allows physically proximate attackers to access user information via log.

    Published: 25 Mar 2021
    5.5
    Medium

    CVE-2021-25349

    Last Modified: 21 Nov 2024

    Using unsafe PendingIntent in Slow Motion Editor prior to version 3.5.18.5 allows local attackers unauthorized action without permission via hijacking the PendingIntent.

    Published: 25 Mar 2021
    9.8
    Critical

    CVE-2021-21783

    Last Modified: 21 Nov 2024

    A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 25 Mar 2021
    8.6
    High

    CVE-2021-22659

    Last Modified: 3 Jun 2026

    Rockwell Automation MicroLogix 1400 Version 21.6 and below may allow a remote unauthenticated attacker to send a specially crafted Modbus packet allowing the attacker to retrieve or modify random values in the register. If successfully exploited, this may lead to a buffer overflow resulting in a denial-of-service condition. The FAULT LED will flash RED and communications may be lost. Recovery from denial-of-service condition requires the fault to be cleared by the user.

    Published: 25 Mar 2021
    7.5
    High

    CVE-2021-22496

    Last Modified: 21 Nov 2024

    Authentication Bypass Vulnerability in Micro Focus Access Manager Product, affects all version prior to version 4.5.3.3. The vulnerability could cause information leakage.

    Published: 25 Mar 2021
    7.8
    High

    CVE-2020-6790

    Last Modified: 21 Nov 2024

    Calling an executable through an Uncontrolled Search Path Element in the Bosch Video Streaming Gateway installer up to and including version 6.45.10 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious exe in the same directory where the installer is started from.

    Published: 25 Mar 2021
    7.8
    High

    CVE-2020-6789

    Last Modified: 21 Nov 2024

    Loading a DLL through an Uncontrolled Search Path Element in the Bosch Monitor Wall installer up to and including version 10.00.0164 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious DLL in the same directory where the installer is started from.

    Published: 25 Mar 2021
    7.8
    High

    CVE-2020-6788

    Last Modified: 21 Nov 2024

    Loading a DLL through an Uncontrolled Search Path Element in the Bosch Configuration Manager installer up to and including version 7.21.0078 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious DLL in the same directory where the installer is started from.

    Published: 25 Mar 2021