CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-26295

    Last Modified: 13 Feb 2025

    Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.

    Published: 22 Mar 2021
    3.5
    Low

    CVE-2021-21438

    Last Modified: 21 Nov 2024

    Agents are able to see linked FAQ articles without permissions (defined in FAQ Category). This issue affects: FAQ version 6.0.29 and prior versions, OTRS version 7.0.24 and prior versions.

    Published: 22 Mar 2021
    3.5
    Low

    CVE-2021-21437

    Last Modified: 21 Nov 2024

    Agents are able to see linked Config Items without permissions, which are defined in General Catalog. This issue affects: OTRSCIsInCustomerFrontend 7.0.15 and prior versions, ITSMConfigurationManagement 7.0.24 and prior versions

    Published: 22 Mar 2021
    5.3
    Medium

    CVE-2021-28963

    Last Modified: 21 Nov 2024

    Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.

    Published: 22 Mar 2021
    9.8
    Critical

    CVE-2021-28955

    Last Modified: 21 Nov 2024

    git-bug before 0.7.2 has an Uncontrolled Search Path Element. It will execute git.bat from the current directory in certain PATH situations (most often seen on Windows).

    Published: 22 Mar 2021
    8.8
    High

    CVE-2021-28956

    Last Modified: 21 Nov 2024

    The unofficial vscode-sass-lint (aka Sass Lint) extension through 1.0.7 for Visual Studio Code allows attackers to execute arbitrary binaries if the user opens a crafted workspace. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 22 Mar 2021
    5.3
    Medium

    CVE-2021-26069

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to download temporary files and enumerate project keys via an Information Disclosure vulnerability in the /rest/api/1.0/issues/{id}/ActionsAndOperations API endpoint. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0.

    Published: 22 Mar 2021
    7.2
    High

    CVE-2021-26070

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the `makeRequest` gadget resource. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1.

    Published: 22 Mar 2021
    9.8
    Critical

    CVE-2021-1870

    Last Modified: 23 Oct 2025

    A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

    Published: 22 Mar 2021
    8.8
    High

    CVE-2021-1789

    Last Modified: 23 Oct 2025

    A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 22 Mar 2021
    7.5
    High

    CVE-2019-14840

    Last Modified: 13 May 2025

    A flaw was found in the RHDM, where sensitive HTML form fields like Password has auto-complete enabled which may lead to leak of credentials.

    Published: 22 Mar 2021
    5.5
    Medium

    CVE-2021-28971

    Last Modified: 21 Nov 2024

    In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs, userspace applications (such as perf-fuzzer) can cause a system crash because the PEBS status in a PEBS record is mishandled, aka CID-d88d05a9e0b6.

    Published: 22 Mar 2021
    6.7
    Medium

    CVE-2021-28972

    Last Modified: 21 Nov 2024

    In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a new device name to the driver from userspace, allowing userspace to write data to the kernel stack frame directly. This occurs because add_slot_store and remove_slot_store mishandle drc_name '\0' termination, aka CID-cc7a0bb058b8.

    Published: 22 Mar 2021
    7.5
    High

    CVE-2021-29923

    Last Modified: 21 Nov 2024

    Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation. This affects net.ParseIP and net.ParseCIDR.

    Published: 22 Mar 2021
    6.1
    Medium

    CVE-2021-30154

    Last Modified: 21 Nov 2024

    An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On Special:NewFiles, all the mediastatistics-header-* messages are output in HTML unescaped, leading to XSS.

    Published: 22 Mar 2021
    6.1
    Medium

    CVE-2021-30157

    Last Modified: 21 Nov 2024

    An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On ChangesList special pages such as Special:RecentChanges and Special:Watchlist, some of the rcfilters-filter-* label messages are output in HTML unescaped, leading to XSS.

    Published: 22 Mar 2021
    6.5
    Medium

    CVE-2021-1799

    Last Modified: 21 Nov 2024

    A port redirection issue was addressed with additional port validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. A malicious website may be able to access restricted ports on arbitrary servers.

    Published: 22 Mar 2021
    7.8
    High

    CVE-2021-33034

    Last Modified: 21 Nov 2024

    In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409. This leads to writing an arbitrary value.

    Published: 22 Mar 2021
    7.1
    High

    CVE-2021-3461

    Last Modified: 21 Nov 2024

    A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name].

    Published: 22 Mar 2021
    0
    Low

    CVE-2021-3465

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 22 Mar 2021
    3.3
    Low

    CVE-2020-29623

    Last Modified: 21 Nov 2024

    "Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. A user may be unable to fully delete browsing history.

    Published: 22 Mar 2021
    6.5
    Medium

    CVE-2021-1765

    Last Modified: 21 Nov 2024

    This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. Maliciously crafted web content may violate iframe sandboxing policy.

    Published: 22 Mar 2021
    6.5
    Medium

    CVE-2021-1801

    Last Modified: 21 Nov 2024

    This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Maliciously crafted web content may violate iframe sandboxing policy.

    Published: 22 Mar 2021
    9.8
    Critical

    CVE-2020-13963

    Last Modified: 21 Nov 2024

    SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authentication algorithm, is public. The key for admin is hardcoded in the installation code, and there is no key for publicsp (which is a guest account).

    Published: 21 Mar 2021
    7.5
    High

    CVE-2021-23360

    Last Modified: 21 Nov 2024

    This affects the package killport before 1.0.2. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization. Running this PoC will cause the command touch success to be executed, leading to the creation of a file called success.

    Published: 21 Mar 2021
    8.8
    High

    CVE-2021-28961

    Last Modified: 21 Nov 2024

    applications/luci-app-ddns/luasrc/model/cbi/ddns/detail.lua in the DDNS package for OpenWrt 19.07 allows remote authenticated users to inject arbitrary commands via POST requests.

    Published: 21 Mar 2021
    7.8
    High

    CVE-2021-28953

    Last Modified: 21 Nov 2024

    The unofficial C/C++ Advanced Lint extension before 1.9.0 for Visual Studio Code allows attackers to execute arbitrary binaries if the user opens a crafted repository.

    Published: 21 Mar 2021
    7.8
    High

    CVE-2021-28954

    Last Modified: 21 Nov 2024

    In Chris Walz bit before 1.0.5 on Windows, attackers can run arbitrary code via a .exe file in a crafted repository.

    Published: 21 Mar 2021
    6.1
    Medium

    CVE-2021-28957

    Last Modified: 17 Dec 2025

    An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in lxml 4.6.3.

    Published: 21 Mar 2021
    7.5
    High

    CVE-2021-28117

    Last Modified: 21 Nov 2024

    libdiscover/backends/KNSBackend/KNSResource.cpp in KDE Discover before 5.21.3 automatically creates links to potentially dangerous URLs (that are neither https:// nor http://) based on the content of the store.kde.org web site. (5.18.7 is also a fixed version.)

    Published: 20 Mar 2021
    7.5
    High

    CVE-2021-21267

    Last Modified: 21 Nov 2024

    Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before version 2.0.0, email address validation is vulnerable to a denial-of-service attack where some input (for example `a@0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.`) will freeze the program or web browser page executing the code. This affects any current schema-inspector users using any version to validate email addresses. Users who do not do email validation, and instead do other types of validation (like string min or max length, etc), are not affected. Users should upgrade to version 2.0.0, which uses a regex expression that isn't vulnerable to ReDoS.

    Published: 19 Mar 2021
    6.1
    Medium

    CVE-2019-14831

    Last Modified: 21 Nov 2024

    A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where forum subscribe link contained an open redirect if forced subscription mode was enabled. If a forum's subscription mode was set to "forced subscription", the forum's subscribe link contained an open redirect.

    Published: 19 Mar 2021
    6.1
    Medium

    CVE-2019-14830

    Last Modified: 21 Nov 2024

    A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where the mobile launch endpoint contained an open redirect in some circumstances, which could result in a user's mobile access token being exposed. (Note: This does not affect sites with a forced URL scheme configured, mobile service disabled, or where the mobile app login method is "via the app").

    Published: 19 Mar 2021
    4.3
    Medium

    CVE-2019-14829

    Last Modified: 21 Nov 2024

    A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions where activity creation capabilities were not correctly respected when selecting the activity to use for a course in single activity mode.

    Published: 19 Mar 2021
    4.3
    Medium

    CVE-2019-14828

    Last Modified: 21 Nov 2024

    A vulnerability was found in Moodle affecting 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where users with the capability to create courses were assigned as a teacher in those courses, regardless of whether they had the capability to be automatically assigned that role.

    Published: 19 Mar 2021
    —
    Unknown

    CVE-2019-10151

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 19 Mar 2021
    6.1
    Medium

    CVE-2021-27519

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "srch" parameter.

    Published: 19 Mar 2021
    6.1
    Medium

    CVE-2021-27520

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "author" parameter.

    Published: 19 Mar 2021
    6.7
    Medium

    CVE-2021-20077

    Last Modified: 21 Nov 2024

    Nessus Agent versions 7.2.0 through 8.2.2 were found to inadvertently capture the IAM role security token on the local host during initial linking of the Nessus Agent when installed on an Amazon EC2 instance. This could allow a privileged attacker to obtain the token.

    Published: 19 Mar 2021
    9.1
    Critical

    CVE-2021-26990

    Last Modified: 21 Nov 2024

    Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability that could allow a remote attacker to overwrite arbitrary system files.

    Published: 19 Mar 2021
    7.5
    High

    CVE-2021-26992

    Last Modified: 21 Nov 2024

    Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability which could allow a remote attacker to cause a Denial of Service (DoS).

    Published: 19 Mar 2021
    7.5
    High

    CVE-2021-26991

    Last Modified: 21 Nov 2024

    Cloud Manager versions prior to 3.9.4 contain an insecure Cross-Origin Resource Sharing (CORS) policy which could allow a remote attacker to interact with Cloud Manager.

    Published: 19 Mar 2021
    4.8
    Medium

    CVE-2021-25278

    Last Modified: 21 Nov 2024

    FTAPI 4.0 through 4.10 allows XSS via an SVG document to the Background Image upload feature in the Submit Box Template Editor.

    Published: 19 Mar 2021
    6.1
    Medium

    CVE-2021-25277

    Last Modified: 21 Nov 2024

    FTAPI 4.0 - 4.10 allows XSS via a crafted filename to the alternative text hover box in the file submission component.

    Published: 19 Mar 2021
    6.5
    Medium

    CVE-2021-21390

    Last Modified: 21 Nov 2024

    MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage service. In MinIO before version RELEASE.2021-03-17T02-33-02Z, there is a vulnerability which enables MITM modification of request bodies that are meant to have integrity guaranteed by chunk signatures. In a PUT request using aws-chunked encoding, MinIO ordinarily verifies signatures at the end of a chunk. This check can be skipped if the client sends a false chunk size that is much greater than the actual data sent: the server accepts and completes the request without ever reaching the end of the chunk + thereby without ever checking the chunk signature. This is fixed in version RELEASE.2021-03-17T02-33-02Z. As a workaround one can avoid using "aws-chunked" encoding-based chunk signature upload requests instead use TLS. MinIO SDKs automatically disable chunked encoding signature when the server endpoint is configured with TLS.

    Published: 19 Mar 2021
    8.1
    High

    CVE-2021-21387

    Last Modified: 21 Nov 2024

    Wrongthink peer-to-peer, end-to-end encrypted messenger with PeerJS and Axolotl ratchet. In wrongthink from version 2.0.0 and before 2.3.0 there was a set of vulnerabilities causing inadequate encryption strength. Part of the secret identity key was disclosed by the fingerprint used for connection. Additionally, the safety number was improperly calculated. It was computed using part of one of the public identity keys instead of being derived from both public identity keys. This caused issues in computing safety numbers which would potentially be exploitable in the real world. Additionally there was inadequate encryption strength due to use of 1024-bit DSA keys. These issues are all fixed in version 2.3.0.

    Published: 19 Mar 2021
    5.3
    Medium

    CVE-2020-4635

    Last Modified: 21 Nov 2024

    IBM Resilient SOAR 40 and earlier could disclose sensitive information by allowing a user to enumerate usernames.

    Published: 19 Mar 2021
    5.5
    Medium

    CVE-2021-27506

    Last Modified: 21 Nov 2024

    The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to DoS in case of parsing of malformed png files. This affect Netasq versions 9.1.0 to 9.1.11 and SNS versions 1.0.0 to 4.2.0. This issue is fixed in SNS 3.7.19, 3.11.7 and 4.2.1.

    Published: 19 Mar 2021
    5.3
    Medium

    CVE-2021-28090

    Last Modified: 21 Nov 2024

    Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka TROVE-2021-002.

    Published: 19 Mar 2021
    7.5
    High

    CVE-2021-28089

    Last Modified: 21 Nov 2024

    Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.

    Published: 19 Mar 2021