CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2020-6578

    Last Modified: 21 Nov 2024

    Zen Cart 1.5.6d allows reflected XSS via the main_page parameter to includes/templates/template_default/common/tpl_main_page.php or includes/templates/responsive_classic/common/tpl_main_page.php.

    Published: 19 Mar 2021
    9.8
    Critical

    CVE-2020-6577

    Last Modified: 21 Nov 2024

    The IT-Recht Kanzlei plugin in Zen Cart 1.5.6c (German edition) allows itrk-api.php rechtstext_language SQL Injection.

    Published: 19 Mar 2021
    6.1
    Medium

    CVE-2021-28126

    Last Modified: 21 Nov 2024

    index.jsp in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a Stored cross-site scripting (XSS) vulnerability

    Published: 19 Mar 2021
    7.5
    High

    CVE-2021-28110

    Last Modified: 21 Nov 2024

    /exec in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a vulnerability in its XML parser.

    Published: 19 Mar 2021
    6.1
    Medium

    CVE-2021-28109

    Last Modified: 21 Nov 2024

    TranzWare (POI) FIMI before 4.2.20.4.2 allows login_tw.php reflected Cross-Site Scripting (XSS).

    Published: 19 Mar 2021
    5.4
    Medium

    CVE-2021-3327

    Last Modified: 21 Nov 2024

    Ovation Dynamic Content 1.10.1 for Elementor allows XSS via the post_title parameter.

    Published: 19 Mar 2021
    8.1
    High

    CVE-2021-27221

    Last Modified: 21 Nov 2024

    MikroTik RouterOS 6.47.9 allows remote authenticated ftp users to create or overwrite arbitrary .rsc files via the /export command. NOTE: the vendor's position is that this is intended behavior because of how user policies work

    Published: 19 Mar 2021
    4.7
    Medium

    CVE-2020-27170

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka CID-f232326f6966. This affects pointer types that do not define a ptr_limit.

    Published: 19 Mar 2021
    5.5
    Medium

    CVE-2021-27906

    Last Modified: 13 Feb 2025

    A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.

    Published: 19 Mar 2021
    6
    Medium

    CVE-2020-27171

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c has an off-by-one error (with a resultant integer underflow) affecting out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka CID-10d2bb2e6b1d.

    Published: 19 Mar 2021
    5.3
    Medium

    CVE-2021-30158

    Last Modified: 21 Nov 2024

    An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. This has security relevance because a blocked user might have accidentally shared a token, or might know that a token has been compromised, and yet is not able to block any potential future use of the token by an unauthorized party.

    Published: 19 Mar 2021
    5.5
    Medium

    CVE-2021-27807

    Last Modified: 13 Feb 2025

    A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.

    Published: 19 Mar 2021
    7.2
    High

    CVE-2021-27928

    Last Modified: 21 Nov 2024

    A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL. An untrusted search path leads to eval injection, in which a database SUPER user can execute OS commands after modifying wsrep_provider and wsrep_notify_cmd. NOTE: this does not affect an Oracle product.

    Published: 19 Mar 2021
    5.5
    Medium

    CVE-2021-29649

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.11.11. The user mode driver (UMD) has a copy_process() memory leak, related to a lack of cleanup steps in kernel/usermode_driver.c and kernel/bpf/preload/bpf_preload_kern.c, aka CID-f60a85cad677.

    Published: 19 Mar 2021
    6.3
    Medium

    CVE-2021-21384

    Last Modified: 21 Nov 2024

    shescape is a simple shell escape package for JavaScript. In shescape before version 1.1.3, anyone using _Shescape_ to defend against shell injection may still be vulnerable against shell injection if the attacker manages to insert a into the payload. For an example see the referenced GitHub Security Advisory. The problem has been patched in version 1.1.3. No further changes are required.

    Published: 18 Mar 2021
    6.5
    Medium

    CVE-2021-28653

    Last Modified: 21 Nov 2024

    The iOS and macOS apps before 1.4.1 for the Western Digital G-Technology ArmorLock NVMe SSD store keys insecurely. They choose a non-preferred storage mechanism if the device has Secure Enclave support but lacks biometric authentication hardware.

    Published: 18 Mar 2021
    9.8
    Critical

    CVE-2021-26275

    Last Modified: 21 Nov 2024

    The eslint-fixer package through 0.1.5 for Node.js allows command injection via shell metacharacters to the fix function. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. The ozum/eslint-fixer GitHub repository has been intentionally deleted

    Published: 18 Mar 2021
    6.1
    Medium

    CVE-2021-27436

    Last Modified: 21 Nov 2024

    WebAccess/SCADA Versions 9.0 and prior is vulnerable to cross-site scripting, which may allow an attacker to send malicious JavaScript code to an unsuspecting user, which could result in hijacking of the user’s cookie/session tokens, redirecting the user to a malicious webpage and performing unintended browser actions.

    Published: 18 Mar 2021
    5.3
    Medium

    CVE-2020-36144

    Last Modified: 21 Nov 2024

    Redash 8.0.0 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided template since the username included in the search filter lacks sanitization.

    Published: 18 Mar 2021
    7.8
    High

    CVE-2020-9367

    Last Modified: 21 Nov 2024

    The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 10.0.486 is vulnerable to DLL Hijacking: dcinventory.exe and dcconfig.exe try to load CSUNSAPI.dll without supplying the complete path. The issue is aggravated because this DLL is missing from the installation, thus making it possible to hijack the DLL and subsequently inject code, leading to an escalation of privilege to NT AUTHORITY\SYSTEM.

    Published: 18 Mar 2021
    7.8
    High

    CVE-2020-26886

    Last Modified: 21 Nov 2024

    Softaculous before 5.5.7 is affected by a code execution vulnerability because of External Initialization of Trusted Variables or Data Stores. This leads to privilege escalation on the local host.

    Published: 18 Mar 2021
    5.3
    Medium

    CVE-2021-25764

    Last Modified: 21 Nov 2024

    In JetBrains PhpStorm before 2020.3, source code could be added to debug logs.

    Published: 18 Mar 2021
    7.5
    High

    CVE-2020-26797

    Last Modified: 21 Nov 2024

    Mediainfo before version 20.08 has a heap buffer overflow vulnerability via MediaInfoLib::File_Gxf::ChooseParser_ChannelGrouping.

    Published: 18 Mar 2021
    —
    Unknown

    CVE-2019-14908

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 18 Mar 2021
    —
    Unknown

    CVE-2019-14903

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 18 Mar 2021
    6.1
    Medium

    CVE-2021-28160

    Last Modified: 21 Nov 2024

    Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) suffers from a reflected XSS vulnerability due to unsanitized SSID value when the latter is displayed in the /repeater.html page ("Repeater Wizard" homepage section).

    Published: 18 Mar 2021
    7.2
    High

    CVE-2021-1287

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition on the affected device.

    Published: 18 Mar 2021
    —
    Unknown

    CVE-2019-14848

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 18 Mar 2021
    5.3
    Medium

    CVE-2021-27656

    Last Modified: 21 Nov 2024

    A vulnerability in exacqVision Web Service 20.12.2.0 and prior could allow an unauthenticated attacker to view system-level information about the exacqVision Web Service and the operating system.

    Published: 18 Mar 2021
    10
    Critical

    CVE-2020-14516

    Last Modified: 21 Nov 2024

    In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 hashing algorithm with FactoryTalk Services Platform that prevents the user password from being hashed properly.

    Published: 18 Mar 2021
    7.6
    High

    CVE-2021-21383

    Last Modified: 21 Nov 2024

    Wiki.js an open-source wiki app built on Node.js. Wiki.js before version 2.5.191 is vulnerable to stored cross-site scripting through mustache expressions in code blocks. This vulnerability exists due to mustache expressions being parsed by Vue during content injection even though it is contained within a `<pre>` element. By creating a crafted wiki page, a malicious Wiki.js user may stage a stored cross-site scripting attack. This allows the attacker to execute malicious JavaScript when the page is viewed by other users. For an example see referenced GitHub Security Advisory. Commit 5ffa189383dd716f12b56b8cae2ba0d075996cf1 fixes this vulnerability by adding the v-pre directive to all `<pre>` tags during the render.

    Published: 18 Mar 2021
    7.8
    High

    CVE-2021-22665

    Last Modified: 21 Nov 2024

    Rockwell Automation DriveTools SP v5.13 and below and Drives AOP v4.12 and below both contain a vulnerability that a local attacker with limited privileges may be able to exploit resulting in privilege escalation and complete control of the system.

    Published: 18 Mar 2021
    7.8
    High

    CVE-2020-26155

    Last Modified: 21 Nov 2024

    Multiple files and folders in Utimaco SecurityServer 4.20.0.4 and 4.31.1.0. are installed with Read/Write permissions for authenticated users, which allows for binaries to be manipulated by non-administrator users. Additionally, entries are made to the PATH environment variable which, in conjunction with these weak permissions, could enable an attacker to perform a DLL hijacking attack.

    Published: 18 Mar 2021
    4.3
    Medium

    CVE-2021-26216

    Last Modified: 21 Nov 2024

    SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditFolder.php.

    Published: 18 Mar 2021
    4.3
    Medium

    CVE-2021-26215

    Last Modified: 21 Nov 2024

    SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditDocument.php.

    Published: 18 Mar 2021
    5.4
    Medium

    CVE-2021-28145

    Last Modified: 21 Nov 2024

    Concrete CMS (formerly concrete5) before 8.5.5 allows remote authenticated users to conduct XSS attacks via a crafted survey block. This requires at least Editor privileges.

    Published: 18 Mar 2021
    7.8
    High

    CVE-2021-28791

    Last Modified: 21 Nov 2024

    The unofficial SwiftFormat extension before 1.3.7 for Visual Studio Code allows remote attackers to execute arbitrary code by constructing a malicious workspace with a crafted swiftformat.path configuration value that triggers execution upon opening the workspace.

    Published: 18 Mar 2021
    7.8
    High

    CVE-2021-28789

    Last Modified: 21 Nov 2024

    The unofficial apple/swift-format extension before 1.1.2 for Visual Studio Code allows remote attackers to execute arbitrary code by constructing a malicious workspace with a crafted apple-swift-format.path configuration value that triggers execution upon opening the workspace.

    Published: 18 Mar 2021
    6.1
    Medium

    CVE-2021-28796

    Last Modified: 21 Nov 2024

    Increments Qiita::Markdown before 0.33.0 allows XSS in transformers.

    Published: 18 Mar 2021
    9.8
    Critical

    CVE-2021-28794

    Last Modified: 21 Nov 2024

    The unofficial ShellCheck extension before 0.13.4 for Visual Studio Code mishandles shellcheck.executablePath.

    Published: 18 Mar 2021
    7.8
    High

    CVE-2021-28792

    Last Modified: 21 Nov 2024

    The unofficial Swift Development Environment extension before 2.12.1 for Visual Studio Code allows remote attackers to execute arbitrary code by constructing a malicious workspace with a crafted sourcekit-lsp.serverPath, swift.languageServerPath, swift.path.sourcekite, swift.path.sourcekiteDockerMode, swift.path.swift_driver_bin, or swift.path.shell configuration value that triggers execution upon opening the workspace.

    Published: 18 Mar 2021
    7.8
    High

    CVE-2021-28790

    Last Modified: 21 Nov 2024

    The unofficial SwiftLint extension before 1.4.5 for Visual Studio Code allows remote attackers to execute arbitrary code by constructing a malicious workspace with a crafted swiftlint.path configuration value that triggers execution upon opening the workspace.

    Published: 18 Mar 2021
    7.2
    High

    CVE-2021-24142

    Last Modified: 21 Nov 2024

    Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise its "Redirect From" column when importing a CSV file, allowing high privilege users to perform SQL injections.

    Published: 18 Mar 2021
    7.5
    High

    CVE-2021-24146

    Last Modified: 21 Nov 2024

    Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example.

    Published: 18 Mar 2021
    8.8
    High

    CVE-2021-24143

    Last Modified: 21 Nov 2024

    Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, allowing accounts with post permission, such as author, to perform SQL injections.

    Published: 18 Mar 2021
    7.8
    High

    CVE-2021-24144

    Last Modified: 21 Nov 2024

    Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability that lets remote attackers inject arbitrary formulas into CSV files.

    Published: 18 Mar 2021
    9.8
    Critical

    CVE-2021-24148

    Last Modified: 21 Nov 2024

    A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email address.

    Published: 18 Mar 2021
    7.2
    High

    CVE-2021-24145

    Last Modified: 21 Nov 2024

    Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing PHP ones to be uploaded by administrator by using the 'text/csv' content-type in the request.

    Published: 18 Mar 2021
    5.4
    Medium

    CVE-2021-24147

    Last Modified: 21 Nov 2024

    Unvalidated input and lack of output encoding in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not sanitise the mic_comment field (Notes on time) when adding/editing an event, allowing users with privilege as low as author to add events with a Cross-Site Scripting payload in them, which will be triggered in the frontend when viewing the event.

    Published: 18 Mar 2021
    8.8
    High

    CVE-2021-24149

    Last Modified: 21 Nov 2024

    Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[post_id] POST parameter in the mec_fes_form AJAX action when logged in as an author+, leading to an authenticated SQL Injection issue.

    Published: 18 Mar 2021