CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-22860

    Last Modified: 21 Nov 2024

    EIC e-document system does not perform completed identity verification for sorting and filtering personnel data. The vulnerability allows remote attacker to obtain users’ credential information without logging in the system, and further acquire the privileged permissions and execute arbitrary commends.

    Published: 17 Mar 2021
    9.8
    Critical

    CVE-2021-22859

    Last Modified: 21 Nov 2024

    The users’ data querying function of EIC e-document system does not filter the special characters which resulted in remote attackers can inject SQL syntax and execute arbitrary commands without privilege.

    Published: 17 Mar 2021
    7.5
    High

    CVE-2020-13924

    Last Modified: 13 Feb 2025

    In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directories to download files.

    Published: 17 Mar 2021
    7.8
    High

    CVE-2020-35519

    Last Modified: 21 Nov 2024

    An out-of-bounds (OOB) memory access flaw was found in x25_bind in net/x25/af_x25.c in the Linux kernel version v5.12-rc5. A bounds check failure allows a local attacker with a user account on the system to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

    Published: 17 Mar 2021
    7.8
    High

    CVE-2020-11309

    Last Modified: 21 Nov 2024

    Use after free in GPU driver while mapping the user memory to GPU memory due to improper check of referenced memory in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 17 Mar 2021
    6.8
    Medium

    CVE-2020-11305

    Last Modified: 21 Nov 2024

    Integer overflow in boot due to improper length check on arguments received in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music

    Published: 17 Mar 2021
    6.8
    Medium

    CVE-2020-11308

    Last Modified: 21 Nov 2024

    Buffer overflow occurs when trying to convert ASCII string to Unicode string if the actual size is more than required in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

    Published: 17 Mar 2021
    9.8
    Critical

    CVE-2020-11299

    Last Modified: 21 Nov 2024

    Buffer overflow can occur in video while playing the non-standard clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 17 Mar 2021
    7
    High

    CVE-2020-11290

    Last Modified: 21 Nov 2024

    Use after free condition in msm ioctl events due to race between the ioctl register and deregister events in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 17 Mar 2021
    7.8
    High

    CVE-2020-11228

    Last Modified: 21 Nov 2024

    Part of RPM region was not protected from xblSec itself due to improper policy and leads to unprivileged access in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

    Published: 17 Mar 2021
    6.4
    Medium

    CVE-2020-11230

    Last Modified: 21 Nov 2024

    Potential arbitrary memory corruption when the qseecom driver updates ion physical addresses in the buffer as it exposes a physical address to user land in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 17 Mar 2021
    9.8
    Critical

    CVE-2020-11227

    Last Modified: 21 Nov 2024

    Out of bound write while parsing RTT/TTY packet parsing due to lack of check of buffer size before copying into buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 17 Mar 2021
    7.5
    High

    CVE-2020-11226

    Last Modified: 21 Nov 2024

    Out of bound memory read in Data modem while unpacking data due to lack of offset length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 17 Mar 2021
    9.1
    Critical

    CVE-2020-11222

    Last Modified: 21 Nov 2024

    Buffer over read while processing MT SMS with maximum length due to improper length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile

    Published: 17 Mar 2021
    6.4
    Medium

    CVE-2020-11220

    Last Modified: 21 Nov 2024

    While processing storage SCM commands there is a time of check or time of use window where a pointer used could be invalid at a specific time while executing the storage SCM call in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

    Published: 17 Mar 2021
    5.5
    Medium

    CVE-2020-11221

    Last Modified: 21 Nov 2024

    Usage of syscall by non-secure entity can allow extraction of secure QTEE diagnostic information in clear text form due to insufficient checks in the syscall handler and leads to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 17 Mar 2021
    7.5
    High

    CVE-2020-11218

    Last Modified: 21 Nov 2024

    Denial of service in baseband when NW configures LTE betaOffset-RI-Index due to lack of data validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 17 Mar 2021
    9.8
    Critical

    CVE-2020-11192

    Last Modified: 21 Nov 2024

    Out of bound write while parsing SDP string due to missing check on null termination in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 17 Mar 2021
    5.5
    Medium

    CVE-2020-11199

    Last Modified: 21 Nov 2024

    HLOS to access EL3 stack canary by just mapping imem region due to Improper access control and can lead to information exposure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 17 Mar 2021
    9.1
    Critical

    CVE-2020-11190

    Last Modified: 21 Nov 2024

    Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 17 Mar 2021
    9.1
    Critical

    CVE-2020-11189

    Last Modified: 21 Nov 2024

    Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 17 Mar 2021
    5.5
    Medium

    CVE-2020-11186

    Last Modified: 21 Nov 2024

    Modem will enter into busy mode in an infinite loop while parsing histogram dimension due to improper validation of input received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile

    Published: 17 Mar 2021
    9.1
    Critical

    CVE-2020-11188

    Last Modified: 21 Nov 2024

    Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 17 Mar 2021
    9.1
    Critical

    CVE-2020-11171

    Last Modified: 21 Nov 2024

    Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 17 Mar 2021
    9.1
    Critical

    CVE-2020-11166

    Last Modified: 21 Nov 2024

    Potential out of bound read exception when UE receives unusually large number of padding octets in the beginning of ROHC header in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 17 Mar 2021
    7.8
    High

    CVE-2017-20002

    Last Modified: 21 Nov 2024

    The Debian shadow package before 1:4.5-1 for Shadow incorrectly lists pts/0 and pts/1 as physical terminals in /etc/securetty. This allows local users to login as password-less users even if they are connected by non-physical means such as SSH (hence bypassing PAM's nullok_secure configuration). This notably affects environments such as virtual machines automatically generated with a default blank root password, allowing all local users to escalate privileges.

    Published: 17 Mar 2021
    4.1
    Medium

    CVE-2019-3867

    Last Modified: 21 Nov 2024

    A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or delete a user's container repository. Red Hat Quay 2 and 3 are vulnerable to this issue.

    Published: 17 Mar 2021
    7.5
    High

    CVE-2019-14852

    Last Modified: 21 Nov 2024

    A flaw was found in 3scale’s APIcast gateway that enabled the TLS 1.0 protocol. An attacker could target traffic using this weaker protocol and break its encryption, gaining access to unauthorized information. Version shipped in Red Hat 3scale API Management Platform is vulnerable to this issue.

    Published: 17 Mar 2021
    5.5
    Medium

    CVE-2021-23215

    Last Modified: 21 Nov 2024

    An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR.

    Published: 17 Mar 2021
    8.8
    High

    CVE-2021-23169

    Last Modified: 21 Nov 2024

    A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3.0.1. An attacker could use this flaw to execute arbitrary code with the permissions of the user running the application compiled against OpenEXR.

    Published: 17 Mar 2021
    5.5
    Medium

    CVE-2021-26945

    Last Modified: 21 Nov 2024

    An integer overflow leading to a heap-buffer overflow was found in OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR.

    Published: 17 Mar 2021
    5.5
    Medium

    CVE-2021-26260

    Last Modified: 21 Nov 2024

    An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different flaw from CVE-2021-23215.

    Published: 17 Mar 2021
    —
    Unknown

    CVE-2019-3898

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 16 Mar 2021
    —
    Unknown

    CVE-2019-3853

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 16 Mar 2021
    —
    Unknown

    CVE-2019-3903

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 16 Mar 2021
    7.5
    High

    CVE-2021-3127

    Last Modified: 30 Mar 2026

    NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have Incorrect Access Control because Import Token bindings are mishandled.

    Published: 16 Mar 2021
    7.5
    High

    CVE-2021-28295

    Last Modified: 21 Nov 2024

    Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php, which may lead to database information disclosure.

    Published: 16 Mar 2021
    9.8
    Critical

    CVE-2021-28294

    Last Modified: 21 Nov 2024

    Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code execution (RCE).

    Published: 16 Mar 2021
    9.8
    Critical

    CVE-2021-28381

    Last Modified: 21 Nov 2024

    The vhs (aka VHS: Fluid ViewHelpers) extension before 5.1.1 for TYPO3 allows SQL injection via isLanguageViewHelper.

    Published: 16 Mar 2021
    5.4
    Medium

    CVE-2021-28380

    Last Modified: 21 Nov 2024

    The aimeos (aka Aimeos shop and e-commerce framework) extension before 19.10.12 and 20.x before 20.10.5 for TYPO3 allows XSS via a backend user account.

    Published: 16 Mar 2021
    7.5
    High

    CVE-2021-3445

    Last Modified: 21 Nov 2024

    A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability.

    Published: 16 Mar 2021
    9.1
    Critical

    CVE-2020-28899

    Last Modified: 21 Nov 2024

    The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote unauthenticated attackers (via crafted JSON action data to /cgi-bin/gui.cgi) to use all features provided by the router. Examples: change the router password, retrieve the Wi-Fi passphrase, send an SMS message, or modify the IP forwarding to access the internal network.

    Published: 16 Mar 2021
    6.1
    Medium

    CVE-2021-27938

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in the Silverstripe CMS 3 and 4 version of the symbiote/silverstripe-queuedjobs module. A Cross Site Scripting vulnerability allows an attacker to inject an arbitrary payload in the CreateQueuedJobTask dev task via a specially crafted URL.

    Published: 16 Mar 2021
    9.8
    Critical

    CVE-2021-25916

    Last Modified: 30 Apr 2025

    Prototype pollution vulnerability in 'patchmerge' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.

    Published: 16 Mar 2021
    2.3
    Low

    CVE-2021-22887

    Last Modified: 21 Nov 2024

    A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Before an attacker can compromise the BIOS, they must exploit the device.

    Published: 16 Mar 2021
    9.8
    Critical

    CVE-2020-24264

    Last Modified: 21 Nov 2024

    Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution. The restriction checks for bind mounts are applied only on the client-side and not the server-side, which can lead to spawning a container with bind mount. Once such a container is spawned, it can be leveraged to break out of the container leading to complete Docker host machine takeover.

    Published: 16 Mar 2021
    8.8
    High

    CVE-2020-24263

    Last Modified: 21 Nov 2024

    Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution. A non-admin user is allowed to spawn new containers with critical capabilities such as SYS_MODULE, which can be used to take over the Docker host.

    Published: 16 Mar 2021
    8.8
    High

    CVE-2021-21193

    Last Modified: 24 Oct 2025

    Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 16 Mar 2021
    8.8
    High

    CVE-2021-21192

    Last Modified: 21 Nov 2024

    Heap buffer overflow in tab groups in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 16 Mar 2021
    8.8
    High

    CVE-2021-21191

    Last Modified: 21 Nov 2024

    Use after free in WebRTC in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 16 Mar 2021