CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-27817

    Last Modified: 21 Nov 2024

    A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar where the suffix is JPG, which is uploaded after modifying the phar suffix.

    Published: 15 Mar 2021
    9.8
    Critical

    CVE-2020-24877

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access restriction bypass.

    Published: 15 Mar 2021
    5.6
    Medium

    CVE-2021-23355

    Last Modified: 21 Nov 2024

    This affects all versions of package ps-kill. If (attacker-controlled) user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization in the index.js file. PoC (provided by reporter): var ps_kill = require('ps-kill'); ps_kill.kill('$(touch success)',function(){});

    Published: 15 Mar 2021
    5.6
    Medium

    CVE-2021-23356

    Last Modified: 21 Nov 2024

    This affects all versions of package kill-process-by-name. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization in the index.js file.

    Published: 15 Mar 2021
    6.1
    Medium

    CVE-2021-27695

    Last Modified: 21 Nov 2024

    Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbitrary web script or HTML via any "Add" sections, such as Add Card Building & Floor, or others in the Name and Code Parameters.

    Published: 15 Mar 2021
    4.3
    Medium

    CVE-2021-20440

    Last Modified: 21 Nov 2024

    IBM API Connect 10.0.0.0, and 2018.4.1.0 through 2018.4.1.13 does not restrict member registration to the intended recepient. An attacker who is a valid user in the user registry used by API Manager can use a stolen invitation link and register themselves as a member of an API provider organization. IBM X-Force ID: 196536.

    Published: 15 Mar 2021
    7.3
    High

    CVE-2020-4184

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.2 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 174802..

    Published: 15 Mar 2021
    6.5
    Medium

    CVE-2021-3167

    Last Modified: 21 Nov 2024

    In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster server logs.

    Published: 15 Mar 2021
    6.1
    Medium

    CVE-2021-26924

    Last Modified: 21 Nov 2024

    An issue was discovered in Argo CD before 1.8.4. Browser XSS protection is not activated due to the missing XSS protection header.

    Published: 15 Mar 2021
    7.5
    High

    CVE-2021-26923

    Last Modified: 21 Nov 2024

    An issue was discovered in Argo CD before 1.8.4. Accessing the endpoint /api/version leaks internal information for the system, and this endpoint is not protected with authentication.

    Published: 15 Mar 2021
    7.8
    High

    CVE-2021-27892

    Last Modified: 21 Nov 2024

    SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation. ConnectSecure on Windows is affected.

    Published: 15 Mar 2021
    8.8
    High

    CVE-2021-27891

    Last Modified: 21 Nov 2024

    SSH Tectia Client and Server before 6.4.19 on Windows have weak key generation. ConnectSecure on Windows is affected.

    Published: 15 Mar 2021
    7
    High

    CVE-2021-27893

    Last Modified: 21 Nov 2024

    SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation in nonstandard conditions. ConnectSecure on Windows is affected.

    Published: 15 Mar 2021
    6.8
    Medium

    CVE-2021-27208

    Last Modified: 21 Nov 2024

    When booting a Zync-7000 SOC device from nand flash memory, the nand driver in the ROM does not validate the inputs when reading in any parameters in the nand’s parameter page. IF a field read in from the parameter page is too large, this causes a buffer overflow that could lead to arbitrary code execution. Physical access and modification of the board assembly on which the Zynq-7000 SoC device mounted is needed to replace the original NAND flash memory with a NAND flash emulation device for this attack to be successful.

    Published: 15 Mar 2021
    9.8
    Critical

    CVE-2020-35358

    Last Modified: 21 Nov 2024

    DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability. On changing a password, both sessions using the changed password and old sessions in any other browser or device do not expire and remain active. Such flaws frequently give attackers unauthorized access to some system data or functionality.

    Published: 15 Mar 2021
    7.5
    High

    CVE-2021-27576

    Last Modified: 13 Feb 2025

    If was found that the NetTest web service can be used to overload the bandwidth of a Apache OpenMeetings server. This issue was addressed in Apache OpenMeetings 6.0.0

    Published: 15 Mar 2021
    8.8
    High

    CVE-2021-28379

    Last Modified: 21 Nov 2024

    web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different origin.

    Published: 15 Mar 2021
    3.7
    Low

    CVE-2021-28378

    Last Modified: 21 Nov 2024

    Gitea 1.12.x and 1.13.x before 1.13.4 allows XSS via certain issue data in some situations.

    Published: 15 Mar 2021
    7.5
    High

    CVE-2021-28374

    Last Modified: 21 Nov 2024

    The Debian courier-authlib package before 0.71.1-2 for Courier Authentication Library creates a /run/courier/authdaemon directory with weak permissions, allowing an attacker to read user information. This may include a cleartext password in some configurations. In general, it includes the user's existence, uid and gids, home and/or Maildir directory, quota, and some type of password information (such as a hash).

    Published: 15 Mar 2021
    6.5
    Medium

    CVE-2021-28363

    Last Modified: 21 Nov 2024

    The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if an SSLContext isn't given via proxy_config) doesn't verify the hostname of the certificate. This means certificates for different servers that still validate properly with the default urllib3 SSLContext will be silently accepted.

    Published: 15 Mar 2021
    7.8
    High

    CVE-2021-28375

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not prevent user applications from sending kernel RPC messages, aka CID-20c40794eb85. This is a related issue to CVE-2019-2308.

    Published: 15 Mar 2021
    5.5
    Medium

    CVE-2021-29646

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.11.11. tipc_nl_retrieve_key in net/tipc/node.c does not properly validate certain data sizes, aka CID-0217ed2848e8.

    Published: 15 Mar 2021
    9.8
    Critical

    CVE-2021-3466

    Last Modified: 21 Nov 2024

    A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to write arbitrary data in an application that uses libmicrohttpd. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Only version 0.9.70 is vulnerable.

    Published: 15 Mar 2021
    5.3
    Medium

    CVE-2021-3474

    Last Modified: 21 Nov 2024

    There's a flaw in OpenEXR in versions before 3.0.0-beta. A crafted input file that is processed by OpenEXR could cause a shift overflow in the FastHufDecoder, potentially leading to problems with application availability.

    Published: 15 Mar 2021
    5.3
    Medium

    CVE-2021-3475

    Last Modified: 21 Nov 2024

    There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker who can submit a crafted file to be processed by OpenEXR could cause an integer overflow, potentially leading to problems with application availability.

    Published: 15 Mar 2021
    5.5
    Medium

    CVE-2021-29650

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.11.11. The netfilter subsystem allows attackers to cause a denial of service (panic) because net/netfilter/x_tables.c and include/linux/netfilter/x_tables.h lack a full memory barrier upon the assignment of a new table value, aka CID-175e476b8cdf.

    Published: 15 Mar 2021
    7.8
    High

    CVE-2021-3497

    Last Modified: 17 Mar 2026

    GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska files.

    Published: 15 Mar 2021
    7.8
    High

    CVE-2021-3498

    Last Modified: 17 Mar 2026

    GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files.

    Published: 15 Mar 2021
    5.5
    Medium

    CVE-2021-3522

    Last Modified: 28 May 2026

    GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.

    Published: 15 Mar 2021
    9.8
    Critical

    CVE-2021-28834

    Last Modified: 21 Nov 2024

    Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.

    Published: 14 Mar 2021
    5.5
    Medium

    CVE-2021-29647

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.11.11. qrtr_recvmsg in net/qrtr/qrtr.c allows attackers to obtain sensitive information from kernel memory because of a partially uninitialized data structure, aka CID-50535249f624.

    Published: 14 Mar 2021
    7.8
    High

    CVE-2021-29266

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.11.9. drivers/vhost/vdpa.c has a use-after-free because v->config_ctx has an invalid value upon re-opening a character device, aka CID-f6bbf0010ba0.

    Published: 14 Mar 2021
    5.3
    Medium

    CVE-2021-30004

    Last Modified: 7 Jul 2026

    In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c.

    Published: 14 Mar 2021
    7.5
    High

    CVE-2021-28373

    Last Modified: 21 Nov 2024

    The auth_internal plugin in Tiny Tiny RSS (aka tt-rss) before 2021-03-12 allows an attacker to log in via the OTP code without a valid password. NOTE: this issue only affected the git master branch for a short time. However, all end users are explicitly directed to use the git master branch in production. Semantic version numbers such as 21.03 appear to exist, but are automatically generated from the year and month. They are not releases.

    Published: 13 Mar 2021
    8.8
    High

    CVE-2020-35682

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).

    Published: 13 Mar 2021
    4.9
    Medium

    CVE-2021-20018

    Last Modified: 21 Nov 2024

    A post-authenticated vulnerability in SonicWall SMA100 allows an attacker to export the configuration file to the specified email address. This vulnerability impacts SMA100 version 10.2.0.5 and earlier.

    Published: 13 Mar 2021
    8.8
    High

    CVE-2021-20017

    Last Modified: 21 Nov 2024

    A post-authenticated command injection vulnerability in SonicWall SMA100 allows an authenticated attacker to execute OS commands as a 'nobody' user. This vulnerability impacts SMA100 version 10.2.0.5 and earlier.

    Published: 13 Mar 2021
    6.1
    Medium

    CVE-2021-28162

    Last Modified: 21 Nov 2024

    In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.

    Published: 12 Mar 2021
    6.1
    Medium

    CVE-2021-28161

    Last Modified: 21 Nov 2024

    In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript code can be injected.

    Published: 12 Mar 2021
    7.8
    High

    CVE-2021-21518

    Last Modified: 21 Nov 2024

    Dell SupportAssist Client for Consumer PCs versions 3.7.x, 3.6.x, 3.4.x, 3.3.x, Dell SupportAssist Client for Business PCs versions 2.0.x, 2.1.x, 2.2.x, and Dell SupportAssist Client ProManage 1.x contain a DLL injection vulnerability in the Costura Fody plugin. A local user with low privileges could potentially exploit this vulnerability, leading to the execution of arbitrary executable on the operating system with SYSTEM privileges.

    Published: 12 Mar 2021
    7.8
    High

    CVE-2021-21082

    Last Modified: 23 Apr 2025

    Adobe Photoshop versions 21.2.5 (and earlier) and 22.2 (and earlier) are affected by a Memory Corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Mar 2021
    6.5
    Medium

    CVE-2021-21078

    Last Modified: 23 Apr 2025

    Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by an Unquoted Service Path vulnerability in CCXProcess that could allow an attacker to achieve arbitrary code execution in the process of the current user. Exploitation of this issue requires user interaction

    Published: 12 Mar 2021
    7.1
    High

    CVE-2021-21074

    Last Modified: 23 Apr 2025

    Adobe Animate version 21.0.3 (and earlier) is affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Mar 2021
    7.8
    High

    CVE-2021-21056

    Last Modified: 23 Apr 2025

    Adobe Framemaker version 2020.0.1 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Mar 2021
    7.8
    High

    CVE-2021-21085

    Last Modified: 23 Apr 2025

    Adobe Connect version 11.0.7 (and earlier) is affected by an Input Validation vulnerability in the export feature. An attacker could exploit this vulnerability by injecting a payload into an online event form and achieve code execution if the victim exports and opens the data on their local machine.

    Published: 12 Mar 2021
    7.8
    High

    CVE-2021-21071

    Last Modified: 23 Apr 2025

    Adobe Animate version 21.0.3 (and earlier) is affected by a Memory Corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Mar 2021
    7.8
    High

    CVE-2021-21067

    Last Modified: 23 Apr 2025

    Adobe Photoshop versions 21.2.5 (and earlier) and 22.2 (and earlier) are affected by an Out-of-bounds Write vulnerability in the CoolType library. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Mar 2021
    7.1
    High

    CVE-2021-21075

    Last Modified: 23 Apr 2025

    Adobe Animate version 21.0.3 (and earlier) is affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Mar 2021
    6.1
    Medium

    CVE-2021-21080

    Last Modified: 23 Apr 2025

    Adobe Connect version 11.0.7 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious JavaScript content that may be executed within the context of the victim's browser when they browse to the page containing the vulnerable field.

    Published: 12 Mar 2021
    7.1
    High

    CVE-2021-21076

    Last Modified: 23 Apr 2025

    Adobe Animate version 21.0.3 (and earlier) is affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Mar 2021