CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2016-20009

    Last Modified: 21 Nov 2024

    A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 11 Mar 2021
    9.1
    Critical

    CVE-2021-28154

    Last Modified: 21 Nov 2024

    Camunda Modeler (aka camunda-modeler) through 4.6.0 allows arbitrary file access. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which manipulates the readFile and writeFile APIs. NOTE: the vendor states "The way we secured the app is that it does not allow any remote scripts to be opened, no unsafe scripts to be evaluated, no remote sites to be browsed.

    Published: 11 Mar 2021
    8.8
    High

    CVE-2020-24984

    Last Modified: 21 Nov 2024

    An issue was discovered in Quadbase EspressReports ES 7 Update 9. It allows CSRF, whereby an attacker may be able to trick an authenticated admin level user into uploading malicious files to the web server.

    Published: 11 Mar 2021
    7.8
    High

    CVE-2021-22709

    Last Modified: 21 Nov 2024

    A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in loss of data or remote code execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.

    Published: 11 Mar 2021
    7.8
    High

    CVE-2021-22710

    Last Modified: 21 Nov 2024

    A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could cause remote code execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.

    Published: 11 Mar 2021
    7.8
    High

    CVE-2021-22712

    Last Modified: 21 Nov 2024

    A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in arbitrary read or write conditions when malicious CGF (Configuration Group File) file is imported to IGSS Definition due to an unchecked pointer address.

    Published: 11 Mar 2021
    7.5
    High

    CVE-2020-36277

    Last Modified: 21 Nov 2024

    Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in pixconv.c.

    Published: 11 Mar 2021
    7.8
    High

    CVE-2021-22711

    Last Modified: 21 Nov 2024

    A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in arbitrary read or write conditions when malicious CGF (Configuration Group File) file is imported to IGSS Definition due to missing validation of input data.

    Published: 11 Mar 2021
    7.5
    High

    CVE-2021-22713

    Last Modified: 29 May 2026

    A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION8650, ION8800, ION7650, ION7700/73xx, and ION83xx/84xx/85xx/8600 (see security notifcation for affected versions), which could cause the meter to reboot.

    Published: 11 Mar 2021
    9.8
    Critical

    CVE-2021-22714

    Last Modified: 21 Nov 2024

    A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION7400, PM8000 and ION9000 (All versions prior to V3.0.0), which could cause the meter to reboot or allow for remote code execution.

    Published: 11 Mar 2021
    9.8
    Critical

    CVE-2020-29045

    Last Modified: 21 Nov 2024

    The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm_cart cookie in load_cart_from_cookie in includes/class-cart-manager.php.

    Published: 11 Mar 2021
    6.5
    Medium

    CVE-2020-14989

    Last Modified: 21 Nov 2024

    An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows CSRF if the attacker uses GET where POST was intended.

    Published: 11 Mar 2021
    5.4
    Medium

    CVE-2020-14988

    Last Modified: 21 Nov 2024

    An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows XSS in the login page via the loginmessage parameter, the text editor via the src attribute of HTML elements, the translations menu via the foldername parameter, the author page via the link URL, or the upload image functionality via an SVG document containing JavaScript.

    Published: 11 Mar 2021
    7.2
    High

    CVE-2020-14987

    Last Modified: 21 Nov 2024

    An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows remote attackers to execute arbitrary code because there is a mishandling of the capability for administrators to write and run Groovy scripts within the updater editor. An attacker must use an AST transforming annotation such as @Grab.

    Published: 11 Mar 2021
    9.8
    Critical

    CVE-2021-28141

    Last Modified: 30 Jun 2025

    An issue was discovered in Progress Telerik UI for ASP.NET AJAX 2021.1.224. It allows unauthorized access to MicrosoftAjax.js through the Telerik.Web.UI.WebResource.axd file. This may allow the attacker to gain unauthorized access to the server and execute code. To exploit, one must use the parameter _TSM_HiddenField_ and inject a command at the end of the URI. NOTE: the vendor states that this is not a vulnerability. The request's output does not indicate that a "true" command was executed on the server, and the request's output does not leak any private source code or data from the server

    Published: 11 Mar 2021
    5.4
    Medium

    CVE-2021-28088

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) in modules/content/admin/content.php in ImpressCMS profile 1.4.2 allows remote attackers to inject arbitrary web script or HTML parameters through the "Display Name" field.

    Published: 11 Mar 2021
    5.4
    Medium

    CVE-2021-27679

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Navigation in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the field name.

    Published: 11 Mar 2021
    5.4
    Medium

    CVE-2021-27678

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Snippets in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the field name.

    Published: 11 Mar 2021
    5.4
    Medium

    CVE-2021-27677

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Galleries in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the field name.

    Published: 11 Mar 2021
    5.4
    Medium

    CVE-2021-26776

    Last Modified: 21 Nov 2024

    CSZ CMS 1.2.9 is affected by a cross-site scripting (XSS) vulnerability in multiple pages through the field name.

    Published: 11 Mar 2021
    8.8
    High

    CVE-2021-28144

    Last Modified: 21 Nov 2024

    prog.cgi on D-Link DIR-3060 devices before 1.11b04 HF2 allows remote authenticated users to inject arbitrary commands in an admin or root context because SetVirtualServerSettings calls CheckArpTables, which calls popen unsafely.

    Published: 11 Mar 2021
    7.8
    High

    CVE-2021-27077

    Last Modified: 19 Aug 2026

    Windows Win32k Elevation of Privilege Vulnerability

    Published: 11 Mar 2021
    8.8
    High

    CVE-2021-27076

    Last Modified: 19 Aug 2026

    Microsoft SharePoint Server Remote Code Execution Vulnerability

    Published: 11 Mar 2021
    6.8
    Medium

    CVE-2021-27075

    Last Modified: 19 Aug 2026

    Azure Virtual Machine Information Disclosure Vulnerability

    Published: 11 Mar 2021
    6.2
    Medium

    CVE-2021-27074

    Last Modified: 19 Aug 2026

    Azure Sphere Unsigned Code Execution Vulnerability

    Published: 11 Mar 2021
    7.3
    High

    CVE-2021-27070

    Last Modified: 19 Aug 2026

    Windows 10 Update Assistant Elevation of Privilege Vulnerability

    Published: 11 Mar 2021
    4.3
    Medium

    CVE-2021-27066

    Last Modified: 19 Aug 2026

    Windows Admin Center Security Feature Bypass Vulnerability

    Published: 11 Mar 2021
    7.5
    High

    CVE-2021-27063

    Last Modified: 19 Aug 2026

    Windows DNS Server Denial of Service Vulnerability

    Published: 11 Mar 2021
    7.8
    High

    CVE-2021-27062

    Last Modified: 19 Aug 2026

    HEVC Video Extensions Remote Code Execution Vulnerability

    Published: 11 Mar 2021
    7.8
    High

    CVE-2021-27061

    Last Modified: 19 Aug 2026

    HEVC Video Extensions Remote Code Execution Vulnerability

    Published: 11 Mar 2021
    7.8
    High

    CVE-2021-27060

    Last Modified: 19 Aug 2026

    Visual Studio Code Remote Code Execution Vulnerability

    Published: 11 Mar 2021
    7.6
    High

    CVE-2021-27059

    Last Modified: 19 Aug 2026

    Microsoft Office Remote Code Execution Vulnerability

    Published: 11 Mar 2021
    7.8
    High

    CVE-2021-27058

    Last Modified: 19 Aug 2026

    Microsoft Office ClickToRun Remote Code Execution Vulnerability

    Published: 11 Mar 2021
    7.8
    High

    CVE-2021-27057

    Last Modified: 19 Aug 2026

    Microsoft Office Remote Code Execution Vulnerability

    Published: 11 Mar 2021
    7.8
    High

    CVE-2021-27056

    Last Modified: 19 Aug 2026

    Microsoft PowerPoint Remote Code Execution Vulnerability

    Published: 11 Mar 2021
    7
    High

    CVE-2021-27055

    Last Modified: 19 Aug 2026

    Microsoft Visio Security Feature Bypass Vulnerability

    Published: 11 Mar 2021
    9.3
    Critical

    CVE-2021-27080

    Last Modified: 19 Aug 2026

    Azure Sphere Unsigned Code Execution Vulnerability

    Published: 11 Mar 2021
    7.8
    High

    CVE-2021-27081

    Last Modified: 19 Aug 2026

    Visual Studio Code ESLint Extension Remote Code Execution Vulnerability

    Published: 11 Mar 2021
    7.8
    High

    CVE-2021-27082

    Last Modified: 19 Aug 2026

    Quantum Development Kit for Visual Studio Code Remote Code Execution Vulnerability

    Published: 11 Mar 2021
    7.8
    High

    CVE-2021-27083

    Last Modified: 19 Aug 2026

    Remote Development Extension for Visual Studio Code Remote Code Execution Vulnerability

    Published: 11 Mar 2021
    7.8
    High

    CVE-2021-27084

    Last Modified: 19 Aug 2026

    Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability

    Published: 11 Mar 2021
    8.8
    High

    CVE-2021-27085

    Last Modified: 19 Aug 2026

    Internet Explorer Remote Code Execution Vulnerability

    Published: 11 Mar 2021
    7.8
    High

    CVE-2021-27054

    Last Modified: 19 Aug 2026

    Microsoft Excel Remote Code Execution Vulnerability

    Published: 11 Mar 2021
    7.8
    High

    CVE-2021-27053

    Last Modified: 19 Aug 2026

    Microsoft Excel Remote Code Execution Vulnerability

    Published: 11 Mar 2021
    5.3
    Medium

    CVE-2021-27052

    Last Modified: 19 Aug 2026

    Microsoft SharePoint Server Information Disclosure Vulnerability

    Published: 11 Mar 2021
    7.8
    High

    CVE-2021-27051

    Last Modified: 19 Aug 2026

    HEVC Video Extensions Remote Code Execution Vulnerability

    Published: 11 Mar 2021
    7.8
    High

    CVE-2021-27050

    Last Modified: 19 Aug 2026

    HEVC Video Extensions Remote Code Execution Vulnerability

    Published: 11 Mar 2021
    7.8
    High

    CVE-2021-27049

    Last Modified: 19 Aug 2026

    HEVC Video Extensions Remote Code Execution Vulnerability

    Published: 11 Mar 2021
    7.8
    High

    CVE-2021-27048

    Last Modified: 19 Aug 2026

    HEVC Video Extensions Remote Code Execution Vulnerability

    Published: 11 Mar 2021
    7.8
    High

    CVE-2021-27047

    Last Modified: 19 Aug 2026

    HEVC Video Extensions Remote Code Execution Vulnerability

    Published: 11 Mar 2021