CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-2021-24104

    Last Modified: 19 Aug 2026

    Microsoft SharePoint Server Spoofing Vulnerability

    Published: 11 Mar 2021
    7
    High

    CVE-2021-24095

    Last Modified: 19 Aug 2026

    DirectX Elevation of Privilege Vulnerability

    Published: 11 Mar 2021
    7.8
    High

    CVE-2021-24090

    Last Modified: 19 Aug 2026

    Windows Error Reporting Elevation of Privilege Vulnerability

    Published: 11 Mar 2021
    7.8
    High

    CVE-2021-24089

    Last Modified: 19 Aug 2026

    HEVC Video Extensions Remote Code Execution Vulnerability

    Published: 11 Mar 2021
    7.1
    High

    CVE-2021-1729

    Last Modified: 19 Aug 2026

    Windows Update Stack Setup Elevation of Privilege Vulnerability

    Published: 11 Mar 2021
    9.8
    Critical

    CVE-2021-28132

    Last Modified: 21 Nov 2024

    LUCY Security Awareness Software through 4.7.x allows unauthenticated remote code execution because the Migration Tool (in the Support section) allows upload of .php files within a system.tar.gz file. The .php file becomes accessible with a public/system/static URI.

    Published: 11 Mar 2021
    6.4
    Medium

    CVE-2021-20261

    Last Modified: 21 Nov 2024

    A race condition was found in the Linux kernels implementation of the floppy disk drive controller driver software. The impact of this issue is lessened by the fact that the default permissions on the floppy device (/dev/fd0) are restricted to root. If the permissions on the device have changed the impact changes greatly. In the default configuration root (or equivalent) permissions are required to attack this flaw.

    Published: 11 Mar 2021
    5.3
    Medium

    CVE-2021-21363

    Last Modified: 21 Nov 2024

    swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in different languages by parsing your OpenAPI / Swagger definition. In swagger-codegen before version 2.4.19, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared temporary directory and race to complete the creation of the temporary subdirectory. This vulnerability is local privilege escalation because the contents of the `outputFolder` can be appended to by an attacker. As such, code written to this directory, when executed can be attacker controlled. For more details refer to the referenced GitHub Security Advisory. This vulnerability is fixed in version 2.4.19. Note this is a distinct vulnerability from CVE-2021-21364.

    Published: 11 Mar 2021
    5.3
    Medium

    CVE-2021-21364

    Last Modified: 21 Nov 2024

    swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in different languages by parsing your OpenAPI / Swagger definition. In swagger-codegen before version 2.4.19, on Unix-Like systems, the system temporary directory is shared between all local users. When files/directories are created, the default `umask` settings for the process are respected. As a result, by default, most processes/apis will create files/directories with the permissions `-rw-r--r--` and `drwxr-xr-x` respectively, unless an API that explicitly sets safe file permissions is used. Because this vulnerability impacts generated code, the generated code will remain vulnerable until fixed manually! This vulnerability is fixed in version 2.4.19. Note this is a distinct vulnerability from CVE-2021-21363.

    Published: 11 Mar 2021
    9.8
    Critical

    CVE-2020-1900

    Last Modified: 21 Nov 2024

    When unserializing an object with dynamic properties HHVM needs to pre-reserve the full size of the dynamic property array before inserting anything into it. Otherwise the array might resize, invalidating previously stored references. This pre-reservation was not occurring in HHVM prior to v4.32.3, between versions 4.33.0 and 4.56.0, 4.57.0, 4.58.0, 4.58.1, 4.59.0, 4.60.0, 4.61.0, 4.62.0.

    Published: 11 Mar 2021
    7.5
    High

    CVE-2020-1899

    Last Modified: 21 Nov 2024

    The unserialize() function supported a type code, "S", which was meant to be supported only for APC serialization. This type code allowed arbitrary memory addresses to be accessed as if they were static StringData objects. This issue affected HHVM prior to v4.32.3, between versions 4.33.0 and 4.56.0, 4.57.0, 4.58.0, 4.58.1, 4.59.0, 4.60.0, 4.61.0, 4.62.0.

    Published: 11 Mar 2021
    7.5
    High

    CVE-2020-1898

    Last Modified: 21 Nov 2024

    The fb_unserialize function did not impose a depth limit for nested deserialization. That meant a maliciously constructed string could cause deserialization to recurse, leading to stack exhaustion. This issue affected HHVM prior to v4.32.3, between versions 4.33.0 and 4.56.0, 4.57.0, 4.58.0, 4.58.1, 4.59.0, 4.60.0, 4.61.0, 4.62.0.

    Published: 11 Mar 2021
    9.8
    Critical

    CVE-2021-28134

    Last Modified: 21 Nov 2024

    Clipper before 1.0.5 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal API.

    Published: 11 Mar 2021
    7.5
    High

    CVE-2021-28092

    Last Modified: 21 Nov 2024

    The is-svg package 2.1.0 through 4.2.1 for Node.js uses a regular expression that is vulnerable to Regular Expression Denial of Service (ReDoS). If an attacker provides a malicious string, is-svg will get stuck processing the input for a very long time.

    Published: 11 Mar 2021
    6.3
    Medium

    CVE-2021-22191

    Last Modified: 21 Nov 2024

    Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet injection or crafted capture file.

    Published: 11 Mar 2021
    6.5
    Medium

    CVE-2021-21375

    Last Modified: 21 Nov 2024

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In PJSIP version 2.10 and earlier, after an initial INVITE has been sent, when two 183 responses are received, with the first one causing negotiation failure, a crash will occur. This results in a denial of service.

    Published: 10 Mar 2021
    6.8
    Medium

    CVE-2020-15260

    Last Modified: 21 Nov 2024

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In version 2.10 and earlier, PJSIP transport can be reused if they have the same IP address + port + protocol. However, this is insufficient for secure transport since it lacks remote hostname authentication. Suppose we have created a TLS connection to `sip.foo.com`, which has an IP address `100.1.1.1`. If we want to create a TLS connection to another hostname, say `sip.bar.com`, which has the same IP address, then it will reuse that existing connection, even though `100.1.1.1` does not have certificate to authenticate as `sip.bar.com`. The vulnerability allows for an insecure interaction without user awareness. It affects users who need access to connections to different destinations that translate to the same address, and allows man-in-the-middle attack if attacker can route a connection to another destination such as in the case of DNS spoofing.

    Published: 10 Mar 2021
    5
    Medium

    CVE-2021-21371

    Last Modified: 21 Nov 2024

    Tenable for Jira Cloud is an open source project designed to pull Tenable.io vulnerability data, then generate Jira Tasks and sub-tasks based on the vulnerabilities' current state. It published in pypi as "tenable-jira-cloud". In tenable-jira-cloud before version 1.1.21, it is possible to run arbitrary commands through the yaml.load() method. This could allow an attacker with local access to the host to run arbitrary code by running the application with a specially crafted YAML configuration file. This is fixed in version 1.1.21 by using yaml.safe_load() instead of yaml.load().

    Published: 10 Mar 2021
    6.8
    Medium

    CVE-2021-21265

    Last Modified: 30 May 2025

    October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October before version 1.1.2, when running on poorly configured servers (i.e. the server routes any request, regardless of the HOST header to an October CMS instance) the potential exists for Host Header Poisoning attacks to succeed. This has been addressed in version 1.1.2 by adding a feature to allow a set of trusted hosts to be specified in the application. As a workaround one may set the configuration setting cms.linkPolicy to force.

    Published: 10 Mar 2021
    6.5
    Medium

    CVE-2020-35233

    Last Modified: 21 Nov 2024

    The TFTP server fails to handle multiple connections on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices, and allows external attackers to force device reboots by sending concurrent connections, aka a denial of service attack.

    Published: 10 Mar 2021
    —
    Unknown

    CVE-2020-35232

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-35782. Reason: This candidate is a reservation duplicate of CVE-2020-35782. Notes: All CVE users should reference CVE-2020-35782 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 10 Mar 2021
    8.8
    High

    CVE-2020-35231

    Last Modified: 21 Nov 2024

    The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was affected by an authentication issue that allows an attacker to bypass access controls and obtain full control of the device.

    Published: 10 Mar 2021
    6.8
    Medium

    CVE-2020-35230

    Last Modified: 21 Nov 2024

    Multiple integer overflow parameters were found in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices. Most of the integer parameters sent through the web server can be abused to cause a denial of service attack.

    Published: 10 Mar 2021
    8.8
    High

    CVE-2020-35229

    Last Modified: 21 Nov 2024

    The authentication token required to execute NSDP write requests on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices is not properly invalidated and can be reused until a new token is generated, which allows attackers (with access to network traffic) to effectively gain administrative privileges.

    Published: 10 Mar 2021
    5.1
    Medium

    CVE-2021-3034

    Last Modified: 21 Nov 2024

    An information exposure through log file vulnerability exists in Cortex XSOAR software where the secrets configured for the SAML single sign-on (SSO) integration can be logged to the '/var/log/demisto/' server logs when testing the integration during setup. This logged information includes the private key and identity provider certificate used to configure the SAML SSO integration. This issue impacts: Cortex XSOAR 5.5.0 builds earlier than 98622; Cortex XSOAR 6.0.1 builds earlier than 830029; Cortex XSOAR 6.0.2 builds earlier than 98623; Cortex XSOAR 6.1.0 builds earlier than 848144.

    Published: 10 Mar 2021
    4.8
    Medium

    CVE-2020-35228

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the administration web panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allows remote attackers to inject arbitrary web script or HTML via the language parameter.

    Published: 10 Mar 2021
    7.2
    High

    CVE-2020-35227

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in the access control section on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices (in the administration web panel) allows an attacker to inject IP addresses into the whitelist via the checkedList parameter to the delete command.

    Published: 10 Mar 2021
    7.1
    High

    CVE-2020-35226

    Last Modified: 21 Nov 2024

    NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allow unauthenticated users to modify the switch DHCP configuration by sending the corresponding write request command.

    Published: 10 Mar 2021
    6.8
    Medium

    CVE-2020-35225

    Last Modified: 21 Nov 2024

    The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was not properly validating the length of string parameters sent in write requests, potentially allowing denial of service attacks.

    Published: 10 Mar 2021
    6.5
    Medium

    CVE-2020-35224

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in the NSDP protocol authentication method on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allows remote unauthenticated attackers to force a device reboot.

    Published: 10 Mar 2021
    8.8
    High

    CVE-2020-35223

    Last Modified: 21 Nov 2024

    The CSRF protection mechanism implemented in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices could be bypassed by omitting the CSRF token parameter in HTTP requests.

    Published: 10 Mar 2021
    —
    Unknown

    CVE-2020-35222

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-35783. Reason: This candidate is a reservation duplicate of CVE-2020-35783. Notes: All CVE users should reference CVE-2020-35783 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 10 Mar 2021
    8.8
    High

    CVE-2020-35221

    Last Modified: 21 Nov 2024

    The hashing algorithm implemented for NSDP password authentication on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was found to be insecure, allowing attackers (with access to a network capture) to quickly generate multiple collisions to generate valid passwords, or infer some parts of the original.

    Published: 10 Mar 2021
    —
    Unknown

    CVE-2020-35220

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-35801. Reason: This candidate is a reservation duplicate of CVE-2020-35801. Notes: All CVE users should reference CVE-2020-35801 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 10 Mar 2021
    7.5
    High

    CVE-2020-19419

    Last Modified: 21 Nov 2024

    Incorrect Access Control in Emerson Smart Wireless Gateway 1420 4.6.59 allows remote attackers to obtain sensitive device information from the administrator console without authentication.

    Published: 10 Mar 2021
    8.8
    High

    CVE-2020-19417

    Last Modified: 21 Nov 2024

    Emerson Smart Wireless Gateway 1420 4.6.59 allows non-privileged users (such as the default account 'maint') to perform administrative tasks by sending specially crafted HTTP requests to the application.

    Published: 10 Mar 2021
    7.8
    High

    CVE-2021-1640

    Last Modified: 19 Aug 2026

    Windows Print Spooler Elevation of Privilege Vulnerability

    Published: 10 Mar 2021
    7.8
    High

    CVE-2021-0465

    Last Modified: 21 Nov 2024

    In GenerateFaceMask of face.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-172005755

    Published: 10 Mar 2021
    7.8
    High

    CVE-2021-0464

    Last Modified: 21 Nov 2024

    In sound_trigger_event_alloc of platform.h, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-167663878

    Published: 10 Mar 2021
    5.5
    Medium

    CVE-2021-0463

    Last Modified: 21 Nov 2024

    In convertToHidl of convert.cpp, there is a possible out of bounds read due to uninitialized data from ReturnFrameworkMessage. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-154867068

    Published: 10 Mar 2021
    6.7
    Medium

    CVE-2021-0462

    Last Modified: 21 Nov 2024

    In the NXP NFC firmware, there is a possible insecure firmware update due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-168799695

    Published: 10 Mar 2021
    6.7
    Medium

    CVE-2021-0461

    Last Modified: 21 Nov 2024

    In iaxxx_core_sensor_change_state of iaxxx-module.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-175124074

    Published: 10 Mar 2021
    4.4
    Medium

    CVE-2021-0460

    Last Modified: 21 Nov 2024

    In the FingerTipS touch screen driver, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-156739245

    Published: 10 Mar 2021
    4.4
    Medium

    CVE-2021-0459

    Last Modified: 21 Nov 2024

    In fts_driver_test_write of fts_proc.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-157154534

    Published: 10 Mar 2021
    4.4
    Medium

    CVE-2021-0458

    Last Modified: 21 Nov 2024

    In the FingerTipS touch screen driver, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-157156744

    Published: 10 Mar 2021
    6.7
    Medium

    CVE-2021-0457

    Last Modified: 21 Nov 2024

    In the FingerTipS touch screen driver, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-157155375

    Published: 10 Mar 2021
    6.7
    Medium

    CVE-2021-0456

    Last Modified: 21 Nov 2024

    In the Citadel chip firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-174769927

    Published: 10 Mar 2021
    6.7
    Medium

    CVE-2021-0455

    Last Modified: 21 Nov 2024

    In the Citadel chip firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-175116439

    Published: 10 Mar 2021
    6.7
    Medium

    CVE-2021-0454

    Last Modified: 21 Nov 2024

    In the Citadel chip firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-175117047

    Published: 10 Mar 2021
    4.4
    Medium

    CVE-2021-0453

    Last Modified: 21 Nov 2024

    In the Titan-M chip firmware, there is a possible disclosure of stack memory due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-175117199

    Published: 10 Mar 2021