CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2020-23722

    Last Modified: 21 Nov 2024

    An issue was discovered in FUEL CMS 1.4.7. There is a escalation of privilege vulnerability to obtain super admin privilege via the "id" and "fuel_id" parameters.

    Published: 10 Mar 2021
    5.4
    Medium

    CVE-2020-23721

    Last Modified: 21 Nov 2024

    An issue was discovered in FUEL CMS V1.4.7. An attacker can use a XSS payload and bypass a filter via /fuelCM/fuel/pages/edit/1?lang=english.

    Published: 10 Mar 2021
    6.1
    Medium

    CVE-2021-28007

    Last Modified: 21 Nov 2024

    Web Based Quiz System 1.0 is affected by cross-site scripting (XSS) in register.php through the name parameter.

    Published: 10 Mar 2021
    4.8
    Medium

    CVE-2021-20673

    Last Modified: 21 Nov 2024

    Stored cross-site scripting vulnerability in Admin Page of GROWI (v4.2 Series) versions from v4.2.0 to v4.2.7 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors.

    Published: 10 Mar 2021
    7.2
    High

    CVE-2021-20671

    Last Modified: 21 Nov 2024

    Invalid file validation on the upload feature in GROWI versions v4.2.2 allows a remote attacker with administrative privilege to overwrite the files on the server, which may lead to arbitrary code execution.

    Published: 10 Mar 2021
    6.1
    Medium

    CVE-2021-20672

    Last Modified: 21 Nov 2024

    Reflected cross-site scripting vulnerability due to insufficient verification of URL query parameters in GROWI (v4.2 Series) versions from v4.2.0 to v4.2.7 allows remote attackers to inject an arbitrary script via unspecified vectors.

    Published: 10 Mar 2021
    7.5
    High

    CVE-2021-20670

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in GROWI versions v4.2.2 and earlier allows a remote unauthenticated attacker to read the user's personal information and/or server's internal information via unspecified vectors.

    Published: 10 Mar 2021
    4.7
    Medium

    CVE-2021-20669

    Last Modified: 21 Nov 2024

    Path traversal vulnerability in GROWI versions v4.2.2 and earlier allows an attacker with administrator rights to read and/or delete an arbitrary path via a specially crafted URL.

    Published: 10 Mar 2021
    5.4
    Medium

    CVE-2021-20667

    Last Modified: 21 Nov 2024

    Stored cross-site scripting vulnerability due to inadequate CSP (Content Security Policy) configuration in GROWI versions v4.2.2 and earlier allows remote authenticated attackers to inject an arbitrary script via a specially crafted content.

    Published: 10 Mar 2021
    2.7
    Low

    CVE-2021-20668

    Last Modified: 21 Nov 2024

    Path traversal vulnerability in GROWI versions v4.2.2 and earlier allows an attacker with administrator rights to read an arbitrary path via a specially crafted URL.

    Published: 10 Mar 2021
    7.8
    High

    CVE-2021-3310

    Last Modified: 21 Nov 2024

    Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can lead to code execution and information disclosure (by reading local files).

    Published: 10 Mar 2021
    7.5
    High

    CVE-2020-29238

    Last Modified: 21 Nov 2024

    An integer buffer overflow in the Nginx webserver of ExpressVPN Router version 1 allows remote attackers to obtain sensitive information when the server running as reverse proxy via specially crafted request.

    Published: 10 Mar 2021
    5.7
    Medium

    CVE-2021-3426

    Last Modified: 18 Dec 2025

    There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9, Python versions before 3.9.3 and Python versions before 3.10.0a7.

    Published: 10 Mar 2021
    7.5
    High

    CVE-2021-28361

    Last Modified: 21 Nov 2024

    An issue was discovered in Storage Performance Development Kit (SPDK) before 20.01.01. If a PDU is sent to the iSCSI target with a zero length (but data is expected), the iSCSI target can crash with a NULL pointer dereference.

    Published: 10 Mar 2021
    8.1
    High

    CVE-2021-21772

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 10 Mar 2021
    8.8
    High

    CVE-2021-28660

    Last Modified: 21 Nov 2024

    rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the ->ssid[] array. NOTE: from the perspective of kernel.org releases, CVE IDs are not normally used for drivers/staging/* (unfinished work); however, system integrators may have situations in which a drivers/staging issue is relevant to their own customer base.

    Published: 10 Mar 2021
    7.5
    High

    CVE-2021-27918

    Last Modified: 21 Nov 2024

    encoding/xml in Go before 1.15.9 and 1.16.x before 1.16.1 has an infinite loop if a custom TokenReader (for xml.NewTokenDecoder) returns EOF in the middle of an element. This can occur in the Decode, DecodeElement, or Skip method.

    Published: 10 Mar 2021
    5.5
    Medium

    CVE-2021-27919

    Last Modified: 21 Nov 2024

    archive/zip in Go 1.16.x before 1.16.1 allows attackers to cause a denial of service (panic) upon attempted use of the Reader.Open API for a ZIP archive in which ../ occurs at the beginning of any filename.

    Published: 10 Mar 2021
    7.8
    High

    CVE-2021-28952

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 5.11.8. The sound/soc/qcom/sdm845.c soundwire device driver has a buffer overflow when an unexpected port ID number is encountered, aka CID-1c668e1c0a0f. (This has been fixed in 5.12-rc4.)

    Published: 10 Mar 2021
    4.7
    Medium

    CVE-2021-29265

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.11.7. usbip_sockfd_store in drivers/usb/usbip/stub_dev.c allows attackers to cause a denial of service (GPF) because the stub-up sequence has race conditions during an update of the local and shared status, aka CID-9380afd6df70.

    Published: 10 Mar 2021
    7.5
    High

    CVE-2021-33198

    Last Modified: 21 Nov 2024

    In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.

    Published: 10 Mar 2021
    6.5
    Medium

    CVE-2021-20205

    Last Modified: 21 Nov 2024

    Libjpeg-turbo versions 2.0.91 and 2.0.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted GIF image.

    Published: 10 Mar 2021
    5.5
    Medium

    CVE-2021-3468

    Last Modified: 13 Feb 2025

    A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.

    Published: 10 Mar 2021
    7.5
    High

    CVE-2020-27632

    Last Modified: 21 Nov 2024

    In SIMATIC MV400 family versions prior to v7.0.6, the ISN generator is initialized with a constant value and has constant increments. An attacker could predict and hijack TCP sessions.

    Published: 10 Mar 2021
    5.3
    Medium

    CVE-2021-28153

    Last Modified: 21 Nov 2024

    An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which could conceivably have security relevance if the symlink is attacker-controlled. (If the path is a symlink to a file that already exists, then the contents of that file correctly remain unchanged.)

    Published: 10 Mar 2021
    9.8
    Critical

    CVE-2021-28119

    Last Modified: 21 Nov 2024

    Twinkle Tray (aka twinkle-tray) through 1.13.3 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal API.

    Published: 9 Mar 2021
    6.1
    Medium

    CVE-2021-28115

    Last Modified: 21 Nov 2024

    The OUGC Feedback plugin before 1.8.23 for MyBB allows XSS via the comment field of feedback during an edit operation.

    Published: 9 Mar 2021
    8
    High

    CVE-2021-23273

    Last Modified: 21 Nov 2024

    The Spotfire client component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Desktop, and TIBCO Spotfire Server contains a vulnerability that theoretically allows a low privileged attacker with network access to execute a stored Cross Site Scripting (XSS) attack on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analyst: versions 10.3.3 and below, versions 10.10.0, 10.10.1, and 10.10.2, versions 10.7.0, 10.8.0, 10.9.0, 11.0.0, and 11.1.0, TIBCO Spotfire Analytics Platform for AWS Marketplace: versions 11.1.0 and below, TIBCO Spotfire Desktop: versions 10.3.3 and below, versions 10.10.0, 10.10.1, and 10.10.2, versions 10.7.0, 10.8.0, 10.9.0, 11.0.0, and 11.1.0, and TIBCO Spotfire Server: versions 10.3.11 and below, versions 10.10.0, 10.10.1, 10.10.2, and 10.10.3, versions 10.7.0, 10.8.0, 10.8.1, 10.9.0, 11.0.0, and 11.1.0.

    Published: 9 Mar 2021
    7.5
    High

    CVE-2020-28952

    Last Modified: 21 Nov 2024

    An issue was discovered on Athom Homey and Homey Pro devices before 5.0.0. ZigBee hub devices should generate a unique Standard Network Key that is then exchanged with all enrolled devices so that all inter-device communication is encrypted. However, the cited Athom products use another widely known key that is designed for testing purposes: "01030507090b0d0f00020406080a0c0d" (the decimal equivalent of 1 3 5 7 9 11 13 15 0 2 4 6 8 10 12 13), which is human generated and static across all issued devices.

    Published: 9 Mar 2021
    8.6
    High

    CVE-2021-23352

    Last Modified: 21 Nov 2024

    This affects the package madge before 4.0.1. It is possible to specify a custom Graphviz path via the graphVizPath option parameter which when the .image(), .svg() or .dot() functions are called, is executed by the childprocess.exec function.

    Published: 9 Mar 2021
    5.9
    Medium

    CVE-2021-23353

    Last Modified: 21 Nov 2024

    This affects the package jspdf before 2.3.1. ReDoS is possible via the addImage function.

    Published: 9 Mar 2021
    6.5
    Medium

    CVE-2021-21369

    Last Modified: 21 Nov 2024

    Hyperledger Besu is an open-source, MainNet compatible, Ethereum client written in Java. In Besu before version 1.5.1 there is a denial-of-service vulnerability involving the HTTP JSON-RPC API service. If username and password authentication is enabled for the HTTP JSON-RPC API service, then prior to making any requests to an API endpoint the requestor must use the login endpoint to obtain a JSON web token (JWT) using their credentials. A single user can readily overload the login endpoint with invalid requests (incorrect password). As the supplied password is checked for validity on the main vertx event loop and takes a relatively long time this can cause the processing of other valid requests to fail. A valid username is required for this vulnerability to be exposed. This has been fixed in version 1.5.1.

    Published: 9 Mar 2021
    6.1
    Medium

    CVE-2020-28150

    Last Modified: 21 Nov 2024

    I-Net Software Clear Reports 20.10.136 web application accepts a user-controlled input that specifies a link to an external site, and uses the user supplied data in a Redirect.

    Published: 9 Mar 2021
    8.8
    High

    CVE-2021-21190

    Last Modified: 21 Nov 2024

    Uninitialized data in PDFium in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.

    Published: 9 Mar 2021
    8.8
    High

    CVE-2021-21188

    Last Modified: 21 Nov 2024

    Use after free in Blink in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 9 Mar 2021
    4.3
    Medium

    CVE-2021-21189

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in payments in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 9 Mar 2021
    4.3
    Medium

    CVE-2021-21187

    Last Modified: 21 Nov 2024

    Insufficient data validation in URL formatting in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

    Published: 9 Mar 2021
    4.3
    Medium

    CVE-2021-21185

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in extensions in Google Chrome prior to 89.0.4389.72 allowed an attacker who convinced a user to install a malicious extension to obtain sensitive information via a crafted Chrome Extension.

    Published: 9 Mar 2021
    4.3
    Medium

    CVE-2021-21186

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in QR scanning in Google Chrome on iOS prior to 89.0.4389.72 allowed an attacker who convinced the user to scan a QR code to bypass navigation restrictions via a crafted QR code.

    Published: 9 Mar 2021
    4.3
    Medium

    CVE-2021-21184

    Last Modified: 21 Nov 2024

    Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 9 Mar 2021
    4.3
    Medium

    CVE-2021-21183

    Last Modified: 21 Nov 2024

    Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 9 Mar 2021
    6.5
    Medium

    CVE-2021-21181

    Last Modified: 21 Nov 2024

    Side-channel information leakage in autofill in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

    Published: 9 Mar 2021
    6.5
    Medium

    CVE-2021-21182

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in navigations in Google Chrome prior to 89.0.4389.72 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.

    Published: 9 Mar 2021
    8.8
    High

    CVE-2021-21180

    Last Modified: 21 Nov 2024

    Use after free in tab search in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 9 Mar 2021
    8.8
    High

    CVE-2021-21179

    Last Modified: 21 Nov 2024

    Use after free in Network Internals in Google Chrome on Linux prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 9 Mar 2021
    6.5
    Medium

    CVE-2021-21178

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Compositing in Google Chrome on Linux and Windows prior to 89.0.4389.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 9 Mar 2021
    6.5
    Medium

    CVE-2021-21177

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Autofill in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

    Published: 9 Mar 2021
    6.5
    Medium

    CVE-2021-21175

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Site isolation in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 9 Mar 2021
    6.5
    Medium

    CVE-2021-21176

    Last Modified: 21 Nov 2024

    Inappropriate implementation in full screen mode in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 9 Mar 2021
    8.8
    High

    CVE-2021-21174

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Referrer in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 9 Mar 2021