CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2021-21172

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 89.0.4389.72 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.

    Published: 9 Mar 2021
    6.5
    Medium

    CVE-2021-21173

    Last Modified: 21 Nov 2024

    Side-channel information leakage in Network Internals in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 9 Mar 2021
    6.5
    Medium

    CVE-2021-21171

    Last Modified: 21 Nov 2024

    Incorrect security UI in TabStrip and Navigation in Google Chrome on Android prior to 89.0.4389.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 9 Mar 2021
    6.5
    Medium

    CVE-2021-21170

    Last Modified: 21 Nov 2024

    Incorrect security UI in Loader in Google Chrome prior to 89.0.4389.72 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 9 Mar 2021
    8.8
    High

    CVE-2021-21169

    Last Modified: 21 Nov 2024

    Out of bounds memory access in V8 in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

    Published: 9 Mar 2021
    6.5
    Medium

    CVE-2021-21168

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in appcache in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

    Published: 9 Mar 2021
    8.8
    High

    CVE-2021-21167

    Last Modified: 21 Nov 2024

    Use after free in bookmarks in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 9 Mar 2021
    8.8
    High

    CVE-2021-21165

    Last Modified: 21 Nov 2024

    Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 9 Mar 2021
    8.8
    High

    CVE-2021-21166

    Last Modified: 24 Oct 2025

    Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 9 Mar 2021
    6.5
    Medium

    CVE-2021-21164

    Last Modified: 21 Nov 2024

    Insufficient data validation in Chrome on iOS in Google Chrome on iOS prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 9 Mar 2021
    6.5
    Medium

    CVE-2021-21163

    Last Modified: 21 Nov 2024

    Insufficient data validation in Reader Mode in Google Chrome on iOS prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page and a malicious server.

    Published: 9 Mar 2021
    8.8
    High

    CVE-2021-21161

    Last Modified: 21 Nov 2024

    Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 9 Mar 2021
    8.8
    High

    CVE-2021-21162

    Last Modified: 21 Nov 2024

    Use after free in WebRTC in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 9 Mar 2021
    8.8
    High

    CVE-2021-21160

    Last Modified: 21 Nov 2024

    Heap buffer overflow in WebAudio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 9 Mar 2021
    8.8
    High

    CVE-2021-21159

    Last Modified: 21 Nov 2024

    Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 9 Mar 2021
    4.9
    Medium

    CVE-2021-3417

    Last Modified: 21 Nov 2024

    An internal product security audit of LXCO, prior to version 1.2.2, discovered that credentials for Lenovo XClarity Administrator (LXCA), if added as a Resource Manager, are encoded then written to an internal LXCO log file each time a session is established with LXCA. Affected logs are captured in the First Failure Data Capture (FFDC) service log. The FFDC service log is only generated when requested by a privileged LXCO user and it is only accessible to the privileged LXCO user that requested the file.

    Published: 9 Mar 2021
    5.5
    Medium

    CVE-2020-8357

    Last Modified: 21 Nov 2024

    A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.200.2042, that could allow configuration files to be written to non-standard locations.

    Published: 9 Mar 2021
    4.9
    Medium

    CVE-2020-8356

    Last Modified: 21 Nov 2024

    An internal product security audit of LXCO, prior to version 1.2.2, discovered that optional passwords, if specified, for the Syslog and SMTP forwarders are written to an internal LXCO log file in clear text. Affected logs are captured in the First Failure Data Capture (FFDC) service log. The FFDC service log is only generated when requested by a privileged LXCO user and it is only accessible to the privileged LXCO user that requested the file.

    Published: 9 Mar 2021
    4.7
    Medium

    CVE-2020-35451

    Last Modified: 13 Feb 2025

    There is a race condition in OozieSharelibCLI in Apache Oozie before version 5.2.1 which allows a malicious attacker to replace the files in Oozie's sharelib during it's creation.

    Published: 9 Mar 2021
    5.3
    Medium

    CVE-2021-20341

    Last Modified: 21 Nov 2024

    IBM Cloud Pak for Multicloud Management Monitoring 2.2 returns potentially sensitive information in headers which could lead to further attacks against the system. IBM X-Force ID: 194513.

    Published: 9 Mar 2021
    9.8
    Critical

    CVE-2021-25915

    Last Modified: 30 Apr 2025

    Prototype pollution vulnerability in 'changeset' versions 0.0.1 through 0.2.5 allows an attacker to cause a denial of service and may lead to remote code execution.

    Published: 9 Mar 2021
    7.8
    High

    CVE-2021-27592

    Last Modified: 21 Nov 2024

    When a user opens manipulated Universal 3D (.U3D) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

    Published: 9 Mar 2021
    7.8
    High

    CVE-2021-27590

    Last Modified: 21 Nov 2024

    When a user opens manipulated Tag Image File Format (.TIFF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the application.

    Published: 9 Mar 2021
    3.3
    Low

    CVE-2021-27584

    Last Modified: 21 Nov 2024

    When a user opens manipulated PhotoShop Document (.PSD) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the application.

    Published: 9 Mar 2021
    7.8
    High

    CVE-2021-27588

    Last Modified: 21 Nov 2024

    When a user opens manipulated HPGL format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the application.

    Published: 9 Mar 2021
    7.8
    High

    CVE-2021-27586

    Last Modified: 21 Nov 2024

    When a user opens manipulated Interchange File Format (.IFF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the application.

    Published: 9 Mar 2021
    7.8
    High

    CVE-2021-27587

    Last Modified: 21 Nov 2024

    When a user opens manipulated Jupiter Tessellation (.JT) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the application.

    Published: 9 Mar 2021
    7.8
    High

    CVE-2021-27591

    Last Modified: 21 Nov 2024

    When a user opens manipulated Portable Document Format (.PDF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the application.

    Published: 9 Mar 2021
    7.8
    High

    CVE-2021-27589

    Last Modified: 21 Nov 2024

    When a user opens manipulated Scalable Vector Graphics (.SVG) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the application.

    Published: 9 Mar 2021
    7.8
    High

    CVE-2021-27585

    Last Modified: 21 Nov 2024

    When a user opens manipulated Computer Graphics Metafile (.CGM) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the application.

    Published: 9 Mar 2021
    9.8
    Critical

    CVE-2021-21484

    Last Modified: 21 Nov 2024

    LDAP authentication in SAP HANA Database version 2.0 can be bypassed if the attached LDAP directory server is configured to enable unauthenticated bind.

    Published: 9 Mar 2021
    8.8
    High

    CVE-2021-21487

    Last Modified: 21 Nov 2024

    SAP Payment Engine version 500, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

    Published: 9 Mar 2021
    8.8
    High

    CVE-2021-21480

    Last Modified: 5 May 2025

    SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment). An attacker can intercept a request to the server, inject malicious JSP code in the request and forward to server. When this dashboard is opened by users having at least SAP_XMII Developer role, malicious content in the dashboard gets executed, leading to remote code execution in the server, which allows privilege escalation. The malicious JSP code can contain certain OS commands, through which an attacker can read sensitive files in the server, modify files or even delete contents in the server thus compromising the confidentiality, integrity and availability of the server hosting the SAP MII application. Also, an attacker authenticated as a developer can use the application to upload and execute a file which will permit them to execute operating systems commands completely compromising the server hosting the application.

    Published: 9 Mar 2021
    3.3
    Low

    CVE-2021-21493

    Last Modified: 21 Nov 2024

    When a user opens manipulated Graphics Interchange Format (.GIF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the application.

    Published: 9 Mar 2021
    8.8
    High

    CVE-2021-21486

    Last Modified: 21 Nov 2024

    SAP Enterprise Financial Services versions, 101, 102, 103, 104, 105, 600, 603, 604, 605, 606, 616, 617, 618, 800, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

    Published: 9 Mar 2021
    6.5
    Medium

    CVE-2021-21488

    Last Modified: 21 Nov 2024

    Knowledge Management versions 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 allows a remote attacker with basic privileges to deserialize user-controlled data without verification, leading to insecure deserialization which triggers the attacker’s code, therefore impacting Availability.

    Published: 9 Mar 2021
    8.8
    High

    CVE-2021-21481

    Last Modified: 21 Nov 2024

    The MigrationService, which is part of SAP NetWeaver versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform an authorization check. This might allow an unauthorized attacker to access configuration objects, including such that grant administrative privileges. This could result in complete compromise of system confidentiality, integrity, and availability.

    Published: 9 Mar 2021
    7.5
    High

    CVE-2021-20276

    Last Modified: 21 Nov 2024

    A flaw was found in privoxy before 3.0.32. Invalid memory access with an invalid pattern passed to pcre_compile() may lead to denial of service.

    Published: 9 Mar 2021
    7.5
    High

    CVE-2021-20275

    Last Modified: 21 Nov 2024

    A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_complete() leading to denial of service.

    Published: 9 Mar 2021
    7.5
    High

    CVE-2021-20274

    Last Modified: 21 Nov 2024

    A flaw was found in privoxy before 3.0.32. A crash may occur due a NULL-pointer dereference when the socks server misbehaves.

    Published: 9 Mar 2021
    7.5
    High

    CVE-2021-20273

    Last Modified: 21 Nov 2024

    A flaw was found in privoxy before 3.0.32. A crash can occur via a crafted CGI request if Privoxy is toggled off.

    Published: 9 Mar 2021
    7.5
    High

    CVE-2021-20272

    Last Modified: 21 Nov 2024

    A flaw was found in privoxy before 3.0.32. An assertion failure could be triggered with a crafted CGI request leading to server crash.

    Published: 9 Mar 2021
    6.1
    Medium

    CVE-2021-28006

    Last Modified: 21 Nov 2024

    Web Based Quiz System 1.0 is affected by cross-site scripting (XSS) in admin.php through the options parameter.

    Published: 9 Mar 2021
    5.3
    Medium

    CVE-2021-21361

    Last Modified: 21 Nov 2024

    The `com.bmuschko:gradle-vagrant-plugin` Gradle plugin contains an information disclosure vulnerability due to the logging of the system environment variables. When this Gradle plugin is executed in public CI/CD, this can lead to sensitive credentials being exposed to malicious actors. This is fixed in version 3.0.0.

    Published: 9 Mar 2021
    5.3
    Medium

    CVE-2021-21360

    Last Modified: 21 Nov 2024

    Products.GenericSetup is a mini-framework for expressing the configured state of a Zope Site as a set of filesystem artifacts. In Products.GenericSetup before version 2.1.1 there is an information disclosure vulnerability - anonymous visitors may view log and snapshot files generated by the Generic Setup Tool. The problem has been fixed in version 2.1.1. Depending on how you have installed Products.GenericSetup, you should change the buildout version pin to 2.1.1 and re-run the buildout, or if you used pip simply do pip install `"Products.GenericSetup>=2.1.1"`.

    Published: 9 Mar 2021
    8.8
    High

    CVE-2020-13936

    Last Modified: 13 Feb 2025

    An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.

    Published: 9 Mar 2021
    6.1
    Medium

    CVE-2020-13959

    Last Modified: 13 Feb 2025

    The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered as part of the URL. An attacker can set an XSS payload file as this vm file in the URL which results in this payload being executed. XSS vulnerabilities allow attackers to execute arbitrary JavaScript in the context of the attacked website and the attacked user. This can be abused to steal session cookies, perform requests in the name of the victim or for phishing attacks.

    Published: 9 Mar 2021
    5.6
    Medium

    CVE-2021-24033

    Last Modified: 21 Nov 2024

    react-dev-utils prior to v11.0.4 exposes a function, getProcessForPort, where an input argument is concatenated into a command string to be executed. This function is typically used from react-scripts (in Create React App projects), where the usage is safe. Only when this function is manually invoked with user-provided values (ie: by custom code) is there the potential for command injection. If you're consuming it from react-scripts then this issue does not affect you.

    Published: 9 Mar 2021
    5.9
    Medium

    CVE-2021-21295

    Last Modified: 21 Nov 2024

    Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerability that enables request smuggling. If a Content-Length header is present in the original HTTP/2 request, the field is not validated by `Http2MultiplexHandler` as it is propagated up. This is fine as long as the request is not proxied through as HTTP/1.1. If the request comes in as an HTTP/2 stream, gets converted into the HTTP/1.1 domain objects (`HttpRequest`, `HttpContent`, etc.) via `Http2StreamFrameToHttpObjectCodec `and then sent up to the child channel's pipeline and proxied through a remote peer as HTTP/1.1 this may result in request smuggling. In a proxy case, users may assume the content-length is validated somehow, which is not the case. If the request is forwarded to a backend channel that is a HTTP/1.1 connection, the Content-Length now has meaning and needs to be checked. An attacker can smuggle requests inside the body as it gets downgraded from HTTP/2 to HTTP/1.1. For an example attack refer to the linked GitHub Advisory. Users are only affected if all of this is true: `HTTP2MultiplexCodec` or `Http2FrameCodec` is used, `Http2StreamFrameToHttpObjectCodec` is used to convert to HTTP/1.1 objects, and these HTTP/1.1 objects are forwarded to another remote peer. This has been patched in 4.1.60.Final As a workaround, the user can do the validation by themselves by implementing a custom `ChannelInboundHandler` that is put in the `ChannelPipeline` behind `Http2StreamFrameToHttpObjectCodec`.

    Published: 9 Mar 2021
    7.8
    High

    CVE-2020-27225

    Last Modified: 21 Nov 2024

    In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to the local help web server, allowing an unauthenticated local attacker to issue active help commands to the associated Eclipse Platform process or Eclipse Rich Client Platform process.

    Published: 9 Mar 2021