CVE Feed

    Dashboard / CVE

    8.2
    High

    CVE-2020-5148

    Last Modified: 21 Nov 2024

    SonicWall SSO-agent default configuration uses NetAPI to probe the associated IP's in the network, this client probing method allows a potential attacker to capture the password hash of the privileged user and potentially forces the SSO Agent to authenticate allowing an attacker to bypass firewall access controls.

    Published: 5 Mar 2021
    7.5
    High

    CVE-2020-36255

    Last Modified: 21 Nov 2024

    An issue was discovered in IdentityModel (aka ScottBrady.IdentityModel) before 1.3.0. The Branca implementation allows an attacker to modify and forge authentication tokens.

    Published: 5 Mar 2021
    9.8
    Critical

    CVE-2021-27965

    Last Modified: 21 Nov 2024

    The MsIo64.sys driver before 1.1.19.1016 in MSI Dragon Center before 2.0.98.0 has a buffer overflow that allows privilege escalation via a crafted 0x80102040, 0x80102044, 0x80102050, or 0x80102054 IOCTL request.

    Published: 5 Mar 2021
    8.2
    High

    CVE-2021-27963

    Last Modified: 21 Nov 2024

    SonLogger before 6.4.1 is affected by user creation with any user permissions profile (e.g., SuperAdmin). An anonymous user can send a POST request to /User/saveUser without any authentication or session header.

    Published: 5 Mar 2021
    9.8
    Critical

    CVE-2021-27964

    Last Modified: 21 Nov 2024

    SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Config/SaveUploadedHotspotLogoFile without any authentication or session header. There is no check for the file extension or content of the uploaded file.

    Published: 5 Mar 2021
    —
    Unknown

    CVE-2019-18351

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-18790. Reason: This candidate is a duplicate of CVE-2019-18790. Notes: All CVE users should reference CVE-2019-18790 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 5 Mar 2021
    3.4
    Low

    CVE-2020-35501

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernels implementation of audit rules, where a syscall can unexpectedly not be correctly not be logged by the audit subsystem

    Published: 5 Mar 2021
    8.1
    High

    CVE-2020-28502

    Last Modified: 21 Nov 2024

    This affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are sent synchronously (async=False on xhr.open), malicious user input flowing into xhr.send could result in arbitrary code being injected and run.

    Published: 5 Mar 2021
    6.3
    Medium

    CVE-2021-21334

    Last Modified: 21 Nov 2024

    In containerd (an industry-standard container runtime) before versions 1.3.10 and 1.4.4, containers launched through containerd's CRI implementation (through Kubernetes, crictl, or any other pod/container client that uses the containerd CRI service) that share the same image may receive incorrect environment variables, including values that are defined for other containers. If the affected containers have different security contexts, this may allow sensitive information to be unintentionally shared. If you are not using containerd's CRI implementation (through one of the mechanisms described above), you are not vulnerable to this issue. If you are not launching multiple containers or Kubernetes pods from the same image which have different environment variables, you are not vulnerable to this issue. If you are not launching multiple containers or Kubernetes pods from the same image in rapid succession, you have reduced likelihood of being vulnerable to this issue This vulnerability has been fixed in containerd 1.3.10 and containerd 1.4.4. Users should update to these versions.

    Published: 5 Mar 2021
    7.1
    High

    CVE-2021-27364

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.

    Published: 5 Mar 2021
    7.8
    High

    CVE-2021-27365

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink message.

    Published: 5 Mar 2021
    6.5
    Medium

    CVE-2021-28039

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, an x86 PV guest OS user can crash a Dom0 or driver domain via a large amount of I/O activity. The issue relates to misuse of guest physical addresses when a configuration has CONFIG_XEN_UNPOPULATED_ALLOC but not CONFIG_XEN_BALLOON_MEMORY_HOTPLUG.

    Published: 5 Mar 2021
    9.8
    Critical

    CVE-2021-28879

    Last Modified: 21 Nov 2024

    In the standard library in Rust before 1.52.0, the Zip implementation can report an incorrect size due to an integer overflow. This bug can lead to a buffer overflow when a consumed Zip iterator is used again.

    Published: 5 Mar 2021
    5.5
    Medium

    CVE-2021-29264

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 5.11.10. drivers/net/ethernet/freescale/gianfar.c in the Freescale Gianfar Ethernet driver allows attackers to cause a system crash because a negative fragment size is calculated in situations involving an rx queue overrun when jumbo packets are used and NAPI is enabled, aka CID-d8861bab48b6.

    Published: 5 Mar 2021
    4.4
    Medium

    CVE-2021-27363

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscsi_transport structure. When an iSCSI transport is registered with the iSCSI subsystem, the transport's handle is available to unprivileged users via the sysfs file system, at /sys/class/iscsi_transport/$TRANSPORT_NAME/handle. When read, the show_transport_handle function (in drivers/scsi/scsi_transport_iscsi.c) is called, which leaks the handle. This handle is actually the pointer to an iscsi_transport struct in the kernel module's global variables.

    Published: 5 Mar 2021
    6.5
    Medium

    CVE-2021-20278

    Last Modified: 21 Nov 2024

    An authentication bypass vulnerability was found in Kiali in versions before 1.31.0 when the authentication strategy `OpenID` is used. When RBAC is enabled, Kiali assumes that some of the token validation is handled by the underlying cluster. When OpenID `implicit flow` is used with RBAC turned off, this token validation doesn't occur, and this allows a malicious user to bypass the authentication.

    Published: 5 Mar 2021
    6.5
    Medium

    CVE-2021-28038

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver lacks necessary treatment of errors such as failed memory allocations (as a result of changes to the handling of grant mapping errors). A host OS denial of service may occur during misbehavior of a networking frontend driver. NOTE: this issue exists because of an incomplete fix for CVE-2021-26931.

    Published: 5 Mar 2021
    9.8
    Critical

    CVE-2021-27314

    Last Modified: 21 Nov 2024

    SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via username parameter at login page.

    Published: 4 Mar 2021
    7.5
    High

    CVE-2019-18630

    Last Modified: 21 Nov 2024

    On Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200, portions of the drive containing executable code were not encrypted thus leaving it open to potential cryptographic information disclosure.

    Published: 4 Mar 2021
    7.8
    High

    CVE-2021-3404

    Last Modified: 21 Nov 2024

    In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a heap buffer overflow which can be triggered via a crafted file.

    Published: 4 Mar 2021
    7.8
    High

    CVE-2021-3403

    Last Modified: 21 Nov 2024

    In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a double free which can be triggered via a crafted file.

    Published: 4 Mar 2021
    2.1
    Low

    CVE-2021-25348

    Last Modified: 21 Nov 2024

    Improper permission grant check in Samsung Internet prior to version 13.0.1.60 allows access to files in internal storage without authorized STORAGE permission.

    Published: 4 Mar 2021
    7.1
    High

    CVE-2021-25346

    Last Modified: 21 Nov 2024

    A possible arbitrary memory overwrite vulnerabilities in quram library version prior to SMR Jan-2021 Release 1 allow arbitrary code execution.

    Published: 4 Mar 2021
    5.3
    Medium

    CVE-2021-25347

    Last Modified: 21 Nov 2024

    Hijacking vulnerability in Samsung Email application version prior to SMR Feb-2021 Release 1 allows attackers to intercept when the provider is executed.

    Published: 4 Mar 2021
    4
    Medium

    CVE-2021-25345

    Last Modified: 21 Nov 2024

    Graphic format mismatch while converting video format in hwcomposer prior to SMR Mar-2021 Release 1 results in kernel panic due to unsupported format.

    Published: 4 Mar 2021
    6.2
    Medium

    CVE-2021-25344

    Last Modified: 21 Nov 2024

    Missing permission check in knox_custom service prior to SMR Mar-2021 Release 1 allows attackers to gain access to device's serial number without permission.

    Published: 4 Mar 2021
    4
    Medium

    CVE-2021-25343

    Last Modified: 21 Nov 2024

    Calling of non-existent provider in Samsung Members prior to version 2.4.81.13 (in Android O(8.1) and below) and 3.8.00.13 (in Android P(9.0) and above) allows unauthorized actions including denial of service attack by hijacking the provider.

    Published: 4 Mar 2021
    4
    Medium

    CVE-2021-25342

    Last Modified: 21 Nov 2024

    Calling of non-existent provider in SMP sdk prior to version 3.0.9 allows unauthorized actions including denial of service attack by hijacking the provider.

    Published: 4 Mar 2021
    4
    Medium

    CVE-2021-25341

    Last Modified: 21 Nov 2024

    Calling of non-existent provider in S Assistant prior to version 6.5.01.22 allows unauthorized actions including denial of service attack by hijacking the provider.

    Published: 4 Mar 2021
    5.1
    Medium

    CVE-2021-25340

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Samsung keyboard version prior to SMR Feb-2021 Release 1 allows physically proximate attackers to change in arbitrary settings during Initialization State.

    Published: 4 Mar 2021
    4.4
    Medium

    CVE-2021-25339

    Last Modified: 21 Nov 2024

    Improper address validation in HArx in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given a compromised kernel, to corrupt EL2 memory.

    Published: 4 Mar 2021
    4.4
    Medium

    CVE-2021-25338

    Last Modified: 21 Nov 2024

    Improper memory access control in RKP in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given a compromised kernel, to write certain part of RKP EL2 memory region.

    Published: 4 Mar 2021
    4.4
    Medium

    CVE-2021-25337

    Last Modified: 30 Oct 2025

    Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files.

    Published: 4 Mar 2021
    2.8
    Low

    CVE-2021-25336

    Last Modified: 21 Nov 2024

    Improper access control in NotificationManagerService in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to acquire notification access via sending a crafted malicious intent.

    Published: 4 Mar 2021
    2.5
    Low

    CVE-2021-25335

    Last Modified: 21 Nov 2024

    Improper lockscreen status check in cocktailbar service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows unauthenticated users to access hidden notification contents over the lockscreen in specific condition.

    Published: 4 Mar 2021
    5.5
    Medium

    CVE-2021-25334

    Last Modified: 21 Nov 2024

    Improper input check in wallpaper service in Samsung mobile devices prior to SMR Feb-2021 Release 1 allows untrusted application to cause permanent denial of service.

    Published: 4 Mar 2021
    3.2
    Low

    CVE-2021-25333

    Last Modified: 21 Nov 2024

    Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen via scanning specific QR code.

    Published: 4 Mar 2021
    3.2
    Low

    CVE-2021-25332

    Last Modified: 21 Nov 2024

    Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to contacts information over the lockscreen in specific condition.

    Published: 4 Mar 2021
    3.2
    Low

    CVE-2021-25331

    Last Modified: 21 Nov 2024

    Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen in specific condition.

    Published: 4 Mar 2021
    6.5
    Medium

    CVE-2021-26989

    Last Modified: 21 Nov 2024

    Clustered Data ONTAP versions prior to 9.3P21, 9.5P16, 9.6P12, 9.7P9 and 9.8 are susceptible to a vulnerability which could allow a remote authenticated attacker to cause a Denial of Service (DoS) on clustered Data ONTAP configured for SMB access.

    Published: 4 Mar 2021
    3.5
    Low

    CVE-2021-26988

    Last Modified: 21 Nov 2024

    Clustered Data ONTAP versions prior to 9.3P21, 9.5P16, 9.6P12, 9.7P8 and 9.8 are susceptible to a vulnerability which could allow unauthorized tenant users to discover information related to converting a 7-Mode directory to Cluster-mode such as Storage Virtual Machine (SVM) names, volume names, directory paths and Job IDs.

    Published: 4 Mar 2021
    9.8
    Critical

    CVE-2021-26293

    Last Modified: 21 Nov 2024

    An issue was discovered in AfterLogic Aurora through 8.5.3 and WebMail Pro through 8.5.3, when DAV is enabled. They allow directory traversal to create new files (such as an executable file under the web root). This is related to DAVServer.php in 8.x and DAV/Server.php in 7.x.

    Published: 4 Mar 2021
    9.8
    Critical

    CVE-2020-8298

    Last Modified: 21 Nov 2024

    fs-path node module before 0.0.25 is vulnerable to command injection by way of user-supplied inputs via the `copy`, `copySync`, `remove`, and `removeSync` methods.

    Published: 4 Mar 2021
    5.4
    Medium

    CVE-2021-20351

    Last Modified: 21 Nov 2024

    IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194708.

    Published: 4 Mar 2021
    5.4
    Medium

    CVE-2021-20350

    Last Modified: 21 Nov 2024

    IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194707.

    Published: 4 Mar 2021
    5.4
    Medium

    CVE-2021-20340

    Last Modified: 21 Nov 2024

    IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194451.

    Published: 4 Mar 2021
    5.4
    Medium

    CVE-2020-4975

    Last Modified: 21 Nov 2024

    IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192435.

    Published: 4 Mar 2021
    5.4
    Medium

    CVE-2020-4866

    Last Modified: 21 Nov 2024

    IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190742.

    Published: 4 Mar 2021
    5.4
    Medium

    CVE-2020-4863

    Last Modified: 21 Nov 2024

    IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190566.

    Published: 4 Mar 2021
    5.4
    Medium

    CVE-2020-4857

    Last Modified: 21 Nov 2024

    IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190460.

    Published: 4 Mar 2021