CVE Feed

    Dashboard / CVE

    9.1
    Critical

    CVE-2021-26412

    Last Modified: 19 Aug 2026

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Published: 2 Mar 2021
    4.3
    Medium

    CVE-2020-12530

    Last Modified: 21 Nov 2024

    An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. There is an XSS issue in the redirect.php allowing an attacker to inject code via a get parameter.

    Published: 2 Mar 2021
    5.8
    Medium

    CVE-2020-12529

    Last Modified: 21 Nov 2024

    An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2 There is a SSRF in the LDAP access check, allowing an attacker to scan for open ports.

    Published: 2 Mar 2021
    6.5
    Medium

    CVE-2020-12528

    Last Modified: 21 Nov 2024

    An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. Improper use of access validation allows a logged in user to kill web2go sessions in the account he should not have access to.

    Published: 2 Mar 2021
    6.5
    Medium

    CVE-2020-12527

    Last Modified: 21 Nov 2024

    An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. Improper access validation allows a logged in user to shutdown or reboot devices in his account without having corresponding permissions.

    Published: 2 Mar 2021
    6.8
    Medium

    CVE-2021-21258

    Last Modified: 21 Nov 2024

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI from version 9.5.0 and before version 9.5.4, there is a cross-site scripting injection vulnerability when using ajax/kanban.php. This is fixed in version 9.5.4.

    Published: 2 Mar 2021
    5.8
    Medium

    CVE-2021-21255

    Last Modified: 21 Nov 2024

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI version 9.5.3, it was possible to switch entities with IDOR from a logged in user. This is fixed in version 9.5.4.

    Published: 2 Mar 2021
    8.8
    High

    CVE-2021-27885

    Last Modified: 21 Nov 2024

    usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.

    Published: 2 Mar 2021
    4.3
    Medium

    CVE-2021-22187

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 13.6.7. A potential resource exhaustion issue that allowed running or pending jobs to continue even after project was deleted.

    Published: 2 Mar 2021
    3.3
    Low

    CVE-2021-22294

    Last Modified: 21 Nov 2024

    A component API of the HarmonyOS 2.0 has a permission bypass vulnerability. Local attackers may exploit this vulnerability to issue commands repeatedly, exhausting system service resources.

    Published: 2 Mar 2021
    9.8
    Critical

    CVE-2020-28657

    Last Modified: 21 Nov 2024

    In bPanel 2.0, the administrative ajax endpoints (aka ajax/aj_*.php) are accessible without authentication and allow SQL injections, which could lead to platform compromise.

    Published: 2 Mar 2021
    5.5
    Medium

    CVE-2021-22296

    Last Modified: 21 Nov 2024

    A component of HarmonyOS 2.0 has a DoS vulnerability. Local attackers may exploit this vulnerability to mount a file system to the target device, causing DoS of the file system.

    Published: 2 Mar 2021
    7.5
    High

    CVE-2020-14372

    Last Modified: 21 Nov 2024

    A flaw was found in grub2 in versions prior to 2.06, where it incorrectly enables the usage of the ACPI command when Secure Boot is enabled. This flaw allows an attacker with privileged access to craft a Secondary System Description Table (SSDT) containing code to overwrite the Linux kernel lockdown variable content directly into memory. The table is further loaded and executed by the kernel, defeating its Secure Boot lockdown and allowing the attacker to load unsigned code. The highest threat from this vulnerability is to data confidentiality and integrity, as well as system availability.

    Published: 2 Mar 2021
    8.2
    High

    CVE-2020-25632

    Last Modified: 21 Nov 2024

    A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking if any other dependent module is still loaded leading to a use-after-free scenario. This could allow arbitrary code to be executed or a bypass of Secure Boot protections. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 2 Mar 2021
    7.5
    High

    CVE-2020-27779

    Last Modified: 21 Nov 2024

    A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove address ranges from memory creating an opportunity to circumvent SecureBoot protections after proper triage about grub's memory layout. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 2 Mar 2021
    6.7
    Medium

    CVE-2021-20225

    Last Modified: 21 Nov 2024

    A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a heap-allocated buffer by calling certain commands with a large number of specific short forms of options. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 2 Mar 2021
    6.4
    Medium

    CVE-2021-3418

    Last Modified: 21 Nov 2024

    If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot mode and will implement lockdown, yet it could have been tampered. This flaw is a reintroduction of CVE-2020-15705 and only affects grub2 versions prior to 2.06 and upstream and distributions using the shim_lock mechanism.

    Published: 2 Mar 2021
    7.6
    High

    CVE-2020-25647

    Last Modified: 21 Nov 2024

    A flaw was found in grub2 in versions prior to 2.06. During USB device initialization, descriptors are read with very little bounds checking and assumes the USB device is providing sane values. If properly exploited, an attacker could trigger memory corruption leading to arbitrary code execution allowing a bypass of the Secure Boot mechanism. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 2 Mar 2021
    6.7
    Medium

    CVE-2020-27749

    Last Modified: 21 Nov 2024

    A flaw was found in grub2 in versions prior to 2.06. Variable names present are expanded in the supplied command line into their corresponding variable contents, using a 1kB stack buffer for temporary storage, without sufficient bounds checking. If the function is called with a command line that references a variable with a sufficiently large payload, it is possible to overflow the stack buffer, corrupt the stack frame and control execution which could also circumvent Secure Boot protections. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 2 Mar 2021
    8.2
    High

    CVE-2021-20233

    Last Modified: 21 Nov 2024

    A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters, while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each quote in the input. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 2 Mar 2021
    7.5
    High

    CVE-2021-25330

    Last Modified: 21 Nov 2024

    Calling of non-existent provider in MobileWips application prior to SMR Feb-2021 Release 1 allows unauthorized actions including denial of service attack by hijacking the provider.

    Published: 2 Mar 2021
    5.3
    Medium

    CVE-2021-3384

    Last Modified: 21 Nov 2024

    A vulnerability in Stormshield Network Security could allow an attacker to trigger a protection related to ARP/NDP tables management, which would temporarily prevent the system to contact new hosts via IPv4 or IPv6. This affects versions 2.0.0 to 2.7.7, 2.8.0 to 2.16.0, 3.0.0 to 3.7.16, 3.8.0 to 3.11.4, and 4.0.0 to 4.1.5. Fixed in versions 2.7.8, 3.7.17, 3.11.5, and 4.2.0.

    Published: 2 Mar 2021
    3.3
    Low

    CVE-2020-4726

    Last Modified: 21 Nov 2024

    The IBM Application Performance Monitoring UI (IBM Cloud APM 8.1.4) allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 187975.

    Published: 2 Mar 2021
    3.5
    Low

    CVE-2020-4725

    Last Modified: 21 Nov 2024

    IBM Monitoring (IBM Cloud APM 8.1.4 ) could allow an authenticated user to modify HTML content by sending a specially crafted HTTP request to the APM UI, which could mislead another user. IBM X-Force ID: 187974.

    Published: 2 Mar 2021
    4.9
    Medium

    CVE-2020-4719

    Last Modified: 21 Nov 2024

    The IBM Cloud APM 8.1.4 server will issue a DNS request to resolve any hostname specified in the Cloud Event Management Webhook URL configuration definition. This could enable an authenticated user with admin authorization to create DNS query strings that are not hostnames. IBM X-Force ID: 187861.

    Published: 2 Mar 2021
    5.4
    Medium

    CVE-2020-23518

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in UltimateKode Neo Billing - Accounting, Invoicing And CRM Software up to version 3.5 which allows remote attackers to inject arbitrary web script or HTML.

    Published: 2 Mar 2021
    4.9
    Medium

    CVE-2021-21514

    Last Modified: 21 Nov 2024

    Dell EMC OpenManage Server Administrator (OMSA) versions 9.5 and prior contain a path traversal vulnerability. A remote user with admin privileges could potentially exploit this vulnerability to view arbitrary files on the target system by sending a specially crafted URL request.

    Published: 2 Mar 2021
    8.6
    High

    CVE-2021-21513

    Last Modified: 21 Nov 2024

    Dell EMC OpenManage Server Administrator (OMSA) version 9.5 Microsoft Windows installations with Distributed Web Server (DWS) enabled configuration contains an authentication bypass vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain admin access on the affected system.

    Published: 2 Mar 2021
    6.1
    Medium

    CVE-2020-25902

    Last Modified: 21 Nov 2024

    Blackboard Collaborate Ultra 20.02 is affected by a cross-site scripting (XSS) vulnerability. The XSS payload will execute on the class room, which leads to stealing cookies from users who join the class. NOTE: Third-parties dispute the validity of this entry as a possible false positive during research

    Published: 2 Mar 2021
    6.1
    Medium

    CVE-2020-1936

    Last Modified: 13 Feb 2025

    A cross-site scripting issue was found in Apache Ambari Views. This was addressed in Apache Ambari 2.7.4.

    Published: 2 Mar 2021
    5.5
    Medium

    CVE-2021-27904

    Last Modified: 21 Nov 2024

    An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139. In the implementation of Sharing Groups, the "all org" flag sometimes provided view access to unintended actors.

    Published: 2 Mar 2021
    6.8
    Medium

    CVE-2021-27901

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 11 software. They mishandle fingerprint recognition because local high beam mode (LHBM) does not function properly during bright illumination. The LG ID is LVE-SMP-210001 (March 2021).

    Published: 2 Mar 2021
    2.6
    Low

    CVE-2021-21320

    Last Modified: 21 Nov 2024

    matrix-react-sdk is an npm package which is a Matrix SDK for React Javascript. In matrix-react-sdk before version 3.15.0, the user content sandbox can be abused to trick users into opening unexpected documents. The content is opened with a `blob` origin that cannot access Matrix user data, so messages and secrets are not at risk. This has been fixed in version 3.15.0.

    Published: 2 Mar 2021
    9.8
    Critical

    CVE-2021-27730

    Last Modified: 21 Nov 2024

    Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint. The fixed version is FTA_9_12_444 and later.

    Published: 2 Mar 2021
    6.1
    Medium

    CVE-2021-27731

    Last Modified: 21 Nov 2024

    Accellion FTA 9_12_432 and earlier is affected by stored XSS via a crafted POST request to a user endpoint. The fixed version is FTA_9_12_444 and later.

    Published: 2 Mar 2021
    9.8
    Critical

    CVE-2021-25309

    Last Modified: 21 Nov 2024

    The telnet administrator service running on port 650 on Gigaset DX600A v41.00-175 devices does not implement any lockout or throttling functionality. This situation (together with the weak password policy that forces a 4-digit password) allows remote attackers to easily obtain administrative access via brute-force attacks.

    Published: 2 Mar 2021
    7.5
    High

    CVE-2021-25306

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in the AT command interface of Gigaset DX600A v41.00-175 devices allows remote attackers to force a device reboot by sending relatively long AT commands.

    Published: 2 Mar 2021
    9.8
    Critical

    CVE-2021-27804

    Last Modified: 21 Nov 2024

    JPEG XL (aka jpeg-xl) through 0.3.2 allows writable memory corruption.

    Published: 2 Mar 2021
    6.1
    Medium

    CVE-2021-27888

    Last Modified: 21 Nov 2024

    ZendTo before 6.06-4 Beta allows XSS during the display of a drop-off in which a filename has unexpected characters.

    Published: 2 Mar 2021
    5.5
    Medium

    CVE-2021-20269

    Last Modified: 21 Nov 2024

    A flaw was found in the permissions of a log file created by kexec-tools. This flaw allows a local unprivileged user to read this file and leak kernel internal information from a previous panic. The highest threat from this vulnerability is to confidentiality. This flaw affects kexec-tools shipped by Fedora versions prior to 2.0.21-8 and RHEL versions prior to 2.0.20-47.

    Published: 2 Mar 2021
    6.1
    Medium

    CVE-2020-25715

    Last Modified: 21 Nov 2024

    A flaw was found in pki-core 10.9.0. A specially crafted POST request can be used to reflect a DOM-based cross-site scripting (XSS) attack to inject code into the search query form which can get automatically executed. The highest threat from this vulnerability is to data integrity.

    Published: 2 Mar 2021
    5.5
    Medium

    CVE-2021-3467

    Last Modified: 21 Nov 2024

    A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF box in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened.

    Published: 2 Mar 2021
    9.8
    Critical

    CVE-2021-27886

    Last Modified: 21 Nov 2024

    rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter of an API request. NOTE: this is NOT a Docker, Inc. product.

    Published: 1 Mar 2021
    —
    Unknown

    CVE-2016-8155

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 1 Mar 2021
    —
    Unknown

    CVE-2016-8158

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 1 Mar 2021
    —
    Unknown

    CVE-2016-8156

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 1 Mar 2021
    —
    Unknown

    CVE-2016-8157

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 1 Mar 2021
    —
    Unknown

    CVE-2016-8159

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 1 Mar 2021
    —
    Unknown

    CVE-2016-8160

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 1 Mar 2021
    —
    Unknown

    CVE-2016-8148

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 1 Mar 2021