CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2016-8015

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 1 Mar 2021
    —
    Unknown

    CVE-2016-8045

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 1 Mar 2021
    —
    Unknown

    CVE-2016-8014

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 1 Mar 2021
    —
    Unknown

    CVE-2016-8044

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 1 Mar 2021
    —
    Unknown

    CVE-2016-8046

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 1 Mar 2021
    —
    Unknown

    CVE-2016-8043

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 1 Mar 2021
    —
    Unknown

    CVE-2016-8028

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 1 Mar 2021
    —
    Unknown

    CVE-2016-8040

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 1 Mar 2021
    —
    Unknown

    CVE-2016-8041

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 1 Mar 2021
    —
    Unknown

    CVE-2016-8042

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 1 Mar 2021
    —
    Unknown

    CVE-2016-8003

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 1 Mar 2021
    —
    Unknown

    CVE-2016-8004

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 1 Mar 2021
    —
    Unknown

    CVE-2016-8001

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 1 Mar 2021
    —
    Unknown

    CVE-2016-8013

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 1 Mar 2021
    5.1
    Medium

    CVE-2021-27884

    Last Modified: 21 Nov 2024

    Weak JSON Web Token (JWT) signing secret generation in YMFE YApi through 1.9.2 allows recreation of other users' JWT tokens. This occurs because Math.random in Node.js is used.

    Published: 1 Mar 2021
    8.2
    High

    CVE-2021-27877

    Last Modified: 3 Nov 2025

    An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer used in current versions of the product, but hadn't yet been disabled. An attacker could remotely exploit this scheme to gain unauthorized access to an Agent and execute privileged commands.

    Published: 1 Mar 2021
    8.8
    High

    CVE-2021-27878

    Last Modified: 3 Nov 2025

    An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. The attacker could use one of these commands to execute an arbitrary command on the system using system privileges.

    Published: 1 Mar 2021
    8.1
    High

    CVE-2021-27876

    Last Modified: 3 Nov 2025

    An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. By using crafted input parameters in one of these commands, an attacker can access an arbitrary file on the system using System privileges.

    Published: 1 Mar 2021
    8.8
    High

    CVE-2021-26704

    Last Modified: 21 Nov 2024

    EPrints 3.4.2 allows remote attackers to execute arbitrary commands via crafted input to the verb parameter in a cgi/toolbox/toolbox URI.

    Published: 1 Mar 2021
    9.8
    Critical

    CVE-2021-26703

    Last Modified: 21 Nov 2024

    EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input to a cgi/ajax/phrase URI.

    Published: 1 Mar 2021
    9.8
    Critical

    CVE-2021-3342

    Last Modified: 21 Nov 2024

    EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a cgi/latex2png?latex= URI.

    Published: 1 Mar 2021
    6.1
    Medium

    CVE-2021-26475

    Last Modified: 21 Nov 2024

    EPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI.

    Published: 1 Mar 2021
    9.8
    Critical

    CVE-2021-26476

    Last Modified: 21 Nov 2024

    EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI.

    Published: 1 Mar 2021
    6.1
    Medium

    CVE-2021-26702

    Last Modified: 21 Nov 2024

    EPrints 3.4.2 exposes a reflected XSS opportunity in the dataset parameter to the cgi/dataset_dictionary URI.

    Published: 1 Mar 2021
    7.2
    High

    CVE-2021-21517

    Last Modified: 21 Nov 2024

    SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML parser that processes user-supplied DTD input without sufficient validation. A remote unauthenticated attacker can potentially exploit this vulnerability to read system files as a non-root user and may be able to temporarily disrupt the ESRS service.

    Published: 1 Mar 2021
    9
    Critical

    CVE-2021-21515

    Last Modified: 21 Nov 2024

    Dell EMC SourceOne, versions 7.2SP10 and prior, contain a Stored Cross-Site Scripting vulnerability. A remote low privileged attacker may potentially exploit this vulnerability, to hijack user sessions or to trick a victim application user to unknowingly send arbitrary requests to the server.

    Published: 1 Mar 2021
    5.3
    Medium

    CVE-2021-3332

    Last Modified: 21 Nov 2024

    WPS Hide Login 1.6.1 allows remote attackers to bypass a protection mechanism via post_password.

    Published: 1 Mar 2021
    6.1
    Medium

    CVE-2021-27317

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to inject arbitrary web script or HTML via the comment parameter.

    Published: 1 Mar 2021
    6.1
    Medium

    CVE-2021-27318

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to inject arbitrary web script or HTML via the lastname parameter.

    Published: 1 Mar 2021
    8.2
    High

    CVE-2021-21378

    Last Modified: 21 Nov 2024

    Envoy is a cloud-native high-performance edge/middle/service proxy. In Envoy version 1.17.0 an attacker can bypass authentication by presenting a JWT token with an issuer that is not in the provider list when Envoy's JWT Authentication filter is configured with the `allow_missing` requirement under `requires_any` due to a mistake in implementation. Envoy's JWT Authentication filter can be configured with the `allow_missing` requirement that will be satisfied if JWT is missing (JwtMissed error) and fail if JWT is presented or invalid. Due to a mistake in implementation, a JwtUnknownIssuer error was mistakenly converted to JwtMissed when `requires_any` was configured. So if `allow_missing` was configured under `requires_any`, an attacker can bypass authentication by presenting a JWT token with an issuer that is not in the provider list. Integrity may be impacted depending on configuration if the JWT token is used to protect against writes or modifications. This regression was introduced on 2020/11/12 in PR 13839 which fixed handling `allow_missing` under RequiresAny in a JwtRequirement (see issue 13458). The AnyVerifier aggregates the children verifiers' results into a final status where JwtMissing is the default error. However, a JwtUnknownIssuer was mistakenly treated the same as a JwtMissing error and the resulting final aggregation was the default JwtMissing. As a result, `allow_missing` would allow a JWT token with an unknown issuer status. This is fixed in version 1.17.1 by PR 15194. The fix works by preferring JwtUnknownIssuer over a JwtMissing error, fixing the accidental conversion and bypass with `allow_missing`. A user could detect whether a bypass occurred if they have Envoy logs enabled with debug verbosity. Users can enable component level debug logs for JWT. The JWT filter logs will indicate that there is a request with a JWT token and a failure that the JWT token is missing.

    Published: 1 Mar 2021
    5.3
    Medium

    CVE-2021-22114

    Last Modified: 21 Nov 2024

    Addresses partial fix in CVE-2018-1263. Spring-integration-zip, versions prior to 1.0.4, exposes an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z), that holds path traversal filenames. So when the filename gets concatenated to the target extraction directory, the final path ends up outside of the target folder.

    Published: 1 Mar 2021
    9.8
    Critical

    CVE-2021-25914

    Last Modified: 30 Apr 2025

    Prototype pollution vulnerability in 'object-collider' versions 1.0.0 through 1.0.3 allows attacker to cause a denial of service and may lead to remote code execution.

    Published: 1 Mar 2021
    5.3
    Medium

    CVE-2020-36240

    Last Modified: 21 Nov 2024

    The ResourceDownloadRewriteRule class in Crowd before version 4.0.4, and from version 4.1.0 before 4.1.2 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.

    Published: 1 Mar 2021
    5.5
    Medium

    CVE-2020-9479

    Last Modified: 13 Feb 2025

    When loading a UDF, a specially crafted zip file could allow files to be placed outside of the UDF deployment directory. This issue affected Apache AsterixDB unreleased builds between commits 580b81aa5e8888b8e1b0620521a1c9680e54df73 and 28c0ee84f1387ab5d0659e9e822f4e3923ddc22d. Note: this CVE may be REJECTed as the issue did not affect any released versions of Apache AsterixDB

    Published: 1 Mar 2021
    9.8
    Critical

    CVE-2021-25833

    Last Modified: 21 Nov 2024

    A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21. The file extension is controlled by an attacker through the request data and leads to arbitrary file overwriting. Using this vulnerability, a remote attacker can obtain remote code execution on DocumentServer.

    Published: 1 Mar 2021
    9.8
    Critical

    CVE-2021-25832

    Last Modified: 21 Nov 2024

    A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v6.0.0. Using this vulnerability, an attacker is able to gain remote code executions on DocumentServer.

    Published: 1 Mar 2021
    9.8
    Critical

    CVE-2021-25831

    Last Modified: 21 Nov 2024

    A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. An attacker must request the conversion of the crafted file from PPTT into PPTX format. Using the chain of two other bugs related to improper string handling, a remote attacker can obtain remote code execution on DocumentServer.

    Published: 1 Mar 2021
    9.8
    Critical

    CVE-2021-25830

    Last Modified: 21 Nov 2024

    A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13. An attacker must request the conversion of the crafted file from DOCT into DOCX format. Using the chain of two other bugs related to improper string handling, an attacker can achieve remote code execution on DocumentServer.

    Published: 1 Mar 2021
    7.5
    High

    CVE-2021-25829

    Last Modified: 21 Nov 2024

    An improper binary stream data handling issue was found in the [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. Using this bug, an attacker is able to produce a denial of service attack that can eventually shut down the target server.

    Published: 1 Mar 2021
    5.4
    Medium

    CVE-2021-27225

    Last Modified: 21 Nov 2024

    In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects that they are not authorized to access.

    Published: 1 Mar 2021
    7
    High

    CVE-2021-25329

    Last Modified: 25 Aug 2026

    The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.

    Published: 1 Mar 2021
    7.5
    High

    CVE-2021-25122

    Last Modified: 25 Aug 2026

    When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.

    Published: 1 Mar 2021
    6.8
    Medium

    CVE-2021-20262

    Last Modified: 21 Nov 2024

    A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the password. This flaw allows an attacker to take over an account if they can obtain temporary, physical access to a user’s browser. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

    Published: 1 Mar 2021
    4.3
    Medium

    CVE-2021-22134

    Last Modified: 21 Nov 2024

    A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query against a recently updated document. This affects documents that have been updated and not yet refreshed in the index. This could result in the search disclosing the existence of documents and fields the attacker should not be able to view.

    Published: 1 Mar 2021
    4.8
    Medium

    CVE-2021-23346

    Last Modified: 21 Nov 2024

    This affects the package html-parse-stringify before 2.0.1; all versions of package html-parse-stringify2. Sending certain input could cause one of the regular expressions that is used for parsing to backtrack, freezing the process.

    Published: 1 Mar 2021
    5.5
    Medium

    CVE-2021-28650

    Last Modified: 21 Nov 2024

    autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-36241.

    Published: 1 Mar 2021
    6.5
    Medium

    CVE-2020-7929

    Last Modified: 21 Nov 2024

    A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type of regex. This issue affects MongoDB Server v3.6 versions prior to 3.6.21 and MongoDB Server v4.0 versions prior to 4.0.20.

    Published: 1 Mar 2021
    2.7
    Low

    CVE-2021-20286

    Last Modified: 21 Nov 2024

    A flaw was found in libnbd 1.7.3. An assertion failure in nbd_unlocked_opt_go in ilb/opt.c may lead to denial of service.

    Published: 1 Mar 2021
    5.5
    Medium

    CVE-2021-3446

    Last Modified: 21 Nov 2024

    A flaw was found in libtpms in versions before 0.8.2. The commonly used integration of libtpms with OpenSSL contained a vulnerability related to the returned IV (initialization vector) when certain symmetric ciphers were used. Instead of returning the last IV it returned the initial IV to the caller, thus weakening the subsequent encryption and decryption steps. The highest threat from this vulnerability is to data confidentiality.

    Published: 1 Mar 2021
    4.9
    Medium

    CVE-2018-25004

    Last Modified: 21 Nov 2024

    A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects MongoDB Server v4.0 versions prior to 4.0.6 and MongoDB Server v3.6 versions prior to 3.6.11.

    Published: 1 Mar 2021