CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2019-18943

    Last Modified: 21 Nov 2024

    Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to XML External Entity Processing (XXE) on certain operations.

    Published: 26 Feb 2021
    5.5
    Medium

    CVE-2019-18942

    Last Modified: 21 Nov 2024

    Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to stored XSS. The application reflects previously stored user input without encoding.

    Published: 26 Feb 2021
    4.9
    Medium

    CVE-2019-18944

    Last Modified: 21 Nov 2024

    Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to reflected XSS.

    Published: 26 Feb 2021
    7.3
    High

    CVE-2019-18945

    Last Modified: 21 Nov 2024

    Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to privilege escalation vulnerability.

    Published: 26 Feb 2021
    3.5
    Low

    CVE-2019-18947

    Last Modified: 21 Nov 2024

    Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to information disclosure.

    Published: 26 Feb 2021
    4.8
    Medium

    CVE-2019-18946

    Last Modified: 21 Nov 2024

    Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to session fixation.

    Published: 26 Feb 2021
    4.4
    Medium

    CVE-2021-21724

    Last Modified: 21 Nov 2024

    A ZTE product has a memory leak vulnerability. Due to the product's improper handling of memory release in certain scenarios, a local attacker with device permissions repeatedly attenuated the optical signal to cause memory leak and abnormal service. This affects: ZXR10 8900E, all versions up to V3.03.20R2B30P1.

    Published: 26 Feb 2021
    5.3
    Medium

    CVE-2021-23977

    Last Modified: 21 Nov 2024

    Firefox for Android suffered from a time-of-check-time-of-use vulnerability that allowed a malicious application to read sensitive data from application directories. Note: This issue is only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 86.

    Published: 26 Feb 2021
    4.3
    Medium

    CVE-2021-23963

    Last Modified: 21 Nov 2024

    When sharing geolocation during an active WebRTC share, Firefox could have reset the webRTC sharing state in the user interface, leading to loss of control over the currently granted permission. This vulnerability affects Firefox < 85.

    Published: 26 Feb 2021
    6.1
    Medium

    CVE-2021-23955

    Last Modified: 21 Nov 2024

    The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to clickjacking attacks. This vulnerability affects Firefox < 85.

    Published: 26 Feb 2021
    6.5
    Medium

    CVE-2021-23956

    Last Modified: 21 Nov 2024

    An ambiguous file picker design could have confused users who intended to select and upload a single file into uploading a whole directory. This was addressed by adding a new prompt. This vulnerability affects Firefox < 85.

    Published: 26 Feb 2021
    7.4
    High

    CVE-2021-23957

    Last Modified: 21 Nov 2024

    Navigations through the Android-specific `intent` URL scheme could have been misused to escape iframe sandbox. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.

    Published: 26 Feb 2021
    6.5
    Medium

    CVE-2021-23958

    Last Modified: 21 Nov 2024

    The browser could have been confused into transferring a screen sharing state into another tab, which would leak unintended information. This vulnerability affects Firefox < 85.

    Published: 26 Feb 2021
    6.1
    Medium

    CVE-2021-23959

    Last Modified: 21 Nov 2024

    An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.

    Published: 26 Feb 2021
    7.4
    High

    CVE-2021-23961

    Last Modified: 21 Nov 2024

    Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 85.

    Published: 26 Feb 2021
    8.8
    High

    CVE-2021-23962

    Last Modified: 21 Nov 2024

    Incorrect use of the '<RowCountChanged>' method could have led to a user-after-poison and a potentially exploitable crash. This vulnerability affects Firefox < 85.

    Published: 26 Feb 2021
    6.5
    Medium

    CVE-2021-23970

    Last Modified: 21 Nov 2024

    Context-specific code was included in a shared jump table; resulting in assertions being triggered in multithreaded wasm code. This vulnerability affects Firefox < 86.

    Published: 26 Feb 2021
    6.5
    Medium

    CVE-2021-23971

    Last Modified: 21 Nov 2024

    When processing a redirect with a conflicting Referrer-Policy, Firefox would have adopted the redirect's Referrer-Policy. This would have potentially resulted in more information than intended by the original origin being provided to the destination of the redirect. This vulnerability affects Firefox < 86.

    Published: 26 Feb 2021
    8.8
    High

    CVE-2021-23972

    Last Modified: 21 Nov 2024

    One phishing tactic on the web is to provide a link with HTTP Auth. For example 'https://[email protected]'. To mitigate this type of attack, Firefox will display a warning dialog; however, this warning dialog would not have been displayed if evil.com used a redirect that was cached by the browser. This vulnerability affects Firefox < 86.

    Published: 26 Feb 2021
    6.1
    Medium

    CVE-2021-23974

    Last Modified: 21 Nov 2024

    The DOMParser API did not properly process '<noscript>' elements for escaping. This could be used as an mXSS vector to bypass an HTML Sanitizer. This vulnerability affects Firefox < 86.

    Published: 26 Feb 2021
    6.5
    Medium

    CVE-2021-23975

    Last Modified: 21 Nov 2024

    The developer page about:memory has a Measure function for exploring what object types the browser has allocated and their sizes. When this function was invoked we incorrectly called the sizeof function, instead of using the API method that checks for invalid pointers. This vulnerability affects Firefox < 86.

    Published: 26 Feb 2021
    8.1
    High

    CVE-2021-23976

    Last Modified: 21 Nov 2024

    When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to cross-origin attacks on targeted websites. Note: This issue is a different issue from CVE-2020-26954 and only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 86.

    Published: 26 Feb 2021
    5.3
    Medium

    CVE-2021-21328

    Last Modified: 21 Nov 2024

    Vapor is a web framework for Swift. In Vapor before version 4.40.1, there is a DoS attack against anyone who Bootstraps a metrics backend for their Vapor app. The following is the attack vector: 1. send unlimited requests against a vapor instance with different paths. this will create unlimited counters and timers, which will eventually drain the system. 2. downstream services might suffer from this attack as well by being spammed with error paths. This has been patched in 4.40.1. The `DefaultResponder` will rewrite any undefined route paths for to `vapor_route_undefined` to avoid unlimited counters.

    Published: 26 Feb 2021
    5.2
    Medium

    CVE-2020-27223

    Last Modified: 20 Aug 2025

    In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.

    Published: 26 Feb 2021
    5.5
    Medium

    CVE-2021-30178

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 5.11.11. synic_get in arch/x86/kvm/hyperv.c has a NULL pointer dereference for certain accesses to the SynIC Hyper-V context, aka CID-919f4ebc5987.

    Published: 26 Feb 2021
    7.8
    High

    CVE-2021-26700

    Last Modified: 16 Jul 2025

    Visual Studio Code npm-script Extension Remote Code Execution Vulnerability

    Published: 25 Feb 2021
    7.8
    High

    CVE-2021-25195

    Last Modified: 21 Nov 2024

    Windows PKU2U Elevation of Privilege Vulnerability

    Published: 25 Feb 2021
    5.7
    Medium

    CVE-2021-24114

    Last Modified: 21 Nov 2024

    Microsoft Teams iOS Information Disclosure Vulnerability

    Published: 25 Feb 2021
    5.4
    Medium

    CVE-2021-24113

    Last Modified: 21 Nov 2024

    Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

    Published: 25 Feb 2021
    6.8
    Medium

    CVE-2021-24109

    Last Modified: 21 Nov 2024

    Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability

    Published: 25 Feb 2021
    5.5
    Medium

    CVE-2021-24106

    Last Modified: 21 Nov 2024

    Windows DirectX Information Disclosure Vulnerability

    Published: 25 Feb 2021
    8.4
    High

    CVE-2021-24105

    Last Modified: 24 Feb 2026

    <p>Depending on configuration of various package managers it is possible for an attacker to insert a malicious package into a package manager's repository which can be retrieved and used during development, build, and release processes. This insertion could lead to remote code execution. We believe this vulnerability affects multiple package managers across multiple languages, including but not limited to: Python/pip, .NET/NuGet, Java/Maven, JavaScript/npm.</p> <p><strong>Attack scenarios</strong></p> <p>An attacker could take advantage of this ecosystem-wide issue to cause harm in a variety of ways. The original attack scenarios were discovered by Alex Birsan and are detailed in their whitepaper, <a href="https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610">Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies</a>.</p> <ul> <li><p>With basic knowledge of the target ecosystems, an attacker could create an empty shell for a package and insert malicious code in the install scripts, give it a high version, and publish it to the public repository. Vulnerable victim machines will download the higher version of the package between the public and private repositories and attempt to install it. Due to code incompatibility it will probably error out upon import or upon compilation, making it easier to detect; however the attacker would have gained code execution by that point.</p> </li> <li><p>An advanced attacker with some inside knowledge of the target could take a copy of a working package, insert the malicious code (in the package itself or in the install), and then publish it to a public repository. The package will likely install and import correctly, granting the attacker an initial foothold and persistence.</p> </li> </ul> <p>These two methods could affect target organizations at any of these various levels:</p> <ul> <li>Developer machines</li> <li>An entire team if the configuration to import the malicious package is uploaded to a code repository</li> <li>Continuous integration pipelines if they pull the malicious packages during the build, test, and/or deploy stages</li> <li>Customers, download servers, production services if the malicious code has not been detected</li> </ul> <p>This remote code execution vulnerability can only be addressed by reconfiguring installation tools and workflows, and not by correcting anything in the package repositories themselves. See the <strong>FAQ</strong> section of this CVE for configuration guidance.</p>

    Published: 25 Feb 2021
    7.8
    High

    CVE-2021-24103

    Last Modified: 21 Nov 2024

    Windows Event Tracing Elevation of Privilege Vulnerability

    Published: 25 Feb 2021
    6.5
    Medium

    CVE-2021-24101

    Last Modified: 21 Nov 2024

    Microsoft Dataverse Information Disclosure Vulnerability

    Published: 25 Feb 2021
    7.8
    High

    CVE-2021-24102

    Last Modified: 21 Nov 2024

    Windows Event Tracing Elevation of Privilege Vulnerability

    Published: 25 Feb 2021
    5
    Medium

    CVE-2021-24100

    Last Modified: 21 Nov 2024

    Microsoft Edge for Android Information Disclosure Vulnerability

    Published: 25 Feb 2021
    5.5
    Medium

    CVE-2021-24098

    Last Modified: 21 Nov 2024

    Windows Console Driver Denial of Service Vulnerability

    Published: 25 Feb 2021
    6.5
    Medium

    CVE-2021-24099

    Last Modified: 21 Nov 2024

    Skype for Business and Lync Denial of Service Vulnerability

    Published: 25 Feb 2021
    9.8
    Critical

    CVE-2021-24094

    Last Modified: 21 Nov 2024

    Windows TCP/IP Remote Code Execution Vulnerability

    Published: 25 Feb 2021
    7.8
    High

    CVE-2021-24096

    Last Modified: 21 Nov 2024

    Windows Kernel Elevation of Privilege Vulnerability

    Published: 25 Feb 2021
    8.8
    High

    CVE-2021-24093

    Last Modified: 21 Nov 2024

    Windows Graphics Component Remote Code Execution Vulnerability

    Published: 25 Feb 2021
    7.8
    High

    CVE-2021-24092

    Last Modified: 21 Nov 2024

    Microsoft Defender Elevation of Privilege Vulnerability

    Published: 25 Feb 2021
    8.8
    High

    CVE-2021-24088

    Last Modified: 21 Nov 2024

    Windows Local Spooler Remote Code Execution Vulnerability

    Published: 25 Feb 2021
    7.8
    High

    CVE-2021-24091

    Last Modified: 21 Nov 2024

    Windows Camera Codec Pack Remote Code Execution Vulnerability

    Published: 25 Feb 2021
    7.5
    High

    CVE-2021-24086

    Last Modified: 21 Nov 2024

    Windows TCP/IP Denial of Service Vulnerability

    Published: 25 Feb 2021
    7
    High

    CVE-2021-24087

    Last Modified: 21 Nov 2024

    Azure IoT CLI extension Elevation of Privilege Vulnerability

    Published: 25 Feb 2021
    6.5
    Medium

    CVE-2021-24085

    Last Modified: 21 Nov 2024

    Microsoft Exchange Server Spoofing Vulnerability

    Published: 25 Feb 2021
    7.8
    High

    CVE-2021-24083

    Last Modified: 21 Nov 2024

    Windows Address Book Remote Code Execution Vulnerability

    Published: 25 Feb 2021
    5.5
    Medium

    CVE-2021-24084

    Last Modified: 21 Nov 2024

    Windows Mobile Device Management Information Disclosure Vulnerability

    Published: 25 Feb 2021
    4.3
    Medium

    CVE-2021-24082

    Last Modified: 21 Nov 2024

    Microsoft.PowerShell.Utility Module WDAC Security Feature Bypass Vulnerability

    Published: 25 Feb 2021