CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2021-20661

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows authenticated attackers to delete arbitrary files and/or directories on the server via unspecified vectors.

    Published: 24 Feb 2021
    6.1
    Medium

    CVE-2021-20660

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to inject an arbitrary script via unspecified vectors.

    Published: 24 Feb 2021
    8.8
    High

    CVE-2021-20659

    Last Modified: 21 Nov 2024

    SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecified vectors. If the file is PHP script, an attacker may execute arbitrary code.

    Published: 24 Feb 2021
    9.8
    Critical

    CVE-2021-20658

    Last Modified: 21 Nov 2024

    SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server privilege via unspecified vectors.

    Published: 24 Feb 2021
    4.3
    Medium

    CVE-2021-20656

    Last Modified: 21 Nov 2024

    Exposure of information through directory listing in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to obtain the information inside the system, such as directories and/or file configurations via unspecified vectors.

    Published: 24 Feb 2021
    5.4
    Medium

    CVE-2021-20657

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to obtain and/or alter the setting information without the access privilege via unspecified vectors.

    Published: 24 Feb 2021
    8.8
    High

    CVE-2021-21974

    Last Modified: 2 Jun 2026

    OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service resulting in remote code execution.

    Published: 24 Feb 2021
    8.2
    High

    CVE-2020-11987

    Last Modified: 3 Nov 2025

    Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

    Published: 24 Feb 2021
    7.8
    High

    CVE-2021-20259

    Last Modified: 21 Nov 2024

    A flaw was found in the Foreman project. The Proxmox compute resource exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Versions before foreman_fog_proxmox 0.13.1 are affected

    Published: 24 Feb 2021
    7.8
    High

    CVE-2021-20260

    Last Modified: 21 Nov 2024

    A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 24 Feb 2021
    2.5
    Low

    CVE-2021-27645

    Last Modified: 9 Jun 2025

    The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service or Denial of Service on the local system. This is related to netgroupcache.c.

    Published: 24 Feb 2021
    8.2
    High

    CVE-2020-11988

    Last Modified: 21 Nov 2024

    Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.

    Published: 24 Feb 2021
    —
    Unknown

    CVE-2021-27650

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 24 Feb 2021
    6
    Medium

    CVE-2021-3416

    Last Modified: 21 Nov 2024

    A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0. The issue occurs in loopback mode of a NIC wherein reentrant DMA checks get bypassed. A guest user/process may use this flaw to consume CPU cycles or crash the QEMU process on the host resulting in DoS scenario.

    Published: 24 Feb 2021
    4.3
    Medium

    CVE-2021-21323

    Last Modified: 21 Nov 2024

    Brave is an open source web browser with a focus on privacy and security. In Brave versions 1.17.73-1.20.103, the CNAME adblocking feature added in Brave 1.17.73 accidentally initiated DNS requests that bypassed the Brave Tor proxy. Users with adblocking enabled would leak DNS requests from Tor windows to their DNS provider. (DNS requests that were not initiated by CNAME adblocking would go through Tor as expected.) This is fixed in Brave version 1.20.108

    Published: 23 Feb 2021
    7.8
    High

    CVE-2021-3410

    Last Modified: 21 Nov 2024

    A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may lead to local execution of arbitrary code in the user context.

    Published: 23 Feb 2021
    5.5
    Medium

    CVE-2021-3407

    Last Modified: 13 Feb 2025

    A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences.

    Published: 23 Feb 2021
    6.5
    Medium

    CVE-2021-3405

    Last Modified: 21 Nov 2024

    A flaw was found in libebml before 1.4.2. A heap overflow bug exists in the implementation of EbmlString::ReadData and EbmlUnicodeString::ReadData in libebml.

    Published: 23 Feb 2021
    5.3
    Medium

    CVE-2021-26595

    Last Modified: 21 Nov 2024

    In Directus 8.x through 8.8.1, an attacker can learn sensitive information such as the version of the CMS, the PHP version used by the site, and the name of the DBMS, simply by view the result of the api-aa, called automatically upon a connection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 23 Feb 2021
    8.8
    High

    CVE-2021-26594

    Last Modified: 21 Nov 2024

    In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any control by the back end. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 23 Feb 2021
    7.5
    High

    CVE-2021-26593

    Last Modified: 21 Nov 2024

    In Directus 8.x through 8.8.1, an attacker can see all users in the CMS using the API /users/{id}. For each call, they get in response a lot of information about the user (such as email address, first name, and last name) but also the secret for 2FA if one exists. This secret can be regenerated. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 23 Feb 2021
    5.3
    Medium

    CVE-2021-27583

    Last Modified: 21 Nov 2024

    In Directus 8.x through 8.8.1, an attacker can discover whether a user is present in the database through the password reset feature. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 23 Feb 2021
    7.4
    High

    CVE-2021-20247

    Last Modified: 21 Nov 2024

    A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not occur allowing a malicious or compromised server to use specially crafted mailbox names containing '..' path components to access data outside the designated mailbox on the opposite end of the synchronization channel. The highest threat from this vulnerability is to data confidentiality and integrity.

    Published: 23 Feb 2021
    4.3
    Medium

    CVE-2020-8297

    Last Modified: 21 Nov 2024

    Nextcloud Deck before 1.0.2 suffers from an insecure direct object reference (IDOR) vulnerability that permits users with a duplicate user identifier to access deck data of a previous deleted user.

    Published: 23 Feb 2021
    7.5
    High

    CVE-2021-22882

    Last Modified: 21 Nov 2024

    UniFi Protect before v1.17.1 allows an attacker to use spoofed cameras to perform a denial-of-service attack that may cause the UniFi Protect controller to crash.

    Published: 23 Feb 2021
    7.8
    High

    CVE-2020-28587

    Last Modified: 21 Nov 2024

    A specially crafted document can cause the document parser to copy data from a particular record type into a static-sized buffer within an object that is smaller than the size used for the copy, which will cause a heap-based buffer overflow. An attacker can entice the victim to open a document to trigger this vulnerability. This affects SoftMaker Software GmbH SoftMaker Office PlanMaker 2021 (Revision 1014).

    Published: 23 Feb 2021
    5.3
    Medium

    CVE-2020-7120

    Last Modified: 21 Nov 2024

    A local authenticated buffer overflow vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in ClearPass OnGuard could allow local authenticated users to cause a buffer overflow condition. A successful exploit could allow a local attacker to execute arbitrary code within the context the binary is running in, which is a lower privileged account.

    Published: 23 Feb 2021
    7.8
    High

    CVE-2021-26677

    Last Modified: 21 Nov 2024

    A local authenticated escalation of privilege vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in ClearPass OnGuard could allow local authenticated users on a Windows platform to elevate their privileges. A successful exploit could allow an attacker to execute arbitrary code with SYSTEM level privileges.

    Published: 23 Feb 2021
    7.2
    High

    CVE-2021-26679

    Last Modified: 21 Nov 2024

    A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.

    Published: 23 Feb 2021
    7.2
    High

    CVE-2021-26680

    Last Modified: 21 Nov 2024

    A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.

    Published: 23 Feb 2021
    9.1
    Critical

    CVE-2021-27582

    Last Modified: 21 Nov 2024

    org/mitre/oauth2/web/OAuthConfirmationController.java in the OpenID Connect server implementation for MITREid Connect through 1.3.3 contains a Mass Assignment (aka Autobinding) vulnerability. This arises due to unsafe usage of the @ModelAttribute annotation during the OAuth authorization flow, in which HTTP request parameters affect an authorizationRequest.

    Published: 23 Feb 2021
    6.1
    Medium

    CVE-2021-26678

    Last Modified: 21 Nov 2024

    A remote unauthenticated stored cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the web-based management interface of ClearPass could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim’s browser in the context of the affected interface.

    Published: 23 Feb 2021
    7.8
    High

    CVE-2021-22651

    Last Modified: 21 Nov 2024

    When loading a specially crafted file, Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10.1 are, while processing the extraction of temporary files, suffering from a directory traversal vulnerability, which allows an attacker to store arbitrary scripts into automatic startup folders.

    Published: 23 Feb 2021
    7.2
    High

    CVE-2021-26684

    Last Modified: 21 Nov 2024

    A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.

    Published: 23 Feb 2021
    6.1
    Medium

    CVE-2021-26682

    Last Modified: 21 Nov 2024

    A remote reflected cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the guest portal interface of ClearPass could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the portal. A successful exploit could allow an attacker to execute arbitrary script code in a victim’s browser in the context of the guest portal interface.

    Published: 23 Feb 2021
    7.2
    High

    CVE-2021-26681

    Last Modified: 21 Nov 2024

    A remote authenticated command Injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass CLI could allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.

    Published: 23 Feb 2021
    7.2
    High

    CVE-2021-26683

    Last Modified: 21 Nov 2024

    A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.

    Published: 23 Feb 2021
    6.5
    Medium

    CVE-2021-26686

    Last Modified: 21 Nov 2024

    A remote authenticated SQL Injection vulnerabilitiy was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the web-based management interface API of ClearPass could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass instance. An attacker could exploit this vulnerability to obtain and modify sensitive information in the underlying database.

    Published: 23 Feb 2021
    7.8
    High

    CVE-2021-27579

    Last Modified: 21 Nov 2024

    Snow Inventory Agent through 6.7.0 on Windows uses CPUID to report on processor types and versions that may be deployed and in use across an IT environment. A privilege-escalation vulnerability exists if CPUID is enabled, and thus it should be disabled via configuration settings.

    Published: 23 Feb 2021
    6.5
    Medium

    CVE-2021-26685

    Last Modified: 21 Nov 2024

    A remote authenticated SQL Injection vulnerabilitiy was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the web-based management interface API of ClearPass could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass instance. An attacker could exploit this vulnerability to obtain and modify sensitive information in the underlying database.

    Published: 23 Feb 2021
    5.4
    Medium

    CVE-2020-26609

    Last Modified: 21 Nov 2024

    fastadmin V1.0.0.20200506_beta contains a cross-site scripting (XSS) vulnerability which may allow an attacker to obtain administrator credentials to log in to the background.

    Published: 23 Feb 2021
    7.8
    High

    CVE-2020-16243

    Last Modified: 21 Nov 2024

    Multiple buffer overflow vulnerabilities exist when LeviStudioU (Version 2019-09-21 and prior) processes project files. Opening a specially crafted project file could allow an attacker to exploit and execute code under the privileges of the application.

    Published: 23 Feb 2021
    8.8
    High

    CVE-2020-25161

    Last Modified: 21 Nov 2024

    The WADashboard component of WebAccess/SCADA Versions 9.0 and prior may allow an attacker to control or influence a path used in an operation on the filesystem and remotely execute code as an administrator.

    Published: 23 Feb 2021
    5.3
    Medium

    CVE-2021-22113

    Last Modified: 21 Nov 2024

    Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vulnerable to bypassing the “Sensitive Headers” restriction when executing requests with specially constructed URLs. Applications that use Spring Security's StrictHttpFirewall (enabled by default for all URLs) are not affected by the vulnerability, as they reject requests that allow bypassing.

    Published: 23 Feb 2021
    7.4
    High

    CVE-2020-7847

    Last Modified: 21 Nov 2024

    The ipTIME NAS product allows an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can be leveraged to gain remote code execution. This issue affects: pTIME NAS 1.4.36.

    Published: 23 Feb 2021
    7.8
    High

    CVE-2021-25630

    Last Modified: 21 Nov 2024

    "loolforkit" is a privileged program that is supposed to be run by a special, non-privileged "lool" user. Before doing anything else "loolforkit" checks, if it was invoked by the "lool" user, and refuses to run with privileges, if it's not the case. In the vulnerable version of "loolforkit" this check was wrong, so a normal user could start "loolforkit" and eventually get local root privileges.

    Published: 23 Feb 2021
    —
    Unknown

    CVE-2020-28432

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 23 Feb 2021
    —
    Unknown

    CVE-2020-28430

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 23 Feb 2021
    4.3
    Medium

    CVE-2020-4953

    Last Modified: 21 Nov 2024

    IBM Planning Analytics 2.0 could allow a remote authenticated attacker to obtain information about an organization's internal structure by exposing sensitive information in HTTP repsonses. IBM X-Force ID: 192029.

    Published: 23 Feb 2021
    —
    Unknown

    CVE-2020-28431

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 23 Feb 2021