CVE Feed

    Dashboard / CVE

    7.3
    High

    CVE-2020-28429

    Last Modified: 21 Nov 2024

    All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geojson2kml"); a("./","& touch JHU",function(){})

    Published: 23 Feb 2021
    5.5
    Medium

    CVE-2021-27550

    Last Modified: 21 Nov 2024

    Polaris Office v9.102.66 is affected by a divide-by-zero error in PolarisOffice.exe and EngineDLL.dll that may cause a local denial of service. To exploit the vulnerability, someone must open a crafted PDF file.

    Published: 23 Feb 2021
    7.5
    High

    CVE-2021-3252

    Last Modified: 21 Nov 2024

    KACO New Energy XP100U Up to XP-JAVA 2.0 is affected by incorrect access control. Credentials will always be returned in plain-text from the local server during the KACO XP100U authentication process, regardless of whatever passwords have been provided, which leads to an information disclosure vulnerability.

    Published: 23 Feb 2021
    3.5
    Low

    CVE-2020-8902

    Last Modified: 21 Nov 2024

    Rendertron versions prior to 3.0.0 are are susceptible to a Server-Side Request Forgery (SSRF) attack. An attacker can use a specially crafted webpage to force a rendertron headless chrome process to render internal sites it has access to, and display it as a screenshot. Suggested mitigations are to upgrade your rendertron to version 3.0.0, or, if you cannot update, to secure the infrastructure to limit the headless chrome's access to your internal domain.

    Published: 23 Feb 2021
    6.1
    Medium

    CVE-2020-13697

    Last Modified: 21 Nov 2024

    An issue was discovered in RouterNanoHTTPD.java in NanoHTTPD through 2.3.1. The GeneralHandler class implements a basic GET handler that prints debug information as an HTML page. Any web server that extends this class without implementing its own GET handler is vulnerable to reflected XSS, because the GeneralHandler GET handler prints user input passed through the query string without any sanitization.

    Published: 23 Feb 2021
    5.5
    Medium

    CVE-2020-27819

    Last Modified: 21 Nov 2024

    An issue was discovered in libxls before and including 1.6.1 when reading Microsoft Excel files. A NULL pointer dereference vulnerability exists when parsing XLS cells in libxls/xls2csv.c:199. It could allow a remote attacker to cause a denial of service via crafted XLS file.

    Published: 23 Feb 2021
    7.1
    High

    CVE-2020-29075

    Last Modified: 21 Nov 2024

    Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.30180 (and earlier) are affected by an information exposure vulnerability, that could enable an attacker to get a DNS interaction and track if the user has opened or closed a PDF file when loaded from the filesystem without a prompt. User interaction is required to exploit this vulnerability.

    Published: 23 Feb 2021
    7.8
    High

    CVE-2021-22647

    Last Modified: 21 Nov 2024

    Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10.1 are vulnerable to multiple out-of-bounds write issues while processing project files, which may allow an attacker to execute arbitrary code.

    Published: 23 Feb 2021
    7.8
    High

    CVE-2021-22643

    Last Modified: 21 Nov 2024

    Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10.1 are vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to execute arbitrary code.

    Published: 23 Feb 2021
    7.8
    High

    CVE-2021-22645

    Last Modified: 21 Nov 2024

    Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10.1 are vulnerable to an attack because the .bip documents display a “load” command, which can be pointed to a .dll from a remote network share. As a result, the .dll entry point can be executed without sufficient UI warning.

    Published: 23 Feb 2021
    7.8
    High

    CVE-2021-22649

    Last Modified: 21 Nov 2024

    Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10.1 have multiple NULL pointer dereference issues while processing project files, which may allow an attacker to execute arbitrary code.

    Published: 23 Feb 2021
    6.1
    Medium

    CVE-2020-35852

    Last Modified: 21 Nov 2024

    Chatbox is affected by cross-site scripting (XSS). An attacker has to upload any XSS payload with SVG, XML file in Chatbox. There is no restriction on file upload in Chatbox which leads to stored XSS.

    Published: 23 Feb 2021
    10
    Critical

    CVE-2021-21322

    Last Modified: 21 Nov 2024

    fastify-http-proxy is an npm package which is a fastify plugin for proxying your http requests to another server, with hooks. By crafting a specific URL, it is possible to escape the prefix of the proxied backend service. If the base url of the proxied server is `/pub/`, a user expect that accessing `/priv` on the target service would not be possible. In affected versions, it is possible. This is fixed in version 4.3.1.

    Published: 23 Feb 2021
    4.3
    Medium

    CVE-2021-23969

    Last Modified: 21 Nov 2024

    As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested by the page, pre-redirects. If that’s not possible, user agents need to strip the URL down to an origin to avoid unintentional leakage." Under certain types of redirects, Firefox incorrectly set the source file to be the destination of the redirects. This was fixed to be the redirect destination's origin. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.

    Published: 23 Feb 2021
    5.9
    Medium

    CVE-2021-27568

    Last Modified: 21 Nov 2024

    An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.

    Published: 23 Feb 2021
    6.5
    Medium

    CVE-2021-23973

    Last Modified: 21 Nov 2024

    When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have revealed information about the resource. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.

    Published: 23 Feb 2021
    8.8
    High

    CVE-2021-23978

    Last Modified: 21 Nov 2024

    Mozilla developers reported memory safety bugs present in Firefox 85 and Firefox ESR 78.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.

    Published: 23 Feb 2021
    5.5
    Medium

    CVE-2021-36980

    Last Modified: 5 May 2025

    Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_decode) during the decoding of a RAW_ENCAP action.

    Published: 23 Feb 2021
    4.3
    Medium

    CVE-2021-23968

    Last Modified: 21 Nov 2024

    If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. This could be used to leak sensitive information contained in such URIs. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.

    Published: 23 Feb 2021
    10
    Critical

    CVE-2021-21321

    Last Modified: 21 Nov 2024

    fastify-reply-from is an npm package which is a fastify plugin to forward the current http request to another server. In fastify-reply-from before version 4.0.2, by crafting a specific URL, it is possible to escape the prefix of the proxied backend service. If the base url of the proxied server is "/pub/", a user expect that accessing "/priv" on the target service would not be possible. In affected versions, it is possible. This is fixed in version 4.0.2.

    Published: 23 Feb 2021
    5.9
    Medium

    CVE-2021-27189

    Last Modified: 21 Nov 2024

    The CIRA Canadian Shield app before 4.0.13 for iOS lacks SSL Certificate Validation.

    Published: 22 Feb 2021
    5.5
    Medium

    CVE-2021-23827

    Last Modified: 21 Nov 2024

    Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive media (such as private pictures) in the Cache and uploadtemps directories. It fails to effectively clear cached pictures, even after deletion via normal methodology within the client, or by utilizing the "Explode message/Explode now" functionality. Local filesystem access is needed by the attacker.

    Published: 22 Feb 2021
    8.8
    High

    CVE-2021-21156

    Last Modified: 21 Nov 2024

    Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted script.

    Published: 22 Feb 2021
    8.8
    High

    CVE-2021-21157

    Last Modified: 21 Nov 2024

    Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 22 Feb 2021
    9.6
    Critical

    CVE-2021-21155

    Last Modified: 21 Nov 2024

    Heap buffer overflow in Tab Strip in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

    Published: 22 Feb 2021
    8.8
    High

    CVE-2021-21153

    Last Modified: 21 Nov 2024

    Stack buffer overflow in GPU Process in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

    Published: 22 Feb 2021
    9.6
    Critical

    CVE-2021-21154

    Last Modified: 21 Nov 2024

    Heap buffer overflow in Tab Strip in Google Chrome prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

    Published: 22 Feb 2021
    8.8
    High

    CVE-2021-21152

    Last Modified: 21 Nov 2024

    Heap buffer overflow in Media in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 22 Feb 2021
    9.6
    Critical

    CVE-2021-21150

    Last Modified: 21 Nov 2024

    Use after free in Downloads in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

    Published: 22 Feb 2021
    9.6
    Critical

    CVE-2021-21151

    Last Modified: 21 Nov 2024

    Use after free in Payments in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

    Published: 22 Feb 2021
    8.8
    High

    CVE-2021-21149

    Last Modified: 21 Nov 2024

    Stack buffer overflow in Data Transfer in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.

    Published: 22 Feb 2021
    5
    Medium

    CVE-2020-36232

    Last Modified: 21 Nov 2024

    The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, from version 4.4.0 before 4.4.12, and from version 5.0.0 before 5.0.1 allowed unexpected DNS lookups and requests to arbitrary services as it incorrectly obtained application base url information from the executing http request which could be attacker controlled.

    Published: 22 Feb 2021
    8.6
    High

    CVE-2021-26724

    Last Modified: 21 Nov 2024

    OS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and CMC allows authenticated administrators to perform remote code execution. This issue affects: Nozomi Networks Guardian 20.0.7.3 version 20.0.7.3 and prior versions. Nozomi Networks CMC 20.0.7.3 version 20.0.7.3 and prior versions.

    Published: 22 Feb 2021
    8.6
    High

    CVE-2021-26725

    Last Modified: 21 Nov 2024

    Path Traversal vulnerability when changing timezone using web GUI of Nozomi Networks Guardian, CMC allows an authenticated administrator to read-protected system files. This issue affects: Nozomi Networks Guardian 20.0.7.3 version 20.0.7.3 and prior versions. Nozomi Networks CMC 20.0.7.3 version 20.0.7.3 and prior versions.

    Published: 22 Feb 2021
    5.4
    Medium

    CVE-2021-27279

    Last Modified: 21 Nov 2024

    MyBB before 1.8.25 allows stored XSS via nested [email] tags with MyCode (aka BBCode).

    Published: 22 Feb 2021
    5.3
    Medium

    CVE-2021-27549

    Last Modified: 21 Nov 2024

    Genymotion Desktop through 3.2.0 leaks the host's clipboard data to the Android application by default. NOTE: the vendor's position is that this is intended behavior that can be changed through the Settings > Device screen

    Published: 22 Feb 2021
    9.8
    Critical

    CVE-2021-27228

    Last Modified: 21 Nov 2024

    An issue was discovered in Shinobi through ocean version 1. lib/auth.js has Incorrect Access Control. Valid API Keys are held in an internal JS Object. Therefore an attacker can use JS Proto Method names (such as constructor or hasOwnProperty) to convince the System that the supplied API Key exists in the underlying JS object, and consequently achieve complete access to User/Admin/Super API functions, as demonstrated by a /super/constructor/accounts/list URI.

    Published: 22 Feb 2021
    6.8
    Medium

    CVE-2020-22475

    Last Modified: 21 Nov 2024

    "Tasks" application version before 9.7.3 is affected by insecure permissions. The VoiceCommandActivity application component allows arbitrary applications on a device to add tasks with no restrictions.

    Published: 22 Feb 2021
    6.5
    Medium

    CVE-2020-22474

    Last Modified: 21 Nov 2024

    In webERP 4.15, the ManualContents.php file allows users to specify the "Language" parameter, which can lead to local file inclusion.

    Published: 22 Feb 2021
    5.4
    Medium

    CVE-2021-27564

    Last Modified: 21 Nov 2024

    A stored XSS issue exists in Appspace 6.2.4. After a user is authenticated and enters an XSS payload under the groups section of the network tab, it is stored as the group name. Whenever another member visits that group, this payload executes.

    Published: 22 Feb 2021
    7.8
    High

    CVE-2020-24175

    Last Modified: 21 Nov 2024

    Buffer overflow in Yz1 0.30 and 0.32, as used in IZArc 4.4, ZipGenius 6.3.2.3116, and Explzh (extension) 8.14, allows attackers to execute arbitrary code via a crafted archive file, related to filename handling.

    Published: 22 Feb 2021
    9.8
    Critical

    CVE-2020-21224

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0. A remote attacker can send a malicious login packet to the control server

    Published: 22 Feb 2021
    6.1
    Medium

    CVE-2020-19762

    Last Modified: 21 Nov 2024

    Automated Logic Corporation (ALC) WebCTRL System 6.5 and prior allows remote attackers to execute any JavaScript code via a XSS payload for the first parameter in a GET request.

    Published: 22 Feb 2021
    5.4
    Medium

    CVE-2021-27368

    Last Modified: 21 Nov 2024

    The Contact page in Monica 2.19.1 allows stored XSS via the First Name field.

    Published: 22 Feb 2021
    5.4
    Medium

    CVE-2021-27370

    Last Modified: 21 Nov 2024

    The Contact page in Monica 2.19.1 allows stored XSS via the Last Name field.

    Published: 22 Feb 2021
    5.4
    Medium

    CVE-2021-27371

    Last Modified: 21 Nov 2024

    The Contact page in Monica 2.19.1 allows stored XSS via the Description field.

    Published: 22 Feb 2021
    5.4
    Medium

    CVE-2021-27559

    Last Modified: 21 Nov 2024

    The Contact page in Monica 2.19.1 allows stored XSS via the Nickname field.

    Published: 22 Feb 2021
    5.4
    Medium

    CVE-2021-27369

    Last Modified: 21 Nov 2024

    The Contact page in Monica 2.19.1 allows stored XSS via the Middle Name field.

    Published: 22 Feb 2021
    9.8
    Critical

    CVE-2021-3120

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers to achieve remote code execution on the operating system in the security context of the web server. In order to exploit this vulnerability, an attacker must be able to place a valid Gift Card product into the shopping cart. An uploaded file is placed at a predetermined path on the web server with a user-specified filename and extension. This occurs because the ywgc-upload-picture parameter can have a .php value even though the intention was to only allow uploads of Gift Card images.

    Published: 22 Feb 2021
    6
    Medium

    CVE-2020-3664

    Last Modified: 21 Nov 2024

    Out of bound read access in hypervisor due to an invalid read access attempt by passing invalid addresses in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 22 Feb 2021