CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2020-24392

    Last Modified: 21 Nov 2024

    In voloko twitter-stream 0.1.10, missing TLS hostname validation allows an attacker to perform a man-in-the-middle attack against users of the library (because eventmachine is misused).

    Published: 19 Feb 2021
    8.8
    High

    CVE-2020-12873

    Last Modified: 21 Nov 2024

    An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a FreeMarker template (e.g., a webscript) may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running Alfresco.

    Published: 19 Feb 2021
    6.5
    Medium

    CVE-2020-12668

    Last Modified: 21 Nov 2024

    Jinjava before 2.5.4 allow access to arbitrary classes by calling Java methods on objects passed into a Jinjava context. This could allow for abuse of the application class loader, including Arbitrary File Disclosure.

    Published: 19 Feb 2021
    6.1
    Medium

    CVE-2021-3189

    Last Modified: 21 Nov 2024

    The slashify package 1.0.0 for Node.js allows open-redirect attacks, as demonstrated by a localhost:3000///example.com/ substring.

    Published: 19 Feb 2021
    7.5
    High

    CVE-2021-27509

    Last Modified: 21 Nov 2024

    In Visualware MyConnection Server before 11.0b build 5382, each published report is not associated with its own access code.

    Published: 19 Feb 2021
    —
    Unknown

    CVE-2020-27785

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-29074. Reason: This candidate is a reservation duplicate of CVE-2020-29074. Notes: All CVE users should reference CVE-2020-29074 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 19 Feb 2021
    7.5
    High

    CVE-2021-20588

    Last Modified: 13 Jun 2025

    Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3 all versions, FR Configurator2 versions 1.24A and prior, GT Designer3 Version1(GOT1000) versions 1.250L and prior, GT Designer3 Version1(GOT2000) versions 1.250L and prior, GT SoftGOT1000 Version3 versions 3.245F and prior, GT SoftGOT2000 Version1 versions 1.250L and prior, GX Configurator-DP versions 7.14Q and prior, GX Configurator-QP all versions, GX Developer versions 8.506C and prior, GX Explorer all versions, GX IEC Developer all versions, GX LogViewer versions 1.115U and prior, GX RemoteService-I all versions, GX Works2 versions 1.597X and prior, GX Works3 versions 1.070Y and prior, iQ Monozukuri ANDON (Data Transfer) versions 1.003D and prior, iQ Monozukuri Process Remote Monitoring (Data Transfer) versions 1.002C and prior, M_CommDTM-HART all versions, M_CommDTM-IO-Link versions 1.03D and prior, MELFA-Works versions 4.4 and prior, MELSEC WinCPU Setting Utility all versions, MELSOFT EM Software Development Kit (EM Configurator) versions 1.015R and prior, MELSOFT Navigator versions 2.74C and prior, MH11 SettingTool Version2 versions 2.004E and prior, MI Configurator versions 1.004E and prior, MT Works2 versions 1.167Z and prior, MX Component versions 5.001B and prior, Network Interface Board CC IE Control utility versions 1.29F and prior, Network Interface Board CC IE Field Utility versions 1.16S and prior, Network Interface Board CC-Link Ver.2 Utility versions 1.23Z and prior, Network Interface Board MNETH utility versions 34L and prior, PX Developer versions 1.53F and prior, RT ToolBox2 versions 3.73B and prior, RT ToolBox3 versions 1.82L and prior, Setting/monitoring tools for the C Controller module (SW4PVC-CCPU) versions 4.12N and prior, and SLMP Data Collector versions 1.04E and prior) allows a remote unauthenticated attacker to cause a DoS condition on the software products, and possibly to execute a malicious code on the personal computer running the software products although it has not been reproduced, by spoofing MELSEC, GOT or FREQROL and returning crafted reply packets.

    Published: 19 Feb 2021
    7.5
    High

    CVE-2021-20587

    Last Modified: 13 Jun 2025

    Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3 all versions, FR Configurator2 versions 1.24A and prior, GT Designer3 Version1(GOT1000) versions 1.250L and prior, GT Designer3 Version1(GOT2000) versions 1.250L and prior, GT SoftGOT1000 Version3 versions 3.245F and prior, GT SoftGOT2000 Version1 versions 1.250L and prior, GX Configurator-DP versions 7.14Q and prior, GX Configurator-QP all versions, GX Developer versions 8.506C and prior, GX Explorer all versions, GX IEC Developer all versions, GX LogViewer versions 1.115U and prior, GX RemoteService-I all versions, GX Works2 versions 1.597X and prior, GX Works3 versions 1.070Y and prior, iQ Monozukuri ANDON (Data Transfer) versions 1.003D and prior, iQ Monozukuri Process Remote Monitoring (Data Transfer) versions 1.002C and prior, M_CommDTM-HART all versions, M_CommDTM-IO-Link versions 1.03D and prior, MELFA-Works versions 4.4 and prior, MELSEC WinCPU Setting Utility all versions, MELSOFT EM Software Development Kit (EM Configurator) versions 1.015R and prior, MELSOFT Navigator versions 2.74C and prior, MH11 SettingTool Version2 versions 2.004E and prior, MI Configurator versions 1.004E and prior, MT Works2 versions 1.167Z and prior, MX Component versions 5.001B and prior, Network Interface Board CC IE Control utility versions 1.29F and prior, Network Interface Board CC IE Field Utility versions 1.16S and prior, Network Interface Board CC-Link Ver.2 Utility versions 1.23Z and prior, Network Interface Board MNETH utility versions 34L and prior, PX Developer versions 1.53F and prior, RT ToolBox2 versions 3.73B and prior, RT ToolBox3 versions 1.82L and prior, Setting/monitoring tools for the C Controller module (SW4PVC-CCPU) versions 4.12N and prior, and SLMP Data Collector versions 1.04E and prior) allows a remote unauthenticated attacker to cause a DoS condition on the software products, and possibly to execute a malicious code on the personal computer running the software products although it has not been reproduced, by spoofing MELSEC, GOT or FREQROL and returning crafted reply packets.

    Published: 19 Feb 2021
    6.5
    Medium

    CVE-2021-26713

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow in res_rtp_asterisk.c in Sangoma Asterisk before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6 allows an authenticated WebRTC client to cause an Asterisk crash by sending multiple hold/unhold requests in quick succession. This is caused by a signedness comparison mismatch.

    Published: 19 Feb 2021
    5.3
    Medium

    CVE-2021-20256

    Last Modified: 21 Nov 2024

    A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 19 Feb 2021
    5.3
    Medium

    CVE-2021-27351

    Last Modified: 21 Nov 2024

    The Terminate Session feature in the Telegram application through 7.2.1 for Android, and through 2.4.7 for Windows and UNIX, fails to invalidate a recently active session.

    Published: 19 Feb 2021
    6.1
    Medium

    CVE-2021-27214

    Last Modified: 21 Nov 2024

    A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cross-site scripting (XSS) attack against the administrative interface via an HTTP request, a different vulnerability than CVE-2019-3905.

    Published: 19 Feb 2021
    6.5
    Medium

    CVE-2021-27328

    Last Modified: 21 Nov 2024

    Yeastar NeoGate TG400 91.3.0.3 devices are affected by Directory Traversal. An authenticated user can decrypt firmware and can read sensitive information, such as a password or decryption key.

    Published: 19 Feb 2021
    7.5
    High

    CVE-2020-9050

    Last Modified: 21 Nov 2024

    Path Traversal vulnerability exists in Metasys Reporting Engine (MRE) Web Services which could allow a remote unauthenticated attacker to access and download arbitrary files from the system.

    Published: 19 Feb 2021
    7.8
    High

    CVE-2020-25171

    Last Modified: 21 Nov 2024

    The affected Fuji Electric V-Server Lite versions prior to 3.3.24.0 are vulnerable to an out-of-bounds write, which may allow an attacker to remotely execute arbitrary code.

    Published: 19 Feb 2021
    7.8
    High

    CVE-2020-13549

    Last Modified: 21 Nov 2024

    An exploitable local privilege elevation vulnerability exists in the file system permissions of Sytech XL Reporter v14.0.1 install directory. Depending on the vector chosen, an attacker can overwrite service executables and execute arbitrary code with privileges of user set to run the service or replace other files within the installation folder, which would allow for local privilege escalation.

    Published: 19 Feb 2021
    8.6
    High

    CVE-2021-23342

    Last Modified: 21 Nov 2024

    This affects the package docsify before 4.12.0. It is possible to bypass the remediation done by CVE-2020-7680 and execute malicious JavaScript through the following methods 1) When parsing HTML from remote URLs, the HTML code on the main page is sanitized, but this sanitization is not taking place in the sidebar. 2) The isURL external check can be bypassed by inserting more “////” characters

    Published: 19 Feb 2021
    7.9
    High

    CVE-2021-21512

    Last Modified: 21 Nov 2024

    Dell EMC PowerProtect Cyber Recovery, version 19.7.0.1, contains an Information Disclosure vulnerability. A locally authenticated high privileged Cyber Recovery user may potentially exploit this vulnerability leading to the takeover of the notification email account.

    Published: 19 Feb 2021
    6.7
    Medium

    CVE-2020-12374

    Last Modified: 21 Nov 2024

    Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.47 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 19 Feb 2021
    4.5
    Medium

    CVE-2021-22701

    Last Modified: 21 Nov 2024

    A CWE-352: Cross-Site Request Forgery vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause a user to perform an unintended action on the target device when using the HTTP web interface.

    Published: 19 Feb 2021
    7.5
    High

    CVE-2021-22703

    Last Modified: 21 Nov 2024

    A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause disclosure of user credentials when a malicious actor intercepts HTTP network traffic between a user and the device.

    Published: 19 Feb 2021
    7.5
    High

    CVE-2021-22702

    Last Modified: 29 May 2026

    A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION7700/73xx, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause disclosure of user credentials when a malicious actor intercepts Telnet network traffic between a user and the device.

    Published: 19 Feb 2021
    6.5
    Medium

    CVE-2021-3204

    Last Modified: 21 Nov 2024

    SSRF in the document conversion component of Webware Webdesktop 5.1.15 allows an attacker to read all files from the server.

    Published: 19 Feb 2021
    9.6
    Critical

    CVE-2021-3210

    Last Modified: 21 Nov 2024

    components/Modals/HelpTexts/GenericAll/GenericAll.jsx in Bloodhound <= 4.0.1 allows remote attackers to execute arbitrary system commands when the victim imports a malicious data file containing JavaScript in the objectId parameter.

    Published: 19 Feb 2021
    4.3
    Medium

    CVE-2021-3339

    Last Modified: 21 Nov 2024

    ModernFlow before 1.3.00.208 does not constrain web-page access to members of a security group, as demonstrated by the Search Screen and the Profile Screen.

    Published: 19 Feb 2021
    3.9
    Low

    CVE-2020-36248

    Last Modified: 26 Mar 2025

    The ownCloud application before 2.15 for Android allows attackers to use adb to include a PIN preferences value in a backup archive, and consequently bypass the PIN lock feature by restoring from this archive.

    Published: 19 Feb 2021
    7.5
    High

    CVE-2020-36249

    Last Modified: 21 Nov 2024

    The File Firewall before 2.8.0 for ownCloud Server does not properly enforce file-type restrictions for public shares.

    Published: 19 Feb 2021
    6.1
    Medium

    CVE-2020-36250

    Last Modified: 26 Mar 2025

    In the ownCloud application before 2.15 for Android, the lock protection mechanism can be bypassed by moving the system date/time into the past.

    Published: 19 Feb 2021
    3.5
    Low

    CVE-2020-36251

    Last Modified: 21 Nov 2024

    ownCloud Server before 10.3.0 allows an attacker, who has received non-administrative access to a group share, to remove everyone else's access to that share.

    Published: 19 Feb 2021
    6.8
    Medium

    CVE-2020-36252

    Last Modified: 31 Mar 2025

    ownCloud Server 10.x before 10.3.1 allows an attacker, who has one outgoing share from a victim, to access any version of any file by sending a request for a predictable ID number.

    Published: 19 Feb 2021
    8.3
    High

    CVE-2020-10252

    Last Modified: 21 Nov 2024

    An issue was discovered in ownCloud before 10.4. Because of an SSRF issue (via the apps/files_sharing/external remote parameter), an authenticated attacker can interact with local services blindly (aka Blind SSRF) or conduct a Denial Of Service attack.

    Published: 19 Feb 2021
    5.9
    Medium

    CVE-2020-10254

    Last Modified: 21 Nov 2024

    An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password-protected image by displaying its preview.

    Published: 19 Feb 2021
    8.8
    High

    CVE-2020-36247

    Last Modified: 21 Nov 2024

    Open OnDemand before 1.5.7 and 1.6.x before 1.6.22 allows CSRF.

    Published: 19 Feb 2021
    7.8
    High

    CVE-2020-24908

    Last Modified: 21 Nov 2024

    Checkmk before 1.6.0p17 allows local users to obtain SYSTEM privileges via a Trojan horse shell script in the %PROGRAMDATA%\checkmk\agent\local directory.

    Published: 19 Feb 2021
    7.8
    High

    CVE-2020-36246

    Last Modified: 21 Nov 2024

    Amaze File Manager before 3.5.1 allows attackers to obtain root privileges via shell metacharacters in a symbolic link.

    Published: 19 Feb 2021
    6.1
    Medium

    CVE-2021-26746

    Last Modified: 21 Nov 2024

    Chamilo 1.11.14 allows XSS via a main/calendar/agenda_list.php?type= URI.

    Published: 19 Feb 2021
    7.5
    High

    CVE-2021-27405

    Last Modified: 21 Nov 2024

    A ReDoS (regular expression denial of service) flaw was found in the @progfay/scrapbox-parser package before 6.0.3 for Node.js.

    Published: 19 Feb 2021
    6.1
    Medium

    CVE-2021-27403

    Last Modified: 21 Nov 2024

    Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow cgi-bin/te_acceso_router.cgi curWebPage XSS.

    Published: 19 Feb 2021
    6.1
    Medium

    CVE-2021-27404

    Last Modified: 21 Nov 2024

    Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow injection of a Host HTTP header.

    Published: 19 Feb 2021
    9.8
    Critical

    CVE-2019-25024

    Last Modified: 16 Apr 2025

    OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_system.php post_service parameter.

    Published: 19 Feb 2021
    5.3
    Medium

    CVE-2021-42782

    Last Modified: 3 Nov 2025

    Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library.

    Published: 19 Feb 2021
    8.8
    High

    CVE-2021-22112

    Last Modified: 21 Nov 2024

    Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is changed more than once in a single request.A malicious user cannot cause the bug to happen (it must be programmed in). However, if the application's intent is to only allow the user to run with elevated privileges in a small portion of the application, the bug can be leveraged to extend those privileges to the rest of the application.

    Published: 19 Feb 2021
    7.8
    High

    CVE-2020-19513

    Last Modified: 30 Mar 2026

    Buffer overflow in FinalWire Ltd AIDA64 Engineer 6.00.5100 allows attackers to execute arbitrary code by creating a crafted input that will overwrite the SEH handler.

    Published: 18 Feb 2021
    9.8
    Critical

    CVE-2021-26747

    Last Modified: 21 Nov 2024

    Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution.

    Published: 18 Feb 2021
    7.5
    High

    CVE-2021-26712

    Last Modified: 21 Nov 2024

    Incorrect access controls in res_srtp.c in Sangoma Asterisk 13.38.1, 16.16.0, 17.9.1, and 18.2.0 and Certified Asterisk 16.8-cert5 allow a remote unauthenticated attacker to prematurely terminate secure calls by replaying SRTP packets.

    Published: 18 Feb 2021
    6.5
    Medium

    CVE-2020-35776

    Last Modified: 21 Nov 2024

    A buffer overflow in res_pjsip_diversion.c in Sangoma Asterisk versions 13.38.1, 16.15.1, 17.9.1, and 18.1.1 allows remote attacker to crash Asterisk by deliberately misusing SIP 181 responses.

    Published: 18 Feb 2021
    5.9
    Medium

    CVE-2021-26906

    Last Modified: 21 Nov 2024

    An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0; 17.x through 17.9.1; and 18.x through 18.2.0, and Certified Asterisk through 16.8-cert5. An SDP negotiation vulnerability in PJSIP allows a remote server to potentially crash Asterisk by sending specific SIP responses that cause an SDP negotiation failure.

    Published: 18 Feb 2021
    7.5
    High

    CVE-2021-26717

    Last Modified: 21 Nov 2024

    An issue was discovered in Sangoma Asterisk 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6. When re-negotiating for T.38, if the initial remote response was delayed just enough, Asterisk would send both audio and T.38 in the SDP. If this happened, and the remote responded with a declined T.38 stream, then Asterisk would crash.

    Published: 18 Feb 2021
    5.4
    Medium

    CVE-2020-35592

    Last Modified: 21 Nov 2024

    Pi-hole 5.0, 5.1, and 5.1.1 allows XSS via the Options header to the admin/ URI. A remote user is able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a Reflected Cross-Site Scripting attack against other users and steal the session cookie.

    Published: 18 Feb 2021
    5.4
    Medium

    CVE-2020-35591

    Last Modified: 21 Nov 2024

    Pi-hole 5.0, 5.1, and 5.1.1 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious user is able to create a new session cookie value and inject it to a victim. After the victim logs in, the injected cookie becomes valid, giving the attacker access to the user's account through the active session.

    Published: 18 Feb 2021