CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-27335

    Last Modified: 21 Nov 2024

    KollectApps before 4.8.16c is affected by insecure Java deserialization, leading to Remote Code Execution via a ysoserial.payloads.CommonsCollections parameter.

    Published: 18 Feb 2021
    6.3
    Medium

    CVE-2021-3413

    Last Modified: 21 Nov 2024

    A flaw was found in Red Hat Satellite in tfm-rubygem-foreman_azure_rm in versions before 2.2.0. A credential leak was identified which will expose Azure Resource Manager's secret key through JSON of the API output. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 18 Feb 2021
    10
    Critical

    CVE-2021-27329

    Last Modified: 21 Nov 2024

    Friendica 2021.01 allows SSRF via parse_url?binurl= for DNS lookups or HTTP requests to arbitrary domain names.

    Published: 18 Feb 2021
    5.4
    Medium

    CVE-2021-21318

    Last Modified: 21 Nov 2024

    Opencast is a free, open-source platform to support the management of educational audio and video content. In Opencast before version 9.2 there is a vulnerability in which publishing an episode with strict access rules will overwrite the currently set series access. This allows for an easy denial of access for all users without superuser privileges, effectively hiding the series. Access to series and series metadata on the search service (shown in media module and player) depends on the events published which are part of the series. Publishing an event will automatically publish a series and update access to it. Removing an event or republishing the event should do the same. Affected versions of Opencast may not update the series access or remove a published series if an event is being removed. On removal of an episode, this may lead to an access control list for series metadata with broader access rules than the merged access rules of all remaining events, or the series metadata still being available although all episodes of that series have been removed. This problem is fixed in Opencast 9.2.

    Published: 18 Feb 2021
    7.3
    High

    CVE-2020-28499

    Last Modified: 21 Nov 2024

    All versions of package merge are vulnerable to Prototype Pollution via _recursiveMerge .

    Published: 18 Feb 2021
    8.8
    High

    CVE-2021-26068

    Last Modified: 21 Nov 2024

    An endpoint in Atlassian Jira Server for Slack plugin from version 0.0.3 before version 2.0.15 allows remote attackers to execute arbitrary code via a template injection vulnerability.

    Published: 18 Feb 2021
    7.8
    High

    CVE-2020-36233

    Last Modified: 21 Nov 2024

    The Microsoft Windows Installer for Atlassian Bitbucket Server and Data Center before version 6.10.9, 7.x before 7.6.4, and from version 7.7.0 before 7.10.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.

    Published: 18 Feb 2021
    5.4
    Medium

    CVE-2021-20446

    Last Modified: 21 Nov 2024

    IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 196622.

    Published: 18 Feb 2021
    6.5
    Medium

    CVE-2021-20445

    Last Modified: 21 Nov 2024

    IBM Maximo for Civil Infrastructure 7.6.2 could allow a user to obtain sensitive information due to insecure storeage of authentication credentials. IBM X-Force ID: 196621.

    Published: 18 Feb 2021
    6.1
    Medium

    CVE-2021-20444

    Last Modified: 21 Nov 2024

    IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 196620.

    Published: 18 Feb 2021
    8.8
    High

    CVE-2021-20443

    Last Modified: 21 Nov 2024

    IBM Maximo for Civil Infrastructure 7.6.2 includes executable functionality (such as a library) from a source that is outside of the intended control sphere. IBM X-Force ID: 196619.

    Published: 18 Feb 2021
    7.5
    High

    CVE-2021-20354

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 194883.

    Published: 18 Feb 2021
    5.4
    Medium

    CVE-2020-4933

    Last Modified: 21 Nov 2024

    IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191751.

    Published: 18 Feb 2021
    5.3
    Medium

    CVE-2020-29453

    Last Modified: 21 Nov 2024

    The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.

    Published: 18 Feb 2021
    5.3
    Medium

    CVE-2020-29448

    Last Modified: 21 Nov 2024

    The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, from 6.14.0 before 7.4.6, and from 7.5.0 before 7.8.3 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.

    Published: 18 Feb 2021
    7.8
    High

    CVE-2021-27379

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen through 4.11.x, allowing x86 Intel HVM guest OS users to achieve unintended read/write DMA access, and possibly cause a denial of service (host OS crash) or gain privileges. This occurs because a backport missed a flush, and thus IOMMU updates were not always correct. NOTE: this issue exists because of an incomplete fix for CVE-2020-15565.

    Published: 18 Feb 2021
    5.5
    Medium

    CVE-2019-18243

    Last Modified: 21 Nov 2024

    HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through the registry. This may allow privilege escalation.

    Published: 18 Feb 2021
    5.5
    Medium

    CVE-2019-18255

    Last Modified: 21 Nov 2024

    HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through section objects. This may allow privilege escalation.

    Published: 18 Feb 2021
    7.1
    High

    CVE-2021-23340

    Last Modified: 21 Nov 2024

    This affects the package pimcore/pimcore before 6.8.8. A Local FIle Inclusion vulnerability exists in the downloadCsvAction function of the CustomReportController class (bundles/AdminBundle/Controller/Reports/CustomReportController.php). An authenticated user can reach this function with a GET request at the following endpoint: /admin/reports/custom-report/download-csv?exportFile=&91;filename]. Since exportFile variable is not sanitized, an attacker can exploit a local file inclusion vulnerability.

    Published: 18 Feb 2021
    7.5
    High

    CVE-2020-28496

    Last Modified: 21 Nov 2024

    This affects the package three before 0.125.0. This can happen when handling rgb or hsl colors. PoC: var three = require('three') function build_blank (n) { var ret = "rgb(" for (var i = 0; i < n; i++) { ret += " " } return ret + ""; } var Color = three.Color var time = Date.now(); new Color(build_blank(50000)) var time_cost = Date.now() - time; console.log(time_cost+" ms")

    Published: 18 Feb 2021
    9.1
    Critical

    CVE-2020-28490

    Last Modified: 21 Nov 2024

    The package async-git before 1.13.2 are vulnerable to Command Injection via shell meta-characters (back-ticks). For example: git.reset('atouch HACKEDb')

    Published: 18 Feb 2021
    6.5
    Medium

    CVE-2020-35577

    Last Modified: 21 Nov 2024

    In Endalia Selection Portal before 4.205.0, an Insecure Direct Object Reference (IDOR) allows any authenticated user to download every file uploaded to the platform by changing the value of the file identifier (aka CommonDownload identification number).

    Published: 18 Feb 2021
    7.8
    High

    CVE-2020-29664

    Last Modified: 21 Nov 2024

    A command injection issue in dji_sys in DJI Mavic 2 Remote Controller before firmware version 01.00.0510 allows for code execution via a malicious firmware upgrade packet.

    Published: 18 Feb 2021
    9.8
    Critical

    CVE-2021-27376

    Last Modified: 21 Nov 2024

    An issue was discovered in the nb-connect crate before 1.0.3 for Rust. It may have invalid memory access for certain versions of the standard library because it relies on a direct cast of std::net::SocketAddrV4 and std::net::SocketAddrV6 data structures.

    Published: 18 Feb 2021
    9.8
    Critical

    CVE-2021-27377

    Last Modified: 21 Nov 2024

    An issue was discovered in the yottadb crate before 1.2.0 for Rust. For some memory-allocation patterns, ydb_subscript_next_st and ydb_subscript_prev_st have a use-after-free.

    Published: 18 Feb 2021
    9.8
    Critical

    CVE-2021-27378

    Last Modified: 21 Nov 2024

    An issue was discovered in the rand_core crate before 0.6.2 for Rust. Because read_u32_into and read_u64_into mishandle certain buffer-length checks, a random number generator may be seeded with too little data.

    Published: 18 Feb 2021
    6.5
    Medium

    CVE-2021-27124

    Last Modified: 21 Nov 2024

    SQL injection in the expertise parameter in search_result.php in Doctor Appointment System v1.0 allows an authenticated patient user to dump the database credentials via a SQL injection attack.

    Published: 18 Feb 2021
    5.3
    Medium

    CVE-2021-27375

    Last Modified: 21 Nov 2024

    Traefik before 2.4.5 allows the loading of IFRAME elements from other domains.

    Published: 18 Feb 2021
    6.5
    Medium

    CVE-2020-28463

    Last Modified: 21 Nov 2024

    All versions of package reportlab are vulnerable to Server-side Request Forgery (SSRF) via img tags. In order to reduce risk, use trustedSchemes & trustedHosts (see in Reportlab's documentation) Steps to reproduce by Karan Bamal: 1. Download and install the latest package of reportlab 2. Go to demos -> odyssey -> dodyssey 3. In the text file odyssey.txt that needs to be converted to pdf inject <img src="http://127.0.0.1:5000" valign="top"/> 4. Create a nc listener nc -lp 5000 5. Run python3 dodyssey.py 6. You will get a hit on your nc showing we have successfully proceded to send a server side request 7. dodyssey.py will show error since there is no img file on the url, but we are able to do SSRF

    Published: 18 Feb 2021
    7.5
    High

    CVE-2020-28491

    Last Modified: 21 Nov 2024

    This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.

    Published: 18 Feb 2021
    7.5
    High

    CVE-2021-22884

    Last Modified: 30 Apr 2025

    Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof its responses, the DNS rebinding protection can be bypassed by using the “localhost6” domain. As long as the attacker uses the “localhost6” domain, they can still apply the attack described in CVE-2018-7160.

    Published: 18 Feb 2021
    7.5
    High

    CVE-2021-23341

    Last Modified: 21 Nov 2024

    The package prismjs before 1.23.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the prism-asciidoc, prism-rest, prism-tap and prism-eiffel components.

    Published: 18 Feb 2021
    7.5
    High

    CVE-2021-26296

    Last Modified: 13 Feb 2025

    In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens. Due to that limitation, it is possible (although difficult) for an attacker to calculate a future CSRF token value and to use that value to trick a user into executing unwanted actions on an application.

    Published: 18 Feb 2021
    5.5
    Medium

    CVE-2021-20255

    Last Modified: 21 Nov 2024

    A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing controller commands due to a DMA reentry issue. This flaw allows a guest user or process to consume CPU cycles or crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

    Published: 18 Feb 2021
    8.8
    High

    CVE-2020-9306

    Last Modified: 21 Nov 2024

    Tesla SolarCity Solar Monitoring Gateway through 5.46.43 has a "Use of Hard-coded Credentials" issue because Digi ConnectPort X2e uses a .pyc file to store the cleartext password for the python user account.

    Published: 17 Feb 2021
    7.8
    High

    CVE-2020-12878

    Last Modified: 21 Nov 2024

    Digi ConnectPort X2e before 3.2.30.6 allows an attacker to escalate privileges from the python user to root via a symlink attack that uses chown, related to /etc/init.d/S50dropbear.sh and the /WEB/python/.ssh directory.

    Published: 17 Feb 2021
    7.8
    High

    CVE-2021-27138

    Last Modified: 3 Nov 2025

    The boot loader in Das U-Boot before 2021.04-rc2 mishandles use of unit addresses in a FIT.

    Published: 17 Feb 2021
    7.8
    High

    CVE-2021-27097

    Last Modified: 3 Nov 2025

    The boot loader in Das U-Boot before 2021.04-rc2 mishandles a modified FIT.

    Published: 17 Feb 2021
    7.5
    High

    CVE-2021-27374

    Last Modified: 21 Nov 2024

    VertiGIS WebOffice 10.7 SP1 before patch20210202 and 10.8 SP1 before patch20210207 allows attackers to achieve "Zugriff auf Inhalte der WebOffice Applikation."

    Published: 17 Feb 2021
    8.8
    High

    CVE-2020-36245

    Last Modified: 21 Nov 2024

    GramAddict through 1.2.3 allows remote attackers to execute arbitrary code because of use of UIAutomator2 and ATX-Agent. The attacker must be able to reach TCP port 7912, e.g., by being on the same Wi-Fi network.

    Published: 17 Feb 2021
    7.8
    High

    CVE-2021-26720

    Last Modified: 21 Nov 2024

    avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of service or create arbitrary empty files via a symlink attack on files under /run/avahi-daemon. NOTE: this only affects the packaging for Debian GNU/Linux (used indirectly by SUSE), not the upstream Avahi product.

    Published: 17 Feb 2021
    7.4
    High

    CVE-2021-26911

    Last Modified: 21 Nov 2024

    core/imap/MCIMAPSession.cpp in Canary Mail before 3.22 has Missing SSL Certificate Validation for IMAP in STARTTLS mode.

    Published: 17 Feb 2021
    7.5
    High

    CVE-2021-27367

    Last Modified: 21 Nov 2024

    Controller/Backend/FileEditController.php and Controller/Backend/FilemanagerController.php in Bolt before 4.1.13 allow Directory Traversal.

    Published: 17 Feb 2021
    5.9
    Medium

    CVE-2020-25605

    Last Modified: 21 Nov 2024

    Cleartext transmission of sensitive information in Agora Video SDK prior to 3.1 allows a remote attacker to obtain access to audio and video of any ongoing Agora video call through observation of cleartext network traffic.

    Published: 17 Feb 2021
    8.8
    High

    CVE-2021-3396

    Last Modified: 21 Nov 2024

    OpenNMS Meridian 2016, 2017, 2018 before 2018.1.25, 2019 before 2019.1.16, and 2020 before 2020.1.5, Horizon 1.2 through 27.0.4, and Newts <1.5.3 has Incorrect Access Control, which allows local and remote code execution using JEXL expressions.

    Published: 17 Feb 2021
    8.8
    High

    CVE-2020-13555

    Last Modified: 21 Nov 2024

    An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In COM Server Application Privilege Escalation, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.

    Published: 17 Feb 2021
    8.8
    High

    CVE-2020-13553

    Last Modified: 21 Nov 2024

    An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webvrpcs Run Key Privilege Escalation in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.

    Published: 17 Feb 2021
    8.8
    High

    CVE-2020-13551

    Last Modified: 21 Nov 2024

    An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via PostgreSQL executable, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.

    Published: 17 Feb 2021
    8.8
    High

    CVE-2020-13552

    Last Modified: 21 Nov 2024

    An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via multiple service executables in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.

    Published: 17 Feb 2021
    7.7
    High

    CVE-2020-13550

    Last Modified: 21 Nov 2024

    A local file inclusion vulnerability exists in the installation functionality of Advantech WebAccess/SCADA 9.0.1. A specially crafted application can lead to information disclosure. An attacker can send an authenticated HTTP request to trigger this vulnerability.

    Published: 17 Feb 2021