CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-27103

    Last Modified: 3 Nov 2025

    Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later.

    Published: 16 Feb 2021
    7.8
    High

    CVE-2021-27102

    Last Modified: 3 Nov 2025

    Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later.

    Published: 16 Feb 2021
    9.8
    Critical

    CVE-2021-27101

    Last Modified: 3 Nov 2025

    Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA_9_12_380 and later.

    Published: 16 Feb 2021
    5.3
    Medium

    CVE-2020-28918

    Last Modified: 30 May 2025

    DualShield 5.9.8.0821 allows username enumeration on its login form. A valid username results in prompting for the password, whereas an invalid one will produce an "unknown username" error message.

    Published: 16 Feb 2021
    5.5
    Medium

    CVE-2021-27203

    Last Modified: 21 Nov 2024

    In Dekart Private Disk 2.15, invalid use of the Type3 user buffer for IOCTL codes using METHOD_NEITHER results in arbitrary memory dereferencing.

    Published: 16 Feb 2021
    7.2
    High

    CVE-2021-20072

    Last Modified: 21 Nov 2024

    Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to arbitrarily access and delete files via an authenticated directory traveral.

    Published: 16 Feb 2021
    4.8
    Medium

    CVE-2021-20071

    Last Modified: 21 Nov 2024

    Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scriptings attacks via the sms.php dialogs.

    Published: 16 Feb 2021
    4.8
    Medium

    CVE-2021-20070

    Last Modified: 21 Nov 2024

    Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scriptings attacks via the virtualization.php dialogs.

    Published: 16 Feb 2021
    7.8
    High

    CVE-2021-20075

    Last Modified: 21 Nov 2024

    Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for privilege escalation via configd.

    Published: 16 Feb 2021
    8.8
    High

    CVE-2021-20074

    Last Modified: 21 Nov 2024

    Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows users to escape the provided command line interface and execute arbitrary OS commands.

    Published: 16 Feb 2021
    8.8
    High

    CVE-2021-20073

    Last Modified: 21 Nov 2024

    Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for cross-site request forgeries.

    Published: 16 Feb 2021
    4.8
    Medium

    CVE-2021-20069

    Last Modified: 21 Nov 2024

    Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scripting attacks via the regionalSettings.php dialogs.

    Published: 16 Feb 2021
    4.8
    Medium

    CVE-2021-20068

    Last Modified: 21 Nov 2024

    Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scripting attacks via the error handling functionality of web pages.

    Published: 16 Feb 2021
    5.3
    Medium

    CVE-2021-20067

    Last Modified: 21 Nov 2024

    Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to view sensitive syslog events without authentication.

    Published: 16 Feb 2021
    7.8
    High

    CVE-2020-11635

    Last Modified: 21 Nov 2024

    The Zscaler Client Connector prior to 3.1.0 did not sufficiently validate RPC clients, which allows a local adversary to execute code with system privileges or perform limited actions for which they did not have privileges.

    Published: 16 Feb 2021
    4.4
    Medium

    CVE-2020-29457

    Last Modified: 21 Nov 2024

    A Privilege Elevation vulnerability in OPC UA .NET Standard Stack 1.4.363.107 could allow a rogue application to establish a secure connection.

    Published: 16 Feb 2021
    4.8
    Medium

    CVE-2021-27237

    Last Modified: 21 Nov 2024

    The admin panel in BlackCat CMS 1.3.6 allows stored XSS (by an admin) via the Display Name field to backend/preferences/ajax_save.php.

    Published: 16 Feb 2021
    5.3
    Medium

    CVE-2021-21317

    Last Modified: 21 Nov 2024

    uap-core in an open-source npm package which contains the core of BrowserScope's original user agent string parser. In uap-core before version 0.11.0, some regexes are vulnerable to regular expression denial of service (REDoS) due to overlapping capture groups. This allows remote attackers to overload a server by setting the User-Agent header in an HTTP(S) request to maliciously crafted long strings. This is fixed in version 0.11.0. Downstream packages such as uap-python, uap-ruby etc which depend upon uap-core follow different version schemes.

    Published: 16 Feb 2021
    6.3
    Medium

    CVE-2021-21316

    Last Modified: 21 Nov 2024

    less-openui5 is an npm package which enables building OpenUI5 themes with Less.js. In less-openui5 before version 0.10., when processing theming resources (i.e. `*.less` files) with less-openui5 that originate from an untrusted source, those resources might contain JavaScript code which will be executed in the context of the build process. While this is a feature of the Less.js library it is an unexpected behavior in the context of OpenUI5 and SAPUI5 development. Especially in the context of UI5 Tooling which relies on less-openui5. An attacker might create a library or theme-library containing a custom control or theme, hiding malicious JavaScript code in one of the .less files. Refer to the referenced GHSA-3crj-w4f5-gwh4 for examples. Starting with Less.js version 3.0.0, the Inline JavaScript feature is disabled by default. less-openui5 however currently uses a fork of Less.js v1.6.3. Note that disabling the Inline JavaScript feature in Less.js versions 1.x, still evaluates code has additional double codes around it. We decided to remove the inline JavaScript evaluation feature completely from the code of our Less.js fork. This fix is available in less-openui5 version 0.10.0.

    Published: 16 Feb 2021
    7.1
    High

    CVE-2021-21315

    Last Modified: 24 Oct 2025

    The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem was fixed in version 5.3.1. As a workaround instead of upgrading, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() ... do only allow strings, reject any arrays. String sanitation works as expected.

    Published: 16 Feb 2021
    8.6
    High

    CVE-2021-20987

    Last Modified: 21 Nov 2024

    A denial of service and memory corruption vulnerability was found in Hilscher EtherNet/IP Core V2 prior to V2.13.0.21that may lead to code injection through network or make devices crash without recovery.

    Published: 16 Feb 2021
    7.5
    High

    CVE-2021-20986

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability was found in Hilscher PROFINET IO Device V3 in versions prior to V3.14.0.7. This may lead to unexpected loss of cyclic communication or interruption of acyclic communication.

    Published: 16 Feb 2021
    5.3
    Medium

    CVE-2020-35561

    Last Modified: 21 Nov 2024

    An issue was discovered MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. There is an SSRF in the HA module allowing an unauthenticated attacker to scan for open ports.

    Published: 16 Feb 2021
    5.4
    Medium

    CVE-2020-29027

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) vulnerability in GUI of Secomea SiteManager could allow an attacker to cause an XSS Attack. This issue affects: Secomea SiteManager all versions prior to 9.3.

    Published: 16 Feb 2021
    9.8
    Critical

    CVE-2020-35565

    Last Modified: 21 Nov 2024

    An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The login pages bruteforce detection is disabled by default.

    Published: 16 Feb 2021
    7.8
    High

    CVE-2020-35567

    Last Modified: 21 Nov 2024

    An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The software uses a secure password for database access, but this password is shared across instances.

    Published: 16 Feb 2021
    5.4
    Medium

    CVE-2020-29025

    Last Modified: 21 Nov 2024

    A vulnerability in SiteManager-Embedded (SM-E) Web server which may allow attacker to construct a URL that if visited by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application. This issue affects all versions and variants of SM-E prior to version 9.3

    Published: 16 Feb 2021
    4.3
    Medium

    CVE-2020-35568

    Last Modified: 21 Nov 2024

    An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. An incomplete filter applied to a database response allows an authenticated attacker to gain non-public information about other users and devices in the account.

    Published: 16 Feb 2021
    4.3
    Medium

    CVE-2020-35559

    Last Modified: 21 Nov 2024

    An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an unused function that allows an authenticated attacker to use up all available IPs of an account and thus not allow creation of new devices and users.

    Published: 16 Feb 2021
    5.3
    Medium

    CVE-2020-35566

    Last Modified: 21 Nov 2024

    An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. An attacker can read arbitrary JSON files via Local File Inclusion.

    Published: 16 Feb 2021
    6.1
    Medium

    CVE-2020-35569

    Last Modified: 21 Nov 2024

    An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is a self XSS issue with a crafted cookie in the login page.

    Published: 16 Feb 2021
    7.5
    High

    CVE-2020-35564

    Last Modified: 21 Nov 2024

    An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an outdated and unused component allowing for malicious user input of active code.

    Published: 16 Feb 2021
    5.4
    Medium

    CVE-2020-35563

    Last Modified: 21 Nov 2024

    An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an incomplete XSS filter allowing an attacker to inject crafted malicious code into the page.

    Published: 16 Feb 2021
    6.1
    Medium

    CVE-2020-35560

    Last Modified: 21 Nov 2024

    An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an unauthenticated open redirect in the redirect.php.

    Published: 16 Feb 2021
    7.5
    High

    CVE-2020-35558

    Last Modified: 21 Nov 2024

    An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. There is an SSRF in the in the MySQL access check, allowing an attacker to scan for open ports and gain some information about possible credentials.

    Published: 16 Feb 2021
    5.3
    Medium

    CVE-2020-35570

    Last Modified: 21 Nov 2024

    An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. An unauthenticated attacker is able to access files (that should have been restricted) via forceful browsing.

    Published: 16 Feb 2021
    6.5
    Medium

    CVE-2020-35557

    Last Modified: 21 Nov 2024

    An issue in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 allows a logged in user to see devices in the account he should not have access to due to improper use of access validation.

    Published: 16 Feb 2021
    3.5
    Low

    CVE-2020-29023

    Last Modified: 21 Nov 2024

    Improper Encoding or Escaping of Output from CSV Report Generator of Secomea GateManager allows an authenticated administrator to generate a CSV file that may run arbitrary commands on a victim's computer when opened in a spreadsheet program (like Excel). This issue affects: Secomea GateManager all versions prior to 9.3.

    Published: 16 Feb 2021
    5.3
    Medium

    CVE-2020-29022

    Last Modified: 21 Nov 2024

    Failure to Sanitize host header value on output in the GateManager Web server could allow an attacker to conduct web cache poisoning attacks. This issue affects Secomea GateManager all versions prior to 9.3

    Published: 16 Feb 2021
    5.3
    Medium

    CVE-2020-29024

    Last Modified: 21 Nov 2024

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in (GTA) GoToAppliance of Secomea GateManager could allow an attacker to gain access to sensitive cookies. This issue affects: Secomea GateManager all versions prior to 9.3.

    Published: 16 Feb 2021
    9.8
    Critical

    CVE-2021-25648

    Last Modified: 21 Nov 2024

    Mobile application "Testes de Codigo" 11.4 and prior allows an attacker to gain access to the administrative interface and premium features by tampering the boolean value of parameters "isAdmin" and "isPremium" located on device storage.

    Published: 16 Feb 2021
    8.8
    High

    CVE-2021-27232

    Last Modified: 21 Nov 2024

    The RTSPLive555.dll ActiveX control in Pelco Digital Sentry Server 7.18.72.11464 has a SetCameraConnectionParameter stack-based buffer overflow. This can be exploited by a remote attacker to potentially execute arbitrary attacker-supplied code. The victim would have to visit a malicious webpage using Internet Explorer where the exploit could be triggered.

    Published: 16 Feb 2021
    5.5
    Medium

    CVE-2020-25340

    Last Modified: 21 Nov 2024

    An issue was discovered in NFStream 5.2.0. Because some allocated modules are not correctly freed, if the nfstream object is directly destroyed without being used after it is created, it will cause a memory leak that may result in a local denial of service (DoS).

    Published: 16 Feb 2021
    9.8
    Critical

    CVE-2020-24841

    Last Modified: 21 Nov 2024

    PNPSCADA 2.200816204020 allows SQL injection via parameter 'interf' in /browse.jsp. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

    Published: 16 Feb 2021
    4.9
    Medium

    CVE-2021-27233

    Last Modified: 21 Nov 2024

    An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. On the admin portal of the web application, password information for external systems is visible in cleartext. The Settings.asp page is affected by this issue.

    Published: 16 Feb 2021
    9.8
    Critical

    CVE-2021-27234

    Last Modified: 21 Nov 2024

    An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. The web application suffers from SQL injection on Adminlog.asp, Archivemsgs.asp, Deletelog.asp, Eventlog.asp, and Evmlog.asp.

    Published: 16 Feb 2021
    4.9
    Medium

    CVE-2021-27235

    Last Modified: 21 Nov 2024

    An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. On the admin portal of the web application, there is a functionality at diagzip.asp that allows anyone to export tables of a database.

    Published: 16 Feb 2021
    9.8
    Critical

    CVE-2021-27236

    Last Modified: 21 Nov 2024

    An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. getfile.asp allows Unauthenticated Local File Inclusion, which can be leveraged to achieve Remote Code Execution.

    Published: 16 Feb 2021
    5.4
    Medium

    CVE-2021-27231

    Last Modified: 21 Nov 2024

    Hestia Control Panel 1.3.5 and below, in a shared-hosting environment, sometimes allows remote authenticated users to create a subdomain for a different customer's domain name, leading to spoofing of services or email messages.

    Published: 16 Feb 2021
    8.8
    High

    CVE-2021-27229

    Last Modified: 21 Nov 2024

    Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on the Open Webpage text.

    Published: 16 Feb 2021