CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2020-4956

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Operations Center 7.1 and 8.1 is vulnerable to a denial of service, caused by a RPC that allows certain cache values to be set and dumped to a file. By setting a grossly large cache value and dumping that cached value to a file multiple times, a remote attacker could exploit this vulnerability to cause the consumption of all memory resources. IBM X-Force ID: 192156.

    Published: 15 Feb 2021
    8
    High

    CVE-2020-4955

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Operations Center 7.1 and 8.1could allow a remote attacker to execute arbitrary code on the system, caused by improper parameter validation. By creating an unspecified servlet request with specially crafted input parameters, an attacker could exploit this vulnerability to load a malicious .dll with elevated privileges. IBM X-Force ID: 192155.

    Published: 15 Feb 2021
    5.4
    Medium

    CVE-2020-4954

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote attacker to bypass authentication restrictions, caused by improper session validation . By using the configuration panel to obtain a valid session using an attacker controlled IBM Spectrum Protect server, an attacker could exploit this vulnerability to bypass authentication and gain access to a limited number of debug functions, such as logging levels. IBM X-Force ID: 192153.

    Published: 15 Feb 2021
    9.8
    Critical

    CVE-2020-35775

    Last Modified: 21 Nov 2024

    CITSmart before 9.1.2.23 allows LDAP Injection.

    Published: 15 Feb 2021
    6.1
    Medium

    CVE-2021-25299

    Last Modified: 21 Nov 2024

    Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to steal his/her session cookies or it can be chained with the previous bugs to get one-click remote command execution (RCE) on the Nagios XI server.

    Published: 15 Feb 2021
    4.3
    Medium

    CVE-2020-29451

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate Jira projects via an Information Disclosure vulnerability in the Jira Projects plugin report page. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.14.1.

    Published: 15 Feb 2021
    4.8
    Medium

    CVE-2020-36234

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Screens Modal view. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0.

    Published: 15 Feb 2021
    8.8
    High

    CVE-2021-25298

    Last Modified: 3 Nov 2025

    Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.

    Published: 15 Feb 2021
    8.8
    High

    CVE-2021-25297

    Last Modified: 3 Nov 2025

    Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.

    Published: 15 Feb 2021
    8.8
    High

    CVE-2021-25296

    Last Modified: 3 Nov 2025

    Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.

    Published: 15 Feb 2021
    8.8
    High

    CVE-2020-13558

    Last Modified: 21 Nov 2024

    A code execution vulnerability exists in the AudioSourceProviderGStreamer functionality of Webkit WebKitGTK 2.30.1. A specially crafted web page can lead to a use after free.

    Published: 15 Feb 2021
    5.3
    Medium

    CVE-2020-28500

    Last Modified: 21 Nov 2024

    Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.

    Published: 15 Feb 2021
    3.9
    Low

    CVE-2020-36314

    Last Modified: 21 Nov 2024

    fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.

    Published: 15 Feb 2021
    7.5
    High

    CVE-2021-20299

    Last Modified: 21 Nov 2024

    A flaw was found in OpenEXR's Multipart input file functionality. A crafted multi-part input file with no actual parts can trigger a NULL pointer dereference. The highest threat from this vulnerability is to system availability.

    Published: 15 Feb 2021
    5.5
    Medium

    CVE-2021-20302

    Last Modified: 21 Nov 2024

    A flaw was found in OpenEXR's TiledInputFile functionality. This flaw allows an attacker who can submit a crafted single-part non-image to be processed by OpenEXR, to trigger a floating-point exception error. The highest threat from this vulnerability is to system availability.

    Published: 15 Feb 2021
    7.2
    High

    CVE-2021-23337

    Last Modified: 21 Nov 2024

    Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

    Published: 15 Feb 2021
    5.3
    Medium

    CVE-2021-20296

    Last Modified: 21 Nov 2024

    A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file supplied by an attacker, that is processed by the Dwa decompression functionality of OpenEXR's IlmImf library, could cause a NULL pointer dereference. The highest threat from this vulnerability is to system availability.

    Published: 15 Feb 2021
    7.5
    High

    CVE-2021-20298

    Last Modified: 21 Nov 2024

    A flaw was found in OpenEXR's B44Compressor. This flaw allows an attacker who can submit a crafted file to be processed by OpenEXR, to exhaust all memory accessible to the application. The highest threat from this vulnerability is to system availability.

    Published: 15 Feb 2021
    5.5
    Medium

    CVE-2021-20300

    Last Modified: 21 Nov 2024

    A flaw was found in OpenEXR's hufUncompress functionality in OpenEXR/IlmImf/ImfHuf.cpp. This flaw allows an attacker who can submit a crafted file that is processed by OpenEXR, to trigger an integer overflow. The highest threat from this vulnerability is to system availability.

    Published: 15 Feb 2021
    6.1
    Medium

    CVE-2021-20303

    Last Modified: 21 Nov 2024

    A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc.cpp. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer overflow, leading to an out-of-bounds write on the heap. The greatest impact of this flaw is to application availability, with some potential impact to data integrity as well.

    Published: 15 Feb 2021
    5.3
    Medium

    CVE-2021-3476

    Last Modified: 21 Nov 2024

    A flaw was found in OpenEXR's B44 uncompression functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to OpenEXR could trigger shift overflows, potentially affecting application availability.

    Published: 15 Feb 2021
    5.5
    Medium

    CVE-2021-3477

    Last Modified: 21 Nov 2024

    There's a flaw in OpenEXR's deep tile sample size calculations in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer overflow, subsequently leading to an out-of-bounds read. The greatest risk of this flaw is to application availability.

    Published: 15 Feb 2021
    5.5
    Medium

    CVE-2021-3478

    Last Modified: 21 Nov 2024

    There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to be processed by OpenEXR could consume excessive system memory. The greatest impact of this flaw is to system availability.

    Published: 15 Feb 2021
    5.5
    Medium

    CVE-2021-3479

    Last Modified: 21 Nov 2024

    There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger excessive consumption of memory, resulting in an impact to system availability.

    Published: 15 Feb 2021
    9
    Critical

    CVE-2021-43616

    Last Modified: 21 Nov 2024

    The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact version match requirement in package-lock.json. NOTE: The npm team believes this is not a vulnerability. It would require someone to socially engineer package.json which has different dependencies than package-lock.json. That user would have to have file system or write access to change dependencies. The npm team states preventing malicious actors from socially engineering or gaining file system access is outside the scope of the npm CLI.

    Published: 15 Feb 2021
    7.5
    High

    CVE-2021-20304

    Last Modified: 21 Nov 2024

    A flaw was found in OpenEXR's hufDecode functionality. This flaw allows an attacker who can pass a crafted file to be processed by OpenEXR, to trigger an undefined right shift error. The highest threat from this vulnerability is to system availability.

    Published: 15 Feb 2021
    5.3
    Medium

    CVE-2020-36237

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field options via an Information Disclosure vulnerability in the /rest/api/2/customFieldOption/ endpoint. The affected versions are before version 8.15.0.

    Published: 14 Feb 2021
    6.1
    Medium

    CVE-2020-36236

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the ViewWorkflowSchemes.jspa and ListWorkflows.jspa endpoints. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0.

    Published: 14 Feb 2021
    5.3
    Medium

    CVE-2020-36235

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field and custom SLA names via an Information Disclosure vulnerability in the mobile site view. The affected versions are before version 8.13.2, and from version 8.14.0 before 8.14.1.

    Published: 14 Feb 2021
    6.1
    Medium

    CVE-2021-26929

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library before 2.3.7 is used). The attacker can send a plain text e-mail message, with JavaScript encoded as a link or email that is mishandled by preProcess in Text2html.php, because bespoke use of \x00\x00\x00 and \x01\x01\x01 interferes with XSS defenses.

    Published: 14 Feb 2021
    9.8
    Critical

    CVE-2019-25019

    Last Modified: 21 Nov 2024

    LimeSurvey before 4.0.0-RC4 allows SQL injection via the participant model.

    Published: 14 Feb 2021
    9.8
    Critical

    CVE-2021-27213

    Last Modified: 21 Nov 2024

    config.py in pystemon before 2021-02-13 allows code execution via YAML deserialization because SafeLoader and safe_load are not used.

    Published: 14 Feb 2021
    7.5
    High

    CVE-2021-27212

    Last Modified: 21 Nov 2024

    In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short timestamp. This is related to schema_init.c and checkTime.

    Published: 14 Feb 2021
    7.1
    High

    CVE-2021-27209

    Last Modified: 21 Nov 2024

    In the management interface on TP-Link Archer C5v 1.7_181221 devices, credentials are sent in a base64 format over cleartext HTTP.

    Published: 13 Feb 2021
    6.5
    Medium

    CVE-2021-27210

    Last Modified: 21 Nov 2024

    TP-Link Archer C5v 1.7_181221 devices allows remote attackers to retrieve cleartext credentials via [USER_CFG#0,0,0,0,0,0#0,0,0,0,0,0]0,0 to the /cgi?1&5 URI.

    Published: 13 Feb 2021
    5.9
    Medium

    CVE-2021-23336

    Last Modified: 17 Dec 2025

    The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with default configuration) and the server. This can result in malicious requests being cached as completely safe ones, as the proxy would usually not see the semicolon as a separator, and therefore would not include it in a cache key of an unkeyed parameter.

    Published: 13 Feb 2021
    6.7
    Medium

    CVE-2021-0941

    Last Modified: 21 Nov 2024

    In bpf_skb_change_head of filter.c, there is a possible out of bounds read due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-154177719References: Upstream kernel

    Published: 13 Feb 2021
    7.8
    High

    CVE-2021-3444

    Last Modified: 21 Nov 2024

    The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0. A local attacker with the ability to load bpf programs could use this gain out-of-bounds reads in kernel memory leading to information disclosure (kernel memory), and possibly out-of-bounds writes that could potentially lead to code execution. This issue was addressed in the upstream kernel in commit 9b00f1b78809 ("bpf: Fix truncation handling for mod32 dst reg wrt zero") and in Linux stable kernels 5.11.2, 5.10.19, and 5.4.101.

    Published: 13 Feb 2021
    8.8
    High

    CVE-2021-26751

    Last Modified: 21 Nov 2024

    NeDi 1.9C allows an authenticated user to perform a SQL Injection in the Monitoring History function on the endpoint /Monitoring-History.php via the det HTTP GET parameter. This allows an attacker to access all the data in the database and obtain access to the NeDi application.

    Published: 12 Feb 2021
    8.8
    High

    CVE-2021-26752

    Last Modified: 21 Nov 2024

    NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /Nodes-Traffic.php via the md or ag HTTP GET parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all application data.

    Published: 12 Feb 2021
    9.9
    Critical

    CVE-2021-26753

    Last Modified: 21 Nov 2024

    NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all application data.

    Published: 12 Feb 2021
    9.8
    Critical

    CVE-2021-22504

    Last Modified: 21 Nov 2024

    Arbitrary code execution vulnerability on Micro Focus Operations Bridge Manager product, affecting versions 10.1x, 10.6x, 2018.05, 2018.11, 2019.05, 2019.11, 2020.05, 2020.10. The vulnerability could allow remote attackers to execute arbitrary code on an OBM server.

    Published: 12 Feb 2021
    7.5
    High

    CVE-2021-22977

    Last Modified: 21 Nov 2024

    On BIG-IP version 16.0.0-16.0.1 and 14.1.2.4-14.1.3, cooperation between malicious HTTP client code and a malicious server may cause TMM to restart and generate a core file. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

    Published: 12 Feb 2021
    6.1
    Medium

    CVE-2021-22984

    Last Modified: 21 Nov 2024

    On BIG-IP Advanced WAF and ASM version 15.1.x before 15.1.0.2, 15.0.x before 15.0.1.4, 14.1.x before 14.1.2.5, 13.1.x before 13.1.3.4, 12.1.x before 12.1.5.2, and 11.6.x before 11.6.5.2, when receiving a unauthenticated client request with a maliciously crafted URI, a BIG-IP Advanced WAF or ASM virtual server configured with a DoS profile with Proactive Bot Defense (versions prior to 14.1.0), or a Bot Defense profile (versions 14.1.0 and later), may subject clients and web servers to Open Redirection attacks. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

    Published: 12 Feb 2021
    8.3
    High

    CVE-2021-22978

    Last Modified: 21 Nov 2024

    On BIG-IP version 16.0.x before 16.0.1, 15.1.x before 15.1.1, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all 12.1.x and 11.6.x versions, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete compromise of BIG-IP if the victim user is granted the admin role. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

    Published: 12 Feb 2021
    5.4
    Medium

    CVE-2021-22983

    Last Modified: 21 Nov 2024

    On BIG-IP AFM version 15.1.x before 15.1.1, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.5, authenticated users accessing the Configuration utility for AFM are vulnerable to a cross-site scripting attack if they attempt to access a maliciously-crafted URL. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

    Published: 12 Feb 2021
    6.1
    Medium

    CVE-2021-22979

    Last Modified: 21 Nov 2024

    On BIG-IP version 16.0.x before 16.0.1, 15.1.x before 15.1.1, 14.1.x before 14.1.2.8, 13.1.x before 13.1.3.5, and all 12.1.x versions, a reflected Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility when Fraud Protection Service is provisioned and allows an attacker to execute JavaScript in the context of the current logged-in user. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

    Published: 12 Feb 2021
    7.8
    High

    CVE-2021-22980

    Last Modified: 21 Nov 2024

    In Edge Client version 7.2.x before 7.2.1.1, 7.1.9.x before 7.1.9.8, and 7.1.x-7.1.8.x before 7.1.8.5, an untrusted search path vulnerability in the BIG-IP APM Client Troubleshooting Utility (CTU) for Windows could allow an attacker to load a malicious DLL library from its current directory. User interaction is required to exploit this vulnerability in that the victim must run this utility on the Windows system. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

    Published: 12 Feb 2021
    4.8
    Medium

    CVE-2021-22981

    Last Modified: 21 Nov 2024

    On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiation that is mitigated by the Extended Master Secret (EMS) extension defined in RFC 7627. TLS connections that do not use EMS are vulnerable to man-in-the-middle attacks during renegotiation. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

    Published: 12 Feb 2021
    7.5
    High

    CVE-2021-22985

    Last Modified: 21 Nov 2024

    On BIG-IP APM version 16.0.x before 16.0.1.1, under certain conditions, when processing VPN traffic with APM, TMM consumes excessive memory. A malicious, authenticated VPN user may abuse this to perform a DoS attack against the APM. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

    Published: 12 Feb 2021