CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2021-22982

    Last Modified: 21 Nov 2024

    On BIG-IP DNS and GTM version 13.1.x before 13.1.0.4, and all versions of 12.1.x and 11.6.x, big3d does not securely handle and parse certain payloads resulting in a buffer overflow. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

    Published: 12 Feb 2021
    7.5
    High

    CVE-2021-22976

    Last Modified: 21 Nov 2024

    On BIG-IP Advanced WAF and ASM version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, and all 12.1.x versions, when the BIG-IP ASM system processes WebSocket requests with JSON payloads, an unusually large number of parameters can cause excessive CPU usage in the BIG-IP ASM bd process. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

    Published: 12 Feb 2021
    7.5
    High

    CVE-2021-20412

    Last Modified: 21 Nov 2024

    IBM Security Verify Information Queue 1.0.6 and 1.0.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 198192.

    Published: 12 Feb 2021
    8.1
    High

    CVE-2021-20411

    Last Modified: 21 Nov 2024

    IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to impersonate another user on the system due to incorrectly updating the session identifier. IBM X-Force ID: 198191.

    Published: 12 Feb 2021
    5.3
    Medium

    CVE-2021-20410

    Last Modified: 21 Nov 2024

    IBM Security Verify Information Queue 1.0.6 and 1.0.7 sends user credentials in plain clear text which can be read by an authenticated user using man in the middle techniques. IBM X-Force ID: 198190.

    Published: 12 Feb 2021
    5.9
    Medium

    CVE-2021-20409

    Last Modified: 21 Nov 2024

    IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 196188.

    Published: 12 Feb 2021
    5.5
    Medium

    CVE-2021-20408

    Last Modified: 21 Nov 2024

    IBM Security Verify Information Queue 1.0.6 and 1.0.7 could disclose highly sensitive information to a local user due to inproper storage of a plaintext cryptographic key. IBM X-Force ID: 198187.

    Published: 12 Feb 2021
    5.3
    Medium

    CVE-2021-20407

    Last Modified: 21 Nov 2024

    IBM Security Verify Information Queue 1.0.6 and 1.0.7 discloses sensitive information in source code that could be used in further attacks against the system. IBM X-Force ID: 196185.

    Published: 12 Feb 2021
    2.2
    Low

    CVE-2021-20406

    Last Modified: 21 Nov 2024

    IBM Security Verify Information Queue 1.0.6 and 1.0.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196184.

    Published: 12 Feb 2021
    7.5
    High

    CVE-2021-22974

    Last Modified: 21 Nov 2024

    On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6 and all versions of BIG-IQ 7.x and 6.x, an authenticated attacker with access to iControl REST over the control plane may be able to take advantage of a race condition to execute commands with an elevated privilege level. This vulnerability is due to an incomplete fix for CVE-2017-6167. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

    Published: 12 Feb 2021
    7.5
    High

    CVE-2021-22973

    Last Modified: 21 Nov 2024

    On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all 12.1.x versions, JSON parser function does not protect against out-of-bounds memory accesses or writes. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

    Published: 12 Feb 2021
    7.5
    High

    CVE-2021-22975

    Last Modified: 21 Nov 2024

    On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, and 14.1.x before 14.1.3.1, under some circumstances, Traffic Management Microkernel (TMM) may restart on the BIG-IP system while passing large bursts of traffic. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

    Published: 12 Feb 2021
    8.1
    High

    CVE-2021-27197

    Last Modified: 21 Nov 2024

    DSUtility.dll in Pelco Digital Sentry Server before 7.19.67 has an arbitrary file write vulnerability. The AppendToTextFile method doesn't check if it's being called from the application or from a malicious user. The vulnerability is triggered when a remote attacker crafts an HTML page (e.g., with "OBJECT classid=" and "<SCRIPT language='vbscript'>") to overwrite arbitrary files.

    Published: 12 Feb 2021
    7.5
    High

    CVE-2021-27188

    Last Modified: 21 Nov 2024

    The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 allows attackers to cause a denial of service (access suspended for five hours) by making five invalid login attempts to a victim's account.

    Published: 12 Feb 2021
    7.5
    High

    CVE-2021-27187

    Last Modified: 21 Nov 2024

    The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 stores authentication credentials in cleartext in login.sav when the Save Password box is checked.

    Published: 12 Feb 2021
    5.5
    Medium

    CVE-2021-27204

    Last Modified: 21 Nov 2024

    Telegram before 7.4 (212543) Stable on macOS stores the local passcode in cleartext, leading to information disclosure.

    Published: 12 Feb 2021
    5.5
    Medium

    CVE-2021-27205

    Last Modified: 21 Nov 2024

    Telegram before 7.4 (212543) Stable on macOS stores the local copy of self-destructed messages in a sandbox path, leading to sensitive information disclosure.

    Published: 12 Feb 2021
    9.1
    Critical

    CVE-2021-20651

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in ELECOM File Manager all versions allows remote attackers to create an arbitrary file or overwrite an existing file in a directory which can be accessed with the application privileges via unspecified vectors.

    Published: 12 Feb 2021
    6.5
    Medium

    CVE-2021-20650

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in ELECOM NCC-EWF100RMWH2 allows remote attackers to hijack the authentication of administrators and execute an arbitrary request via unspecified vector. As a result, the device settings may be altered and/or telnet daemon may be started.

    Published: 12 Feb 2021
    6.8
    Medium

    CVE-2021-20648

    Last Modified: 21 Nov 2024

    ELECOM WRC-300FEBK-S allows an attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.

    Published: 12 Feb 2021
    4.8
    Medium

    CVE-2021-20649

    Last Modified: 21 Nov 2024

    ELECOM WRC-300FEBK-S contains an improper certificate validation vulnerability. Via a man-in-the-middle attack, an attacker may alter the communication response. As a result, an arbitrary OS command may be executed on the affected device.

    Published: 12 Feb 2021
    6.5
    Medium

    CVE-2021-20647

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in ELECOM WRC-300FEBK-S allows remote attackers to hijack the authentication of administrators and execute an arbitrary request via unspecified vector. As a result, the device settings may be altered and/or telnet daemon may be started.

    Published: 12 Feb 2021
    5.4
    Medium

    CVE-2021-20645

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in ELECOM WRC-300FEBK-A allows remote authenticated attackers to inject arbitrary script via unspecified vectors.

    Published: 12 Feb 2021
    6.5
    Medium

    CVE-2021-20646

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in ELECOM WRC-300FEBK-A allows remote attackers to hijack the authentication of administrators and execute an arbitrary request via unspecified vector. As a result, the device settings may be altered and/or telnet daemon may be started.

    Published: 12 Feb 2021
    6.1
    Medium

    CVE-2021-20644

    Last Modified: 21 Nov 2024

    ELECOM WRC-1467GHBK-A allows arbitrary scripts to be executed on the user's web browser by displaying a specially crafted SSID on the web setup page.

    Published: 12 Feb 2021
    7.5
    High

    CVE-2021-20643

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in ELECOM LD-PS/U1 allows remote attackers to change the administrative password of the affected device by processing a specially crafted request.

    Published: 12 Feb 2021
    6.5
    Medium

    CVE-2021-20641

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/RS allows remote attackers to hijack the authentication of administrators via a specially crafted URL. As a result, unintended operations to the device such as changes of the device settings may be conducted.

    Published: 12 Feb 2021
    6.5
    Medium

    CVE-2021-20642

    Last Modified: 21 Nov 2024

    Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/RS allows a remote attacker to cause a denial-of-service (DoS) condition by sending a specially crafted URL.

    Published: 12 Feb 2021
    6.8
    Medium

    CVE-2021-20640

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute an arbitrary OS command via unspecified vectors.

    Published: 12 Feb 2021
    6.8
    Medium

    CVE-2021-20638

    Last Modified: 21 Nov 2024

    LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.

    Published: 12 Feb 2021
    6.8
    Medium

    CVE-2021-20639

    Last Modified: 21 Nov 2024

    LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.

    Published: 12 Feb 2021
    6.5
    Medium

    CVE-2021-20637

    Last Modified: 21 Nov 2024

    Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/PR5B allows a remote attacker to cause a denial-of-service (DoS) condition by sending a specially crafted URL.

    Published: 12 Feb 2021
    6.5
    Medium

    CVE-2021-20636

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/PR5B allows remote attackers to hijack the authentication of administrators via a specially crafted URL. As a result, unintended operations to the device such as changes of the device settings may be conducted.

    Published: 12 Feb 2021
    6.5
    Medium

    CVE-2021-20635

    Last Modified: 21 Nov 2024

    Improper restriction of excessive authentication attempts in LOGITEC LAN-WH450N/GR allows an attacker in the wireless range of the device to recover PIN and access the network.

    Published: 12 Feb 2021
    5.4
    Medium

    CVE-2021-27190

    Last Modified: 21 Nov 2024

    A Stored Cross Site Scripting(XSS) Vulnerability was discovered in PEEL SHOPPING 9.3.0 and 9.4.0, which are publicly available. The user supplied input containing polyglot payload is echoed back in javascript code in HTML response. This allows an attacker to input malicious JavaScript which can steal cookie, redirect them to other malicious website, etc.

    Published: 12 Feb 2021
    7.5
    High

    CVE-2013-20001

    Last Modified: 3 Nov 2025

    An issue was discovered in OpenZFS through 2.0.3. When an NFS share is exported to IPv6 addresses via the sharenfs feature, there is a silent failure to parse the IPv6 address data, and access is allowed to everyone. IPv6 restrictions from the configuration are not applied.

    Published: 12 Feb 2021
    7.3
    High

    CVE-2021-3412

    Last Modified: 21 Nov 2024

    It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login controls, and access privileged information, or possibly conduct further attacks.

    Published: 12 Feb 2021
    8.8
    High

    CVE-2020-27869

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to escalate privileges on affected installations of SolarWinds Network Performance Monitor 2020 HF1, NPM: 2020.2. Authentication is required to exploit this vulnerability. The specific flaw exists within the WriteToFile method. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges and reset the password for the Admin user. Was ZDI-CAN-11804.

    Published: 11 Feb 2021
    9.8
    Critical

    CVE-2020-27868

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Qognify Ocularis 5.9.0.395. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of serialized objects provided to the EventCoordinator endpoint. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-11257.

    Published: 11 Feb 2021
    6.8
    Medium

    CVE-2020-27867

    Last Modified: 21 Nov 2024

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6020, R6080, R6120, R6220, R6260, R6700v2, R6800, R6900v2, R7450, JNR3210, WNR2020, Nighthawk AC2100, and Nighthawk AC2400 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the mini_httpd service, which listens on TCP port 80 by default. When parsing the funjsq_access_token parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-11653.

    Published: 11 Feb 2021
    8.8
    High

    CVE-2020-27866

    Last Modified: 21 Nov 2024

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6020, R6080, R6120, R6220, R6260, R6700v2, R6800, R6900v2, R7450, JNR3210, WNR2020, Nighthawk AC2100, and Nighthawk AC2400 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the mini_httpd service, which listens on TCP port 80 by default. The issue results from incorrect string matching logic when accessing protected pages. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-11355.

    Published: 11 Feb 2021
    8.8
    High

    CVE-2020-27865

    Last Modified: 21 Nov 2024

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 firmware version 1.04B03 WiFi extenders. Authentication is not required to exploit this vulnerability. The specific flaw exists within the uhttpd service, which listens on TCP port 80 by default. The issue results from incorrect string matching logic when accessing protected pages. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of the device. Was ZDI-CAN-10894.

    Published: 11 Feb 2021
    8.8
    High

    CVE-2020-27864

    Last Modified: 21 Nov 2024

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 firmware version 1.04B03 WiFi extenders. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HNAP service, which listens on TCP port 80 by default. When parsing the Authorization request header, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-10880.

    Published: 11 Feb 2021
    6.5
    Medium

    CVE-2020-27863

    Last Modified: 21 Nov 2024

    This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DVA-2800 and DSL-2888A routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the dhttpd service, which listens on TCP port 8008 by default. The issue results from incorrect string matching logic when accessing protected pages. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-10912.

    Published: 11 Feb 2021
    8.8
    High

    CVE-2020-27861

    Last Modified: 21 Nov 2024

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Orbi 2.5.1.16 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UA_Parser utility. A crafted Host Name option in a DHCP request can trigger execution of a system call composed from a user-supplied string. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-11076.

    Published: 11 Feb 2021
    8.8
    High

    CVE-2020-27862

    Last Modified: 21 Nov 2024

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DVA-2800 and DSL-2888A routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the dhttpd service, which listens on TCP port 8008 by default. When parsing the path parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the web server. Was ZDI-CAN-10911.

    Published: 11 Feb 2021
    7.8
    High

    CVE-2020-27860

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.0.1.35811. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of XFA templates. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-11727.

    Published: 11 Feb 2021
    6.1
    Medium

    CVE-2021-21310

    Last Modified: 21 Nov 2024

    NextAuth.js (next-auth) is am open source authentication solution for Next.js applications. In next-auth before version 3.3.0 there is a token verification vulnerability. Implementations using the Prisma database adapter in conjunction with the Email provider are impacted. Implementations using the Email provider with the default database adapter are not impacted. Implementations using the Prisma database adapter but not using the Email provider are not impacted. The Prisma database adapter was checking the verification token, but was not verifying the email address associated with that token. This made it possible to use a valid token to sign in as another user when using the Prima adapter in conjunction with the Email provider. This issue is specific to the community supported Prisma adapter. This issue is fixed in version 3.3.0.

    Published: 11 Feb 2021
    7.2
    High

    CVE-2021-21311

    Last Modified: 24 Oct 2025

    Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. This is fixed in version 4.7.9.

    Published: 11 Feb 2021
    7.2
    High

    CVE-2021-21976

    Last Modified: 21 Nov 2024

    vSphere Replication 8.3.x prior to 8.3.1.2, 8.2.x prior to 8.2.1.1, 8.1.x prior to 8.1.2.3 and 6.5.x prior to 6.5.1.5 contain a post-authentication command injection vulnerability which may allow an authenticated admin user to perform a remote code execution.

    Published: 11 Feb 2021