CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2021-26936

    Last Modified: 21 Nov 2024

    The replay-sorcery program in ReplaySorcery 0.4.0 through 0.5.0, when using the default setuid-root configuration, allows a local attacker to escalate privileges to root by specifying video output paths in privileged locations.

    Published: 10 Feb 2021
    9.1
    Critical

    CVE-2021-3033

    Last Modified: 21 Nov 2024

    An improper verification of cryptographic signature vulnerability exists in the Palo Alto Networks Prisma Cloud Compute console. This vulnerability enables an attacker to bypass signature validation during SAML authentication by logging in to the Prisma Cloud Compute console as any authorized user. This issue impacts: All versions of Prisma Cloud Compute 19.11, Prisma Cloud Compute 20.04, and Prisma Cloud Compute 20.09; Prisma Cloud Compute 20.12 before update 1. Prisma Cloud Compute SaaS version is not impacted by this vulnerability.

    Published: 10 Feb 2021
    8.2
    High

    CVE-2021-20353

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 194882.

    Published: 10 Feb 2021
    7.5
    High

    CVE-2020-5023

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Plus 10.1.0 through 10.1.7 could allow a remote user to inject arbitrary data iwhich could cause the serivce to crash due to excess resource consumption. IBM X-Force ID: 193659.

    Published: 10 Feb 2021
    7.8
    High

    CVE-2020-13546

    Last Modified: 21 Nov 2024

    In SoftMaker Software GmbH SoftMaker Office TextMaker 2021 (revision 1014), a specially crafted document can cause the document parser to miscalculate a length used to allocate a buffer, later upon usage of this buffer the application will write outside its bounds resulting in a heap-based buffer overflow. An attacker can entice the victim to open a document to trigger this vulnerability.

    Published: 10 Feb 2021
    8.8
    High

    CVE-2021-0325

    Last Modified: 21 Nov 2024

    In ih264d_parse_pslice of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-174238784

    Published: 10 Feb 2021
    7.8
    High

    CVE-2021-0327

    Last Modified: 21 Nov 2024

    In getContentProviderImpl of ActivityManagerService.java, there is a possible permission bypass due to non-restored binder identities. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-172935267

    Published: 10 Feb 2021
    7.8
    High

    CVE-2021-0328

    Last Modified: 21 Nov 2024

    In onBatchScanReports and deliverBatchScan of GattService.java, there is a possible way to retrieve Bluetooth scan results without permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-172670415

    Published: 10 Feb 2021
    7.8
    High

    CVE-2021-0329

    Last Modified: 21 Nov 2024

    In several native functions called by AdvertiseManager.java, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the Bluetooth server with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-171400004

    Published: 10 Feb 2021
    7.3
    High

    CVE-2021-0314

    Last Modified: 21 Nov 2024

    In onCreate of UninstallerActivity, there is a possible way to uninstall an all without informed user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-171221302

    Published: 10 Feb 2021
    7.8
    High

    CVE-2021-0330

    Last Modified: 21 Nov 2024

    In add_user_ce and remove_user_ce of storaged.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in storaged with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11Android ID: A-170732441

    Published: 10 Feb 2021
    7.3
    High

    CVE-2021-0331

    Last Modified: 21 Nov 2024

    In onCreate of NotificationAccessConfirmationActivity.java, there is a possible overlay attack due to an insecure default value. This could lead to local escalation of privilege and notification access with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-170731783

    Published: 10 Feb 2021
    7.8
    High

    CVE-2021-0332

    Last Modified: 21 Nov 2024

    In bootFinished of SurfaceFlinger.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-169256435

    Published: 10 Feb 2021
    7.3
    High

    CVE-2021-0333

    Last Modified: 21 Nov 2024

    In onCreate of BluetoothPermissionActivity.java, there is a possible permissions bypass due to a tapjacking overlay that obscures the phonebook permissions dialog when a Bluetooth device is connecting. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-168504491

    Published: 10 Feb 2021
    7.8
    High

    CVE-2021-0334

    Last Modified: 21 Nov 2024

    In onTargetSelected of ResolverActivity.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-163358811

    Published: 10 Feb 2021
    6.5
    Medium

    CVE-2021-0335

    Last Modified: 21 Nov 2024

    In process of C2SoftHevcDec.cpp, there is a possible out of bounds write due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-160346309

    Published: 10 Feb 2021
    7.8
    High

    CVE-2021-0336

    Last Modified: 21 Nov 2024

    In onReceive of BluetoothPermissionRequest.java, there is a possible permissions bypass due to a mutable PendingIntent. This could lead to local escalation of privilege that bypasses a permission check, with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-158219161

    Published: 10 Feb 2021
    7.8
    High

    CVE-2021-0337

    Last Modified: 21 Nov 2024

    In moveInMediaStore of FileSystemProvider.java, there is a possible file exposure due to stale metadata. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-157474195

    Published: 10 Feb 2021
    5.5
    Medium

    CVE-2021-0338

    Last Modified: 21 Nov 2024

    In SystemSettingsValidators, there is a possible permanent denial of service due to missing bounds checks on UI settings. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-156260178

    Published: 10 Feb 2021
    7.8
    High

    CVE-2021-0302

    Last Modified: 21 Nov 2024

    In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10Android ID: A-155287782

    Published: 10 Feb 2021
    7.8
    High

    CVE-2021-0305

    Last Modified: 21 Nov 2024

    In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10Android ID: A-154015447

    Published: 10 Feb 2021
    7.8
    High

    CVE-2021-0339

    Last Modified: 21 Nov 2024

    In loadAnimation of WindowContainer.java, there is a possible way to keep displaying a malicious app while a target app is brought to the foreground. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-8.1 Android-9Android ID: A-145728687

    Published: 10 Feb 2021
    8.8
    High

    CVE-2021-0340

    Last Modified: 21 Nov 2024

    In parseNextBox of IsoInterface.java, there is a possible leak of unredacted location information due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-134155286

    Published: 10 Feb 2021
    7.5
    High

    CVE-2020-24838

    Last Modified: 21 Nov 2024

    An integer overflow has been found in the the latest version of Issuer. The total issuedCount can be zero if the parameter is overly large. An attacker can obtain the private key of the owner issued with a certain 'amount', and the issuedCount can be zero if there is an overflow.

    Published: 10 Feb 2021
    7.5
    High

    CVE-2020-24837

    Last Modified: 21 Nov 2024

    An integer underflow has been found in the latest version of ZCFees. The variables 'currPeriodIdx' and 'lastPeriodExecIdx' are both unsigned integers, and the result of the minus operation may be a negative integer which leads to an underflow. The attackers can modify the current timestamp of the transaction somehow and block the execution of the process function.

    Published: 10 Feb 2021
    6.1
    Medium

    CVE-2020-29171

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in admin/wp-security-blacklist-menu.php in the Tips and Tricks HQ All In One WP Security & Firewall (all-in-one-wp-security-and-firewall) plugin before 4.4.6 for WordPress.

    Published: 10 Feb 2021
    7.5
    High

    CVE-2020-17525

    Last Modified: 13 Feb 2025

    Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the service. This issue was fixed in mod_dav_svn+mod_authz_svn servers 1.14.1 and mod_dav_svn+mod_authz_svn servers 1.10.7

    Published: 10 Feb 2021
    4.8
    Medium

    CVE-2021-23881

    Last Modified: 21 Nov 2024

    A stored cross site scripting vulnerability in ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 February 2021 Update allows an ENS ePO administrator to add a script to a policy event which will trigger the script to be run through a browser block page when a local non-administrator user triggers the policy.

    Published: 10 Feb 2021
    8.2
    High

    CVE-2021-23874

    Last Modified: 3 Nov 2025

    Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP self-defense.

    Published: 10 Feb 2021
    7.8
    High

    CVE-2021-23876

    Last Modified: 21 Nov 2024

    Bypass Remote Procedure call in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and perform arbitrary file modification as the SYSTEM user potentially causing Denial of Service via executing carefully constructed malware.

    Published: 10 Feb 2021
    7.8
    High

    CVE-2021-23873

    Last Modified: 21 Nov 2024

    Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and perform arbitrary file deletion as the SYSTEM user potentially causing Denial of Service via manipulating Junction link, after enumerating certain files, at a specific time.

    Published: 10 Feb 2021
    4
    Medium

    CVE-2021-23883

    Last Modified: 21 Nov 2024

    A Null Pointer Dereference vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows a local administrator to cause Windows to crash via a specific system call which is not handled correctly. This varies by machine and had partial protection prior to this update.

    Published: 10 Feb 2021
    8.2
    High

    CVE-2021-23882

    Last Modified: 21 Nov 2024

    Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows local administrators to prevent the installation of some ENS files by placing carefully crafted files where ENS will be installed. This is only applicable to clean installations of ENS as the Access Control rules will prevent modification prior to up an upgrade.

    Published: 10 Feb 2021
    6.7
    Medium

    CVE-2021-23880

    Last Modified: 21 Nov 2024

    Improper Access Control in attribute in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows authenticated local administrator user to perform an uninstallation of the anti-malware engine via the running of a specific command with the correct parameters.

    Published: 10 Feb 2021
    7.3
    High

    CVE-2021-23878

    Last Modified: 21 Nov 2024

    Clear text storage of sensitive Information in memory vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows a local user to view ENS settings and credentials via accessing process memory after the ENS administrator has performed specific actions. To exploit this, the local user has to access the relevant memory location immediately after an ENS administrator has made a configuration change through the console on their machine

    Published: 10 Feb 2021
    5.4
    Medium

    CVE-2021-20654

    Last Modified: 21 Nov 2024

    Wekan, open source kanban board system, between version 3.12 and 4.11, is vulnerable to multiple stored cross-site scripting. This is named 'Fieldbleed' in the vendor's site.

    Published: 10 Feb 2021
    9.8
    Critical

    CVE-2020-28870

    Last Modified: 21 Nov 2024

    In InoERP 0.7.2, an unauthorized attacker can execute arbitrary code on the server side due to lack of validations in /modules/sys/form_personalization/json_fp.php.

    Published: 10 Feb 2021
    6.6
    Medium

    CVE-2021-27017

    Last Modified: 15 Apr 2026

    Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. This is resolved in the Puppet Agent 7.4.0 release.

    Published: 10 Feb 2021
    7.5
    High

    CVE-2020-13578

    Last Modified: 21 Nov 2024

    A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 10 Feb 2021
    6.3
    Medium

    CVE-2020-26299

    Last Modified: 21 Nov 2024

    ftp-srv is an open-source FTP server designed to be simple yet configurable. In ftp-srv before version 4.4.0 there is a path-traversal vulnerability. Clients of FTP servers utilizing ftp-srv hosted on Windows machines can escape the FTP user's defined root folder using the expected FTP commands, for example, CWD and UPDR. When windows separators exist within the path (`\`), `path.resolve` leaves the upper pointers intact and allows the user to move beyond the root folder defined for that user. We did not take that into account when creating the path resolve function. The issue is patched in version 4.4.0 (commit 457b859450a37cba10ff3c431eb4aa67771122e3).

    Published: 10 Feb 2021
    9.8
    Critical

    CVE-2020-28871

    Last Modified: 21 Nov 2024

    Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the server-side via an insecure file upload.

    Published: 10 Feb 2021
    4.9
    Medium

    CVE-2020-7021

    Last Modified: 21 Nov 2024

    Elasticsearch versions before 7.10.0 and 6.8.14 have an information disclosure issue when audit logging and the emit_request_body option is enabled. The Elasticsearch audit log could contain sensitive information such as password hashes or authentication tokens. This could allow an Elasticsearch administrator to view these details.

    Published: 10 Feb 2021
    7
    High

    CVE-2021-20188

    Last Modified: 21 Nov 2024

    A flaw was found in podman before 1.7.0. File permissions for non-root users running in a privileged container are not correctly checked. This flaw can be abused by a low-privileged user inside the container to access any other file in the container, even if owned by the root user inside the container. It does not allow to directly escape the container, though being a privileged container means that a lot of security features are disabled when running the container. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 10 Feb 2021
    6.5
    Medium

    CVE-2021-20257

    Last Modified: 21 Nov 2024

    An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized with invalid values. This flaw allows a guest to consume CPU cycles on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

    Published: 10 Feb 2021
    3.3
    Low

    CVE-2020-10734

    Last Modified: 21 Nov 2024

    A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes are believed to be vulnerable.

    Published: 10 Feb 2021
    9.8
    Critical

    CVE-2021-27135

    Last Modified: 21 Nov 2024

    xterm before Patch #366 allows remote attackers to execute arbitrary code or cause a denial of service (segmentation fault) via a crafted UTF-8 combining character sequence.

    Published: 10 Feb 2021
    7.5
    High

    CVE-2021-27218

    Last Modified: 21 Nov 2024

    An issue was discovered in GNOME GLib before 2.66.7 and 2.67.x before 2.67.4. If g_byte_array_new_take() was called with a buffer of 4GB or more on a 64-bit platform, the length would be truncated modulo 2**32, causing unintended length truncation.

    Published: 10 Feb 2021
    7.5
    High

    CVE-2020-13574

    Last Modified: 21 Nov 2024

    A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 10 Feb 2021
    9.8
    Critical

    CVE-2020-13576

    Last Modified: 21 Nov 2024

    A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 10 Feb 2021
    7.5
    High

    CVE-2020-13577

    Last Modified: 21 Nov 2024

    A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 10 Feb 2021