CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2020-36244

    Last Modified: 21 Nov 2024

    The daemon in GENIVI diagnostic log and trace (DLT), is vulnerable to a heap-based buffer overflow that could allow an attacker to remotely execute arbitrary code on the DLT-Daemon (versions prior to 2.18.6).

    Published: 10 Feb 2021
    0
    Low

    CVE-2021-3408

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 10 Feb 2021
    2.7
    Low

    CVE-2020-1717

    Last Modified: 21 Nov 2024

    A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.

    Published: 10 Feb 2021
    7.5
    High

    CVE-2020-35498

    Last Modified: 23 Apr 2025

    A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a specially crafted packet causing the resulting megaflow in the kernel to be too wide, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.

    Published: 10 Feb 2021
    7.5
    High

    CVE-2021-0341

    Last Modified: 21 Nov 2024

    In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-171980069

    Published: 10 Feb 2021
    9.8
    Critical

    CVE-2021-26951

    Last Modified: 21 Nov 2024

    An issue was discovered in the calamine crate before 0.17.0 for Rust. It allows attackers to overwrite heap-memory locations because Vec::set_len is used without proper memory claiming, and this uninitialized memory is used for a user-provided Read operation, as demonstrated by Sectors::get.

    Published: 9 Feb 2021
    7.5
    High

    CVE-2021-26952

    Last Modified: 21 Nov 2024

    An issue was discovered in the ms3d crate before 0.1.3 for Rust. It might allow attackers to obtain sensitive information from uninitialized memory locations via IoReader::read.

    Published: 9 Feb 2021
    5.3
    Medium

    CVE-2021-26954

    Last Modified: 21 Nov 2024

    An issue was discovered in the qwutils crate before 0.3.1 for Rust. When a Clone panic occurs, insert_slice_clone can perform a double drop.

    Published: 9 Feb 2021
    9.8
    Critical

    CVE-2021-26955

    Last Modified: 21 Nov 2024

    An issue was discovered in the xcb crate through 2021-02-04 for Rust. It has a soundness violation because xcb::xproto::GetAtomNameReply::name() calls std::str::from_utf8_unchecked() on unvalidated bytes from an X server.

    Published: 9 Feb 2021
    9.8
    Critical

    CVE-2021-26957

    Last Modified: 21 Nov 2024

    An issue was discovered in the xcb crate through 2021-02-04 for Rust. It has a soundness violation because there is an out-of-bounds read in xcb::xproto::change_property(), as demonstrated by a format=32 T=u8 situation where out-of-bounds bytes are sent to an X server.

    Published: 9 Feb 2021
    8.8
    High

    CVE-2021-26958

    Last Modified: 21 Nov 2024

    An issue was discovered in the xcb crate through 2021-02-04 for Rust. It has a soundness violation because transmutation to the wrong type can happen after xcb::base::cast_event uses std::mem::transmute to return a reference to an arbitrary type.

    Published: 9 Feb 2021
    —
    Unknown

    CVE-2021-26959

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-21299. Reason: This candidate is a duplicate of CVE-2021-21299. Notes: All CVE users should reference CVE-2021-21299 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 9 Feb 2021
    9.8
    Critical

    CVE-2021-26956

    Last Modified: 21 Nov 2024

    An issue was discovered in the xcb crate through 2021-02-04 for Rust. It has a soundness violation because bytes from an X server can be interpreted as any data type returned by xcb::xproto::GetPropertyReply::value.

    Published: 9 Feb 2021
    7.5
    High

    CVE-2021-26953

    Last Modified: 21 Nov 2024

    An issue was discovered in the postscript crate before 0.14.0 for Rust. It might allow attackers to obtain sensitive information from uninitialized memory locations via a user-provided Read implementation.

    Published: 9 Feb 2021
    9.6
    Critical

    CVE-2020-35125

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the forms component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript via mautic[return] (a different attack method than CVE-2020-35124, but also related to the Referer concept).

    Published: 9 Feb 2021
    9.8
    Critical

    CVE-2021-21502

    Last Modified: 21 Nov 2024

    Dell PowerScale OneFS versions 8.1.0 – 9.1.0 contain a "use of SSH key past account expiration" vulnerability. A user on the network with the ISI_PRIV_AUTH_SSH RBAC privilege that has an expired account may potentially exploit this vulnerability, giving them access to the same things they had before account expiration. This may by a high privileged account and hence Dell recommends customers upgrade at the earliest opportunity.

    Published: 9 Feb 2021
    5.5
    Medium

    CVE-2020-26196

    Last Modified: 21 Nov 2024

    Dell EMC PowerScale OneFS versions 8.1.0-9.1.0 contain a Backup/Restore Privilege implementation issue. A user with the BackupAdmin role may potentially exploit this vulnerability resulting in the ability to write data outside of the intended file system location.

    Published: 9 Feb 2021
    5.3
    Medium

    CVE-2020-26195

    Last Modified: 21 Nov 2024

    Dell EMC PowerScale OneFS versions 8.1.2 – 9.1.0 contain an issue where the OneFS SMB directory auto-create may erroneously create a directory for a user. A remote unauthenticated attacker may take advantage of this issue to slow down the system.

    Published: 9 Feb 2021
    7
    High

    CVE-2020-26194

    Last Modified: 21 Nov 2024

    Dell EMC PowerScale OneFS versions 8.1.2 and 8.2.2 contain an Incorrect Permission Assignment for a Critical Resource vulnerability. This may allow a non-admin user with either ISI_PRIV_LOGIN_CONSOLE or ISI_PRIV_LOGIN_SSH privileges to exploit the vulnerability, leading to compromised cryptographic operations. Note: no non-admin users or roles have these privileges by default.

    Published: 9 Feb 2021
    7.8
    High

    CVE-2020-26193

    Last Modified: 21 Nov 2024

    Dell EMC PowerScale OneFS versions 8.1.0 - 9.1.0 contain an improper input validation vulnerability. A user with the ISI_PRIV_CLUSTER privilege may exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application.

    Published: 9 Feb 2021
    7.8
    High

    CVE-2020-26192

    Last Modified: 21 Nov 2024

    Dell EMC PowerScale OneFS versions 8.2.0 - 9.1.0 contain a privilege escalation vulnerability. A non-admin user with either ISI_PRIV_LOGIN_CONSOLE or ISI_PRIV_LOGIN_SSH may potentially exploit this vulnerability to read arbitrary data, tamper with system software or deny service to users. Note: no non-admin users or roles have these privileges by default.

    Published: 9 Feb 2021
    7.8
    High

    CVE-2020-26191

    Last Modified: 21 Nov 2024

    Dell EMC PowerScale OneFS versions 8.1.0 - 9.1.0 contain a privilege escalation vulnerability. A user with ISI_PRIV_JOB_ENGINE may use the PermissionRepair job to grant themselves the highest level of RBAC privileges thus being able to read arbitrary data, tamper with system software or deny service to users.

    Published: 9 Feb 2021
    9.1
    Critical

    CVE-2021-21479

    Last Modified: 21 Nov 2024

    In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system.

    Published: 9 Feb 2021
    6.1
    Medium

    CVE-2021-21478

    Last Modified: 21 Nov 2024

    SAP Web Dynpro ABAP allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.

    Published: 9 Feb 2021
    6.1
    Medium

    CVE-2021-21476

    Last Modified: 21 Nov 2024

    SAP UI5 versions before 1.38.49, 1.52.49, 1.60.34, 1.71.31, 1.78.18, 1.84.5, 1.85.4, 1.86.1 allows an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.

    Published: 9 Feb 2021
    6.1
    Medium

    CVE-2021-21444

    Last Modified: 21 Nov 2024

    SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be predictably treated by all user agents. This could, as a result, nullify the added X-Frame-Options header leading to Clickjacking attack.

    Published: 9 Feb 2021
    6.5
    Medium

    CVE-2021-21474

    Last Modified: 21 Nov 2024

    SAP HANA Database, versions - 1.0, 2.0, accepts SAML tokens with MD5 digest, an attacker who manages to obtain an MD5-digest signed SAML Assertion issued for an SAP HANA instance might be able to tamper with it and alter it in a way that the digest continues to be the same and without invalidating the digital signature, this allows them to impersonate as user in HANA database and be able to read the contents in the database.

    Published: 9 Feb 2021
    9.9
    Critical

    CVE-2021-21477

    Last Modified: 21 Nov 2024

    SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attacker with this privilege will be able to inject malicious code in the drools rules which when executed leads to Remote Code Execution vulnerability enabling the attacker to compromise the underlying host enabling him to impair confidentiality, integrity and availability of the application.

    Published: 9 Feb 2021
    7.5
    High

    CVE-2021-21475

    Last Modified: 21 Nov 2024

    Under specific circumstances SAP Master Data Management, versions - 710, 710.750, allows an unauthorized attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs. Due to this Directory Traversal vulnerability the attacker could read content of arbitrary files on the remote server and expose sensitive data.

    Published: 9 Feb 2021
    8.8
    High

    CVE-2021-21472

    Last Modified: 21 Nov 2024

    SAP Software Provisioning Manager 1.0 (SAP NetWeaver Master Data Management Server 7.1) does not have an option to set password during its installation, this allows an authenticated attacker to perform various security attacks like Directory Traversal, Password Brute force Attack, SMB Relay attack, Security Downgrade.

    Published: 9 Feb 2021
    6.1
    Medium

    CVE-2020-22839

    Last Modified: 21 Nov 2024

    Reflected cross-site scripting vulnerability (XSS) in the evoadm.php file in b2evolution cms version 6.11.6-stable allows remote attackers to inject arbitrary webscript or HTML code via the tab3 parameter.

    Published: 9 Feb 2021
    9.8
    Critical

    CVE-2021-26937

    Last Modified: 9 May 2025

    encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence.

    Published: 9 Feb 2021
    8.8
    High

    CVE-2021-26551

    Last Modified: 21 Nov 2024

    An issue was discovered in SmartFoxServer 2.17.0. An attacker can execute arbitrary Python code, and bypass the javashell.py protection mechanism, by creating /config/ConsoleModuleUnlock.txt and editing /config/admin/admintool.xml to enable the Console module.

    Published: 9 Feb 2021
    5.5
    Medium

    CVE-2021-26550

    Last Modified: 21 Nov 2024

    An issue was discovered in SmartFoxServer 2.17.0. Cleartext password disclosure can occur via /config/server.xml.

    Published: 9 Feb 2021
    5.4
    Medium

    CVE-2021-26549

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in SmartFoxServer 2.17.0. Input passed to the AdminTool console is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML code in a user's browser session in context of an affected site.

    Published: 9 Feb 2021
    8.8
    High

    CVE-2020-18215

    Last Modified: 21 Nov 2024

    Multiple SQL Injection vulnerabilities in PHPSHE 1.7 in phpshe/admin.php via the (1) ad_id, (2) menu_id, and (3) cashout_id parameters, which could let a remote malicious user execute arbitrary code.

    Published: 9 Feb 2021
    9.8
    Critical

    CVE-2020-13117

    Last Modified: 19 Aug 2025

    Wavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request.

    Published: 9 Feb 2021
    6.5
    Medium

    CVE-2021-1721

    Last Modified: 28 May 2026

    .NET Core and Visual Studio Denial of Service Vulnerability

    Published: 9 Feb 2021
    9.1
    Critical

    CVE-2020-28645

    Last Modified: 21 Nov 2024

    Deleting users with certain names caused system files to be deleted. Risk is higher for systems which allow users to register themselves and have the data directory in the web root. This affects ownCloud/core versions < 10.6.

    Published: 9 Feb 2021
    5.9
    Medium

    CVE-2021-22267

    Last Modified: 21 Nov 2024

    Idelji Web ViewPoint Suite, as used in conjunction with HPE NonStop, allows a remote replay attack for T0320L01^ABP through T0320L01^ABZ, T0952L01^AAH through T0952L01^AAR, T0986L01 through T0986L01^AAF, T0665L01^AAP, and T0662L01^AAP (L) and T0320H01^ABO through T0320H01^ABY, T0952H01^AAG through T0952H01^AAQ, T0986H01 through T0986H01^AAE, T0665H01^AAO, and T0662H01^AAO (J and H).

    Published: 9 Feb 2021
    4.3
    Medium

    CVE-2020-28644

    Last Modified: 21 Nov 2024

    The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated requests against some ocs API endpoints. This affects ownCloud/core version < 10.6.

    Published: 9 Feb 2021
    8.8
    High

    CVE-2021-3191

    Last Modified: 21 Nov 2024

    Idelji Web ViewPoint Suite, as used in conjunction with HPE NonStop, allows Remote Unauthorized Access for T0320L01^ABY and T0320L01^ACD, T0952L01^AAR through T0952L01^AAX, and T0986L01^AAD through T0986L01^AAJ (L) and T0320H01^ABW through T0320H01^ACC, T0952H01^AAQ through T0952H01^AAW, and T0986H01^AAC through T0986H01^AAI (J and H).

    Published: 9 Feb 2021
    5.7
    Medium

    CVE-2020-16144

    Last Modified: 21 Nov 2024

    When using an object storage like S3 as the file store, when a user creates a public link to a folder where anonymous users can upload files, and another user uploads a virus the files antivirus app would detect the virus but fails to delete it due to permission issues. This affects the files_antivirus component versions before 0.15.2 for ownCloud.

    Published: 9 Feb 2021
    6.1
    Medium

    CVE-2020-35572

    Last Modified: 21 Nov 2024

    Adminer through 4.7.8 allows XSS via the history parameter to the default URI.

    Published: 9 Feb 2021
    6.5
    Medium

    CVE-2020-35943

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)

    Published: 9 Feb 2021
    8.8
    High

    CVE-2020-35942

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusion via settings modification, leading to Remote Code Execution and XSS. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)

    Published: 9 Feb 2021
    7.8
    High

    CVE-2021-22663

    Last Modified: 21 Nov 2024

    Cscape (All versions prior to 9.90 SP3.5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to execute code in the context of the current process.

    Published: 9 Feb 2021
    4.4
    Medium

    CVE-2021-25141

    Last Modified: 21 Nov 2024

    A security vulnerability has been identified in in certain HPE and Aruba L2/L3 switch firmware. A data processing error due to improper handling of an unexpected data type in user supplied information to the switch's management interface has been identified. The data processing error could be exploited to cause a crash or reboot in the switch management interface and/or possibly the switch itself leading to local denial of service (DoS). The user must have administrator privileges to exploit this vulnerability.

    Published: 9 Feb 2021
    9.8
    Critical

    CVE-2021-25140

    Last Modified: 21 Nov 2024

    A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an application that is installed in a VMWare or Microsoft Hyper-V environment that is used to setup and configure an HPE Moonshot 1500 chassis. This vulnerability could be remotely exploited by an unauthenticated user to cause a directory traversal in user supplied input to the `khuploadfile.cgi` CGI ELF. The directory traversal could lead to Remote Code Execution, Denial of Service, and/or compromise system integrity. **Note:** HPE recommends that customers discontinue the use of the HPE Moonshot Provisioning Manager. The HPE Moonshot Provisioning Manager application is discontinued, no longer supported, is not available to download from the HPE Support Center, and no patch is available.

    Published: 9 Feb 2021
    9.8
    Critical

    CVE-2021-25139

    Last Modified: 21 Nov 2024

    A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an application that is installed in a VMWare or Microsoft Hyper-V environment that is used to setup and configure an HPE Moonshot 1500 chassis. This vulnerability could be remotely exploited by an unauthenticated user to cause a stack based buffer overflow using user supplied input to the `khuploadfile.cgi` CGI ELF. The stack based buffer overflow could lead to Remote Code Execution, Denial of Service, and/or compromise system integrity. **Note:** HPE recommends that customers discontinue the use of the HPE Moonshot Provisioning Manager. The HPE Moonshot Provisioning Manager application is discontinued, no longer supported, is not available to download from the HPE Support Center, and no patch is available.

    Published: 9 Feb 2021