CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2021-3394

    Last Modified: 21 Nov 2024

    Millennium Millewin (also known as "Cartella clinica") 13.39.028, 13.39.28.3342, and 13.39.146.1 has insecure folder permissions allowing a malicious user for a local privilege escalation.

    Published: 9 Feb 2021
    5.5
    Medium

    CVE-2020-4996

    Last Modified: 21 Nov 2024

    IBM Security Identity Governance and Intelligence 5.2.6 could allow a local user to obtain sensitive information via the capturing of screenshots of authentication credentials. IBM X-Force ID: 192913.

    Published: 9 Feb 2021
    5.3
    Medium

    CVE-2020-4995

    Last Modified: 21 Nov 2024

    IBM Security Identity Governance and Intelligence 5.2.6 does not invalidate session after logout which could allow a user to obtain sensitive information from another users' session. IBM X-Force ID: 192912.

    Published: 9 Feb 2021
    8.2
    High

    CVE-2020-4795

    Last Modified: 21 Nov 2024

    IBM Security Identity Governance and Intelligence 5.2.6 could disclose sensitive information to an unauthorized user using a specially crafted HTTP request. IBM X-Force ID: 189446.

    Published: 9 Feb 2021
    5.3
    Medium

    CVE-2020-4791

    Last Modified: 21 Nov 2024

    IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to obtain sensitive information using main in the middle attacks due to improper certificate validation. IBM X-Force ID: 189379.

    Published: 9 Feb 2021
    6.5
    Medium

    CVE-2020-4790

    Last Modified: 21 Nov 2024

    IBM Security Identity Governance and Intelligence 5.2.6 could allow a user to cause a denial of service due to improperly validating a supplied URL, rendering the application unusuable. IBM X-Force ID: 189375.

    Published: 9 Feb 2021
    7.8
    High

    CVE-2020-27257

    Last Modified: 21 Nov 2024

    This vulnerability allows local attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can result in a type-confusion condition in the Omron CX-One Version 4.60 and prior devices.

    Published: 9 Feb 2021
    8.8
    High

    CVE-2020-27261

    Last Modified: 21 Nov 2024

    The Omron CX-One Version 4.60 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.

    Published: 9 Feb 2021
    8.8
    High

    CVE-2020-27259

    Last Modified: 21 Nov 2024

    The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which may allow an attacker to remotely execute arbitrary code.

    Published: 9 Feb 2021
    6.5
    Medium

    CVE-2021-26921

    Last Modified: 21 Nov 2024

    In util/session/sessionmanager.go in Argo CD before 1.8.4, tokens continue to work even when the user account is disabled.

    Published: 9 Feb 2021
    6.5
    Medium

    CVE-2021-21141

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass file extension policy via a crafted HTML page.

    Published: 9 Feb 2021
    6.8
    Medium

    CVE-2021-21140

    Last Modified: 21 Nov 2024

    Uninitialized use in USB in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform out of bounds memory access via via a USB device.

    Published: 9 Feb 2021
    8.6
    High

    CVE-2021-21138

    Last Modified: 21 Nov 2024

    Use after free in DevTools in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform a sandbox escape via a crafted file.

    Published: 9 Feb 2021
    6.5
    Medium

    CVE-2021-21139

    Last Modified: 21 Nov 2024

    Inappropriate implementation in iframe sandbox in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 9 Feb 2021
    6.5
    Medium

    CVE-2021-21137

    Last Modified: 21 Nov 2024

    Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page.

    Published: 9 Feb 2021
    6.5
    Medium

    CVE-2021-21135

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Performance API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 9 Feb 2021
    6.5
    Medium

    CVE-2021-21136

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in WebView in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 9 Feb 2021
    6.5
    Medium

    CVE-2021-21134

    Last Modified: 21 Nov 2024

    Incorrect security UI in Page Info in Google Chrome on iOS prior to 88.0.4324.96 allowed a remote attacker to spoof security UI via a crafted HTML page.

    Published: 9 Feb 2021
    9.6
    Critical

    CVE-2021-21132

    Last Modified: 21 Nov 2024

    Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.

    Published: 9 Feb 2021
    6.5
    Medium

    CVE-2021-21133

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Downloads in Google Chrome prior to 88.0.4324.96 allowed an attacker who convinced a user to download files to bypass navigation restrictions via a crafted HTML page.

    Published: 9 Feb 2021
    6.5
    Medium

    CVE-2021-21131

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.

    Published: 9 Feb 2021
    6.5
    Medium

    CVE-2021-21130

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.

    Published: 9 Feb 2021
    6.5
    Medium

    CVE-2021-21129

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.

    Published: 9 Feb 2021
    8.8
    High

    CVE-2021-21128

    Last Modified: 21 Nov 2024

    Heap buffer overflow in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 9 Feb 2021
    6.5
    Medium

    CVE-2021-21126

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension.

    Published: 9 Feb 2021
    8.8
    High

    CVE-2021-21127

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass content security policy via a crafted Chrome Extension.

    Published: 9 Feb 2021
    8.1
    High

    CVE-2021-21125

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.

    Published: 9 Feb 2021
    6.5
    Medium

    CVE-2021-21123

    Last Modified: 21 Nov 2024

    Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.

    Published: 9 Feb 2021
    9.6
    Critical

    CVE-2021-21124

    Last Modified: 21 Nov 2024

    Potential user after free in Speech Recognizer in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

    Published: 9 Feb 2021
    8.8
    High

    CVE-2021-21122

    Last Modified: 21 Nov 2024

    Use after free in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 9 Feb 2021
    8.8
    High

    CVE-2021-21120

    Last Modified: 21 Nov 2024

    Use after free in WebSQL in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 9 Feb 2021
    9.6
    Critical

    CVE-2021-21121

    Last Modified: 21 Nov 2024

    Use after free in Omnibox in Google Chrome on Linux prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

    Published: 9 Feb 2021
    8.8
    High

    CVE-2021-21119

    Last Modified: 21 Nov 2024

    Use after free in Media in Google Chrome prior to 88.0.4324.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

    Published: 9 Feb 2021
    7.8
    High

    CVE-2021-21117

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Cryptohome in Google Chrome prior to 88.0.4324.96 allowed a local attacker to perform OS-level privilege escalation via a crafted file.

    Published: 9 Feb 2021
    8.8
    High

    CVE-2021-21118

    Last Modified: 21 Nov 2024

    Insufficient data validation in V8 in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

    Published: 9 Feb 2021
    6.5
    Medium

    CVE-2021-26719

    Last Modified: 21 Nov 2024

    A directory traversal issue was discovered in Gradle gradle-enterprise-test-distribution-agent before 1.3.2, test-distribution-gradle-plugin before 1.3.2, and gradle-enterprise-maven-extension before 1.8.2. A malicious actor (with certain credentials) can perform a registration step such that crafted TAR archives lead to extraction of files into arbitrary filesystem locations.

    Published: 9 Feb 2021
    4.8
    Medium

    CVE-2020-22841

    Last Modified: 21 Nov 2024

    Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name input field in the plugin module.

    Published: 9 Feb 2021
    6.1
    Medium

    CVE-2020-22840

    Last Modified: 21 Nov 2024

    Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resource via redirect_to parameter in email_passthrough.php.

    Published: 9 Feb 2021
    5.4
    Medium

    CVE-2021-26925

    Last Modified: 21 Nov 2024

    Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering.

    Published: 9 Feb 2021
    6.3
    Medium

    CVE-2021-23327

    Last Modified: 21 Nov 2024

    The package apexcharts before 3.24.0 are vulnerable to Cross-site Scripting (XSS) via lack of sanitization of graph legend fields.

    Published: 9 Feb 2021
    5.7
    Medium

    CVE-2020-13462

    Last Modified: 21 Nov 2024

    Insecure Direct Object Reference (IDOR) exists in Tufin SecureChange, affecting all versions prior to R20-2 GA. Fixed in version R20-2 GA.

    Published: 9 Feb 2021
    4.3
    Medium

    CVE-2020-13461

    Last Modified: 21 Nov 2024

    Username enumeration in present in Tufin SecureTrack. It's affecting all versions of SecureTrack. The vendor has decided not to fix this vulnerability. Vendor's response: "This attack requires access to the internal network. If an attacker is part of the internal network, they do not require access to TOS to know the usernames".

    Published: 9 Feb 2021
    8.8
    High

    CVE-2020-13460

    Last Modified: 21 Nov 2024

    Multiple Cross-Site Request Forgery (CSRF) vulnerabilities were present in Tufin SecureTrack, affecting all versions prior to R20-2 GA.

    Published: 9 Feb 2021
    5.9
    Medium

    CVE-2020-13407

    Last Modified: 21 Nov 2024

    Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by the same victim, or also later by different users). Both stored, and reflected payloads are triggerable by admin, so malicious non-authenticated user could get admin level access. Even malicious low-privileged user can inject XSS, which can be executed by admin, potentially elevating privileges and obtaining admin access. (issue 1 of 3)

    Published: 9 Feb 2021
    5.9
    Medium

    CVE-2020-13409

    Last Modified: 21 Nov 2024

    Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by the same victim, or also later by different users). Both stored, and reflected payloads are triggerable by admin, so malicious non-authenticated user could get admin level access. Even malicious low-privileged user can inject XSS, which can be executed by admin, potentially elevating privileges and obtaining admin access. (issue 3 of 3)

    Published: 9 Feb 2021
    5.9
    Medium

    CVE-2020-13408

    Last Modified: 21 Nov 2024

    Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by the same victim, or also later by different users). Both stored, and reflected payloads are triggerable by admin, so malicious non-authenticated user could get admin level access. Even malicious low-privileged user can inject XSS, which can be executed by admin, potentially elevating privileges and obtaining admin access. (issue 2 of 3)

    Published: 9 Feb 2021
    8.6
    High

    CVE-2020-24685

    Last Modified: 21 Nov 2024

    An unauthenticated specially crafted packet sent by an attacker over the network will cause a denial-of-service (DoS) vulnerability. Vulnerability allows attacker to stop the PLC. After stopping (ERR LED flashing red), physical access to the PLC is required in order to restart the application. This issue affects: ABB AC500 V2 products with onboard Ethernet version 2.8.4 and prior versions.

    Published: 9 Feb 2021
    9.8
    Critical

    CVE-2021-26918

    Last Modified: 21 Nov 2024

    The ProBot bot through 2021-02-08 for Discord might allow attackers to interfere with the intended purpose of the "Send an image when a user joins the server" feature (or possibly have unspecified other impact) because the uploader web service allows double extensions (such as .html.jpg) with the text/html content type. NOTE: there may not be cases in which an uploader web service is customer controlled; however, the nature of the issue has substantial interaction with customer controlled configuration. NOTE: the vendor states "This is just an uploader (like any other one) which uploads files to cloud storage and accepts various file types. There is no kind of vulnerability and it won't compromise either the client side or the server side.

    Published: 9 Feb 2021
    6.5
    Medium

    CVE-2020-28388

    Last Modified: 2 Jun 2026

    A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.20), Nucleus NET (All versions < V5.2), Nucleus ReadyStart V3 (All versions < V2012.12), Nucleus Source Code (All versions), PLUSCONTROL 1st Gen (All versions), TALON TC Compact (BACnet) (All versions < V3.5.5), TALON TC Modular (BACnet) (All versions < V3.5.5). Initial Sequence Numbers (ISNs) for TCP connections are derived from an insufficiently random source. As a result, the ISN of current and future TCP connections could be predictable. An attacker could hijack existing sessions or spoof future ones.

    Published: 9 Feb 2021
    9.8
    Critical

    CVE-2019-17582

    Last Modified: 21 Nov 2024

    A use-after-free in the _zip_dirent_read function of zip_dirent.c in libzip 1.2.0 allows attackers to have an unspecified impact by attempting to unzip a malformed ZIP archive. NOTE: the discoverer states "This use-after-free is triggered prior to the double free reported in CVE-2017-12858."

    Published: 9 Feb 2021