CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2020-36327

    Last Modified: 21 Nov 2024

    Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a dependency of another private gem that is explicitly depended on by the application. NOTE: it is not correct to use CVE-2021-24105 for every "Dependency Confusion" issue in every product.

    Published: 9 Feb 2021
    3.7
    Low

    CVE-2021-28116

    Last Modified: 21 Nov 2024

    Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution as nobody.

    Published: 9 Feb 2021
    5.4
    Medium

    CVE-2021-3294

    Last Modified: 21 Nov 2024

    CASAP Automated Enrollment System 1.0 is affected by cross-site scripting (XSS) in users.php. An attacker can steal a cookie to perform user redirection to a malicious website.

    Published: 8 Feb 2021
    5.5
    Medium

    CVE-2021-26917

    Last Modified: 21 Nov 2024

    PyBitmessage through 0.6.3.2 allows attackers to write screen captures to Potentially Unwanted Directories via a crafted apinotifypath value. NOTE: the discoverer states "security mitigation may not be necessary as there is no evidence yet that these screen intercepts are actually transported away from the local host." NOTE: it is unclear whether there are any common use cases in which apinotifypath is controlled by an attacker

    Published: 8 Feb 2021
    3.5
    Low

    CVE-2020-29021

    Last Modified: 21 Nov 2024

    A vulnerability in web UI input field of GateManager allows authenticated attacker to enter script tags that could cause XSS. This issue affects: GateManager all versions prior to 9.3.

    Published: 8 Feb 2021
    3.3
    Low

    CVE-2020-8590

    Last Modified: 21 Nov 2024

    Clustered Data ONTAP versions prior to 9.1P18 and 9.3P12 are susceptible to a vulnerability which could allow an attacker to discover node names via AutoSupport bundles even when the –remove-private-data parameter is set to true.

    Published: 8 Feb 2021
    3.3
    Low

    CVE-2020-8578

    Last Modified: 21 Nov 2024

    Clustered Data ONTAP versions prior to 9.3P20 are susceptible to a vulnerability which could allow an attacker to discover node names via AutoSupport bundles even when the –remove-private-data parameter is set to true.

    Published: 8 Feb 2021
    5.5
    Medium

    CVE-2020-8587

    Last Modified: 21 Nov 2024

    OnCommand System Manager 9.x versions prior to 9.3P20 and 9.4 prior to 9.4P3 are susceptible to a vulnerability that could allow HTTP clients to cache sensitive responses making them accessible to an attacker who has access to the system where the client runs.

    Published: 8 Feb 2021
    6.1
    Medium

    CVE-2020-13947

    Last Modified: 21 Nov 2024

    An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0.

    Published: 8 Feb 2021
    9.8
    Critical

    CVE-2021-25913

    Last Modified: 21 Nov 2024

    Prototype pollution vulnerability in 'set-or-get' version 1.0.0 through 1.2.10 allows an attacker to cause a denial of service and may lead to remote code execution.

    Published: 8 Feb 2021
    6.1
    Medium

    CVE-2021-26916

    Last Modified: 21 Nov 2024

    In nopCommerce 4.30, a Reflected XSS issue in the Discount Coupon component allows remote attackers to inject arbitrary web script or HTML through the Filters/CheckDiscountCouponAttribute.cs discountcode parameter.

    Published: 8 Feb 2021
    9.8
    Critical

    CVE-2021-22502

    Last Modified: 27 Oct 2025

    Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server.

    Published: 8 Feb 2021
    8.1
    High

    CVE-2021-26915

    Last Modified: 21 Nov 2024

    NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in webrepdb StatusServlet.

    Published: 8 Feb 2021
    8.1
    High

    CVE-2021-26914

    Last Modified: 21 Nov 2024

    NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in MvcUtil valueStringToObject.

    Published: 8 Feb 2021
    8.1
    High

    CVE-2021-26913

    Last Modified: 21 Nov 2024

    NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in RpcServlet.

    Published: 8 Feb 2021
    8.1
    High

    CVE-2021-26912

    Last Modified: 21 Nov 2024

    NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in SupportRpcServlet.

    Published: 8 Feb 2021
    8.1
    High

    CVE-2021-26220

    Last Modified: 21 Nov 2024

    The ezxml_toxml function in ezxml 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting the memory pool.

    Published: 8 Feb 2021
    8.1
    High

    CVE-2021-26221

    Last Modified: 21 Nov 2024

    The ezxml_new function in ezXML 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting the memory pool.

    Published: 8 Feb 2021
    8.1
    High

    CVE-2021-26222

    Last Modified: 21 Nov 2024

    The ezxml_new function in ezXML 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting the memory pool.

    Published: 8 Feb 2021
    9.1
    Critical

    CVE-2021-26528

    Last Modified: 21 Nov 2024

    The mg_http_serve_file function in Cesanta Mongoose HTTP server 7.0 is vulnerable to remote OOB write attack via connection request after exhausting memory pool.

    Published: 8 Feb 2021
    9.1
    Critical

    CVE-2021-26529

    Last Modified: 21 Nov 2024

    The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 and 6.7-6.18 (compiled with mbedTLS support) is vulnerable to remote OOB write attack via connection request after exhausting memory pool.

    Published: 8 Feb 2021
    9.1
    Critical

    CVE-2021-26530

    Last Modified: 21 Nov 2024

    The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 (compiled with OpenSSL support) is vulnerable to remote OOB write attack via connection request after exhausting memory pool.

    Published: 8 Feb 2021
    6.5
    Medium

    CVE-2020-36149

    Last Modified: 21 Nov 2024

    Incorrect handling of input data in changeAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentation fault error in case of restrictive memory protection or near NULL pointer overwrite in case of no memory restrictions (e.g. in embedded environments).

    Published: 8 Feb 2021
    6.5
    Medium

    CVE-2020-36150

    Last Modified: 21 Nov 2024

    Incorrect handling of input data in loudness function in the libmysofa library 0.5 - 1.1 will lead to heap buffer overflow and access to unallocated memory block.

    Published: 8 Feb 2021
    6.5
    Medium

    CVE-2020-36151

    Last Modified: 21 Nov 2024

    Incorrect handling of input data in mysofa_resampler_reset_mem function in the libmysofa library 0.5 - 1.1 will lead to heap buffer overflow and overwriting large memory block.

    Published: 8 Feb 2021
    8.8
    High

    CVE-2020-36152

    Last Modified: 21 Nov 2024

    Buffer overflow in readDataVar in hdf/dataobject.c in Symonics libmysofa 0.5 - 1.1 allows attackers to execute arbitrary code via a crafted SOFA.

    Published: 8 Feb 2021
    6.5
    Medium

    CVE-2020-36148

    Last Modified: 21 Nov 2024

    Incorrect handling of input data in verifyAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentation fault error in case of restrictive memory protection or near NULL pointer overwrite in case of no memory restrictions (e.g. in embedded environments).

    Published: 8 Feb 2021
    7.5
    High

    CVE-2020-24944

    Last Modified: 21 Nov 2024

    picoquic (before 3rd of July 2020) allows attackers to cause a denial of service (infinite loop) via a crafted QUIC frame, related to the picoquic_decode_frames and picoquic_decode_stream_frame functions and epoch==3.

    Published: 8 Feb 2021
    6.2
    Medium

    CVE-2021-21290

    Last Modified: 21 Nov 2024

    Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involving an insecure temp file. When netty's multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. Of note, this does not impact modern MacOS Operating Systems. The method "File.createTempFile" on unix-like systems creates a random file, but, by default will create this file with the permissions "-rw-r--r--". Thus, if sensitive information is written to this file, other local users can read this information. This is the case in netty's "AbstractDiskHttpData" is vulnerable. This has been fixed in version 4.1.59.Final. As a workaround, one may specify your own "java.io.tmpdir" when you start the JVM or use "DefaultHttpDataFactory.setBaseDir(...)" to set the directory to something that is only readable by the current user.

    Published: 8 Feb 2021
    7.8
    High

    CVE-2021-26576

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so uploadsshkey function.

    Published: 8 Feb 2021
    7.8
    High

    CVE-2021-26910

    Last Modified: 21 Nov 2024

    Firejail before 0.9.64.4 allows attackers to bypass intended access restrictions because there is a TOCTOU race condition between a stat operation and an OverlayFS mount operation.

    Published: 8 Feb 2021
    7.8
    High

    CVE-2021-26574

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a path traversal vulnerability in libifc.so webdeletevideofile function.

    Published: 8 Feb 2021
    7.8
    High

    CVE-2021-26577

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so uploadsshkey function.

    Published: 8 Feb 2021
    7.8
    High

    CVE-2021-26575

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a path traversal vulnerability in libifc.so webdeletesolvideofile function.

    Published: 8 Feb 2021
    7.4
    High

    CVE-2021-21305

    Last Modified: 21 Nov 2024

    CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions 1.3.2 and 2.1.1, there is a code injection vulnerability. The "#manipulate!" method inappropriately evals the content of mutation option(:read/:write), allowing attackers to craft a string that can be executed as a Ruby code. If an application developer supplies untrusted inputs to the option, it will lead to remote code execution(RCE). This is fixed in versions 1.3.2 and 2.1.1.

    Published: 8 Feb 2021
    4.3
    Medium

    CVE-2021-21288

    Last Modified: 21 Nov 2024

    CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions 1.3.2 and 2.1.1 the download feature has an SSRF vulnerability, allowing attacks to provide DNS entries or IP addresses that are intended for internal use and gather information about the Intranet infrastructure of the platform. This is fixed in versions 1.3.2 and 2.1.1.

    Published: 8 Feb 2021
    6.5
    Medium

    CVE-2021-26905

    Last Modified: 21 Nov 2024

    1Password SCIM Bridge before 1.6.2 mishandles validation of authenticated requests for log files, leading to disclosure of a TLS private key.

    Published: 8 Feb 2021
    7.8
    High

    CVE-2021-26573

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgeneratesslcfg function.

    Published: 8 Feb 2021
    7.8
    High

    CVE-2021-25172

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so websetdefaultlangcfg function.

    Published: 8 Feb 2021
    7.8
    High

    CVE-2021-26572

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgetactivexcfg function.

    Published: 8 Feb 2021
    7.8
    High

    CVE-2021-26570

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webifc_setadconfig function.

    Published: 8 Feb 2021
    7.8
    High

    CVE-2021-26571

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgetactivexcfg function.

    Published: 8 Feb 2021
    9.8
    Critical

    CVE-2020-7786

    Last Modified: 21 Nov 2024

    This affects all versions of package macfromip. The injection point is located in line 66 in macfromip.js.

    Published: 8 Feb 2021
    7.8
    High

    CVE-2021-25171

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so websetlicensecfg function.

    Published: 8 Feb 2021
    9.8
    Critical

    CVE-2020-7782

    Last Modified: 21 Nov 2024

    This affects all versions of package spritesheet-js. It depends on a vulnerable package platform-command. The injection point is located in line 32 in lib/generator.js, which is triggered by main entry of the package.

    Published: 8 Feb 2021
    9.8
    Critical

    CVE-2020-7785

    Last Modified: 21 Nov 2024

    This affects all versions of package node-ps. The injection point is located in line 72 in lib/index.js.

    Published: 8 Feb 2021
    7.8
    High

    CVE-2021-25169

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so websetservicecfg function.

    Published: 8 Feb 2021
    7.8
    High

    CVE-2021-25170

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so websetremoteimageinfo function.

    Published: 8 Feb 2021
    7.8
    High

    CVE-2021-25168

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webupdatecomponent function.

    Published: 8 Feb 2021
    7.5
    High

    CVE-2021-25835

    Last Modified: 21 Nov 2024

    Cosmos Network Ethermint <= v0.4.0 is affected by a cross-chain transaction replay vulnerability in the EVM module. Since ethermint uses the same chainIDEpoch and signature schemes with ethereum for compatibility, a verified signature in ethereum is still valid in ethermint with the same msg content and chainIDEpoch, which enables "cross-chain transaction replay" attack.

    Published: 8 Feb 2021