CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2021-25142

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webstartflash function.

    Published: 8 Feb 2021
    7.5
    High

    CVE-2021-25837

    Last Modified: 21 Nov 2024

    Cosmos Network Ethermint <= v0.4.0 is affected by cache lifecycle inconsistency in the EVM module. Due to the inconsistency between the Storage caching cycle and the Tx processing cycle, Storage changes caused by a failed transaction are improperly reserved in memory. Although the bad storage cache data will be discarded at EndBlock, it is still valid in the current block, which enables many possible attacks such as an "arbitrary mint token".

    Published: 8 Feb 2021
    7.5
    High

    CVE-2021-25836

    Last Modified: 21 Nov 2024

    Cosmos Network Ethermint <= v0.4.0 is affected by cache lifecycle inconsistency in the EVM module. The bytecode set in a FAILED transaction wrongfully remains in memory(stateObject.code) and is further written to persistent store at the Endblock stage, which may be utilized to build honeypot contracts.

    Published: 8 Feb 2021
    7.5
    High

    CVE-2021-25834

    Last Modified: 21 Nov 2024

    Cosmos Network Ethermint <= v0.4.0 is affected by a transaction replay vulnerability in the EVM module. If the victim sends a very large nonce transaction, the attacker can replay the transaction through the application.

    Published: 8 Feb 2021
    7.2
    High

    CVE-2021-21304

    Last Modified: 21 Nov 2024

    Dynamoose is an open-source modeling tool for Amazon's DynamoDB. In Dynamoose from version 2.0.0 and before version 2.7.0 there was a prototype pollution vulnerability in the internal utility method "lib/utils/object/set.ts". This method is used throughout the codebase for various operations throughout Dynamoose. We have not seen any evidence of this vulnerability being exploited. There is no evidence this vulnerability impacts versions 1.x.x since the vulnerable method was added as part of the v2 rewrite. This vulnerability also impacts v2.x.x beta/alpha versions. Version 2.7.0 includes a patch for this vulnerability.

    Published: 8 Feb 2021
    9.8
    Critical

    CVE-2021-26541

    Last Modified: 21 Nov 2024

    The gitlog function in src/index.ts in gitlog before 4.0.4 has a command injection vulnerability.

    Published: 8 Feb 2021
    6.1
    Medium

    CVE-2021-22122

    Last Modified: 21 Nov 2024

    An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to perform a reflected cross site scripting attack (XSS) by injecting malicious payload in different vulnerable API end-points.

    Published: 8 Feb 2021
    9.8
    Critical

    CVE-2020-6649

    Last Modified: 21 Nov 2024

    An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that session ID (via other, hypothetical attacks)

    Published: 8 Feb 2021
    7.8
    High

    CVE-2021-26825

    Last Modified: 21 Nov 2024

    An integer overflow issue exists in Godot Engine up to v3.2 that can be triggered when loading specially crafted.TGA image files. The vulnerability exists in ImageLoaderTGA::load_image() function at line: const size_t buffer_size = (tga_header.image_width * tga_header.image_height) * pixel_size; The bug leads to Dynamic stack buffer overflow. Depending on the context of the application, attack vector can be local or remote, and can lead to code execution and/or system crash.

    Published: 8 Feb 2021
    7.8
    High

    CVE-2021-26826

    Last Modified: 21 Nov 2024

    A stack overflow issue exists in Godot Engine up to v3.2 and is caused by improper boundary checks when loading .TGA image files. Depending on the context of the application, attack vector can be local or remote, and can lead to code execution and/or system crash.

    Published: 8 Feb 2021
    6.5
    Medium

    CVE-2021-20359

    Last Modified: 21 Nov 2024

    IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 - Business Automation Application Designer Component stores potentially sensitive information in log files that could be obtained by an unauthorized user. IBM X-Force ID: 194966.

    Published: 8 Feb 2021
    6.5
    Medium

    CVE-2021-20358

    Last Modified: 21 Nov 2024

    IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 stores potentially sensitive information in clear text in API connection log files. This information could be obtained by a user with permissions to read log files. IBM X-Force ID: 194965.

    Published: 8 Feb 2021
    9.8
    Critical

    CVE-2020-16629

    Last Modified: 21 Nov 2024

    PhpOK 5.4.137 contains a SQL injection vulnerability that can inject an attachment data through SQL, and then call the attachment replacement function through api.php to write a PHP file to the target path.

    Published: 8 Feb 2021
    5.3
    Medium

    CVE-2021-3293

    Last Modified: 21 Nov 2024

    emlog v5.3.1 has full path disclosure vulnerability in t/index.php, which allows an attacker to see the path to the webroot/file.

    Published: 8 Feb 2021
    5.4
    Medium

    CVE-2020-26052

    Last Modified: 21 Nov 2024

    Online Marriage Registration System 1.0 is affected by stored cross-site scripting (XSS) vulnerabilities in multiple parameters.

    Published: 8 Feb 2021
    9.8
    Critical

    CVE-2020-26051

    Last Modified: 21 Nov 2024

    College Management System Php 1.0 suffers from SQL injection vulnerabilities in the index.php page from POST parameters 'unametxt' and 'pwdtxt', which are not filtered before passing a SQL query.

    Published: 8 Feb 2021
    3.5
    Low

    CVE-2021-21436

    Last Modified: 21 Nov 2024

    Agents are able to see and link Config Items without permissions, which are defined in General Catalog. This issue affects: OTRS AG OTRSCIsInCustomerFrontend 7.0.x version 7.0.14 and prior versions.

    Published: 8 Feb 2021
    5.7
    Medium

    CVE-2021-21435

    Last Modified: 21 Nov 2024

    Article Bcc fields and agent personal information are shown when customer prints the ticket (PDF) via external interface. This issue affects: OTRS AG OTRS 7.0.x version 7.0.23 and prior versions; 8.0.x version 8.0.10 and prior versions.

    Published: 8 Feb 2021
    3.5
    Low

    CVE-2021-21434

    Last Modified: 21 Nov 2024

    Survey administrator can craft a survey in such way that malicious code can be executed in the agent interface (i.e. another agent who wants to make changes in the survey). This issue affects: OTRS AG Survey 6.0.x version 6.0.20 and prior versions; 7.0.x version 7.0.19 and prior versions.

    Published: 8 Feb 2021
    4.3
    Medium

    CVE-2020-1779

    Last Modified: 21 Nov 2024

    When dynamic templates are used (OTRSTicketForms), admin can use OTRS tags which are not masked properly and can reveal sensitive information. This issue affects: OTRS AG OTRSTicketForms 6.0.x version 6.0.40 and prior versions; 7.0.x version 7.0.29 and prior versions; 8.0.x version 8.0.3 and prior versions.

    Published: 8 Feb 2021
    8.8
    High

    CVE-2020-35700

    Last Modified: 21 Nov 2024

    A second-order SQL injection issue in Widgets/TopDevicesController.php (aka the Top Devices dashboard widget) of LibreNMS before 21.1.0 allows remote authenticated attackers to execute arbitrary SQL commands via the sort_order parameter against the /ajax/form/widget-settings endpoint.

    Published: 8 Feb 2021
    9.8
    Critical

    CVE-2020-11920

    Last Modified: 21 Nov 2024

    An issue was discovered in Svakom Siime Eye 14.1.00000001.3.330.0.0.3.14. A command injection vulnerability resides in the HOST/IP section of the NFS settings menu in the webserver running on the device. By injecting Bash commands via shell metacharacters here, the device executes arbitrary code with root privileges (all of the device's services are running as root).

    Published: 8 Feb 2021
    6.8
    Medium

    CVE-2020-11915

    Last Modified: 21 Nov 2024

    An issue was discovered in Svakom Siime Eye 14.1.00000001.3.330.0.0.3.14. By sending a set_params.cgi?telnetd=1&save=1&reboot=1 request to the webserver, it is possible to enable the telnet interface on the device. The telnet interface can then be used to obtain access to the device with root privileges via a reecam4debug default password. This default telnet password is the same across all Siime Eye devices. In order for the attack to be exploited, an attacker must be physically close in order to connect to the device's Wi-Fi access point.

    Published: 8 Feb 2021
    8.1
    High

    CVE-2021-20198

    Last Modified: 21 Nov 2024

    A flaw was found in the OpenShift Installer before version v0.9.0-master.0.20210125200451-95101da940b0. During installation of OpenShift Container Platform 4 clusters, bootstrap nodes are provisioned with anonymous authentication enabled on kubelet port 10250. A remote attacker able to reach this port during installation can make unauthenticated `/exec` requests to execute arbitrary commands within running containers. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 8 Feb 2021
    5.3
    Medium

    CVE-2021-21306

    Last Modified: 21 Nov 2024

    Marked is an open-source markdown parser and compiler (npm package "marked"). In marked from version 1.1.1 and before version 2.0.0, there is a Regular expression Denial of Service vulnerability. This vulnerability can affect anyone who runs user generated code through marked. This vulnerability is fixed in version 2.0.0.

    Published: 8 Feb 2021
    8.1
    High

    CVE-2021-3414

    Last Modified: 21 Nov 2024

    A flaw was found in satellite. When giving granular permission related to the organization, other permissions allowing a user to view and manage other organizations are also granted. The highest threat from this vulnerability is to data confidentiality.

    Published: 8 Feb 2021
    8.8
    High

    CVE-2021-3344

    Last Modified: 21 Nov 2024

    A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside the build context are automatically mounted into the container image under construction. An OpenShift user, able to execute code during build time inside this container can re-use the credentials to overwrite arbitrary container images in internal registries and/or escalate their privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. This affects github.com/openshift/builder v0.0.0-20210125201112-7901cb396121 and before.

    Published: 8 Feb 2021
    9.8
    Critical

    CVE-2021-26754

    Last Modified: 21 Nov 2024

    wpDataTables before 3.4.1 mishandles order direction for server-side tables, aka admin-ajax.php?action=get_wdtable order[0][dir] SQL injection.

    Published: 7 Feb 2021
    6.5
    Medium

    CVE-2021-22161

    Last Modified: 21 Nov 2024

    In OpenWrt 19.07.x before 19.07.7, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and its upstream ISP's router. This occurs when a link prefix route points to a point-to-point link, a destination IPv6 address belongs to the prefix and is not a local IPv6 address, and a router advertisement is received with at least one global unique IPv6 prefix for which the on-link flag is set. This affects the netifd and odhcp6c packages.

    Published: 7 Feb 2021
    7.5
    High

    CVE-2021-26843

    Last Modified: 21 Nov 2024

    An issue was discovered in sthttpd through 2.27.1. On systems where the strcpy function is implemented with memcpy, the de_dotdot function may cause a Denial-of-Service (daemon crash) due to overlapping memory ranges being passed to memcpy. This can triggered with an HTTP GET request for a crafted filename. NOTE: this is similar to CVE-2017-10671, but occurs in a different part of the de_dotdot function.

    Published: 7 Feb 2021
    8.8
    High

    CVE-2020-36243

    Last Modified: 21 Nov 2024

    The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php. To exploit the vulnerability, an authenticated attacker can send a POST request that executes arbitrary OS commands via shell metacharacters.

    Published: 7 Feb 2021
    9.8
    Critical

    CVE-2021-3122

    Last Modified: 21 Nov 2024

    CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (within an XML document sent to port 8089) that enables the remote, unauthenticated execution of an arbitrary command as SYSTEM, as exploited in the wild in 2020 and/or 2021. NOTE: the vendor's position is that exploitation occurs only on devices with a certain "misconfiguration."

    Published: 7 Feb 2021
    6.1
    Medium

    CVE-2021-26723

    Last Modified: 21 Nov 2024

    Jenzabar 9.2.x through 9.2.2 allows /ics?tool=search&query= XSS.

    Published: 6 Feb 2021
    3.3
    Low

    CVE-2021-22305

    Last Modified: 21 Nov 2024

    There is a buffer overflow vulnerability in Mate 30 10.1.0.126(C00E125R5P3). A module does not verify the some input when dealing with messages. Attackers can exploit this vulnerability by sending malicious input through specific module. This could cause buffer overflow, compromising normal service.

    Published: 6 Feb 2021
    3.3
    Low

    CVE-2021-22304

    Last Modified: 21 Nov 2024

    There is a use after free vulnerability in Taurus-AL00A 10.0.0.1(C00E1R1P1). A module may refer to some memory after it has been freed while dealing with some messages. Attackers can exploit this vulnerability by sending specific message to the affected module. This may lead to module crash, compromising normal service.

    Published: 6 Feb 2021
    7.5
    High

    CVE-2021-22293

    Last Modified: 21 Nov 2024

    Some Huawei products have an inconsistent interpretation of HTTP requests vulnerability. Attackers can exploit this vulnerability to cause information leak. Affected product versions include: CampusInsight versions V100R019C10; ManageOne versions 6.5.1.1, 6.5.1.SPC100, 6.5.1.SPC200, 6.5.1RC1, 6.5.1RC2, 8.0.RC2. Affected product versions include: Taurus-AL00A versions 10.0.0.1(C00E1R1P1).

    Published: 6 Feb 2021
    7.5
    High

    CVE-2021-22292

    Last Modified: 21 Nov 2024

    There is a denial of service (DoS) vulnerability in eCNS280 versions V100R005C00, V100R005C10. Due to a design defect, remote unauthorized attackers send a large number of specific messages to affected devices, causing system resource exhaustion and web application DoS.

    Published: 6 Feb 2021
    7.1
    High

    CVE-2021-22302

    Last Modified: 21 Nov 2024

    There is an out-of-bound read vulnerability in Taurus-AL00A 10.0.0.1(C00E1R1P1). A module does not verify the some input. Attackers can exploit this vulnerability by sending malicious input through specific app. This could cause out-of-bound, compromising normal service.

    Published: 6 Feb 2021
    7.8
    High

    CVE-2021-22299

    Last Modified: 21 Nov 2024

    There is a local privilege escalation vulnerability in some Huawei products. A local, authenticated attacker could craft specific commands to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege. Affected product versions include: ManageOne versions 6.5.0,6.5.0.SPC100.B210,6.5.1.1.B010,6.5.1.1.B020,6.5.1.1.B030,6.5.1.1.B040,6.5.1.SPC100.B050,6.5.1.SPC101.B010,6.5.1.SPC101.B040,6.5.1.SPC200,6.5.1.SPC200.B010,6.5.1.SPC200.B030,6.5.1.SPC200.B040,6.5.1.SPC200.B050,6.5.1.SPC200.B060,6.5.1.SPC200.B070,6.5.1RC1.B060,6.5.1RC2.B020,6.5.1RC2.B030,6.5.1RC2.B040,6.5.1RC2.B050,6.5.1RC2.B060,6.5.1RC2.B070,6.5.1RC2.B080,6.5.1RC2.B090,6.5.RC2.B050,8.0.0,8.0.0-LCND81,8.0.0.SPC100,8.0.1,8.0.RC2,8.0.RC3,8.0.RC3.B041,8.0.RC3.SPC100; NFV_FusionSphere versions 6.5.1.SPC23,8.0.0.SPC12; SMC2.0 versions V600R019C00,V600R019C10; iMaster MAE-M versions MAE-TOOL(FusionSphereBasicTemplate_Euler_X86)V100R020C10SPC220.

    Published: 6 Feb 2021
    4.9
    Medium

    CVE-2020-9205

    Last Modified: 21 Nov 2024

    There has a CSV injection vulnerability in ManageOne 8.0.1. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject CSV files to the target device.

    Published: 6 Feb 2021
    6.5
    Medium

    CVE-2021-22298

    Last Modified: 21 Nov 2024

    There is a logic vulnerability in Huawei Gauss100 OLTP Product. An attacker with certain permissions could perform specific SQL statement to exploit this vulnerability. Due to insufficient security design, successful exploit can cause service abnormal. Affected product versions include: ManageOne versions 6.5.1.1.B020, 6.5.1.1.B030, 6.5.1.1.B040, 6.5.1.SPC100.B050, 6.5.1.SPC101.B010, 6.5.1.SPC101.B040, 6.5.1.SPC200, 6.5.1.SPC200.B010, 6.5.1.SPC200.B030, 6.5.1.SPC200.B040, 6.5.1.SPC200.B050, 6.5.1.SPC200.B060, 6.5.1.SPC200.B070, 6.5.1RC1.B070, 6.5.1RC1.B080, 6.5.1RC2.B040, 6.5.1RC2.B050, 6.5.1RC2.B060, 6.5.1RC2.B070, 6.5.1RC2.B080, 6.5.1RC2.B090.

    Published: 6 Feb 2021
    6.8
    Medium

    CVE-2020-9118

    Last Modified: 21 Nov 2024

    There is an insufficient integrity check vulnerability in Huawei Sound X Product. The system does not check certain software package's integrity sufficiently. Successful exploit could allow an attacker to load a crafted software package to the device. Affected product versions include:AIS-BW80H-00 versions 9.0.3.1(H100SP13C00),9.0.3.1(H100SP18C00),9.0.3.1(H100SP3C00),9.0.3.1(H100SP9C00),9.0.3.2(H100SP1C00),9.0.3.2(H100SP2C00),9.0.3.2(H100SP5C00),9.0.3.2(H100SP8C00),9.0.3.3(H100SP1C00).

    Published: 6 Feb 2021
    6.5
    Medium

    CVE-2021-22500

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery vulnerability in Micro Focus Application Performance Management product, affecting versions 9.40, 9.50 and 9.51. The vulnerability could be exploited by attacker to trick the users into executing actions of the attacker's choosing.

    Published: 6 Feb 2021
    4.8
    Medium

    CVE-2021-22499

    Last Modified: 21 Nov 2024

    Persistent Cross-Site scripting vulnerability in Micro Focus Application Performance Management product, affecting versions 9.40, 9.50 and 9.51. The vulnerability could allow persistent XSS attack.

    Published: 6 Feb 2021
    4.6
    Medium

    CVE-2021-22306

    Last Modified: 21 Nov 2024

    There is an out-of-bound read vulnerability in Mate 30 10.0.0.182(C00E180R6P2). A module does not verify the some input when dealing with messages. Attackers can exploit this vulnerability by sending malicious input through specific module. This could cause out-of-bound, compromising normal service.

    Published: 6 Feb 2021
    4.1
    Medium

    CVE-2021-22300

    Last Modified: 21 Nov 2024

    There is an information leak vulnerability in eCNS280_TD versions V100R005C00 and V100R005C10. A command does not have timeout exit mechanism. Temporary file contains sensitive information. This allows attackers to obtain information by inter-process access that requires other methods.

    Published: 6 Feb 2021
    3.3
    Low

    CVE-2021-22303

    Last Modified: 21 Nov 2024

    There is a pointer double free vulnerability in Taurus-AL00A 10.0.0.1(C00E1R1P1). There is a lack of muti-thread protection when a function is called. Attackers can exploit this vulnerability by performing malicious operation to cause pointer double free. This may lead to module crash, compromising normal service.

    Published: 6 Feb 2021
    5.5
    Medium

    CVE-2021-22307

    Last Modified: 21 Nov 2024

    There is a weak algorithm vulnerability in Mate 3010.0.0.203(C00E201R7P2). The protection is insufficient for the modules that should be protected. Local attackers can exploit this vulnerability to affect the integrity of certain module.

    Published: 6 Feb 2021
    6.7
    Medium

    CVE-2021-22301

    Last Modified: 21 Nov 2024

    Mate 30 10.0.0.203(C00E201R7P2) have a buffer overflow vulnerability. After obtaining the root permission, an attacker can exploit the vulnerability to cause buffer overflow.

    Published: 5 Feb 2021
    5.9
    Medium

    CVE-2020-5812

    Last Modified: 21 Nov 2024

    Nessus AMI versions 8.12.0 and earlier were found to either not validate, or incorrectly validate, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack.

    Published: 5 Feb 2021