CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2020-24271

    Last Modified: 21 Nov 2024

    A CSRF vulnerability was discovered in EasyCMS v1.6 that can add an admin account through index.php?s=/admin/rbacuser/insert/navTabId/rbacuser/callbackType/closeCurrent, then post username=***&password=***.

    Published: 1 Feb 2021
    9.8
    Critical

    CVE-2020-36109

    Last Modified: 21 Nov 2024

    ASUS RT-AX86U router firmware below version under 9.0.0.4_386 has a buffer overflow in the blocking_request.cgi function of the httpd module that can cause code execution when an attacker constructs malicious data.

    Published: 1 Feb 2021
    9.8
    Critical

    CVE-2020-28194

    Last Modified: 21 Nov 2024

    Variable underflow exists in accel-ppp radius/packet.c when receiving a RADIUS vendor-specific attribute with length field is less than 2. It has an impact only when the attacker controls the RADIUS server, which can lead to arbitrary code execution.

    Published: 1 Feb 2021
    5.3
    Medium

    CVE-2021-3281

    Last Modified: 21 Nov 2024

    In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "startapp --template" and "startproject --template") allows directory traversal via an archive with absolute paths or relative paths with dot segments.

    Published: 1 Feb 2021
    6.1
    Medium

    CVE-2021-3350

    Last Modified: 21 Nov 2024

    deleteaccount.php in the Delete Account plugin 1.4 for MyBB allows XSS via the deletereason parameter.

    Published: 1 Feb 2021
    9.8
    Critical

    CVE-2020-13858

    Last Modified: 21 Nov 2024

    An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They contain two undocumented administrator accounts. The sftp and mofidev accounts are defined in /etc/passwd and the password is not unique across installations.

    Published: 1 Feb 2021
    9.8
    Critical

    CVE-2020-15836

    Last Modified: 21 Nov 2024

    An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function passes untrusted data to the operating system without proper sanitization. A crafted request can be sent to execute arbitrary commands as root.

    Published: 1 Feb 2021
    9.8
    Critical

    CVE-2020-15835

    Last Modified: 21 Nov 2024

    An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function contains undocumented code that provides the ability to authenticate as root without knowing the actual root password. An adversary with the private key can remotely authenticate to the management interface as root.

    Published: 1 Feb 2021
    7.5
    High

    CVE-2020-15834

    Last Modified: 21 Nov 2024

    An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The wireless network password is exposed in a QR encoded picture that an unauthenticated adversary can download via the web-management interface.

    Published: 1 Feb 2021
    9.8
    Critical

    CVE-2020-15833

    Last Modified: 21 Nov 2024

    An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The Dropbear SSH daemon has been modified to accept an alternate hard-coded path to a public key that allows root access. This key is stored in a /rom location that cannot be modified by the device owner.

    Published: 1 Feb 2021
    7.5
    High

    CVE-2020-15832

    Last Modified: 21 Nov 2024

    An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The poof.cgi script contains undocumented code that provides the ability to remotely reboot the device. An adversary with the private key (but not the root password) can remotely reboot the device.

    Published: 1 Feb 2021
    7.5
    High

    CVE-2020-13860

    Last Modified: 21 Nov 2024

    An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. The one-time password algorithm for the undocumented system account mofidev generates a predictable six-digit password.

    Published: 1 Feb 2021
    9.8
    Critical

    CVE-2020-13859

    Last Modified: 21 Nov 2024

    An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A format error in /etc/shadow, coupled with a logic bug in the LuCI - OpenWrt Configuration Interface framework, allows the undocumented system account mofidev to login to the cgi-bin/luci/quick/wizard management interface without a password by abusing a forgotten-password feature.

    Published: 1 Feb 2021
    7.5
    High

    CVE-2020-13856

    Last Modified: 21 Nov 2024

    An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. Authentication is not required to download the support file that contains sensitive information such as cleartext credentials and password hashes.

    Published: 1 Feb 2021
    7.5
    High

    CVE-2020-13857

    Last Modified: 21 Nov 2024

    An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They can be rebooted by sending an unauthenticated poof.cgi HTTP GET request.

    Published: 1 Feb 2021
    9.8
    Critical

    CVE-2020-26547

    Last Modified: 21 Nov 2024

    Monal before 4.9 does not implement proper sender verification on MAM and Message Carbon (XEP-0280) results. This allows a remote attacker (able to send stanzas to a victim) to inject arbitrary messages into the local history, with full control over the sender and receiver displayed to the victim.

    Published: 1 Feb 2021
    5.3
    Medium

    CVE-2020-28493

    Last Modified: 21 Nov 2024

    This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the most exploitable as it searches for trailing punctuation. This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.

    Published: 1 Feb 2021
    9.3
    Critical

    CVE-2021-21276

    Last Modified: 21 Nov 2024

    Polr is an open source URL shortener. in Polr before version 2.3.0, a vulnerability in the setup process allows attackers to gain admin access to site instances, even if they do not possess an existing account. This vulnerability exists regardless of users' settings. If an attacker crafts a request with specific cookie headers to the /setup/finish endpoint, they may be able to obtain admin privileges on the instance. This is caused by a loose comparison (==) in SetupController that is susceptible to attack. The project has been patched to ensure that a strict comparison (===) is used to verify the setup key, and that /setup/finish verifies that no users table exists before performing any migrations or provisioning any new accounts. This is fixed in version 2.3.0. Users can patch this vulnerability without upgrading by adding abort(404) to the very first line of finishSetup in SetupController.php.

    Published: 1 Feb 2021
    6.5
    Medium

    CVE-2021-21285

    Last Modified: 21 Nov 2024

    In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker image manifest crashes the dockerd daemon. Versions 20.10.3 and 19.03.15 contain patches that prevent the daemon from crashing.

    Published: 1 Feb 2021
    5.3
    Medium

    CVE-2021-3024

    Last Modified: 21 Nov 2024

    HashiCorp Vault and Vault Enterprise disclosed the internal IP address of the Vault node when responding to some invalid, unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7.

    Published: 1 Feb 2021
    3.3
    Low

    CVE-2021-3349

    Last Modified: 21 Nov 2024

    GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted key because Evolution does not retrieve enough information from the GnuPG API. NOTE: third parties dispute the significance of this issue, and dispute whether Evolution is the best place to change this behavior

    Published: 1 Feb 2021
    5.5
    Medium

    CVE-2020-10001

    Last Modified: 21 Nov 2024

    An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to read restricted memory.

    Published: 1 Feb 2021
    3.3
    Low

    CVE-2021-20239

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel in versions before 5.4.92 in the BPF protocol. This flaw allows an attacker with a local account to leak information about kernel internal addresses. The highest threat from this vulnerability is to confidentiality.

    Published: 1 Feb 2021
    5.3
    Medium

    CVE-2020-25594

    Last Modified: 21 Nov 2024

    HashiCorp Vault and Vault Enterprise allowed for enumeration of Secrets Engine mount paths via unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7.

    Published: 1 Feb 2021
    5.5
    Medium

    CVE-2021-20241

    Last Modified: 21 Nov 2024

    A flaw was found in ImageMagick in coders/jp2.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.

    Published: 1 Feb 2021
    5.5
    Medium

    CVE-2021-20245

    Last Modified: 21 Nov 2024

    A flaw was found in ImageMagick in coders/webp.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.

    Published: 1 Feb 2021
    7.4
    High

    CVE-2021-21289

    Last Modified: 21 Nov 2024

    Mechanize is an open-source ruby library that makes automated web interaction easy. In Mechanize from version 2.0.0 and before version 2.7.7 there is a command injection vulnerability. Affected versions of mechanize allow for OS commands to be injected using several classes' methods which implicitly use Ruby's Kernel.open method. Exploitation is possible only if untrusted input is used as a local filename and passed to any of these calls: Mechanize::CookieJar#load, Mechanize::CookieJar#save_as, Mechanize#download, Mechanize::Download#save, Mechanize::File#save, and Mechanize::FileResponse#read_body. This is fixed in version 2.7.7.

    Published: 1 Feb 2021
    7.8
    High

    CVE-2023-1295

    Last Modified: 13 Feb 2025

    A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CLOSE operation in the Linux kernel's versions 5.6 - 5.11 (inclusive), which allows a local user to elevate their privileges to root. Introduced in b5dba59e0cf7e2cc4d3b3b1ac5fe81ddf21959eb, patched in 9eac1904d3364254d622bf2c771c4f85cd435fc2, backported to stable in 788d0824269bef539fe31a785b1517882eafed93.

    Published: 1 Feb 2021
    7.5
    High

    CVE-2021-3282

    Last Modified: 21 Nov 2024

    HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the `remove-peer` raft operator command to be executed against DR secondaries without authentication. Fixed in 1.6.2.

    Published: 1 Feb 2021
    7.5
    High

    CVE-2021-23329

    Last Modified: 21 Nov 2024

    The package nested-object-assign before 1.0.4 are vulnerable to Prototype Pollution via the default function, as demonstrated by running the PoC below.

    Published: 31 Jan 2021
    7.1
    High

    CVE-2021-3549

    Last Modified: 28 Feb 2025

    An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An attacker could use this flaw and pass a large section to avr_elf32_load_records_from_section() probably resulting in a crash or in some cases memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.

    Published: 31 Jan 2021
    7
    High

    CVE-2020-14418

    Last Modified: 21 Nov 2024

    A TOCTOU vulnerability exists in madCodeHook before 2020-07-16 that allows local attackers to elevate their privileges to SYSTEM. This occurs because path redirection can occur via vectors involving directory junctions.

    Published: 30 Jan 2021
    9.8
    Critical

    CVE-2020-15690

    Last Modified: 21 Nov 2024

    In Nim before 1.2.6, the standard library asyncftpclient lacks a check for whether a message contains a newline character.

    Published: 30 Jan 2021
    9.8
    Critical

    CVE-2020-15568

    Last Modified: 21 Nov 2024

    TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php, in which an attacker can trigger a call to the exec method with (for example) OS commands in the opt parameter.

    Published: 30 Jan 2021
    3.2
    Low

    CVE-2021-20203

    Last Modified: 21 Nov 2024

    An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameters. A privileged guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario.

    Published: 30 Jan 2021
    6.5
    Medium

    CVE-2021-21254

    Last Modified: 21 Nov 2024

    CKEditor 5 is an open source rich text editor framework with a modular architecture. The CKEditor 5 Markdown plugin (@ckeditor/ckeditor5-markdown-gfm) before version 25.0.0 has a regex denial of service (ReDoS) vulnerability. The vulnerability allowed to abuse link recognition regular expression, which could cause a significant performance drop resulting in browser tab freeze. It affects all users using CKEditor 5 Markdown plugin at version <= 24.0.0. The problem has been recognized and patched. The fix will be available in version 25.0.0.

    Published: 29 Jan 2021
    9.8
    Critical

    CVE-2020-29557

    Last Modified: 7 Nov 2025

    An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to achieve pre-authentication remote code execution.

    Published: 29 Jan 2021
    5.4
    Medium

    CVE-2020-24666

    Last Modified: 21 Nov 2024

    The Analysis Report in Hitachi Vantara Pentaho through 7.x - 8.x contains a stored Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code. Specifically, the vulnerability lies in the 'Display Name' parameter. Remediated in >= 9.1.0.1

    Published: 29 Jan 2021
    5.4
    Medium

    CVE-2020-24664

    Last Modified: 21 Nov 2024

    The dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains a reflected Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code. Specifically, the vulnerability lies in the 'pho:title' attribute of 'dashboardXml' parameter. Remediated in >= 7.1.0.25, >= 8.2.0.6, and >= 8.3.0.0 GA.

    Published: 29 Jan 2021
    5.4
    Medium

    CVE-2020-24670

    Last Modified: 21 Nov 2024

    The Dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains a reflected Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code. Specifically, the vulnerability lies in the 'type' attribute of 'dashboardXml' parameter. Remediated in >= 7.1.0.25, >= 8.2.0.6, and >= 8.3.0.0 GA.

    Published: 29 Jan 2021
    5.4
    Medium

    CVE-2020-24669

    Last Modified: 21 Nov 2024

    The New Analysis Report in Hitachi Vantara Pentaho through 7.x - 8.x contains a DOM-based Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code. Specifically, the vulnerability lies in the 'Analysis Report Description' field in 'About this Report' section. Remediated in >= 8.3.0.9, >= 9.0.0.1, and >= 9.1.0.0 GA.

    Published: 29 Jan 2021
    7.8
    High

    CVE-2021-25136

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spx_restservice setsolvideoremotestorage_func function.

    Published: 29 Jan 2021
    7.8
    High

    CVE-2021-25135

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spx_restservice setsmtp_func function.

    Published: 29 Jan 2021
    7.8
    High

    CVE-2021-25134

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spx_restservice setremoteimageinfo_func function.

    Published: 29 Jan 2021
    7.8
    High

    CVE-2021-25137

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spx_restservice startflash_func function.

    Published: 29 Jan 2021
    6.5
    Medium

    CVE-2020-24665

    Last Modified: 21 Nov 2024

    The Dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains an XML Entity Expansion injection vulnerability, which allows an authenticated remote users to trigger a denial of service (DoS) condition. Specifically, the vulnerability lies in the 'dashboardXml' parameter. Remediated in >= 7.1.0.25, >= 8.2.0.6, >= 8.3.0.0 GA

    Published: 29 Jan 2021
    7.8
    High

    CVE-2021-25130

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spx_restservice setactdir_func function.

    Published: 29 Jan 2021
    7.8
    High

    CVE-2021-25133

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spx_restservice setradiusconfig_func function.

    Published: 29 Jan 2021
    7.8
    High

    CVE-2021-25132

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spx_restservice setmediaconfig_func function.

    Published: 29 Jan 2021
    7.8
    High

    CVE-2021-25131

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spx_restservice setfwimagelocation_func function.

    Published: 29 Jan 2021