CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2021-25128

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local spx_restservice gethelpdata_func function path traversal vulnerability.

    Published: 29 Jan 2021
    7.8
    High

    CVE-2021-25127

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spx_restservice generatesslcertificate_func function.

    Published: 29 Jan 2021
    7.8
    High

    CVE-2021-25129

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local spx_restservice getvideodata_func function path traversal vulnerability.

    Published: 29 Jan 2021
    7.8
    High

    CVE-2021-25125

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local spx_restservice delsolrecordedvideo_func function path traversal vulnerability.

    Published: 29 Jan 2021
    7.8
    High

    CVE-2021-25126

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spx_restservice downloadkvmjnlp_func function.

    Published: 29 Jan 2021
    7.8
    High

    CVE-2021-25124

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local spx_restservice deletevideo_func function path traversal vulnerability.

    Published: 29 Jan 2021
    7.8
    High

    CVE-2021-25138

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spx_restservice uploadsshkey function.

    Published: 29 Jan 2021
    9.8
    Critical

    CVE-2021-3346

    Last Modified: 21 Nov 2024

    Foris before 101.1.1, as used in Turris OS, lacks certain HTML escaping in the login template.

    Published: 29 Jan 2021
    5.6
    Medium

    CVE-2021-23328

    Last Modified: 21 Nov 2024

    This affects all versions of package iniparserjs. This vulnerability relates when ini_parser.js is concentrating arrays. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program.

    Published: 29 Jan 2021
    7.5
    High

    CVE-2021-20586

    Last Modified: 21 Nov 2024

    Resource management errors vulnerability in a robot controller of MELFA FR Series(controller "CR800-*V*D" of RV-*FR***-D-* all versions, controller "CR800-*HD" of RH-*FRH***-D-* all versions, controller "CR800-*HRD" of RH-*FRHR***-D-* all versions, controller "CR800-*V*R with R16RTCPU" of RV-*FR***-R-* all versions, controller "CR800-*HR with R16RTCPU" of RH-*FRH***-R-* all versions, controller "CR800-*HRR with R16RTCPU" of RH-*FRHR***-R-* all versions, controller "CR800-*V*Q with Q172DSRCPU" of RV-*FR***-Q-* all versions, controller "CR800-*HQ with Q172DSRCPU" of RH-*FRH***-Q-* all versions, controller "CR800-*HRQ with Q172DSRCPU" of RH-*FRHR***-Q-* all versions) and a robot controller of MELFA CR Series(controller "CR800-CVD" of RV-8CRL-D-* all versions, controller "CR800-CHD" of RH-*CRH**-D-* all versions) as well as a cooperative robot ASSISTA(controller "CR800-05VD" of RV-5AS-D-* all versions) allows a remote unauthenticated attacker to cause a DoS of the execution of the robot program and the Ethernet communication by sending a large amount of packets in burst over a short period of time. As a result of DoS, an error may occur. A reset is required to recover it if the error occurs.

    Published: 29 Jan 2021
    8.6
    High

    CVE-2021-25909

    Last Modified: 21 Nov 2024

    ZIV Automation 4CCT-EA6-334126BF firmware version 3.23.80.27.36371, allows an unauthenticated, remote attacker to cause a denial of service condition on the device. An attacker could exploit this vulnerability by sending specific packets to the port 7919.

    Published: 29 Jan 2021
    8
    High

    CVE-2021-25910

    Last Modified: 21 Nov 2024

    Improper Authentication vulnerability in the cookie parameter of ZIV AUTOMATION 4CCT-EA6-334126BF allows a local attacker to perform modifications in several parameters of the affected device as an authenticated user.

    Published: 29 Jan 2021
    7.8
    High

    CVE-2021-25123

    Last Modified: 21 Nov 2024

    The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local buffer overlfow in spx_restservice addlicense_func function.

    Published: 29 Jan 2021
    6.5
    Medium

    CVE-2020-35652

    Last Modified: 21 Nov 2024

    An issue was discovered in res_pjsip_diversion.c in Sangoma Asterisk before 13.38.0, 14.x through 16.x before 16.15.0, 17.x before 17.9.0, and 18.x before 18.1.0. A crash can occur when a SIP message is received with a History-Info header that contains a tel-uri, or when a SIP 181 response is received that contains a tel-uri in the Diversion header.

    Published: 29 Jan 2021
    7.8
    High

    CVE-2020-35145

    Last Modified: 21 Nov 2024

    Acronis True Image for Windows prior to 2021 Update 3 allowed local privilege escalation due to a DLL hijacking vulnerability in multiple components, aka an Untrusted Search Path issue.

    Published: 29 Jan 2021
    6.5
    Medium

    CVE-2020-29604

    Last Modified: 21 Nov 2024

    An issue was discovered in MantisBT before 2.24.4. A missing access check in bug_actiongroup.php allows an attacker (with rights to create new issues) to use the COPY group action to create a clone, including all bugnotes and attachments, of any private issue (i.e., one having Private view status, or belonging to a private Project) via the bug_arr[] parameter. This provides full access to potentially confidential information.

    Published: 29 Jan 2021
    4.3
    Medium

    CVE-2020-29605

    Last Modified: 21 Nov 2024

    An issue was discovered in MantisBT before 2.24.4. Due to insufficient access-level checks, any logged-in user allowed to perform Group Actions can get access to the Summary fields of private Issues via bug_arr[]= in a crafted bug_actiongroup_page.php URL. (The target Issues can have Private view status, or belong to a private Project.)

    Published: 29 Jan 2021
    4.3
    Medium

    CVE-2020-29603

    Last Modified: 21 Nov 2024

    In manage_proj_edit_page.php in MantisBT before 2.24.4, any unprivileged logged-in user can retrieve Private Projects' names via the manage_proj_edit_page.php project_id parameter, without having access to them.

    Published: 29 Jan 2021
    4.9
    Medium

    CVE-2020-29538

    Last Modified: 21 Nov 2024

    Archer before 6.9 P1 (6.9.0.1) contains an improper access control vulnerability in an API. A remote authenticated malicious administrative user can potentially exploit this vulnerability to gather information about the system, and may use this information in subsequent attacks.

    Published: 29 Jan 2021
    4.3
    Medium

    CVE-2020-29536

    Last Modified: 21 Nov 2024

    Archer before 6.8 P2 (6.8.0.2) is affected by a path exposure vulnerability. A remote authenticated malicious attacker with access to service files may obtain sensitive information to use it in further attacks.

    Published: 29 Jan 2021
    4.6
    Medium

    CVE-2020-29537

    Last Modified: 21 Nov 2024

    Archer before 6.8 P2 (6.8.0.2) is affected by an open redirect vulnerability. A remote privileged attacker may potentially redirect legitimate users to arbitrary web sites and conduct phishing attacks. The attacker could then steal the victims' credentials and silently authenticate them to the Archer application without the victims realizing an attack occurred.

    Published: 29 Jan 2021
    5.3
    Medium

    CVE-2020-29535

    Last Modified: 21 Nov 2024

    Archer before 6.8 P4 (6.8.0.4) contains a stored XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When application users access the corrupted data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application.

    Published: 29 Jan 2021
    8
    High

    CVE-2021-3176

    Last Modified: 21 Nov 2024

    The chat window of the Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.15 and 7.x before 7.1.2 could allow an attacker to gain access to user information by sending certain code, due to improper input validation of http links. A successful exploit could allow an attacker to view user information and application data.

    Published: 29 Jan 2021
    9.1
    Critical

    CVE-2020-35547

    Last Modified: 21 Nov 2024

    A library index page in NuPoint Messenger in Mitel MiCollab before 9.2 FP1 could allow an unauthenticated attacker to gain access (view and modify) to user data.

    Published: 29 Jan 2021
    6.5
    Medium

    CVE-2020-28406

    Last Modified: 30 May 2025

    An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access details about jobs he should not have access to via the Audit Trail Feature.

    Published: 29 Jan 2021
    8.8
    High

    CVE-2020-28405

    Last Modified: 30 May 2025

    An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to change the privileges of any user of the application. This can be used to grant himself the administrative role or remove all administrative accounts of the application.

    Published: 29 Jan 2021
    6.5
    Medium

    CVE-2020-28404

    Last Modified: 30 May 2025

    An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access the Billing page without the appropriate privileges.

    Published: 29 Jan 2021
    8
    High

    CVE-2020-28403

    Last Modified: 30 May 2025

    A Cross-Site Request Forgery (CSRF) vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an attacker to change the privileges of any user of the application. This can be used to grant himself administrative role or remove the administrative account of the application.

    Published: 29 Jan 2021
    5.4
    Medium

    CVE-2020-28402

    Last Modified: 30 May 2025

    An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access Launcher Configuration Panel.

    Published: 29 Jan 2021
    6.5
    Medium

    CVE-2020-28401

    Last Modified: 30 May 2025

    An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access WIP details about jobs he should not have access to.

    Published: 29 Jan 2021
    5.4
    Medium

    CVE-2021-3298

    Last Modified: 21 Nov 2024

    Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?action=edit address1 parameter.

    Published: 29 Jan 2021
    8.1
    High

    CVE-2021-3336

    Last Modified: 21 Nov 2024

    DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease processing for certain anomalous peer behavior (sending an ED22519, ED448, ECC, or RSA signature without the corresponding certificate). The client side is affected because man-in-the-middle attackers can impersonate TLS 1.3 servers.

    Published: 29 Jan 2021
    9.8
    Critical

    CVE-2021-26305

    Last Modified: 21 Nov 2024

    An issue was discovered in Deserializer::read_vec in the cdr crate before 0.2.4 for Rust. A user-provided Read implementation can gain access to the old contents of newly allocated heap memory, violating soundness.

    Published: 29 Jan 2021
    7.5
    High

    CVE-2021-26306

    Last Modified: 21 Nov 2024

    An issue was discovered in the raw-cpuid crate before 9.0.0 for Rust. It has unsound transmute calls within as_string() methods.

    Published: 29 Jan 2021
    5.5
    Medium

    CVE-2021-26307

    Last Modified: 21 Nov 2024

    An issue was discovered in the raw-cpuid crate before 9.0.0 for Rust. It allows __cpuid_count() calls even if the processor does not support the CPUID instruction, which is unsound and causes a deterministic crash.

    Published: 29 Jan 2021
    7.5
    High

    CVE-2021-26308

    Last Modified: 21 Nov 2024

    An issue was discovered in the marc crate before 2.0.0 for Rust. A user-provided Read implementation can gain access to the old contents of newly allocated memory, violating soundness.

    Published: 29 Jan 2021
    6.1
    Medium

    CVE-2021-26303

    Last Modified: 21 Nov 2024

    PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the user-profile.php Full Name field.

    Published: 29 Jan 2021
    5.4
    Medium

    CVE-2021-26304

    Last Modified: 21 Nov 2024

    PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the add-expense.php Item parameter.

    Published: 29 Jan 2021
    7.5
    High

    CVE-2021-3341

    Last Modified: 21 Nov 2024

    A path traversal vulnerability in the DxWebEngine component of DH2i DxEnterprise and DxOdyssey for Windows, version 19.5 through 20.x before 20.0.219.0, allows an attacker to read any file on the host file system via an HTTP request.

    Published: 29 Jan 2021
    6.1
    Medium

    CVE-2021-3377

    Last Modified: 3 Nov 2025

    The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTML hyperlinks. Due to insufficient URL sanitization, this feature is affected by a cross-site scripting (XSS) vulnerability. This issue is fixed in v5.0.0.

    Published: 29 Jan 2021
    7.8
    High

    CVE-2021-20268

    Last Modified: 21 Nov 2024

    An out-of-bounds access flaw was found in the Linux kernel's implementation of the eBPF code verifier in the way a user running the eBPF script calls dev_map_init_map or sock_map_alloc. This flaw allows a local user to crash the system or possibly escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

    Published: 29 Jan 2021
    3.7
    Low

    CVE-2021-22174

    Last Modified: 21 Nov 2024

    Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file

    Published: 29 Jan 2021
    8.8
    High

    CVE-2021-25646

    Last Modified: 13 Feb 2025

    Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it is possible for an authenticated user to send a specially-crafted request that forces Druid to run user-provided JavaScript code for that request, regardless of server configuration. This can be leveraged to execute code on the target machine with the privileges of the Druid server process.

    Published: 29 Jan 2021
    7.1
    High

    CVE-2021-26926

    Last Modified: 21 Nov 2024

    A flaw was found in jasper before 2.0.25. An out of bounds read issue was found in jp2_decode function whic may lead to disclosure of information or program crash.

    Published: 29 Jan 2021
    —
    Unknown

    CVE-2021-26319

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 29 Jan 2021
    —
    Unknown

    CVE-2021-26357

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 29 Jan 2021
    —
    Unknown

    CVE-2021-26358

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 29 Jan 2021
    —
    Unknown

    CVE-2021-26374

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 29 Jan 2021
    —
    Unknown

    CVE-2021-26385

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 29 Jan 2021
    —
    Unknown

    CVE-2021-26399

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 29 Jan 2021