CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2021-26405

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 29 Jan 2021
    5.5
    Medium

    CVE-2021-26927

    Last Modified: 21 Nov 2024

    A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of service.

    Published: 29 Jan 2021
    5.5
    Medium

    CVE-2021-46195

    Last Modified: 21 Nov 2024

    GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by consuming excessive CPU and memory resources.

    Published: 29 Jan 2021
    7.5
    High

    CVE-2021-20228

    Last Modified: 21 Nov 2024

    A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.

    Published: 29 Jan 2021
    7.8
    High

    CVE-2021-3345

    Last Modified: 21 Nov 2024

    _gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count value. It is recommended to upgrade to 1.9.1 or later.

    Published: 29 Jan 2021
    3.7
    Low

    CVE-2021-22173

    Last Modified: 21 Nov 2024

    Memory leak in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file

    Published: 29 Jan 2021
    5.5
    Medium

    CVE-2020-8585

    Last Modified: 21 Nov 2024

    OnCommand Unified Manager Core Package versions prior to 5.2.5 may disclose sensitive account information to unauthorized users via the use of PuTTY Link (plink).

    Published: 28 Jan 2021
    8.8
    High

    CVE-2019-25016

    Last Modified: 21 Nov 2024

    In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowed the user to execute any command. Rules that only allowed to authenticated user to execute specific commands were not affected by this issue.

    Published: 28 Jan 2021
    9.8
    Critical

    CVE-2021-3160

    Last Modified: 21 Nov 2024

    Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product allows a remote attacker to inject unsecure serialized Java object using a specially crafted HTTP request, resulting in an unauthenticated remote code execution on the server.

    Published: 28 Jan 2021
    7.5
    High

    CVE-2021-3337

    Last Modified: 21 Nov 2024

    The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading restrictions by clicking on reply or quote in the postbit.

    Published: 28 Jan 2021
    7.2
    High

    CVE-2020-35754

    Last Modified: 21 Nov 2024

    OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Language tab.

    Published: 28 Jan 2021
    5.4
    Medium

    CVE-2020-36115

    Last Modified: 21 Nov 2024

    Stored Cross Site Scripting (XSS) vulnerability in EGavilan Media CRUD Operation with PHP, MySQL, Bootstrap, and Dompdf via First Name or Last Name parameter in the 'Add New Record Feature'.

    Published: 28 Jan 2021
    5.3
    Medium

    CVE-2021-20185

    Last Modified: 21 Nov 2024

    It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages, which could result in client-side (browser) denial of service for users receiving very large messages.

    Published: 28 Jan 2021
    5.4
    Medium

    CVE-2021-25647

    Last Modified: 21 Nov 2024

    Mobile application "Testes de Codigo" v11.3 and prior allows stored XSS by injecting a payload in the "feedback" message field causing it to be stored in the remote database and leading to its execution on client devices when loading the "feedback list", either by accessing the website directly or using the mobile application.

    Published: 28 Jan 2021
    4.3
    Medium

    CVE-2021-20184

    Last Modified: 21 Nov 2024

    It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade related web services meant students were able to view other students grades.

    Published: 28 Jan 2021
    5.4
    Medium

    CVE-2021-20186

    Last Modified: 21 Nov 2024

    It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, additional sanitizing of TeX content was required to prevent the risk of stored XSS.

    Published: 28 Jan 2021
    5.4
    Medium

    CVE-2021-20183

    Last Modified: 21 Nov 2024

    It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficient escaping of search queries.

    Published: 28 Jan 2021
    7.2
    High

    CVE-2021-20187

    Last Modified: 21 Nov 2024

    It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to execute arbitrary PHP scripts via a PHP include used during Shibboleth authentication.

    Published: 28 Jan 2021
    5.4
    Medium

    CVE-2020-26272

    Last Modified: 27 May 2025

    The Electron framework lets users write cross-platform desktop applications using JavaScript, HTML and CSS. In versions of Electron IPC prior to 9.4.0, 10.2.0, 11.1.0, and 12.0.0-beta.9, messages sent from the main process to a subframe in the renderer process, through webContents.sendToFrame, event.reply or when using the remote module, can in some cases be delivered to the wrong frame. If your app uses remote, calls webContents.sendToFrame, or calls event.reply in an IPC message handler then it is impacted by this issue. This has been fixed in versions 9.4.0, 10.2.0, 11.1.0, and 12.0.0-beta.9. There are no known workarounds for this issue.

    Published: 28 Jan 2021
    6.1
    Medium

    CVE-2021-22875

    Last Modified: 21 Nov 2024

    Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in stats.php via the `setPerPage` parameter.

    Published: 28 Jan 2021
    6.1
    Medium

    CVE-2021-22874

    Last Modified: 21 Nov 2024

    Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in userlog-index.php via the `period_preset` parameter.

    Published: 28 Jan 2021
    8.8
    High

    CVE-2020-4888

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.4.0 to 7.4.2 Patch 1 and 7.3.0 to 7.3.3 Patch 7 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-supplied content by the Java deserialization function. By sending a malicious serialized Java object, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 190912.

    Published: 28 Jan 2021
    9.8
    Critical

    CVE-2020-4682

    Last Modified: 21 Nov 2024

    IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization of trusted data. An attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 186509.

    Published: 28 Jan 2021
    8.8
    High

    CVE-2020-13569

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability exists in the GACL functionality of OpenEMR 5.0.2 and development version 6.0.0 (commit babec93f600ff1394f91ccd512bcad85832eb6ce). A specially crafted HTTP request can lead to the execution of arbitrary requests in the context of the victim. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 28 Jan 2021
    8.8
    High

    CVE-2021-20621

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 firmware Ver1.0.2 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 28 Jan 2021
    6.1
    Medium

    CVE-2021-20622

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 firmware Ver1.0.2 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.

    Published: 28 Jan 2021
    6.1
    Medium

    CVE-2021-20620

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Aterm WF800HP firmware Ver1.0.9 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.

    Published: 28 Jan 2021
    8.8
    High

    CVE-2020-5626

    Last Modified: 21 Nov 2024

    Logstorage version 8.0.0 and earlier, and ELC Analytics version 3.0.0 and earlier allow remote attackers to execute arbitrary OS commands via a specially crafted log file.

    Published: 28 Jan 2021
    9.6
    Critical

    CVE-2020-35124

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the assets component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript through the Referer header of asset downloads.

    Published: 28 Jan 2021
    —
    Unknown

    CVE-2021-3142

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-35128. Reason: This candidate is a reservation duplicate of CVE-2020-35128. Notes: All CVE users should reference CVE-2020-35128 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Jan 2021
    9.8
    Critical

    CVE-2020-25785

    Last Modified: 21 Nov 2024

    An issue was discovered on Accfly Wireless Security IR Camera System 720P with software versions v3.10.73 through v4.15.77. There is an unauthenticated stack-based buffer overflow in the function CFtpProtocol::FtpLogin during the update procedure.

    Published: 28 Jan 2021
    9.8
    Critical

    CVE-2020-25784

    Last Modified: 21 Nov 2024

    An issue was discovered on Accfly Wireless Security IR Camera System 720P with software versions v3.10.73 through v4.15.77. There is an unauthenticated stack-based buffer overflow in the function CNetClientGuard::SubOprMsg during incoming message handling.

    Published: 28 Jan 2021
    9.8
    Critical

    CVE-2020-25783

    Last Modified: 21 Nov 2024

    An issue was discovered on Accfly Wireless Security IR Camera System 720P with software versions v3.10.73 through v4.15.77. There is an unauthenticated heap-based buffer overflow in the function CNetClientTalk::OprMsg during incoming message handling.

    Published: 28 Jan 2021
    9.8
    Critical

    CVE-2020-25782

    Last Modified: 21 Nov 2024

    An issue was discovered on Accfly Wireless Security IR Camera 720P System with software versions v3.10.73 through v4.15.77. There is an unauthenticated stack-based buffer overflow in the function CNetClientManage::ServerIP_Proto_Set during incoming message handling.

    Published: 28 Jan 2021
    5.3
    Medium

    CVE-2021-26067

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace that may reveal the path for the home directory in disk and if certain files exists on the tmp directory, via a Sensitive Data Exposure vulnerability in the /chart endpoint. The affected versions are before version 7.2.2.

    Published: 28 Jan 2021
    —
    Unknown

    CVE-2020-0237

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 28 Jan 2021
    7.8
    High

    CVE-2021-3347

    Last Modified: 25 Feb 2026

    An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local users to execute code in the kernel, aka CID-34b1a1ce1458.

    Published: 28 Jan 2021
    7
    High

    CVE-2021-3348

    Last Modified: 21 Nov 2024

    nbd_add_socket in drivers/block/nbd.c in the Linux kernel through 5.10.12 has an ndb_queue_rq use-after-free that could be triggered by local attackers (with access to the nbd device) via an I/O request at a certain point during device setup, aka CID-b98e762e3d71.

    Published: 28 Jan 2021
    9.8
    Critical

    CVE-2021-3331

    Last Modified: 21 Nov 2024

    WinSCP before 5.17.10 allows remote attackers to execute arbitrary programs when the URL handler encounters a crafted URL that loads session settings. (For example, this is exploitable in a default installation in which WinSCP is the handler for sftp:// URLs.)

    Published: 27 Jan 2021
    5.3
    Medium

    CVE-2021-26276

    Last Modified: 21 Nov 2024

    scripts/cli.js in the GoDaddy node-config-shield (aka Config Shield) package before 0.2.2 for Node.js calls eval when processing a set command. NOTE: the vendor reportedly states that this is not a vulnerability. The set command was not intended for use with untrusted data

    Published: 27 Jan 2021
    7.8
    High

    CVE-2021-25247

    Last Modified: 21 Nov 2024

    A DLL hijacking vulnerability Trend Micro HouseCall for Home Networks version 5.3.1063 and below could allow an attacker to use a malicious DLL to escalate privileges and perform arbitrary code execution. An attacker must already have user privileges on the machine to exploit this vulnerability.

    Published: 27 Jan 2021
    5.5
    Medium

    CVE-2021-25226

    Last Modified: 21 Nov 2024

    A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft specific files that can cause a denial-of-service on the affected product. The specific flaw exists within a scan engine component. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 27 Jan 2021
    5.5
    Medium

    CVE-2021-25224

    Last Modified: 21 Nov 2024

    A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft specific files that can cause a denial-of-service on the affected product. The specific flaw exists within a manual scan component. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 27 Jan 2021
    5.5
    Medium

    CVE-2021-25225

    Last Modified: 21 Nov 2024

    A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft specific files that can cause a denial-of-service on the affected product. The specific flaw exists within a scheduled scan component. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 27 Jan 2021
    7.8
    High

    CVE-2021-22637

    Last Modified: 21 Nov 2024

    Multiple stack-based buffer overflow issues have been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).

    Published: 27 Jan 2021
    7.8
    High

    CVE-2021-22655

    Last Modified: 21 Nov 2024

    Multiple out-of-bounds read issues have been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).

    Published: 27 Jan 2021
    7.8
    High

    CVE-2021-22639

    Last Modified: 21 Nov 2024

    An uninitialized pointer issue has been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).

    Published: 27 Jan 2021
    7.8
    High

    CVE-2021-22641

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow issue has been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).

    Published: 27 Jan 2021
    7.8
    High

    CVE-2021-22653

    Last Modified: 21 Nov 2024

    Multiple out-of-bounds write issues have been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).

    Published: 27 Jan 2021
    9.8
    Critical

    CVE-2021-3325

    Last Modified: 21 Nov 2024

    Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation without a hosts_deny option). This issue occurred because a new access-control feature was introduced without considering that some exiting installations became unsafe, upon an update to 3.13.0, unless the new feature was immediately configured.

    Published: 27 Jan 2021