CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2021-26271

    Last Modified: 25 Aug 2026

    It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).

    Published: 26 Jan 2021
    8.6
    High

    CVE-2021-21278

    Last Modified: 21 Nov 2024

    RSSHub is an open source, easy to use, and extensible RSS feed generator. In RSSHub before version 7f1c430 (non-semantic versioning) there is a risk of code injection. Some routes use `eval` or `Function constructor`, which may be injected by the target site with unsafe code, causing server-side security issues The fix in version 7f1c430 is to temporarily remove the problematic route and added a `no-new-func` rule to eslint.

    Published: 26 Jan 2021
    8.1
    High

    CVE-2021-3309

    Last Modified: 21 Nov 2024

    packages/wekan-ldap/server/ldap.js in Wekan before 4.87 can process connections even though they are not authorized by the Certification Authority trust store,

    Published: 26 Jan 2021
    5.5
    Medium

    CVE-2021-3308

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen 4.12.3 through 4.12.4 and 4.13.1 through 4.14.x. An x86 HVM guest with PCI pass through devices can force the allocation of all IDT vectors on the system by rebooting itself with MSI or MSI-X capabilities enabled and entries setup. Such reboots will leak any vectors used by the MSI(-X) entries that the guest might had enabled, and hence will lead to vector exhaustion on the system, not allowing further PCI pass through devices to work properly. HVM guests with PCI pass through devices can mount a Denial of Service (DoS) attack affecting the pass through of PCI devices to other guests or the hardware domain. In the latter case, this would affect the entire host.

    Published: 26 Jan 2021
    7.8
    High

    CVE-2021-22159

    Last Modified: 21 Nov 2024

    Insider Threat Management Windows Agent Local Privilege Escalation Vulnerability The Proofpoint Insider Threat Management (formerly ObserveIT) Agent for Windows before 7.4.3, 7.5.4, 7.6.5, 7.7.5, 7.8.4, 7.9.3, 7.10.2, and 7.11.0.25 as well as versions 7.3 and earlier is missing authentication for a critical function, which allows a local authenticated Windows user to run arbitrary commands with the privileges of the Windows SYSTEM user. Agents for MacOS, Linux, and ITM Cloud are not affected.

    Published: 26 Jan 2021
    7.5
    High

    CVE-2020-27295

    Last Modified: 21 Nov 2024

    The affected product has uncontrolled resource consumption issues, which may allow an attacker to cause a denial-of-service condition on the OPC UA Tunneller (versions prior to 6.3.0.8233).

    Published: 26 Jan 2021
    9.8
    Critical

    CVE-2020-27297

    Last Modified: 21 Nov 2024

    The affected product is vulnerable to a heap-based buffer overflow, which may allow an attacker to manipulate memory with controlled values and remotely execute code on the OPC UA Tunneller (versions prior to 6.3.0.8233).

    Published: 26 Jan 2021
    9.1
    Critical

    CVE-2020-27299

    Last Modified: 21 Nov 2024

    The affected product is vulnerable to an out-of-bounds read, which may allow an attacker to obtain and disclose sensitive data information or cause the device to crash on the OPC UA Tunneller (versions prior to 6.3.0.8233).

    Published: 26 Jan 2021
    7.5
    High

    CVE-2020-27274

    Last Modified: 21 Nov 2024

    Some parsing functions in the affected product do not check the return value of malloc and the thread handling the message is forced to close, which may lead to a denial-of-service condition on the OPC UA Tunneller (versions prior to 6.3.0.8233).

    Published: 26 Jan 2021
    7.5
    High

    CVE-2020-13582

    Last Modified: 21 Nov 2024

    A denial-of-service vulnerability exists in the HTTP Server functionality of Micrium uC-HTTP 3.01.00. A specially crafted HTTP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 26 Jan 2021
    4.6
    Medium

    CVE-2021-23272

    Last Modified: 21 Nov 2024

    The Application Development Clients component of TIBCO Software Inc.'s TIBCO BPM Enterprise and TIBCO BPM Enterprise Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically allows a low privileged attacker with network access to execute a Cross Site Scripting (XSS) attack on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO BPM Enterprise: versions 4.3.0 and below and TIBCO BPM Enterprise Distribution for TIBCO Silver Fabric: versions 4.3.0 and below.

    Published: 26 Jan 2021
    9.8
    Critical

    CVE-2020-35263

    Last Modified: 21 Nov 2024

    EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution.

    Published: 26 Jan 2021
    7.5
    High

    CVE-2020-23449

    Last Modified: 21 Nov 2024

    newbee-mall all versions are affected by incorrect access control to remotely gain privileges through NewBeeMallIndexConfigServiceImpl.java. Unauthorized changes can be made to any user information through the userID.

    Published: 26 Jan 2021
    9.8
    Critical

    CVE-2020-23448

    Last Modified: 21 Nov 2024

    newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginInterceptor.java. The authentication logic of the system's background /admin is in code AdminLoginInterceptor, which can be bypassed.

    Published: 26 Jan 2021
    6.1
    Medium

    CVE-2020-23447

    Last Modified: 21 Nov 2024

    newbee-mall 1.0 is affected by cross-site scripting in shop-cart/settle. Users only need to write xss payload in their address information when buying goods, which is triggered when viewing the "View Recipient Information" of this order in "Order Management Office".

    Published: 26 Jan 2021
    7.5
    High

    CVE-2020-8295

    Last Modified: 21 Nov 2024

    A wrong check in Nextcloud Server 19 and prior allowed to perform a denial of service attack when resetting the password for a user.

    Published: 26 Jan 2021
    6.5
    Medium

    CVE-2020-8293

    Last Modified: 21 Nov 2024

    A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and potential DDoS on later interactions and usage with those rules.

    Published: 26 Jan 2021
    —
    Unknown

    CVE-2020-28492

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA

    Published: 26 Jan 2021
    8.2
    High

    CVE-2020-4949

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192025.

    Published: 26 Jan 2021
    3.3
    Low

    CVE-2020-4889

    Last Modified: 21 Nov 2024

    IBM Spectrum Scale 5.0.0 through 5.0.5.4 and 5.1.0 could allow a local user to poison log files which could impact support and development efforts. IBM X-Force ID: 190971.

    Published: 26 Jan 2021
    7.8
    High

    CVE-2020-27284

    Last Modified: 21 Nov 2024

    TPEditor (v1.98 and prior) is vulnerable to two out-of-bounds write instances in the way it processes project files, allowing an attacker to craft a special project file that may permit arbitrary code execution.

    Published: 26 Jan 2021
    7.8
    High

    CVE-2020-27280

    Last Modified: 21 Nov 2024

    A use after free issue has been identified in the way ISPSoft(v3.12 and prior) processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution.

    Published: 26 Jan 2021
    7.8
    High

    CVE-2020-27288

    Last Modified: 21 Nov 2024

    An untrusted pointer dereference has been identified in the way TPEditor(v1.98 and prior) processes project files, allowing an attacker to craft a special project file that may permit arbitrary code execution.

    Published: 26 Jan 2021
    7.5
    High

    CVE-2020-25169

    Last Modified: 21 Nov 2024

    The affected Reolink P2P products do not sufficiently protect data transferred between the local device and Reolink servers. This can allow an attacker to access sensitive information, such as camera feeds.

    Published: 26 Jan 2021
    7.8
    High

    CVE-2020-25173

    Last Modified: 21 Nov 2024

    An attacker with local network access can obtain a fixed cryptography key which may allow for further compromise of Reolink P2P cameras outside of local network access

    Published: 26 Jan 2021
    5.8
    Medium

    CVE-2020-17522

    Last Modified: 21 Nov 2024

    When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissions that allow bad actors to push arbitrary content into and remove arbitrary content from CDN cache servers. Additionally, these permissions are potentially extended to IP addresses outside the desired range, resulting in them being granted to clients possibly outside the CDN arcitechture.

    Published: 26 Jan 2021
    7.8
    High

    CVE-2021-3297

    Last Modified: 25 Nov 2025

    On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access.

    Published: 26 Jan 2021
    7.5
    High

    CVE-2021-25864

    Last Modified: 21 Nov 2024

    node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in file hue-magic.js, to fetch an arbitrary file.

    Published: 26 Jan 2021
    8.8
    High

    CVE-2021-25863

    Last Modified: 21 Nov 2024

    Open5GS 2.1.3 listens on 0.0.0.0:3000 and has a default password of 1423 for the admin account.

    Published: 26 Jan 2021
    4.8
    Medium

    CVE-2020-36011

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) issue in Add Patient Form in QDOCS Smart Hospital Management System 3.1 allows a remote attacker to inject arbitrary code via the Name, Guardian Name, Email, Address, Remarks, or Any Known Allergies field.

    Published: 26 Jan 2021
    7.2
    High

    CVE-2021-3291

    Last Modified: 21 Nov 2024

    Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting a command.

    Published: 26 Jan 2021
    9.8
    Critical

    CVE-2021-3304

    Last Modified: 21 Nov 2024

    Sagemcom F@ST 3686 v2 3.495 devices have a buffer overflow via a long sessionKey to the goform/login URI.

    Published: 26 Jan 2021
    7.5
    High

    CVE-2021-3223

    Last Modified: 21 Nov 2024

    Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files.

    Published: 26 Jan 2021
    7.5
    High

    CVE-2021-26266

    Last Modified: 21 Nov 2024

    cPanel before 92.0.9 allows a Reseller to bypass the suspension lock (SEC-578).

    Published: 26 Jan 2021
    7.5
    High

    CVE-2021-26267

    Last Modified: 21 Nov 2024

    cPanel before 92.0.9 allows a MySQL user (who has an old-style password hash) to bypass suspension (SEC-579).

    Published: 26 Jan 2021
    —
    Unknown

    CVE-2021-23199

    Last Modified: 7 Nov 2023

    This candidate was in a CNA pool that was not assigned to any issues during 2021.

    Published: 26 Jan 2021
    —
    Unknown

    CVE-2021-23220

    Last Modified: 7 Nov 2023

    This candidate was in a CNA pool that was not assigned to any issues during 2021.

    Published: 26 Jan 2021
    —
    Unknown

    CVE-2021-23185

    Last Modified: 7 Nov 2023

    This candidate was in a CNA pool that was not assigned to any issues during 2021.

    Published: 26 Jan 2021
    —
    Unknown

    CVE-2021-23212

    Last Modified: 7 Nov 2023

    This candidate was in a CNA pool that was not assigned to any issues during 2021.

    Published: 26 Jan 2021
    —
    Unknown

    CVE-2021-23224

    Last Modified: 7 Nov 2023

    This candidate was in a CNA pool that was not assigned to any issues during 2021.

    Published: 26 Jan 2021
    —
    Unknown

    CVE-2021-26246

    Last Modified: 7 Nov 2023

    This candidate was in a CNA pool that was not assigned to any issues during 2021.

    Published: 26 Jan 2021
    —
    Unknown

    CVE-2021-23232

    Last Modified: 7 Nov 2023

    This candidate was in a CNA pool that was not assigned to any issues during 2021.

    Published: 26 Jan 2021
    7.2
    High

    CVE-2020-29001

    Last Modified: 21 Nov 2024

    An issue was discovered on Geeni GNC-CW028 Camera 2.7.2, Geeni GNC-CW025 Doorbell 2.9.5, Merkury MI-CW024 Doorbell 2.9.6, and Merkury MI-CW017 Camera 2.9.6 devices. A vulnerability exists in the RESTful Services API that allows a remote attacker to take full control of the camera with a high-privileged account. The vulnerability exists because a static username and password are compiled into the ppsapp RESTful application.

    Published: 26 Jan 2021
    7.2
    High

    CVE-2020-29000

    Last Modified: 21 Nov 2024

    An issue was discovered on Geeni GNC-CW013 doorbell 1.8.1 devices. A vulnerability exists in the RTSP service that allows a remote attacker to take full control of the device with a high-privileged account. By sending a crafted message, an attacker is able to remotely deliver a telnet session. Any attacker that has the ability to control DNS can exploit this vulnerability to remotely login to the device and gain access to the camera system.

    Published: 26 Jan 2021
    7.2
    High

    CVE-2020-28999

    Last Modified: 21 Nov 2024

    An issue was discovered in Apexis Streaming Video Web Application on Geeni GNC-CW013 doorbell 1.8.1 devices. A remote attacker can take full control of the camera with a high-privileged account. The vulnerability exists because a static username and password are compiled into a shared library (libhipcam.so) used to provide the streaming camera service.

    Published: 26 Jan 2021
    9.8
    Critical

    CVE-2020-28998

    Last Modified: 21 Nov 2024

    An issue was discovered on Geeni GNC-CW013 doorbell 1.8.1 devices. A vulnerability exists in the Telnet service that allows a remote attacker to take full control of the device with a high-privileged account. The vulnerability exists because a system account has a default and static password.

    Published: 26 Jan 2021
    7.8
    High

    CVE-2021-3156

    Last Modified: 10 Nov 2025

    Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

    Published: 26 Jan 2021
    5.3
    Medium

    CVE-2021-21615

    Last Modified: 21 Nov 2024

    Jenkins 2.275 and LTS 2.263.2 allows reading arbitrary files using the file browser for workspaces and archived artifacts due to a time-of-check to time-of-use (TOCTOU) race condition.

    Published: 26 Jan 2021
    8.8
    High

    CVE-2021-23954

    Last Modified: 21 Nov 2024

    Using the new logical assignment operators in a JavaScript switch statement could have caused a type confusion, leading to a memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.

    Published: 26 Jan 2021
    8.8
    High

    CVE-2021-23964

    Last Modified: 21 Nov 2024

    Mozilla developers reported memory safety bugs present in Firefox 84 and Firefox ESR 78.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.

    Published: 26 Jan 2021