CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2019-11302

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 25 Jan 2021
    —
    Unknown

    CVE-2019-11310

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 25 Jan 2021
    —
    Unknown

    CVE-2019-11301

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 25 Jan 2021
    —
    Unknown

    CVE-2019-11295

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 25 Jan 2021
    —
    Unknown

    CVE-2019-11296

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 25 Jan 2021
    —
    Unknown

    CVE-2019-11297

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 25 Jan 2021
    —
    Unknown

    CVE-2019-11298

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 25 Jan 2021
    —
    Unknown

    CVE-2019-11299

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 25 Jan 2021
    —
    Unknown

    CVE-2019-11300

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 25 Jan 2021
    7.8
    High

    CVE-2021-22698

    Last Modified: 21 Nov 2024

    A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior) that could allow a stack-based buffer overflow to occur which could result in remote code execution when a malicious SSD file is uploaded and improperly parsed.

    Published: 25 Jan 2021
    7.8
    High

    CVE-2021-22697

    Last Modified: 21 Nov 2024

    A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior) that could allow a use-after-free condition which could result in remote code execution when a malicious SSD file is uploaded and improperly parsed.

    Published: 25 Jan 2021
    9.8
    Critical

    CVE-2020-28221

    Last Modified: 21 Nov 2024

    A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when the Ethernet Download feature is enable on the HMI.

    Published: 25 Jan 2021
    7.5
    High

    CVE-2020-0236

    Last Modified: 21 Nov 2024

    In A2DP_GetCodecType of a2dp_codec_config, there is a possible out-of-bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android, Versions: Android-10, Android ID: A-79703353.

    Published: 25 Jan 2021
    —
    Unknown

    CVE-2020-17524

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 25 Jan 2021
    9.8
    Critical

    CVE-2021-3278

    Last Modified: 21 Nov 2024

    Local Service Search Engine Management System 1.0 has a vulnerability through authentication bypass using SQL injection . Using this vulnerability, an attacker can bypass the login page.

    Published: 25 Jan 2021
    4.8
    Medium

    CVE-2020-35854

    Last Modified: 21 Nov 2024

    Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body parameter.

    Published: 25 Jan 2021
    4.8
    Medium

    CVE-2020-35853

    Last Modified: 21 Nov 2024

    4images Image Gallery Management System 1.7.11 is affected by cross-site scripting (XSS) in the Image URL. This vulnerability can result in an attacker to inject the XSS payload into the IMAGE URL. Each time a user visits that URL, the XSS triggers and the attacker can be able to steal the cookie according to the crafted payload.

    Published: 25 Jan 2021
    9.1
    Critical

    CVE-2020-35270

    Last Modified: 21 Nov 2024

    Student Result Management System In PHP With Source Code is affected by SQL injection. An attacker can able to access of Admin Panel and manage every account of Result.

    Published: 25 Jan 2021
    7.5
    High

    CVE-2020-36221

    Last Modified: 21 Nov 2024

    An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck).

    Published: 25 Jan 2021
    7.5
    High

    CVE-2020-36222

    Last Modified: 21 Nov 2024

    A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service.

    Published: 25 Jan 2021
    7.5
    High

    CVE-2020-36224

    Last Modified: 21 Nov 2024

    A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting in denial of service.

    Published: 25 Jan 2021
    7.5
    High

    CVE-2020-36225

    Last Modified: 21 Nov 2024

    A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of service.

    Published: 25 Jan 2021
    7.5
    High

    CVE-2020-36226

    Last Modified: 21 Nov 2024

    A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service.

    Published: 25 Jan 2021
    7.5
    High

    CVE-2020-36228

    Last Modified: 21 Nov 2024

    An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service.

    Published: 25 Jan 2021
    7.5
    High

    CVE-2020-36229

    Last Modified: 21 Nov 2024

    A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resulting in denial of service.

    Published: 25 Jan 2021
    7.5
    High

    CVE-2020-36230

    Last Modified: 21 Nov 2024

    A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service.

    Published: 25 Jan 2021
    7.5
    High

    CVE-2020-36227

    Last Modified: 21 Nov 2024

    A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of service.

    Published: 25 Jan 2021
    7.5
    High

    CVE-2020-36223

    Last Modified: 21 Nov 2024

    A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial of service (double free and out-of-bounds read).

    Published: 25 Jan 2021
    8.8
    High

    CVE-2020-17532

    Last Modified: 13 Feb 2025

    When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The problem happens in versions between 2.0.0 ~ 2.1.3 and fixed in Apache ServiceComb-Java-Chassis 2.1.5

    Published: 25 Jan 2021
    9.1
    Critical

    CVE-2021-23901

    Last Modified: 13 Feb 2025

    An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application's processing of XML data. It often allows an attacker to view files on the application server filesystem, and to interact with any back-end or external systems that the application itself can access. This issue is fixed in Apache Nutch 1.18.

    Published: 25 Jan 2021
    7.8
    High

    CVE-2021-26025

    Last Modified: 21 Nov 2024

    PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDStd!zlibVersion+0x0000000000004e5e via a crafted BMP image.

    Published: 25 Jan 2021
    7.8
    High

    CVE-2021-26026

    Last Modified: 21 Nov 2024

    PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDStd!JPEGTransW+0x000000000000c7f4 via a crafted BMP image.

    Published: 25 Jan 2021
    7.5
    High

    CVE-2020-27782

    Last Modified: 21 Nov 2024

    A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters resulting in a denial of service. The highest threat from this vulnerability is to system availability. This affects Undertow 2.1.5.SP1, 2.0.33.SP2, and 2.2.3.SP1.

    Published: 25 Jan 2021
    8.8
    High

    CVE-2020-35576

    Last Modified: 21 Nov 2024

    A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticated users to execute arbitrary code as root via shell metacharacters, a different vulnerability than CVE-2018-12577.

    Published: 25 Jan 2021
    5.4
    Medium

    CVE-2021-3186

    Last Modified: 7 Jul 2025

    A Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47_multi allows remote attackers to inject arbitrary web script or HTML via the Wifi Name parameter.

    Published: 24 Jan 2021
    9.8
    Critical

    CVE-2021-3286

    Last Modified: 21 Nov 2024

    SQL injection exists in Spotweb 1.4.9 because the notAllowedCommands protection mechanism is inadequate, e.g., a variation of the payload may be used. NOTE: this issue exists because of an incomplete fix for CVE-2020-35545.

    Published: 24 Jan 2021
    5.5
    Medium

    CVE-2021-3428

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel. A denial of service problem is identified if an extent tree is corrupted in a crafted ext4 filesystem in fs/ext4/extents.c in ext4_es_cache_extent. Fabricating an integer overflow, A local attacker with a special user privilege may cause a system crash problem which can lead to an availability threat.

    Published: 24 Jan 2021
    5.3
    Medium

    CVE-2021-3285

    Last Modified: 21 Nov 2024

    jxbrowser in TI Code Composer Studio IDE 8.x through 10.x before 10.1.1 does not verify X.509 certificates for HTTPS.

    Published: 23 Jan 2021
    6.5
    Medium

    CVE-2021-20196

    Last Modified: 21 Nov 2024

    A NULL pointer dereference flaw was found in the floppy disk emulator of QEMU. This issue occurs while processing read/write ioport commands if the selected floppy drive is not initialized with a block device. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

    Published: 23 Jan 2021
    —
    Unknown

    CVE-2020-13219

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2020. Notes: none

    Published: 22 Jan 2021
    —
    Unknown

    CVE-2020-13220

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2020. Notes: none

    Published: 22 Jan 2021
    —
    Unknown

    CVE-2020-13221

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2020. Notes: none

    Published: 22 Jan 2021
    —
    Unknown

    CVE-2020-13222

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2020. Notes: none

    Published: 22 Jan 2021
    —
    Unknown

    CVE-2020-13215

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2020. Notes: none

    Published: 22 Jan 2021
    —
    Unknown

    CVE-2020-13209

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2020. Notes: none

    Published: 22 Jan 2021
    —
    Unknown

    CVE-2020-13210

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2020. Notes: none

    Published: 22 Jan 2021
    —
    Unknown

    CVE-2020-13211

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2020. Notes: none

    Published: 22 Jan 2021
    —
    Unknown

    CVE-2020-13212

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2020. Notes: none

    Published: 22 Jan 2021
    —
    Unknown

    CVE-2020-13213

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2020. Notes: none

    Published: 22 Jan 2021
    —
    Unknown

    CVE-2020-13214

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2020. Notes: none

    Published: 22 Jan 2021