CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2020-28487

    Last Modified: 21 Nov 2024

    This affects the package vis-timeline before 7.4.4. An attacker with the ability to control the items of a Timeline element can inject additional script code into the generated application.

    Published: 22 Jan 2021
    7.4
    High

    CVE-2021-21259

    Last Modified: 21 Nov 2024

    HedgeDoc is open source software which lets you create real-time collaborative markdown notes. In HedgeDoc before version 1.7.2, an attacker can inject arbitrary JavaScript into a HedgeDoc note, which is executed when the note is viewed in slide mode. Depending on the configuration of the instance, the attacker may not need authentication to create or edit notes. The problem is patched in HedgeDoc 1.7.2. As a workaround, disallow loading JavaScript from 3rd party sites using the `Content-Security-Policy` header. Note that this will break some embedded content.

    Published: 22 Jan 2021
    4.8
    Medium

    CVE-2021-3271

    Last Modified: 21 Nov 2024

    PressBooks 5.17.3 contains a cross-site scripting (XSS). Stored XSS can be submitted via the Book Info's Long Description Body, and all actions to open or preview the books page will result in the triggering the stored XSS.

    Published: 22 Jan 2021
    7.5
    High

    CVE-2020-4766

    Last Modified: 21 Nov 2024

    IBM MQ Internet Pass-Thru 2.1 and 9.2 could allow a remote user to cause a denial of service by sending malformed MQ data requests which would consume all available resources. IBM X-Force ID: 188093.

    Published: 22 Jan 2021
    9.8
    Critical

    CVE-2020-23262

    Last Modified: 21 Nov 2024

    An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do.

    Published: 22 Jan 2021
    —
    Unknown

    CVE-2020-28488

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 22 Jan 2021
    7.5
    High

    CVE-2020-23162

    Last Modified: 21 Nov 2024

    Sensitive information disclosure and weak encryption in Pyrescom Termod4 time management devices before 10.04k allows remote attackers to read a session-file and obtain plain-text user credentials.

    Published: 22 Jan 2021
    6.5
    Medium

    CVE-2020-23161

    Last Modified: 21 Nov 2024

    Local file inclusion in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to traverse directories and read sensitive files via the Maintenance > Logs menu and manipulating the file-path in the URL.

    Published: 22 Jan 2021
    8.8
    High

    CVE-2020-23160

    Last Modified: 21 Nov 2024

    Remote code execution in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to arbitrary commands as root on the devices.

    Published: 22 Jan 2021
    7.8
    High

    CVE-2021-20194

    Last Modified: 21 Nov 2024

    There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARDENED_USERCOPY not set, and BPF hook to getsockopt is registered). As result of BPF execution, the local user can trigger bug in __cgroup_bpf_run_filter_getsockopt() function that can lead to heap overflow (because of non-hardened usercopy). The impact of attack could be deny of service or possibly privileges escalation.

    Published: 22 Jan 2021
    6.1
    Medium

    CVE-2020-36202

    Last Modified: 21 Nov 2024

    An issue was discovered in the async-h1 crate before 2.3.0 for Rust. Request smuggling can occur when used behind a reverse proxy.

    Published: 22 Jan 2021
    4.7
    Medium

    CVE-2020-36203

    Last Modified: 21 Nov 2024

    An issue was discovered in the reffers crate through 2020-12-01 for Rust. ARefss can contain a !Send,!Sync object, leading to a data race and memory corruption.

    Published: 22 Jan 2021
    4.7
    Medium

    CVE-2020-36204

    Last Modified: 21 Nov 2024

    An issue was discovered in the im crate through 2020-11-09 for Rust. Because TreeFocus does not have bounds on its Send trait or Sync trait, a data race can occur.

    Published: 22 Jan 2021
    5.5
    Medium

    CVE-2020-36205

    Last Modified: 21 Nov 2024

    An issue was discovered in the xcb crate through 2020-12-10 for Rust. base::Error does not have soundness. Because of the public ptr field, a use-after-free or double-free can occur.

    Published: 22 Jan 2021
    7
    High

    CVE-2020-36206

    Last Modified: 21 Nov 2024

    An issue was discovered in the rusb crate before 0.7.0 for Rust. Because of a lack of Send and Sync bounds, a data race and memory corruption can occur.

    Published: 22 Jan 2021
    7
    High

    CVE-2020-36207

    Last Modified: 21 Nov 2024

    An issue was discovered in the aovec crate through 2020-12-10 for Rust. Because Aovec<T> does not have bounds on its Send trait or Sync trait, a data race and memory corruption can occur.

    Published: 22 Jan 2021
    7.8
    High

    CVE-2020-36208

    Last Modified: 21 Nov 2024

    An issue was discovered in the conquer-once crate before 0.3.2 for Rust. Thread crossing can occur for a non-Send but Sync type, leading to memory corruption.

    Published: 22 Jan 2021
    7
    High

    CVE-2020-36209

    Last Modified: 21 Nov 2024

    An issue was discovered in the late-static crate before 0.4.0 for Rust. Because Sync is implemented for LateStatic with T: Send, a data race can occur.

    Published: 22 Jan 2021
    7.8
    High

    CVE-2020-36210

    Last Modified: 21 Nov 2024

    An issue was discovered in the autorand crate before 0.2.3 for Rust. Because of impl Random on arrays, uninitialized memory can be dropped when a panic occurs, leading to memory corruption.

    Published: 22 Jan 2021
    7
    High

    CVE-2020-36211

    Last Modified: 21 Nov 2024

    An issue was discovered in the gfwx crate before 0.3.0 for Rust. Because ImageChunkMut does not have bounds on its Send trait or Sync trait, a data race and memory corruption can occur.

    Published: 22 Jan 2021
    7.5
    High

    CVE-2020-36212

    Last Modified: 21 Nov 2024

    An issue was discovered in the abi_stable crate before 0.9.1 for Rust. DrainFilter lacks soundness because of a double drop.

    Published: 22 Jan 2021
    7.5
    High

    CVE-2020-36213

    Last Modified: 21 Nov 2024

    An issue was discovered in the abi_stable crate before 0.9.1 for Rust. A retain call can create an invalid UTF-8 string, violating soundness.

    Published: 22 Jan 2021
    5.9
    Medium

    CVE-2020-36214

    Last Modified: 21 Nov 2024

    An issue was discovered in the multiqueue2 crate before 0.1.7 for Rust. Because a non-Send type can be sent to a different thread, a data race can occur.

    Published: 22 Jan 2021
    7.5
    High

    CVE-2020-36215

    Last Modified: 21 Nov 2024

    An issue was discovered in the hashconsing crate before 1.1.0 for Rust. Because HConsed does not have bounds on its Send trait or Sync trait, memory corruption can occur.

    Published: 22 Jan 2021
    5.9
    Medium

    CVE-2020-36216

    Last Modified: 21 Nov 2024

    An issue was discovered in Input<R> in the eventio crate before 0.5.1 for Rust. Because a non-Send type can be sent to a different thread, a data race and memory corruption can occur.

    Published: 22 Jan 2021
    5.9
    Medium

    CVE-2020-36217

    Last Modified: 21 Nov 2024

    An issue was discovered in the may_queue crate through 2020-11-10 for Rust. Because Queue does not have bounds on its Send trait or Sync trait, memory corruption can occur.

    Published: 22 Jan 2021
    5.9
    Medium

    CVE-2020-36218

    Last Modified: 21 Nov 2024

    An issue was discovered in the buttplug crate before 1.0.4 for Rust. ButtplugFutureStateShared does not properly consider (!Send|!Sync) objects, leading to a data race.

    Published: 22 Jan 2021
    5.9
    Medium

    CVE-2020-36219

    Last Modified: 21 Nov 2024

    An issue was discovered in the atomic-option crate through 2020-10-31 for Rust. Because AtomicOption<T> implements Sync unconditionally, a data race can occur.

    Published: 22 Jan 2021
    5.9
    Medium

    CVE-2020-36220

    Last Modified: 21 Nov 2024

    An issue was discovered in the va-ts crate before 0.0.4 for Rust. Because Demuxer<T> omits a required T: Send bound, a data race and memory corruption can occur.

    Published: 22 Jan 2021
    9.8
    Critical

    CVE-2021-25900

    Last Modified: 21 Nov 2024

    An issue was discovered in the smallvec crate before 0.6.14 and 1.x before 1.6.1 for Rust. There is a heap-based buffer overflow in SmallVec::insert_many.

    Published: 22 Jan 2021
    5.3
    Medium

    CVE-2021-25901

    Last Modified: 21 Nov 2024

    An issue was discovered in the lazy-init crate through 2021-01-17 for Rust. Lazy lacks a Send bound, leading to a data race.

    Published: 22 Jan 2021
    7.5
    High

    CVE-2021-25902

    Last Modified: 21 Nov 2024

    An issue was discovered in the glsl-layout crate before 0.4.0 for Rust. When a panic occurs, map_array can perform a double drop.

    Published: 22 Jan 2021
    7.5
    High

    CVE-2021-25903

    Last Modified: 21 Nov 2024

    An issue was discovered in the cache crate through 2021-01-01 for Rust. A raw pointer is dereferenced.

    Published: 22 Jan 2021
    7.5
    High

    CVE-2021-25904

    Last Modified: 21 Nov 2024

    An issue was discovered in the av-data crate before 0.3.0 for Rust. A raw pointer is dereferenced, leading to a read of an arbitrary memory address, sometimes causing a segfault.

    Published: 22 Jan 2021
    9.1
    Critical

    CVE-2021-25905

    Last Modified: 21 Nov 2024

    An issue was discovered in the bra crate before 0.1.1 for Rust. It lacks soundness because it can read uninitialized memory.

    Published: 22 Jan 2021
    7.5
    High

    CVE-2021-25906

    Last Modified: 21 Nov 2024

    An issue was discovered in the basic_dsp_matrix crate before 0.9.2 for Rust. When a TransformContent panic occurs, a double drop can be performed.

    Published: 22 Jan 2021
    9.8
    Critical

    CVE-2021-25907

    Last Modified: 21 Nov 2024

    An issue was discovered in the containers crate before 0.9.11 for Rust. When a panic occurs, a util::{mutate,mutate2} double drop can be performed.

    Published: 22 Jan 2021
    7.5
    High

    CVE-2021-25908

    Last Modified: 21 Nov 2024

    An issue was discovered in the fil-ocl crate through 2021-01-04 for Rust. From<EventList> can lead to a double free.

    Published: 22 Jan 2021
    4.6
    Medium

    CVE-2021-22849

    Last Modified: 21 Nov 2024

    Hyweb HyCMS-J1 backend editing function does not filter special characters. Users after log-in can inject JavaScript syntax to perform a stored XSS (Stored Cross-site scripting) attack.

    Published: 22 Jan 2021
    8.8
    High

    CVE-2021-22847

    Last Modified: 21 Nov 2024

    Hyweb HyCMS-J1's API fail to filter POST request parameters. Remote attackers can inject SQL syntax and execute commands without privilege.

    Published: 22 Jan 2021
    9.8
    Critical

    CVE-2021-3193

    Last Modified: 21 Nov 2024

    Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7, allows an unauthenticated attacker to execute remote code as the apache user.

    Published: 22 Jan 2021
    6.1
    Medium

    CVE-2020-35753

    Last Modified: 21 Nov 2024

    The job posting recommendation form in Persis Human Resource Management Portal (Versions 17.2.00 through 17.2.35 and 19.0.00 through 19.0.20), when the "Recommend job posting" function is enabled, allows XSS via the SENDER parameter.

    Published: 22 Jan 2021
    9.8
    Critical

    CVE-2021-3199

    Last Modified: 21 Nov 2024

    Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.

    Published: 22 Jan 2021
    7.7
    High

    CVE-2021-21272

    Last Modified: 21 Nov 2024

    ORAS is open source software which enables a way to push OCI Artifacts to OCI Conformant registries. ORAS is both a CLI for initial testing and a Go Module. In ORAS from version 0.4.0 and before version 0.9.0, there is a "zip-slip" vulnerability. The directory support feature allows the downloaded gzipped tarballs to be automatically extracted to the user-specified directory where the tarball can have symbolic links and hard links. A well-crafted tarball or tarballs allow malicious artifact providers linking, writing, or overwriting specific files on the host filesystem outside of the user-specified directory unexpectedly with the same permissions as the user who runs `oras pull`. Users of the affected versions are impacted if they are `oras` CLI users who runs `oras pull`, or if they are Go programs, which invoke `github.com/deislabs/oras/pkg/content.FileStore`. The problem has been fixed in version 0.9.0. For `oras` CLI users, there is no workarounds other than pulling from a trusted artifact provider. For `oras` package users, the workaround is to not use `github.com/deislabs/oras/pkg/content.FileStore`, and use other content stores instead, or pull from a trusted artifact provider.

    Published: 22 Jan 2021
    5.3
    Medium

    CVE-2021-26539

    Last Modified: 21 Nov 2024

    Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypass hostname whitelist validation set by the "allowedIframeHostnames" option.

    Published: 22 Jan 2021
    6.5
    Medium

    CVE-2021-20252

    Last Modified: 21 Nov 2024

    A flaw was found in Red Hat 3scale API Management Platform 2. The 3scale backend does not perform preventive handling on user-requested date ranges in certain queries allowing a malicious authenticated user to submit a request with a sufficiently large date range to eventually yield an internal server error resulting in denial of service. The highest threat from this vulnerability is to system availability.

    Published: 22 Jan 2021
    6.5
    Medium

    CVE-2020-36200

    Last Modified: 21 Nov 2024

    TinyCheck before commits 9fd360d and ea53de8 allowed an authenticated attacker to send an HTTP GET request to the crafted URLs.

    Published: 21 Jan 2021
    9.8
    Critical

    CVE-2020-36199

    Last Modified: 21 Nov 2024

    TinyCheck before commits 9fd360d and ea53de8 was vulnerable to command injection due to insufficient checks of input parameters in several places.

    Published: 21 Jan 2021
    4.8
    Medium

    CVE-2020-21147

    Last Modified: 21 Nov 2024

    RockOA V1.9.8 is affected by a cross-site scripting (XSS) vulnerability which allows remote attackers to send malicious code to the administrator and execute JavaScript code, because webmain/flow/input/mode_emailmAction.php does not perform strict filtering.

    Published: 21 Jan 2021
    6.1
    Medium

    CVE-2020-21146

    Last Modified: 21 Nov 2024

    Feehi CMS 2.0.8 is affected by a cross-site scripting (XSS) vulnerability. When the user name is inserted as JavaScript code, browsing the post will trigger the XSS.

    Published: 21 Jan 2021