CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2020-4596

    Last Modified: 21 Nov 2024

    IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 184812.

    Published: 13 Jan 2021
    7.5
    High

    CVE-2020-4595

    Last Modified: 21 Nov 2024

    IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 184819.

    Published: 13 Jan 2021
    7.5
    High

    CVE-2020-4594

    Last Modified: 21 Nov 2024

    IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 184800.

    Published: 13 Jan 2021
    4.4
    Medium

    CVE-2021-3032

    Last Modified: 21 Nov 2024

    An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where configuration secrets for the “http”, “email”, and “snmptrap” v3 log forwarding server profiles can be logged to the logrcvr.log system log. Logged information may include up to 1024 bytes of the configuration including the username and password in an encrypted form and private keys used in any certificate profiles set for log forwarding server profiles. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.18; PAN-OS 9.0 versions earlier than PAN-OS 9.0.12; PAN-OS 9.1 versions earlier than PAN-OS 9.1.4; PAN-OS 10.0 versions earlier than PAN-OS 10.0.1.

    Published: 13 Jan 2021
    4.3
    Medium

    CVE-2021-3031

    Last Modified: 21 Nov 2024

    Padding bytes in Ethernet packets on PA-200, PA-220, PA-500, PA-800, PA-2000 Series, PA-3000 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls are not cleared before the data frame is created. This leaks a small amount of random information from the firewall memory into the Ethernet packets. An attacker on the same Ethernet subnet as the PAN-OS firewall is able to collect potentially sensitive information from these packets. This issue is also known as Etherleak and is detected by security scanners as CVE-2003-0001. This issue impacts: PAN-OS 8.1 version earlier than PAN-OS 8.1.18; PAN-OS 9.0 versions earlier than PAN-OS 9.0.12; PAN-OS 9.1 versions earlier than PAN-OS 9.1.5.

    Published: 13 Jan 2021
    9.8
    Critical

    CVE-2020-23653

    Last Modified: 21 Nov 2024

    An insecure unserialize vulnerability was discovered in ThinkAdmin versions 4.x through 6.x in app/admin/controller/api/Update.php and app/wechat/controller/api/Push.php, which may lead to arbitrary remote code execution.

    Published: 13 Jan 2021
    8.1
    High

    CVE-2019-4702

    Last Modified: 12 Aug 2025

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

    Published: 13 Jan 2021
    5.3
    Medium

    CVE-2019-4687

    Last Modified: 12 Aug 2025

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 171823.

    Published: 13 Jan 2021
    7.5
    High

    CVE-2019-4160

    Last Modified: 12 Aug 2025

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158577.

    Published: 13 Jan 2021
    6.8
    Medium

    CVE-2020-15221

    Last Modified: 21 Nov 2024

    Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, by modifying target browser local storage, an XSS can be generated in the iTop console breadcrumb. This is fixed in versions 2.7.2 and 3.0.0.

    Published: 13 Jan 2021
    6.1
    Medium

    CVE-2020-15220

    Last Modified: 21 Nov 2024

    Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, two cookies are created for the same session, which leads to a possibility to steal user session. This is fixed in versions 2.7.2 and 3.0.0.

    Published: 13 Jan 2021
    4.3
    Medium

    CVE-2020-15219

    Last Modified: 21 Nov 2024

    Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, when a download error is triggered in the user portal, an SQL query is displayed to the user. This is fixed in versions 2.7.2 and 3.0.0.

    Published: 13 Jan 2021
    4.3
    Medium

    CVE-2020-35687

    Last Modified: 21 Nov 2024

    PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim.

    Published: 13 Jan 2021
    6.8
    Medium

    CVE-2020-15218

    Last Modified: 21 Nov 2024

    Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, admin pages are cached, so that their content is visible after deconnection by using the browser back button. This is fixed in versions 2.7.2 and 3.0.0.

    Published: 13 Jan 2021
    9.8
    Critical

    CVE-2021-3028

    Last Modified: 21 Nov 2024

    git-big-picture before 1.0.0 mishandles ' characters in a branch name, leading to code execution.

    Published: 13 Jan 2021
    6.1
    Medium

    CVE-2021-21613

    Last Modified: 21 Nov 2024

    Jenkins TICS Plugin 2020.3.0.6 and earlier does not escape TICS service responses, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to control TICS service response content.

    Published: 13 Jan 2021
    5.5
    Medium

    CVE-2021-21614

    Last Modified: 21 Nov 2024

    Jenkins Bumblebee HP ALM Plugin 4.1.5 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

    Published: 13 Jan 2021
    5.5
    Medium

    CVE-2021-21612

    Last Modified: 21 Nov 2024

    Jenkins TraceTronic ECU-TEST Plugin 2.23.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

    Published: 13 Jan 2021
    7.5
    High

    CVE-2021-23900

    Last Modified: 21 Nov 2024

    OWASP json-sanitizer before 1.2.2 can output invalid JSON or throw an undeclared exception for crafted input. This may lead to denial of service if the application is not prepared to handle these situations.

    Published: 13 Jan 2021
    9.8
    Critical

    CVE-2021-23899

    Last Modified: 21 Nov 2024

    OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input. This allows an attacker to inject arbitrary HTML or XML into embedding documents.

    Published: 13 Jan 2021
    7.5
    High

    CVE-2021-3131

    Last Modified: 21 Nov 2024

    The Web server in 1C:Enterprise 8 before 8.3.17.1851 sends base64 encoded credentials in the creds URL parameter.

    Published: 13 Jan 2021
    7.8
    High

    CVE-2021-20616

    Last Modified: 21 Nov 2024

    Untrusted search path vulnerability in the installer of SKYSEA Client View Ver.1.020.05b to Ver.16.001.01g allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 13 Jan 2021
    7.5
    High

    CVE-2020-5686

    Last Modified: 21 Nov 2024

    Incorrect implementation of authentication algorithm issue in UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to access the remote system maintenance feature and obtain the information by sending a specially crafted request to a specific URL.

    Published: 13 Jan 2021
    9.8
    Critical

    CVE-2020-5633

    Last Modified: 21 Nov 2024

    Multiple NEC products (Express5800/T110j, Express5800/T110j-S, Express5800/T110j (2nd-Gen), Express5800/T110j-S (2nd-Gen), iStorage NS100Ti, and Express5800/GT110j) where Baseboard Management Controller (BMC) firmware Rev1.09 and earlier is applied allows remote attackers to bypass authentication and then obtain/modify BMC setting information, obtain monitoring information, or reboot/shut down the vulnerable product via unspecified vectors.

    Published: 13 Jan 2021
    9.8
    Critical

    CVE-2020-5685

    Last Modified: 21 Nov 2024

    UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to execute arbitrary OS commands or cause a denial-of-service (DoS) condition by sending a specially crafted request to a specific URL.

    Published: 13 Jan 2021
    7.8
    High

    CVE-2020-35686

    Last Modified: 21 Nov 2024

    The SECOMN service in Sound Research DCHU model software component modules (APO) through 2.0.9.17, delivered on HP Windows 10 computers, may allow escalation of privilege via a fake DLL. (As a resolution, Windows Update is being submitted for all affected products to update to 2.0.9.18 or later.)

    Published: 13 Jan 2021
    4.5
    Medium

    CVE-2020-36191

    Last Modified: 21 Nov 2024

    JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/user request (to add or remove a user account).

    Published: 13 Jan 2021
    7.5
    High

    CVE-2020-27827

    Last Modified: 3 Dec 2025

    A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.

    Published: 13 Jan 2021
    8.1
    High

    CVE-2020-28374

    Last Modified: 21 Nov 2024

    In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an XCOPY request, aka CID-2896c93811e3. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. The attacker gains control over file access because I/O operations are proxied via an attacker-selected backstore.

    Published: 13 Jan 2021
    5.3
    Medium

    CVE-2021-21252

    Last Modified: 21 Nov 2024

    The jQuery Validation Plugin provides drop-in validation for your existing forms. It is published as an npm package "jquery-validation". jquery-validation before version 1.19.3 contains one or more regular expressions that are vulnerable to ReDoS (Regular Expression Denial of Service). This is fixed in 1.19.3.

    Published: 13 Jan 2021
    6.5
    Medium

    CVE-2021-21602

    Last Modified: 21 Nov 2024

    Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows reading arbitrary files using the file browser for workspaces and archived artifacts by following symlinks.

    Published: 13 Jan 2021
    5.3
    Medium

    CVE-2021-21609

    Last Modified: 21 Nov 2024

    Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not correctly match requested URLs to the list of always accessible paths, allowing attackers without Overall/Read permission to access some URLs as if they did have Overall/Read permission.

    Published: 13 Jan 2021
    9.1
    Critical

    CVE-2021-23926

    Last Modified: 13 Feb 2025

    The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.

    Published: 13 Jan 2021
    —
    Unknown

    CVE-2021-23940

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 13 Jan 2021
    —
    Unknown

    CVE-2021-23950

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 13 Jan 2021
    5.4
    Medium

    CVE-2021-21603

    Last Modified: 21 Nov 2024

    Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape notification bar response contents, resulting in a cross-site scripting (XSS) vulnerability.

    Published: 13 Jan 2021
    8
    High

    CVE-2021-21604

    Last Modified: 21 Nov 2024

    Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows attackers with permission to create or configure various objects to inject crafted content into Old Data Monitor that results in the instantiation of potentially unsafe objects once discarded by an administrator.

    Published: 13 Jan 2021
    8
    High

    CVE-2021-21605

    Last Modified: 21 Nov 2024

    Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows users with Agent/Configure permission to choose agent names that cause Jenkins to override the global `config.xml` file.

    Published: 13 Jan 2021
    4.3
    Medium

    CVE-2021-21606

    Last Modified: 21 Nov 2024

    Jenkins 2.274 and earlier, LTS 2.263.1 and earlier improperly validates the format of a provided fingerprint ID when checking for its existence allowing an attacker to check for the existence of XML files with a short path.

    Published: 13 Jan 2021
    6.5
    Medium

    CVE-2021-21607

    Last Modified: 21 Nov 2024

    Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not limit sizes provided as query parameters to graph-rendering URLs, allowing attackers to request crafted URLs that use all available memory in Jenkins, potentially leading to out of memory errors.

    Published: 13 Jan 2021
    6.1
    Medium

    CVE-2021-21610

    Last Modified: 21 Nov 2024

    Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not implement any restrictions for the URL rendering a formatted preview of markup passed as a query parameter, resulting in a reflected cross-site scripting (XSS) vulnerability if the configured markup formatter does not prohibit unsafe elements (JavaScript) in markup.

    Published: 13 Jan 2021
    5.4
    Medium

    CVE-2021-21611

    Last Modified: 21 Nov 2024

    Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape display names and IDs of item types shown on the New Item page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to specify display names or IDs of item types.

    Published: 13 Jan 2021
    —
    Unknown

    CVE-2021-23938

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 13 Jan 2021
    —
    Unknown

    CVE-2021-23939

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 13 Jan 2021
    —
    Unknown

    CVE-2021-23941

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 13 Jan 2021
    —
    Unknown

    CVE-2021-23942

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 13 Jan 2021
    —
    Unknown

    CVE-2021-23943

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 13 Jan 2021
    —
    Unknown

    CVE-2021-23944

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 13 Jan 2021
    —
    Unknown

    CVE-2021-23945

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 13 Jan 2021
    —
    Unknown

    CVE-2021-23946

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 13 Jan 2021