CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2021-23947

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 13 Jan 2021
    —
    Unknown

    CVE-2021-23948

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 13 Jan 2021
    —
    Unknown

    CVE-2021-23951

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 13 Jan 2021
    —
    Unknown

    CVE-2021-23952

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 13 Jan 2021
    8.1
    High

    CVE-2021-3139

    Last Modified: 21 Nov 2024

    In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. NOTE: relative to CVE-2020-28374, this is a similar mistake in a different algorithm.

    Published: 13 Jan 2021
    7.5
    High

    CVE-2021-3567

    Last Modified: 21 Nov 2024

    A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attacker could use this flaw to bypass screen-locking applications that leverage Caribou as an input mechanism. The highest threat from this vulnerability is to system availability.

    Published: 13 Jan 2021
    —
    Unknown

    CVE-2021-23949

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 13 Jan 2021
    5.5
    Medium

    CVE-2021-20180

    Last Modified: 21 Nov 2024

    A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credentials. The highest threat from this vulnerability is to confidentiality.

    Published: 13 Jan 2021
    5.4
    Medium

    CVE-2021-21608

    Last Modified: 21 Nov 2024

    Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape button labels in the Jenkins UI, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with the ability to control button labels.

    Published: 13 Jan 2021
    6.4
    Medium

    CVE-2021-23927

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.4 allows SSRF via a URL with an @ character in an appsuite/api/oauth/proxy PUT request.

    Published: 12 Jan 2021
    6.1
    Medium

    CVE-2021-23928

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.3 allows XSS via the ajax/apps/manifests query string.

    Published: 12 Jan 2021
    6.1
    Medium

    CVE-2021-23929

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.4 allows XSS via a crafted Content-Disposition header in an uploaded HTML document to an ajax/share/<share-token>?delivery=view URI.

    Published: 12 Jan 2021
    6.1
    Medium

    CVE-2021-23930

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.4 allows XSS via use of the conversion API for a distributedFile.

    Published: 12 Jan 2021
    6.1
    Medium

    CVE-2021-23931

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.4 allows XSS via an inline binary file.

    Published: 12 Jan 2021
    6.1
    Medium

    CVE-2021-23932

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.4 allows XSS via an inline image with a crafted filename.

    Published: 12 Jan 2021
    6.1
    Medium

    CVE-2021-23933

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.4 allows XSS via JavaScript in a Note referenced by a mail:// URL.

    Published: 12 Jan 2021
    6.1
    Medium

    CVE-2021-23934

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.4 allows XSS via a contact whose name contains JavaScript code.

    Published: 12 Jan 2021
    6.1
    Medium

    CVE-2021-23935

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.4 allows XSS via an appointment in which the location contains JavaScript code.

    Published: 12 Jan 2021
    6.1
    Medium

    CVE-2021-23936

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.4 allows XSS via the subject of a task.

    Published: 12 Jan 2021
    —
    Unknown

    CVE-2020-16526

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 12 Jan 2021
    6.1
    Medium

    CVE-2021-23125

    Last Modified: 25 Feb 2026

    An issue was discovered in Joomla! 3.1.0 through 3.9.23. The lack of escaping of image-related parameters in multiple com_tags views cause lead to XSS attack vectors.

    Published: 12 Jan 2021
    6.1
    Medium

    CVE-2021-23124

    Last Modified: 25 Feb 2026

    An issue was discovered in Joomla! 3.9.0 through 3.9.23. The lack of escaping in mod_breadcrumbs aria-label attribute allows XSS attacks.

    Published: 12 Jan 2021
    5.3
    Medium

    CVE-2021-23123

    Last Modified: 25 Feb 2026

    An issue was discovered in Joomla! 3.0.0 through 3.9.23. The lack of ACL checks in the orderPosition endpoint of com_modules leak names of unpublished and/or inaccessible modules.

    Published: 12 Jan 2021
    7.8
    High

    CVE-2020-28386

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP12), Solid Edge SE2021 (All Versions < SE2021MP2). Affected applications lack proper validation of user-supplied data when parsing DFT files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process.

    Published: 12 Jan 2021
    5.5
    Medium

    CVE-2020-28390

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Opcenter Execution Core (V8.2), Opcenter Execution Core (V8.3). The application contains an information leakage vulnerability in the handling of web client sessions. A local attacker who has access to the Web Client Session Storage could disclose the passwords of currently logged-in users.

    Published: 12 Jan 2021
    8.8
    High

    CVE-2020-26995

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing of SGI and RGB files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-11992)

    Published: 12 Jan 2021
    7.8
    High

    CVE-2020-28384

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP12), Solid Edge SE2021 (All Versions < SE2021MP2). Affected applications lack proper validation of user-supplied data when parsing PAR files. This could lead to a stack based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process.

    Published: 12 Jan 2021
    7.8
    High

    CVE-2020-26992

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing CGM files. This could lead to a stack based buffer overflow while trying to copy to a buffer during font string handling. An attacker could leverage this vulnerability to execute code in the context of the current process.

    Published: 12 Jan 2021
    7.8
    High

    CVE-2020-28381

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP12), Solid Edge SE2021 (All Versions < SE2021MP2). Affected applications lack proper validation of user-supplied data when parsing PAR files. This could result in an out of bounds write into uninitialized memory. An attacker could leverage this vulnerability to execute code in the context of the current process.

    Published: 12 Jan 2021
    7.8
    High

    CVE-2020-26993

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing CGM files. This could lead to a stack based buffer overflow while trying to copy to a buffer in the font index handling function. An attacker could leverage this vulnerability to execute code in the context of the current process.

    Published: 12 Jan 2021
    8.8
    High

    CVE-2020-26994

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing of PCX files. This could result in a heap-based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process.

    Published: 12 Jan 2021
    8.8
    High

    CVE-2020-26996

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing of CG4 files. This could result in a memory access past the end of an allocated buffer. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-12027)

    Published: 12 Jan 2021
    7.8
    High

    CVE-2020-28382

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP12), Solid Edge SE2021 (All Versions < SE2021MP2). Affected applications lack proper validation of user-supplied data when parsing PAR files. This could result in a out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process.

    Published: 12 Jan 2021
    7.8
    High

    CVE-2020-28383

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Solid Edge SE2020 (All Versions < SE2020MP12), Solid Edge SE2021 (All Versions < SE2021MP2), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications lack proper validation of user-supplied data when parsing PAR files. This can result in an out of bounds write past the memory location that is a read only image address. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-11885)

    Published: 12 Jan 2021
    8.8
    High

    CVE-2020-26983

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing PDF files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-11900)

    Published: 12 Jan 2021
    8.8
    High

    CVE-2020-26985

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing of RGB and SGI files. This could result in a heap-based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-11986, ZDI-CAN-11994)

    Published: 12 Jan 2021
    8.8
    High

    CVE-2020-26990

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications lack proper validation of user-supplied data when parsing ASM files. A crafted ASM file could trigger a type confusion condition. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-11897)

    Published: 12 Jan 2021
    8.8
    High

    CVE-2020-26986

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing of JT files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-12014)

    Published: 12 Jan 2021
    8.8
    High

    CVE-2020-26987

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing of TGA files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-12016, ZDI-CAN-12017)

    Published: 12 Jan 2021
    8.8
    High

    CVE-2020-26988

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing of PAR files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-11891)

    Published: 12 Jan 2021
    7.8
    High

    CVE-2020-26989

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Solid Edge SE2020 (All Versions < SE2020MP12), Solid Edge SE2021 (All Versions < SE2021MP2), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications lack proper validation of user-supplied data when parsing of PAR files. This could result in a stack based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-11892)

    Published: 12 Jan 2021
    8.8
    High

    CVE-2020-26982

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing CG4 and CGM files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-11898)

    Published: 12 Jan 2021
    8.8
    High

    CVE-2020-26984

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing of JT files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-11972)

    Published: 12 Jan 2021
    8.8
    High

    CVE-2020-26991

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in JT2Go (All versions < V13.1.0.2), Teamcenter Visualization (All versions < V13.1.0.2). Affected applications lack proper validation of user-supplied data when parsing ASM files. This could lead to pointer dereferences of a value obtained from untrusted source. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-11899)

    Published: 12 Jan 2021
    9.8
    Critical

    CVE-2020-15800

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.0). The webserver of the affected devices contains a vulnerability that may lead to a heap overflow condition. An attacker could cause this condition on the webserver by sending specially crafted requests. This could stop the webserver temporarily.

    Published: 12 Jan 2021
    9.8
    Critical

    CVE-2020-25226

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0). The web server of the affected devices contains a vulnerability that may lead to a buffer overflow condition. An attacker could cause this condition on the webserver by sending a specially crafted request. The webserver could stop and not recover anymore.

    Published: 12 Jan 2021
    8.8
    High

    CVE-2020-26980

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing JT files. A crafted JT file could trigger a type confusion condition. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-11881)

    Published: 12 Jan 2021
    6.5
    Medium

    CVE-2020-26981

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). When opening a specially crafted xml file, the application could disclose arbitrary files to remote attackers. This is because of the passing of specially crafted content to the underlying XML parser without taking proper restrictions such as prohibiting an external dtd. (ZDI-CAN-11890)

    Published: 12 Jan 2021
    6.5
    Medium

    CVE-2020-15799

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0). The vulnerability could allow an unauthenticated attacker to reboot the device over the network by using special urls from integrated web server of the affected products.

    Published: 12 Jan 2021
    —
    Unknown

    CVE-2020-6746

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2020. Notes: none

    Published: 12 Jan 2021