CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2021-21464

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 12 Jan 2021
    8.8
    High

    CVE-2021-21451

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated SGI file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 12 Jan 2021
    8.8
    High

    CVE-2021-21455

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated DIB file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 12 Jan 2021
    8.8
    High

    CVE-2021-21452

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated GIF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 12 Jan 2021
    8.8
    High

    CVE-2021-21460

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated DIB file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 12 Jan 2021
    8.8
    High

    CVE-2021-21459

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 12 Jan 2021
    7.8
    High

    CVE-2020-35459

    Last Modified: 21 Nov 2024

    An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were able to execute commands via shell code injection to the crm history commandline, potentially allowing escalation of privileges.

    Published: 12 Jan 2021
    7.5
    High

    CVE-2020-14274

    Last Modified: 21 Nov 2024

    Information disclosure vulnerability in HCL Commerce 9.0.1.9 through 9.0.1.14 and 9.1 through 9.1.4 could allow a remote attacker to obtain user personal data via unknown vectors.

    Published: 12 Jan 2021
    9.8
    Critical

    CVE-2020-14275

    Last Modified: 21 Nov 2024

    Security vulnerability in HCL Commerce 9.0.0.5 through 9.0.0.13, 9.0.1.0 through 9.0.1.14 and 9.1 through 9.1.4 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.

    Published: 12 Jan 2021
    9.8
    Critical

    CVE-2020-35458

    Last Modified: 21 Nov 2024

    An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x. There is a Ruby shell code injection issue via the hawk_remember_me_id parameter in the login_from_cookie cookie. The user logout routine could be used by unauthenticated remote attackers to execute code as hauser.

    Published: 12 Jan 2021
    6.5
    Medium

    CVE-2021-21471

    Last Modified: 21 Nov 2024

    In CLA-Assistant, versions before 2.8.5, due to improper access control an authenticated user could access API endpoints which are not intended to be used by the user. This could impact the integrity of the application.

    Published: 12 Jan 2021
    6.1
    Medium

    CVE-2020-26713

    Last Modified: 21 Nov 2024

    REDCap 10.3.4 contains a XSS vulnerability in the ToDoList function with parameter sort. The information submitted by the user is immediately returned in the response and not escaped leading to the reflected XSS vulnerability. Attackers can exploit vulnerabilities to steal login session information or borrow user rights to perform unauthorized acts.

    Published: 12 Jan 2021
    9.8
    Critical

    CVE-2020-26712

    Last Modified: 21 Nov 2024

    REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses the addition of a string of information from the submitted user that is not validated well in the database query, resulting in an SQL injection vulnerability where an attacker can exploit and compromise all databases.

    Published: 12 Jan 2021
    9.8
    Critical

    CVE-2021-3129

    Last Modified: 10 Nov 2025

    Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2.

    Published: 12 Jan 2021
    6.1
    Medium

    CVE-2020-24701

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI).

    Published: 12 Jan 2021
    5.4
    Medium

    CVE-2020-24700

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconfig. substring.

    Published: 12 Jan 2021
    7.4
    High

    CVE-2021-20218

    Last Modified: 21 Nov 2024

    A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system availability. This has been fixed in kubernetes-client-4.13.2 kubernetes-client-5.0.2 kubernetes-client-4.11.2 kubernetes-client-4.7.2

    Published: 12 Jan 2021
    7.8
    High

    CVE-2020-26050

    Last Modified: 21 Nov 2024

    SaferVPN for Windows Ver 5.0.3.3 through 5.0.4.15 could allow local privilege escalation from low privileged users to SYSTEM via a crafted openssl configuration file. This issue is similar to CVE-2019-12572.

    Published: 12 Jan 2021
    7.5
    High

    CVE-2020-16146

    Last Modified: 21 Nov 2024

    Espressif ESP-IDF 2.x, 3.0.x through 3.0.9, 3.1.x through 3.1.7, 3.2.x through 3.2.3, 3.3.x through 3.3.2, and 4.0.x through 4.0.1 has a Buffer Overflow in BluFi provisioning in btc_blufi_recv_handler function in blufi_prf.c. An attacker can send a crafted BluFi protocol Write Attribute command to characteristic 0xFF01. With manipulated packet fields, there is a buffer overflow.

    Published: 12 Jan 2021
    5.9
    Medium

    CVE-2020-28391

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X-200RNA switch family (All versions < V3.2.7). Devices create a new unique key upon factory reset, except when used with C-PLUG. When used with C-PLUG the devices use the hardcoded private RSA-key shipped with the firmware-image. An attacker could leverage this situation to a man-in-the-middle situation and decrypt previously captured traffic.

    Published: 12 Jan 2021
    5.3
    Medium

    CVE-2020-28469

    Last Modified: 21 Nov 2024

    This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator.

    Published: 12 Jan 2021
    9.1
    Critical

    CVE-2020-8570

    Last Modified: 21 Nov 2024

    Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code.

    Published: 12 Jan 2021
    9.8
    Critical

    CVE-2020-27637

    Last Modified: 21 Nov 2024

    The R programming language’s default package manager CRAN is affected by a path traversal vulnerability that can lead to server compromise. This vulnerability affects packages installed via the R CMD install cli command or the install.packages() function from the interpreter. Update to version 4.0.3

    Published: 12 Jan 2021
    5.9
    Medium

    CVE-2020-28395

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.0). Devices do not create a new unique private key after factory reset. An attacker could leverage this situation to a man-in-the-middle situation and decrypt previously captured traffic.

    Published: 12 Jan 2021
    6.7
    Medium

    CVE-2021-0301

    Last Modified: 21 Nov 2024

    In ged, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android SoC; Android ID: A-172514667.

    Published: 11 Jan 2021
    7.5
    High

    CVE-2021-0313

    Last Modified: 21 Nov 2024

    In isWordBreakAfter of LayoutUtils.cpp, there is a possible way to slow or crash a TextView due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-9, Android-10, Android-11, Android-8.0, Android-8.1; Android ID: A-170968514.

    Published: 11 Jan 2021
    6.5
    Medium

    CVE-2021-0312

    Last Modified: 21 Nov 2024

    In WAVSource::read of WAVExtractor.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-8.1, Android-9, Android-10, Android-11, Android-8.0; Android ID: A-170583712.

    Published: 11 Jan 2021
    7
    High

    CVE-2021-0303

    Last Modified: 21 Nov 2024

    In dispatchGraphTerminationMessage() of packages/services/Car/computepipe/runner/graph/StreamSetObserver.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Android ID: A-170407229.

    Published: 11 Jan 2021
    6.5
    Medium

    CVE-2021-0311

    Last Modified: 21 Nov 2024

    In ElementaryStreamQueue::dequeueAccessUnitH264() of ESQueue.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-9, Android-10, Android-11, Android-8.0, Android-8.1; Android ID: A-170240631.

    Published: 11 Jan 2021
    7.8
    High

    CVE-2021-0310

    Last Modified: 21 Nov 2024

    In LazyServiceRegistrar of LazyServiceRegistrar.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Android ID: A-170212632.

    Published: 11 Jan 2021
    4.7
    Medium

    CVE-2021-0320

    Last Modified: 21 Nov 2024

    In is_device_locked and set_device_locked of keystore_keymaster_enforcement.h, there is a possible bypass of lockscreen requirements for keyguard bound keys due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-11; Android ID: A-169933423.

    Published: 11 Jan 2021
    7.3
    High

    CVE-2021-0315

    Last Modified: 21 Nov 2024

    In onCreate of GrantCredentialsPermissionActivity.java, there is a possible way to convince the user to grant an app access to an account due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-8.1, Android-9, Android-10, Android-11, Android-8.0; Android ID: A-169763814.

    Published: 11 Jan 2021
    9.8
    Critical

    CVE-2020-0471

    Last Modified: 21 Nov 2024

    In reassemble_and_dispatch of packet_fragmenter.cc, there is a possible way to inject packets into an encrypted Bluetooth connection due to improper input validation. This could lead to remote escalation of privilege between two Bluetooth devices by a proximal attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-8.0, Android-8.1, Android-9, Android-10, Android-11; Android ID: A-169327567.

    Published: 11 Jan 2021
    9.8
    Critical

    CVE-2021-0316

    Last Modified: 21 Nov 2024

    In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11, Android-8.0, Android-8.1, Android-9, Android-10; Android ID: A-168802990.

    Published: 11 Jan 2021
    7.8
    High

    CVE-2021-0317

    Last Modified: 21 Nov 2024

    In createOrUpdate of Permission.java and related code, there is possible permission escalation due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-10, Android-11, Android-8.0, Android-8.1, Android-9; Android ID: A-168319670.

    Published: 11 Jan 2021
    7.8
    High

    CVE-2021-0318

    Last Modified: 21 Nov 2024

    In appendEventsToCacheLocked of SensorEventConnection.cpp, there is a possible out of bounds write due to a use-after-free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-9, Android-8.1, Android-10, Android-11; Android ID: A-168211968.

    Published: 11 Jan 2021
    7.3
    High

    CVE-2021-0319

    Last Modified: 21 Nov 2024

    In checkCallerIsSystemOr of CompanionDeviceManagerService.java, there is a possible way to get a nearby Bluetooth device's MAC address without appropriate permissions due to a permissions bypass. This could lead to local escalation of privilege that grants access to nearby MAC addresses, with User execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-8.0, Android-8.1, Android-9, Android-10, Android-11; Android ID: A-167244818.

    Published: 11 Jan 2021
    5.5
    Medium

    CVE-2021-0321

    Last Modified: 21 Nov 2024

    In enforceDumpPermissionForPackage of ActivityManagerService.java, there is a possible way to determine if a package is installed due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Android ID: A-166667403.

    Published: 11 Jan 2021
    5.5
    Medium

    CVE-2021-0304

    Last Modified: 21 Nov 2024

    In several functions of GlobalScreenshot.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure of the user's contacts with User execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-8.0, Android-8.1, Android-9; Android ID: A-162738636.

    Published: 11 Jan 2021
    5
    Medium

    CVE-2021-0322

    Last Modified: 21 Nov 2024

    In onCreate of SlicePermissionActivity.java, there is a possible misleading string displayed due to improper input validation. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.Product: Android; Versions: Android-10, Android-11, Android-9; Android ID: A-159145361.

    Published: 11 Jan 2021
    5.5
    Medium

    CVE-2021-0309

    Last Modified: 21 Nov 2024

    In onCreate of grantCredentialsPermissionActivity, there is a confused deputy. This could lead to local information disclosure and account access with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-8.1, Android-9, Android-10, Android-11, Android-8.0; Android ID: A-158480899.

    Published: 11 Jan 2021
    6.8
    Medium

    CVE-2021-0308

    Last Modified: 21 Nov 2024

    In ReadLogicalParts of basicmbr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-8.1, Android-9, Android-10, Android-11, Android-8.0; Android ID: A-158063095.

    Published: 11 Jan 2021
    7.8
    High

    CVE-2021-0307

    Last Modified: 21 Nov 2024

    In updatePermissionSourcePackage of PermissionManagerService.java, there is a possible automatic runtime permission grant due to a confused deputy. This could lead to local escalation of privilege allowing a malicious app to silently gain access to a dangerous permission with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-11; Android ID: A-155648771.

    Published: 11 Jan 2021
    7.8
    High

    CVE-2021-0306

    Last Modified: 21 Nov 2024

    In addAllPermissions of PermissionManagerService.java, there is a possible permissions bypass when upgrading major Android versions which allows an app to gain the android.permission.ACTIVITY_RECOGNITION permission without user confirmation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11, Android-8.0, Android-8.1, Android-9, Android-10; Android ID: A-154505240.

    Published: 11 Jan 2021
    7.4
    High

    CVE-2021-21241

    Last Modified: 21 Nov 2024

    The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is a independently maintained version of Flask-Security based on the 3.0.0 version of Flask-Security. In Flask-Security-Too from version 3.3.0 and before version 3.4.5, the /login and /change endpoints can return the authenticated user's authentication token in response to a GET request. Since GET requests aren't protected with a CSRF token, this could lead to a malicious 3rd party site acquiring the authentication token. Version 3.4.5 and version 4.0.0 are patched. As a workaround, if you aren't using authentication tokens - you can set the SECURITY_TOKEN_MAX_AGE to "0" (seconds) which should make the token unusable.

    Published: 11 Jan 2021
    7.8
    High

    CVE-2020-27059

    Last Modified: 21 Nov 2024

    In onAuthenticated of AuthenticationClient.java, there is a possible tapjacking attack when requesting the user's fingerprint due to an overlaid window. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-8.0, Android-8.1, Android-9, Android-10, 11; Android ID: A-159249069.

    Published: 11 Jan 2021
    9.8
    Critical

    CVE-2020-24027

    Last Modified: 21 Nov 2024

    In Live Networks, Inc., liblivemedia version 20200625, there is a potential buffer overflow bug in the server handling of a RTSP "PLAY" command, when the command specifies seeking by absolute time.

    Published: 11 Jan 2021
    6.1
    Medium

    CVE-2020-23631

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) in admin/global/manage.php in WDJA CMS 1.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via the tongji parameter.

    Published: 11 Jan 2021
    7.5
    High

    CVE-2020-13559

    Last Modified: 21 Nov 2024

    A denial-of-service vulnerability exists in the traffic-logging functionality of FreyrSCADA IEC-60879-5-104 Server Simulator 21.04.028. A specially crafted packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.

    Published: 11 Jan 2021
    6.5
    Medium

    CVE-2020-4869

    Last Modified: 21 Nov 2024

    IBM MQ Appliance 9.2 CD and 9.2 LTS is vulnerable to a denial of service, caused by a buffer overflow. A remote attacker could send a specially crafted SNMP query to cause the appliance to reload. IBM X-Force ID: 190831.

    Published: 11 Jan 2021