CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2021-25006

    Last Modified: 21 Nov 2024

    The MOLIE WordPress plugin through 0.5 does not escape the course_id parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting issue

    Published: 14 Mar 2022
    9.8
    Critical

    CVE-2021-25003

    Last Modified: 21 Nov 2024

    The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE

    Published: 14 Mar 2022
    6.1
    Medium

    CVE-2021-24996

    Last Modified: 21 Nov 2024

    The IDPay for Contact Form 7 WordPress plugin through 2.1.2 does not sanitise and escape the idpay_error parameter before outputting it back in the page leading to a Reflected Cross-Site Scripting

    Published: 14 Mar 2022
    4.8
    Medium

    CVE-2021-24995

    Last Modified: 21 Nov 2024

    The HTML5 Responsive FAQ WordPress plugin through 2.8.5 does not properly sanitise and escape some of its settings, which could allow a high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

    Published: 14 Mar 2022
    6.4
    Medium

    CVE-2021-24982

    Last Modified: 21 Nov 2024

    The Child Theme Generator WordPress plugin through 2.2.7 does not sanitise escape the parade parameter before outputting it back, leading to a Reflected Cross-Site Scripting in the admin dashboard

    Published: 14 Mar 2022
    4.9
    Medium

    CVE-2021-24966

    Last Modified: 21 Nov 2024

    The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitrary files on the web server, including those outside of the blog folder

    Published: 14 Mar 2022
    8.8
    High

    CVE-2021-24959

    Last Modified: 21 Nov 2024

    The WP Email Users WordPress plugin through 1.7.6 does not escape the data_raw parameter in the weu_selected_users_1 AJAX action, available to any authenticated users, allowing them to perform SQL injection attacks.

    Published: 14 Mar 2022
    5.4
    Medium

    CVE-2021-24958

    Last Modified: 21 Nov 2024

    The Meks Easy Photo Feed Widget WordPress plugin before 1.2.4 does not have capability and CSRF checks in the meks_save_business_selected_account AJAX action, available to any authenticated user, and does not escape some of the settings. As a result, any authenticated user, such as subscriber could update the plugin's settings and put Cross-Site Scripting payloads in them

    Published: 14 Mar 2022
    5.4
    Medium

    CVE-2021-24950

    Last Modified: 21 Nov 2024

    The Insight Core WordPress plugin through 1.0 does not have any authorisation and CSRF checks in the insight_customizer_options_import (available to any authenticated user), does not validate user input before passing it to unserialize(), nor sanitise and escape it before outputting it in the response. As a result, it could allow users with a role as low as Subscriber to perform PHP Object Injection, as well as Stored Cross-Site Scripting attacks

    Published: 14 Mar 2022
    6.1
    Medium

    CVE-2021-24940

    Last Modified: 21 Nov 2024

    The Persian Woocommerce WordPress plugin through 5.8.0 does not escape the s parameter before outputting it back in an attribute in the admin dashboard, which could lead to a Reflected Cross-Site Scripting issue

    Published: 14 Mar 2022
    5.4
    Medium

    CVE-2021-24897

    Last Modified: 21 Nov 2024

    The Add Subtitle WordPress plugin through 1.1.0 does not sanitise or escape the sub-title field (available only with classic editor) when output in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

    Published: 14 Mar 2022
    4.8
    Medium

    CVE-2021-24895

    Last Modified: 21 Nov 2024

    The Cybersoldier WordPress plugin before 1.7.0 does not sanitise and escape the URL settings before outputting it in an attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 14 Mar 2022
    6.5
    Medium

    CVE-2021-24692

    Last Modified: 21 Nov 2024

    The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector.

    Published: 14 Mar 2022
    5.5
    Medium

    CVE-2022-24576

    Last Modified: 21 Nov 2024

    GPAC 1.0.1 is affected by Use After Free through MP4Box.

    Published: 14 Mar 2022
    7.8
    High

    CVE-2022-24575

    Last Modified: 21 Nov 2024

    GPAC 1.0.1 is affected by a stack-based buffer overflow through MP4Box.

    Published: 14 Mar 2022
    5.4
    Medium

    CVE-2022-0946

    Last Modified: 21 Nov 2024

    Stored XSS viva cshtm file upload in GitHub repository star7th/showdoc prior to v2.10.4.

    Published: 14 Mar 2022
    5.4
    Medium

    CVE-2022-0941

    Last Modified: 21 Nov 2024

    Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to v2.10.4.

    Published: 14 Mar 2022
    9.1
    Critical

    CVE-2022-24387

    Last Modified: 11 Mar 2025

    With administrator or admin privileges the application can be tricked into overwriting files in app_data/Config folder, e.g. the systemsettings.xml file. THis is possible in SmarterTrack v100.0.8019.14010

    Published: 14 Mar 2022
    5.4
    Medium

    CVE-2022-0940

    Last Modified: 21 Nov 2024

    Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to v2.10.4.

    Published: 14 Mar 2022
    5.4
    Medium

    CVE-2022-0938

    Last Modified: 21 Nov 2024

    Stored XSS via file upload in GitHub repository star7th/showdoc prior to v2.10.4.

    Published: 14 Mar 2022
    5.4
    Medium

    CVE-2022-0341

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.12.

    Published: 14 Mar 2022
    5.4
    Medium

    CVE-2022-0937

    Last Modified: 21 Nov 2024

    Stored xss in showdoc through file upload in GitHub repository star7th/showdoc prior to 2.10.4.

    Published: 14 Mar 2022
    4.3
    Medium

    CVE-2021-43954

    Last Modified: 21 Nov 2024

    The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enumerate the existence of internal network and filesystem resources via a Server-Side Request Forgery (SSRF) vulnerability.

    Published: 14 Mar 2022
    8.8
    High

    CVE-2021-43304

    Last Modified: 25 Jun 2025

    Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the LZ4::decompressImpl loop and especially the arbitrary copy operation wildCopy<copy_amount>(op, ip, copy_end), don’t exceed the destination buffer’s limits.

    Published: 14 Mar 2022
    8.8
    High

    CVE-2022-24386

    Last Modified: 11 Mar 2025

    Stored XSS in SmarterTools SmarterTrack This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.

    Published: 14 Mar 2022
    5.5
    Medium

    CVE-2022-24574

    Last Modified: 21 Nov 2024

    GPAC 1.0.1 is affected by a NULL pointer dereference in gf_dump_vrml_field.isra ().

    Published: 14 Mar 2022
    7.8
    High

    CVE-2022-24577

    Last Modified: 21 Nov 2024

    GPAC 1.0.1 is affected by a NULL pointer dereference in gf_utf8_wcslen. (gf_utf8_wcslen is a renamed Unicode utf8_wcslen function.)

    Published: 14 Mar 2022
    7.8
    High

    CVE-2022-24578

    Last Modified: 21 Nov 2024

    GPAC 1.0.1 is affected by a heap-based buffer overflow in SFS_AddString () at bifs/script_dec.c.

    Published: 14 Mar 2022
    8.8
    High

    CVE-2021-43305

    Last Modified: 25 Jun 2025

    Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the LZ4::decompressImpl loop and especially the arbitrary copy operation wildCopy<copy_amount>(op, ip, copy_end), don’t exceed the destination buffer’s limits. This issue is very similar to CVE-2021-43304, but the vulnerable copy operation is in a different wildCopy call.

    Published: 14 Mar 2022
    7.8
    High

    CVE-2022-0943

    Last Modified: 21 Nov 2024

    Heap-based Buffer Overflow occurs in vim in GitHub repository vim/vim prior to 8.2.4563.

    Published: 14 Mar 2022
    7.8
    High

    CVE-2022-20001

    Last Modified: 23 Apr 2025

    fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary code execution. git repositories can contain per-repository configuration that change the behavior of git, including running arbitrary commands. When using the default configuration of fish, changing to a directory automatically runs `git` commands in order to display information about the current repository in the prompt. If an attacker can convince a user to change their current directory into one controlled by the attacker, such as on a shared file system or extracted archive, fish will run arbitrary commands under the attacker's control. This problem has been fixed in fish 3.4.0. Note that running git in these directories, including using the git tab completion, remains a potential trigger for this issue. As a workaround, remove the `fish_git_prompt` function from the prompt.

    Published: 14 Mar 2022
    8.1
    High

    CVE-2021-42387

    Last Modified: 25 Jun 2025

    Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data. The offset is later used in the length of a copy operation, without checking the upper bounds of the source of the copy operation.

    Published: 14 Mar 2022
    8.1
    High

    CVE-2021-42388

    Last Modified: 25 Jun 2025

    Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data. The offset is later used in the length of a copy operation, without checking the lower bounds of the source of the copy operation.

    Published: 14 Mar 2022
    9.8
    Critical

    CVE-2022-23943

    Last Modified: 1 May 2025

    Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.

    Published: 14 Mar 2022
    6.5
    Medium

    CVE-2022-24385

    Last Modified: 11 Mar 2025

    A Direct Object Access vulnerability in SmarterTools SmarterTrack leads to information disclosure This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.

    Published: 14 Mar 2022
    7.5
    High

    CVE-2022-22719

    Last Modified: 21 Nov 2024

    A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier.

    Published: 14 Mar 2022
    9.8
    Critical

    CVE-2022-22720

    Last Modified: 21 Nov 2024

    Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

    Published: 14 Mar 2022
    9.1
    Critical

    CVE-2022-22721

    Last Modified: 21 Nov 2024

    If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.

    Published: 14 Mar 2022
    8.8
    High

    CVE-2022-24384

    Last Modified: 11 Mar 2025

    Cross-site Scripting (XSS) vulnerability in SmarterTools SmarterTrack This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.

    Published: 14 Mar 2022
    6.1
    Medium

    CVE-2021-46709

    Last Modified: 21 Nov 2024

    phpLiteAdmin through 1.9.8.2 allows XSS via the index.php newRows parameter (aka num or number).

    Published: 13 Mar 2022
    7.8
    High

    CVE-2022-24696

    Last Modified: 21 Nov 2024

    Mirametrix Glance before 5.1.1.42207 (released on 2018-08-30) allows a local attacker to elevate privileges. NOTE: this is unrelated to products from the glance.com and glance.net websites.

    Published: 13 Mar 2022
    9.8
    Critical

    CVE-2021-45887

    Last Modified: 21 Nov 2024

    An issue was discovered in PONTON X/P Messenger before 3.11.2. Due to path traversal in private/SchemaSetUpload.do for uploaded ZIP files, an executable script can be uploaded by web application administrators, giving the attacker remote code execution on the underlying server via an imgs/*.jsp URI.

    Published: 13 Mar 2022
    8.8
    High

    CVE-2021-45886

    Last Modified: 21 Nov 2024

    An issue was discovered in PONTON X/P Messenger before 3.11.2. Anti-CSRF tokens are globally valid, making the web application vulnerable to a weakened version of CSRF, where an arbitrary token of a low-privileged user (such as operator) can be used to confirm actions of higher-privileged ones (such as xpadmin).

    Published: 13 Mar 2022
    5.4
    Medium

    CVE-2021-45889

    Last Modified: 21 Nov 2024

    An issue was discovered in PONTON X/P Messenger before 3.11.2. Several functions are vulnerable to reflected XSS, as demonstrated by private/index.jsp?partners/ShowNonLocalPartners.do?localID= or private/index.jsp or private/index.jsp?database/databaseTab.jsp or private/index.jsp?activation/activationMainTab.jsp or private/index.jsp?communication/serverTab.jsp or private/index.jsp?emailNotification/notificationTab.jsp.

    Published: 13 Mar 2022
    4.8
    Medium

    CVE-2021-45888

    Last Modified: 21 Nov 2024

    An issue was discovered in PONTON X/P Messenger before 3.11.2. The navigation tree that is shown on the left side of every page of the web application is vulnerable to XSS: it allows injection of JavaScript into its nodes. Creating such nodes is only possible for users who have the role Configuration Administrator or Administrator.

    Published: 13 Mar 2022
    7.8
    High

    CVE-2022-26981

    Last Modified: 21 Nov 2024

    Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (called, indirectly, by tools/lou_checktable.c).

    Published: 13 Mar 2022
    8
    High

    CVE-2022-24128

    Last Modified: 21 Nov 2024

    Timescale TimescaleDB 1.x and 2.x before 2.5.2 may allow privilege escalation during extension installation. The installation process uses commands such as CREATE x IF NOT EXIST that allow an unprivileged user to precreate objects. These objects will be used by the installer (which executes as Superuser), leading to privilege escalation. In order to be able to take advantage of this, an unprivileged user would need to be able to create objects in a database and then get a Superuser to install TimescaleDB into their database. (In the fixed versions, the installation aborts when it finds that an object already exists.)

    Published: 13 Mar 2022
    5.5
    Medium

    CVE-2022-27950

    Last Modified: 21 Nov 2024

    In drivers/hid/hid-elo.c in the Linux kernel before 5.16.11, a memory leak exists for a certain hid_parse error condition.

    Published: 13 Mar 2022
    3.7
    Low

    CVE-2021-36368

    Last Modified: 29 May 2026

    An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but without -oLogLevel=verbose, and an attacker has silently modified the server to support the None authentication option, then the user cannot determine whether FIDO authentication is going to confirm that the user wishes to connect to that server, or that the user wishes to allow that server to connect to a different server on the user's behalf. NOTE: the vendor's position is "this is not an authentication bypass, since nothing is being bypassed.

    Published: 12 Mar 2022
    5.5
    Medium

    CVE-2022-26966

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.16.12. drivers/net/usb/sr9700.c allows attackers to obtain sensitive information from heap memory via crafted frame lengths from a device.

    Published: 12 Mar 2022