CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2022-0347

    Last Modified: 21 Nov 2024

    The LoginPress | Custom Login Page Customizer WordPress plugin before 1.5.12 does not escape the redirect-page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

    Published: 7 Mar 2022
    7.2
    High

    CVE-2022-0267

    Last Modified: 21 Nov 2024

    The AdRotate WordPress plugin before 5.8.22 does not sanitise and escape the adrotate_action before using it in a SQL statement via the adrotate_request_action function available to admins, leading to a SQL injection

    Published: 7 Mar 2022
    5.4
    Medium

    CVE-2022-0205

    Last Modified: 21 Nov 2024

    The YOP Poll WordPress plugin before 6.3.5 does not sanitise and escape some of the settings (available to users with a role as low as author) before outputting them, leading to a Stored Cross-Site Scripting issue

    Published: 7 Mar 2022
    6.5
    Medium

    CVE-2022-0163

    Last Modified: 21 Nov 2024

    The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX action, allowing any authenticated users, such as subscriber, to download arbitrary form's data, which could include sensitive information such as PII depending on the form.

    Published: 7 Mar 2022
    6.5
    Medium

    CVE-2021-25098

    Last Modified: 21 Nov 2024

    The Pricing Tables WordPress Plugin WordPress plugin before 3.1.3 does not verify the CSRF nonce when removing posts, allowing attackers to make a logged in admin remove arbitrary posts from the blog via a CSRF attack, which will be put in the trash

    Published: 7 Mar 2022
    7.5
    High

    CVE-2021-25087

    Last Modified: 21 Mar 2025

    The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).

    Published: 7 Mar 2022
    6.1
    Medium

    CVE-2021-25039

    Last Modified: 21 Nov 2024

    The WordPress Multisite Content Copier/Updater WordPress plugin before 2.1.0 does not sanitise and escape the wmcc_content_type, wmcc_source_blog and wmcc_record_per_page parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

    Published: 7 Mar 2022
    6.1
    Medium

    CVE-2021-25038

    Last Modified: 21 Nov 2024

    The WordPress Multisite User Sync/Unsync WordPress plugin before 2.1.2 does not sanitise and escape the wmus_source_blog and wmus_record_per_page parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

    Published: 7 Mar 2022
    5.3
    Medium

    CVE-2021-25009

    Last Modified: 21 Nov 2024

    The CorreosExpress WordPress plugin through 2.6.0 generates log files which are publicly accessible, and contain sensitive information such as sender/receiver names, phone numbers, physical and email addresses

    Published: 7 Mar 2022
    5.4
    Medium

    CVE-2021-24961

    Last Modified: 21 Nov 2024

    The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 does not escape some of its shortcode argument, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks

    Published: 7 Mar 2022
    5.4
    Medium

    CVE-2021-24960

    Last Modified: 21 Nov 2024

    The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 allows users with a role as low as Contributor to configure the upload form in a way that allows uploading of SVG files, which could be then be used for Cross-Site Scripting attacks

    Published: 7 Mar 2022
    6.1
    Medium

    CVE-2021-24953

    Last Modified: 21 Nov 2024

    The Advanced iFrame WordPress plugin before 2022 does not sanitise and escape the ai_config_id parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

    Published: 7 Mar 2022
    8.8
    High

    CVE-2021-24952

    Last Modified: 12 Mar 2025

    The Conversios.io WordPress plugin before 4.6.2 does not sanitise, validate and escape the sync_progressive_data parameter for the tvcajax_product_sync_bantch_wise AJAX action before using it in a SQL statement, allowing any authenticated user to perform SQL injection attacks.

    Published: 7 Mar 2022
    5.4
    Medium

    CVE-2021-24826

    Last Modified: 21 Nov 2024

    The Custom Content Shortcode WordPress plugin before 4.0.2 does not escape custom fields before outputting them, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed. Please note that such attack is still possible by admin+ in single site blogs by default (but won't be when the unfiltered_html is disallowed)

    Published: 7 Mar 2022
    4.3
    Medium

    CVE-2021-24825

    Last Modified: 21 Nov 2024

    The Custom Content Shortcode WordPress plugin before 4.0.2 does not validate the data passed to its load shortcode, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to display arbitrary files from the filesystem (such as logs, .htaccess etc), as well as perform Local File Inclusion attacks as PHP files will be executed. Please note that such attack is still possible by admin+ in single site blogs by default (but won't be when either the unfiltered_html or file_edit is disallowed)

    Published: 7 Mar 2022
    4.3
    Medium

    CVE-2021-24824

    Last Modified: 21 Nov 2024

    The [field] shortcode included with the Custom Content Shortcode WordPress plugin before 4.0.1, allows authenticated users with a role as low as contributor, to access arbitrary post metadata. This could lead to sensitive data disclosure, for example when used in combination with WooCommerce, the email address of orders can be retrieved

    Published: 7 Mar 2022
    5.4
    Medium

    CVE-2021-24821

    Last Modified: 21 Nov 2024

    The Cost Calculator WordPress plugin before 1.6 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the Description fields of a Cost Calculator > Price Settings (which gets injected on the edit page as well as any page that embeds the calculator using the shortcode), as well as the Text Preview field of a Project (injected on the edit project page)

    Published: 7 Mar 2022
    4.8
    Medium

    CVE-2021-24810

    Last Modified: 21 Nov 2024

    The WP Event Manager WordPress plugin before 3.1.23 does not escape some of its Field Editor settings when outputting them, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 7 Mar 2022
    7.2
    High

    CVE-2021-24778

    Last Modified: 21 Nov 2024

    The test parameter of the xmlfeed in the Tradetracker-Store WordPress plugin before 4.6.60 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

    Published: 7 Mar 2022
    7.2
    High

    CVE-2021-24777

    Last Modified: 21 Nov 2024

    The view submission functionality in the Hotscot Contact Form WordPress plugin before 1.3 makes a get request with the sub_id parameter which not sanitised, escaped or validated before inserting to a SQL statement, leading to an SQL injection.

    Published: 7 Mar 2022
    7.2
    High

    CVE-2021-24216

    Last Modified: 21 Nov 2024

    The All-in-One WP Migration WordPress plugin before 7.41 does not validate uploaded files' extension, which allows administrators to upload PHP files on their site, even on multisite installations.

    Published: 7 Mar 2022
    9.8
    Critical

    CVE-2022-0766

    Last Modified: 21 Nov 2024

    Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.

    Published: 7 Mar 2022
    9.9
    Critical

    CVE-2022-0767

    Last Modified: 21 Nov 2024

    Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.

    Published: 7 Mar 2022
    5.5
    Medium

    CVE-2022-25108

    Last Modified: 21 Nov 2024

    Foxit PDF Reader and Editor before 11.2.1 and PhantomPDF before 10.1.7 allow a NULL pointer dereference during PDF parsing because the pointer is used without proper validation.

    Published: 7 Mar 2022
    7.5
    High

    CVE-2021-44032

    Last Modified: 21 Nov 2024

    TP-Link Omada SDN Software Controller before 5.0.15 does not check if the authentication method specified in a connection request is allowed. An attacker can bypass the captive portal authentication process by using the downgraded "no authentication" method, and access the protected network. For example, the attacker can simply set window.authType=0 in client-side JavaScript.

    Published: 7 Mar 2022
    7.8
    High

    CVE-2021-40376

    Last Modified: 21 Nov 2024

    otris Update Manager 1.2.1.0 allows local users to achieve SYSTEM access via unauthenticated calls to exposed interfaces over a .NET named pipe. A remote attack may be possible as well, by leveraging WsHTTPBinding for HTTP traffic on TCP port 9000.

    Published: 7 Mar 2022
    4.4
    Medium

    CVE-2021-39715

    Last Modified: 21 Nov 2024

    In __show_regs of process.c, there is a possible leak of kernel memory and addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-178379135References: Upstream kernel

    Published: 7 Mar 2022
    7.8
    High

    CVE-2022-0847

    Last Modified: 6 Nov 2025

    A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.

    Published: 7 Mar 2022
    7.2
    High

    CVE-2022-26521

    Last Modified: 21 Nov 2024

    Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Catalog>Media Manager>Images settings can be changed by an administrator (e.g., by configuring .php to be a valid image file type).

    Published: 7 Mar 2022
    7
    High

    CVE-2021-39713

    Last Modified: 21 Nov 2024

    Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel

    Published: 7 Mar 2022
    6.5
    Medium

    CVE-2022-0756

    Last Modified: 21 Nov 2024

    Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.

    Published: 7 Mar 2022
    7
    High

    CVE-2021-39686

    Last Modified: 21 Nov 2024

    In several functions of binder.c, there is a possible way to represent the wrong domain to SELinux due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-200688826References: Upstream kernel

    Published: 7 Mar 2022
    7.8
    High

    CVE-2021-39698

    Last Modified: 21 Nov 2024

    In aio_poll_complete_work of aio.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-185125206References: Upstream kernel

    Published: 7 Mar 2022
    4.4
    Medium

    CVE-2021-39711

    Last Modified: 21 Nov 2024

    In bpf_prog_test_run_skb of test_run.c, there is a possible out of bounds read due to Incorrect Size Value. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-154175781References: Upstream kernel

    Published: 7 Mar 2022
    7.8
    High

    CVE-2021-39714

    Last Modified: 21 Nov 2024

    In ion_buffer_kmap_get of ion.c, there is a possible use-after-free due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-205573273References: Upstream kernel

    Published: 7 Mar 2022
    4.3
    Medium

    CVE-2022-0755

    Last Modified: 21 Nov 2024

    Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.

    Published: 7 Mar 2022
    6.1
    Medium

    CVE-2022-0697

    Last Modified: 21 Nov 2024

    Open Redirect in GitHub repository archivy/archivy prior to 1.7.0.

    Published: 6 Mar 2022
    5.5
    Medium

    CVE-2021-44421

    Last Modified: 21 Nov 2024

    The pointer-validation logic in util/mem_util.rs in Occlum before 0.26.0 for Intel SGX acts as a confused deputy that allows a local attacker to access unauthorized information via side-channel analysis.

    Published: 6 Mar 2022
    5.5
    Medium

    CVE-2021-44749

    Last Modified: 21 Nov 2024

    A vulnerability affecting F-Secure SAFE browser protection was discovered improper URL handling can be triggered to cause universal cross-site scripting through browsing protection in a SAFE web browser. User interaction is required prior to exploitation. A successful exploitation may lead to arbitrary code execution.

    Published: 6 Mar 2022
    5.5
    Medium

    CVE-2021-44748

    Last Modified: 21 Nov 2024

    A vulnerability affecting F-Secure SAFE browser was discovered whereby browsers loads images automatically this vulnerability can be exploited remotely by an attacker to execute the JavaScript can be used to trigger universal cross-site scripting through the browser. User interaction is required prior to exploitation, such as entering a malicious website to trigger the vulnerability.

    Published: 6 Mar 2022
    6.1
    Medium

    CVE-2022-0868

    Last Modified: 21 Nov 2024

    Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10.

    Published: 6 Mar 2022
    6.1
    Medium

    CVE-2022-0869

    Last Modified: 21 Nov 2024

    Multiple Open Redirect in GitHub repository nitely/spirit prior to 0.12.3.

    Published: 6 Mar 2022
    9.8
    Critical

    CVE-2021-46704

    Last Modified: 21 Nov 2024

    In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping host argument (lib/ui/api.ts and lib/ping.ts). The vulnerability arises from insufficient input validation combined with a missing authorization check.

    Published: 6 Mar 2022
    9.8
    Critical

    CVE-2021-46703

    Last Modified: 21 Nov 2024

    In the IsolatedRazorEngine component of Antaris RazorEngine through 4.5.1-alpha001, an attacker can execute arbitrary .NET code in a sandboxed environment (if users can externally control template contents). NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 6 Mar 2022
    7.8
    High

    CVE-2022-26490

    Last Modified: 25 Jun 2025

    st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTION buffer overflows because of untrusted length parameters.

    Published: 6 Mar 2022
    —
    Unknown

    CVE-2022-26487

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-26143. Reason: This candidate is a reservation duplicate of CVE-2022-26143. Notes: All CVE users should reference CVE-2022-26143 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 6 Mar 2022
    9.8
    Critical

    CVE-2022-26495

    Last Modified: 21 Nov 2024

    In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0xffffffff in the name length field will cause a zero-sized buffer to be allocated for the name, resulting in a write to a dangling pointer. This issue exists for the NBD_OPT_INFO, NBD_OPT_GO, and NBD_OPT_EXPORT_NAME messages.

    Published: 6 Mar 2022
    7.4
    High

    CVE-2022-26505

    Last Modified: 21 Nov 2024

    A DNS rebinding issue in ReadyMedia (formerly MiniDLNA) before 1.3.1 allows a remote web server to exfiltrate media files.

    Published: 6 Mar 2022
    9.8
    Critical

    CVE-2022-26496

    Last Modified: 21 Nov 2024

    In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a buffer overflow in the parsing of the name field by sending a crafted NBD_OPT_INFO or NBD_OPT_GO message with an large value as the length of the name.

    Published: 6 Mar 2022
    9.8
    Critical

    CVE-2022-0845

    Last Modified: 21 Nov 2024

    Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0.

    Published: 5 Mar 2022