CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2022-0164

    Last Modified: 21 Nov 2024

    The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber to send arbitrary emails to all subscribed users

    Published: 21 Feb 2022
    8.8
    High

    CVE-2022-0134

    Last Modified: 21 Nov 2024

    The AnyComment WordPress plugin before 0.2.18 does not have CSRF checks in the Import and Revert HyperComments features, allowing attackers to make logged in admin perform such actions via a CSRF attack

    Published: 21 Feb 2022
    7.2
    High

    CVE-2021-4208

    Last Modified: 21 Nov 2024

    The ExportFeed WordPress plugin through 2.0.1.0 does not sanitise and escape the product_id POST parameter before using it in a SQL statement, leading to a SQL injection vulnerability exploitable by high privilege users

    Published: 21 Feb 2022
    4.8
    Medium

    CVE-2021-25101

    Last Modified: 21 Nov 2024

    The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.94 does not sanitise and escape the POST data before outputting it back in attributes of an admin page, leading to a Reflected Cross-Site scripting. Due to the presence of specific parameter value, available to admin users, this can only be exploited by an admin against another admin user.

    Published: 21 Feb 2022
    6.1
    Medium

    CVE-2021-25100

    Last Modified: 21 Nov 2024

    The GiveWP WordPress plugin before 2.17.3 does not escape the s parameter before outputting it back in an attribute in the Donation Forms dashboard, leading to a Reflected Cross-Site Scripting

    Published: 21 Feb 2022
    6.1
    Medium

    CVE-2021-25099

    Last Modified: 21 Nov 2024

    The GiveWP WordPress plugin before 2.17.3 does not sanitise and escape the form_id parameter before outputting it back in the response of an unauthenticated request via the give_checkout_login AJAX action, leading to a Reflected Cross-Site Scripting

    Published: 21 Feb 2022
    8.8
    High

    CVE-2021-25082

    Last Modified: 21 Nov 2024

    The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR

    Published: 21 Feb 2022
    3.5
    Low

    CVE-2021-25075

    Last Modified: 21 Nov 2024

    The Duplicate Page or Post WordPress plugin before 1.5.1 does not have any authorisation and has a flawed CSRF check in the wpdevart_duplicate_post_parametrs_save_in_db AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings, or perform such attack via CSRF. Furthermore, due to the lack of escaping, this could lead to Stored Cross-Site Scripting issues

    Published: 21 Feb 2022
    8.8
    High

    CVE-2021-25069

    Last Modified: 21 Mar 2025

    The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue

    Published: 21 Feb 2022
    5.4
    Medium

    CVE-2021-25060

    Last Modified: 21 Nov 2024

    The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscribers, to call them. Furthermore, due to the lack of sanitisation, it also lead to Stored Cross-Site Scripting issues

    Published: 21 Feb 2022
    5.4
    Medium

    CVE-2021-25058

    Last Modified: 21 Nov 2024

    The Buffer Button WordPress plugin through 1.0 was vulnerable to Authenticated Stored Cross Site Scripting (XSS) within the Twitter username to mention text field.

    Published: 21 Feb 2022
    5.4
    Medium

    CVE-2021-25057

    Last Modified: 21 Nov 2024

    The Translation Exchange WordPress plugin through 1.0.14 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS) within the Project Key text field found in the plugin's settings.

    Published: 21 Feb 2022
    6.1
    Medium

    CVE-2021-25055

    Last Modified: 21 Nov 2024

    The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" parameter.

    Published: 21 Feb 2022
    6.1
    Medium

    CVE-2021-24921

    Last Modified: 21 Nov 2024

    The Advanced Database Cleaner WordPress plugin before 3.0.4 does not sanitise and escape $_GET keys and values before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

    Published: 21 Feb 2022
    9.8
    Critical

    CVE-2021-24867

    Last Modified: 21 Nov 2024

    Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion

    Published: 21 Feb 2022
    7.5
    High

    CVE-2022-25297

    Last Modified: 21 Nov 2024

    This affects the package drogonframework/drogon before 1.7.5. The unsafe handling of file names during upload using HttpFile::save() method may enable attackers to write files to arbitrary locations outside the designated target folder.

    Published: 21 Feb 2022
    —
    Unknown

    CVE-2021-44569

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-3200 Reason: This candidate is a duplicate of CVE-2021-3200. Notes: All CVE users should reference CVE-2021-3200 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Feb 2022
    0
    Low

    CVE-2021-44570

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-3200 Reason: This candidate is a duplicate of CVE-2021-3200. Notes: All CVE users should reference CVE-2021-3200 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Feb 2022
    0
    Low

    CVE-2021-44571

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-3200 Reason: This candidate is a duplicate of CVE-2021-3200. Notes: All CVE users should reference CVE-2021-3200 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Feb 2022
    0
    Low

    CVE-2021-44573

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-3200 Reason: This candidate is a duplicate of CVE-2021-3200. Notes: All CVE users should reference CVE-2021-3200 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Feb 2022
    0
    Low

    CVE-2021-44576

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-3200 Reason: This candidate is a duplicate of CVE-2021-3200. Notes: All CVE users should reference CVE-2021-3200 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Feb 2022
    —
    Unknown

    CVE-2021-44577

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-3200 Reason: This candidate is a duplicate of CVE-2021-3200. Notes: All CVE users should reference CVE-2021-3200 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Feb 2022
    5.5
    Medium

    CVE-2022-0696

    Last Modified: 21 Nov 2024

    NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428.

    Published: 21 Feb 2022
    4.9
    Medium

    CVE-2022-0718

    Last Modified: 21 Nov 2024

    A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.

    Published: 21 Feb 2022
    6.5
    Medium

    CVE-2021-44568

    Last Modified: 21 Nov 2024

    Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the resolve_dependencies function at src/solver.c (line 1940 & line 1995), which could cause a remote Denial of Service.

    Published: 21 Feb 2022
    0
    Low

    CVE-2021-44575

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-3200 Reason: This candidate is a duplicate of CVE-2021-3200. Notes: All CVE users should reference CVE-2021-3200 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Feb 2022
    5.3
    Medium

    CVE-2022-0564

    Last Modified: 25 Apr 2025

    A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An attacker could exploit this vulnerability by sending authentication requests to an affected system. A successful exploit could allow the attacker to compare the response time that are returned by the affected system to determine which accounts are valid user accounts. Affected systems are only vulnerable if they have LDAP configured. The affected URI is /internal_forms_authentication/ the response time of the form is longer if the supplied user does not exists and shorter if the user exists.

    Published: 21 Feb 2022
    9.8
    Critical

    CVE-2022-0691

    Last Modified: 21 Nov 2024

    Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.

    Published: 21 Feb 2022
    4.3
    Medium

    CVE-2022-0708

    Last Modified: 6 Dec 2024

    Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.

    Published: 21 Feb 2022
    0
    Low

    CVE-2021-44574

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-3200 Reason: This candidate is a duplicate of CVE-2021-3200. Notes: All CVE users should reference CVE-2021-3200 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Feb 2022
    7.2
    High

    CVE-2021-46701

    Last Modified: 21 Nov 2024

    PreMiD 2.2.0 allows unintended access via the websocket transport. An attacker can receive events from a socket and emit events to a socket, potentially interfering with a victim's "now playing" status on Discord.

    Published: 20 Feb 2022
    7.8
    High

    CVE-2022-25372

    Last Modified: 21 Nov 2024

    Pritunl Client through 1.2.3019.52 on Windows allows local privilege escalation, related to an ACL entry for CREATOR OWNER in platform_windows.go.

    Published: 20 Feb 2022
    6.1
    Medium

    CVE-2022-23054

    Last Modified: 21 Nov 2024

    Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Summary Widget” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.

    Published: 20 Feb 2022
    6.1
    Medium

    CVE-2022-23053

    Last Modified: 21 Nov 2024

    Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Condition Widget” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.

    Published: 20 Feb 2022
    6.1
    Medium

    CVE-2022-22126

    Last Modified: 21 Nov 2024

    Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Web Page” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.

    Published: 20 Feb 2022
    9.8
    Critical

    CVE-2022-23848

    Last Modified: 21 Nov 2024

    In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability.

    Published: 20 Feb 2022
    4.9
    Medium

    CVE-2022-0688

    Last Modified: 21 Nov 2024

    Business Logic Errors in Packagist microweber/microweber prior to 1.2.11.

    Published: 20 Feb 2022
    6.5
    Medium

    CVE-2021-45007

    Last Modified: 21 Nov 2024

    Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel. NOTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users

    Published: 20 Feb 2022
    9.1
    Critical

    CVE-2022-0686

    Last Modified: 21 Nov 2024

    Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.

    Published: 20 Feb 2022
    7.8
    High

    CVE-2022-0685

    Last Modified: 21 Nov 2024

    Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418.

    Published: 20 Feb 2022
    7.5
    High

    CVE-2022-23308

    Last Modified: 5 May 2025

    valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.

    Published: 20 Feb 2022
    6.5
    Medium

    CVE-2021-46700

    Last Modified: 24 Apr 2026

    In libsixel 1.8.6, sixel_encoder_output_without_macro (called from sixel_encoder_encode_frame in encoder.c) has a double free.

    Published: 19 Feb 2022
    9.8
    Critical

    CVE-2016-1239

    Last Modified: 21 Nov 2024

    duck before 0.10 did not properly handle loading of untrusted code from the current directory.

    Published: 19 Feb 2022
    6.1
    Medium

    CVE-2022-0690

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.

    Published: 19 Feb 2022
    5.3
    Medium

    CVE-2022-0689

    Last Modified: 21 Nov 2024

    Use multiple time the one-time coupon in Packagist microweber/microweber prior to 1.2.11.

    Published: 19 Feb 2022
    8.8
    High

    CVE-2022-23375

    Last Modified: 21 Nov 2024

    WikiDocs version 0.1.18 has an authenticated remote code execution vulnerability. An attacker can upload a malicious file using the image upload form through index.php.

    Published: 19 Feb 2022
    6.1
    Medium

    CVE-2022-23376

    Last Modified: 21 Nov 2024

    WikiDocs version 0.1.18 has multiple reflected XSS vulnerabilities on different pages.

    Published: 19 Feb 2022
    5.5
    Medium

    CVE-2022-0632

    Last Modified: 21 Nov 2024

    NULL Pointer Dereference in Homebrew mruby prior to 3.2.

    Published: 19 Feb 2022
    7.1
    High

    CVE-2022-0630

    Last Modified: 21 Nov 2024

    Out-of-bounds Read in Homebrew mruby prior to 3.2.

    Published: 19 Feb 2022
    6.1
    Medium

    CVE-2022-0678

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.

    Published: 19 Feb 2022