CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2021-25089

    Last Modified: 21 Nov 2024

    The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.69 does not sanitise and escape the updraft_restore parameter before outputting it back in the Restore page, leading to a Reflected Cross-Site Scripting

    Published: 1 Feb 2022
    6.1
    Medium

    CVE-2021-25085

    Last Modified: 21 Nov 2024

    The WOOF WordPress plugin before 1.2.6.3 does not sanitise and escape the woof_redraw_elements before outputing back in an admin page, leading to a Reflected Cross-Site Scripting

    Published: 1 Feb 2022
    6.1
    Medium

    CVE-2021-25063

    Last Modified: 21 Nov 2024

    The Skins for Contact Form 7 WordPress plugin before 2.5.1 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

    Published: 1 Feb 2022
    6.5
    Medium

    CVE-2021-25072

    Last Modified: 21 Nov 2024

    The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.25 does not have CSRF check in place when deleting items, allowing attacker to make a logged in admin delete arbitrary posts via a CSRF attack

    Published: 1 Feb 2022
    6.1
    Medium

    CVE-2021-24983

    Last Modified: 21 Nov 2024

    The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not sanitise and escape POSted parameters sent to the wpassetcleanup_fetch_active_plugins_icons AJAX action (available to admin users), leading to a Reflected Cross-Site Scripting issue

    Published: 1 Feb 2022
    6.1
    Medium

    CVE-2021-24975

    Last Modified: 21 Nov 2024

    The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.24 does not sanitise and escape logged requests before outputting them in the related admin dashboard, leading to an Unauthenticated Stored Cross-Site Scripting issue

    Published: 1 Feb 2022
    4.8
    Medium

    CVE-2021-24944

    Last Modified: 21 Nov 2024

    The Custom Dashboard & Login Page WordPress plugin before 7.0 does not sanitise some of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 1 Feb 2022
    6.1
    Medium

    CVE-2021-24937

    Last Modified: 21 Nov 2024

    The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not escape the wpacu_selected_sub_tab_area parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting issue

    Published: 1 Feb 2022
    6.1
    Medium

    CVE-2021-24934

    Last Modified: 21 Nov 2024

    The Visual CSS Style Editor WordPress plugin before 7.5.4 does not sanitise and escape the wyp_page_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

    Published: 1 Feb 2022
    8.8
    High

    CVE-2021-24919

    Last Modified: 21 Nov 2024

    The Wicked Folders WordPress plugin before 2.8.10 does not sanitise and escape the folder_id parameter before using it in a SQL statement in the wicked_folders_save_sort_order AJAX action, available to any authenticated user. leading to an SQL injection

    Published: 1 Feb 2022
    6.1
    Medium

    CVE-2021-24926

    Last Modified: 21 Nov 2024

    The Domain Check WordPress plugin before 1.0.17 does not sanitise and escape the domain parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue

    Published: 1 Feb 2022
    4.8
    Medium

    CVE-2021-24900

    Last Modified: 21 Nov 2024

    The Ninja Tables WordPress plugin before 4.1.8 does not sanitise and escape some of its table fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 1 Feb 2022
    4.3
    Medium

    CVE-2021-24868

    Last Modified: 21 Nov 2024

    The Document Embedder WordPress plugin before 1.7.9 contains a AJAX action endpoint, which could allow any authenticated user, such as subscriber to enumerate the title of arbitrary private and draft posts.

    Published: 1 Feb 2022
    5.3
    Medium

    CVE-2021-24775

    Last Modified: 21 Nov 2024

    The Document Embedder WordPress plugin before 1.7.5 contains a REST endpoint, which could allow unauthenticated users to enumerate the title of arbitrary private and draft posts.

    Published: 1 Feb 2022
    9.6
    Critical

    CVE-2021-24814

    Last Modified: 21 Nov 2024

    The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.26, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be interpreted by a web browser led to this endpoint. Javascript code may be executed on a victim's browser. If the victim is an administrator with a valid session cookie, full control of the WordPress instance may be taken (AJAX calls and iframe manipulation are possible because the vulnerable endpoint is on the same domain as the admin panel - there is no same-origin restriction).

    Published: 1 Feb 2022
    6.1
    Medium

    CVE-2021-24765

    Last Modified: 21 Nov 2024

    The Perfect Survey WordPress plugin through 1.5.2 does not validate and escape the X-Forwarded-For header value before outputting it in the statistic page when the Anonymize IP setting of a survey is turned off, leading to a Stored Cross-Site Scripting issue

    Published: 1 Feb 2022
    6.1
    Medium

    CVE-2021-24764

    Last Modified: 21 Nov 2024

    The Perfect Survey WordPress plugin before 1.5.2 does not sanitise and escape multiple parameters (id and filters[session_id] of single_statistics page, type and message of importexport page) before outputting them back in pages/attributes in the admin dashboard, leading to Reflected Cross-Site Scripting issues

    Published: 1 Feb 2022
    9.8
    Critical

    CVE-2021-24762

    Last Modified: 21 Nov 2024

    The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection.

    Published: 1 Feb 2022
    8.8
    High

    CVE-2021-24763

    Last Modified: 21 Nov 2024

    The Perfect Survey WordPress plugin before 1.5.2 does not have proper authorisation nor CSRF checks in the save_global_setting AJAX action, allowing unauthenticated users to edit surveys and modify settings. Given the lack of sanitisation and escaping in the settings, this could also lead to a Stored Cross-Site Scripting issue which will be executed in the context of a user viewing any survey

    Published: 1 Feb 2022
    6.5
    Medium

    CVE-2021-24761

    Last Modified: 21 Nov 2024

    The Error Log Viewer WordPress plugin before 1.1.2 does not perform nonce check when deleting a log file and does not have path traversal prevention, which could allow attackers to make a logged in admin delete arbitrary text files on the web server.

    Published: 1 Feb 2022
    4.8
    Medium

    CVE-2021-24707

    Last Modified: 21 Nov 2024

    The Learning Courses WordPress plugin before 5.0 does not sanitise and escape the Email PDT identity token settings, which could allow high privilege users to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 1 Feb 2022
    4.8
    Medium

    CVE-2021-24686

    Last Modified: 21 Nov 2024

    The SVG Support WordPress plugin before 2.3.20 does not escape the "CSS Class to target" setting before outputting it in an attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 1 Feb 2022
    6.1
    Medium

    CVE-2021-24648

    Last Modified: 21 Nov 2024

    The RegistrationMagic WordPress plugin before 5.0.1.9 does not sanitise and escape the rm_search_value parameter before outputting back in an attribute, leading to a Reflected Cross-Site Scripting

    Published: 1 Feb 2022
    8.1
    High

    CVE-2022-23601

    Last Modified: 23 Apr 2025

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony form component provides a CSRF protection mechanism by using a random token injected in the form and using the session to store and control the token submitted by the user. When using the FrameworkBundle, this protection can be enabled or disabled with the configuration. If the configuration is not specified, by default, the mechanism is enabled as long as the session is enabled. In a recent change in the way the configuration is loaded, the default behavior has been dropped and, as a result, the CSRF protection is not enabled in form when not explicitly enabled, which makes the application sensible to CSRF attacks. This issue has been resolved in the patch versions listed and users are advised to update. There are no known workarounds for this issue.

    Published: 1 Feb 2022
    7.4
    High

    CVE-2021-43848

    Last Modified: 23 Apr 2025

    h2o is an open source http server. In code prior to the `8c0eca3` commit h2o may attempt to access uninitialized memory. When receiving QUIC frames in certain order, HTTP/3 server-side implementation of h2o can be misguided to treat uninitialized memory as HTTP/3 frames that have been received. When h2o is used as a reverse proxy, an attacker can abuse this vulnerability to send internal state of h2o to backend servers controlled by the attacker or third party. Also, if there is an HTTP endpoint that reflects the traffic sent from the client, an attacker can use that reflector to obtain internal state of h2o. This internal state includes traffic of other connections in unencrypted form and TLS session tickets. This vulnerability exists in h2o server with HTTP/3 support, between commit 93af138 and d1f0f65. None of the released versions of h2o are affected by this vulnerability. There are no known workarounds. Users of unreleased versions of h2o using HTTP/3 are advised to upgrade immediately.

    Published: 1 Feb 2022
    6.8
    Medium

    CVE-2022-21687

    Last Modified: 5 May 2025

    gh-ost is a triggerless online schema migration solution for MySQL. Versions prior to 1.1.3 are subject to an arbitrary file read vulnerability. The attacker must have access to the target host or trick an administrator into executing a malicious gh-ost command on a host running gh-ost, plus network access from host running gh-ost to the attack's malicious MySQL server. The `-database` parameter does not properly sanitize user input which can lead to arbitrary file reads.

    Published: 1 Feb 2022
    8.3
    High

    CVE-2022-23597

    Last Modified: 5 May 2025

    Element Desktop is a Matrix client for desktop platforms with Element Web at its core. Element Desktop before 1.9.7 is vulnerable to a remote program execution bug with user interaction. The exploit is non-trivial and requires clicking on a malicious link, followed by another button click. To the best of our knowledge, the vulnerability has never been exploited in the wild. If you are using Element Desktop < 1.9.7, we recommend upgrading at your earliest convenience. If successfully exploited, the vulnerability allows an attacker to specify a file path of a binary on the victim's computer which then gets executed. Notably, the attacker does *not* have the ability to specify program arguments. However, in certain unspecified configurations, the attacker may be able to specify an URI instead of a file path which then gets handled using standard platform mechanisms. These may allow exploiting further vulnerabilities in those mechanisms, potentially leading to arbitrary code execution.

    Published: 1 Feb 2022
    7.5
    High

    CVE-2021-41040

    Last Modified: 21 Nov 2024

    In Eclipse Wakaama, ever since its inception until 2021-01-14, the CoAP parsing code does not properly sanitize network-received data.

    Published: 1 Feb 2022
    6.5
    Medium

    CVE-2022-23607

    Last Modified: 21 Nov 2024

    treq is an HTTP library inspired by requests but written on top of Twisted's Agents. Treq's request methods (`treq.get`, `treq.post`, etc.) and `treq.client.HTTPClient` constructor accept cookies as a dictionary. Such cookies are not bound to a single domain, and are therefore sent to *every* domain ("supercookies"). This can potentially cause sensitive information to leak upon an HTTP redirect to a different domain., e.g. should `https://example.com` redirect to `http://cloudstorageprovider.com` the latter will receive the cookie `session`. Treq 2021.1.0 and later bind cookies given to request methods (`treq.request`, `treq.get`, `HTTPClient.request`, `HTTPClient.get`, etc.) to the origin of the *url* parameter. Users are advised to upgrade. For users unable to upgrade Instead of passing a dictionary as the *cookies* argument, pass a `http.cookiejar.CookieJar` instance with properly domain- and scheme-scoped cookies in it.

    Published: 1 Feb 2022
    7.7
    High

    CVE-2022-23602

    Last Modified: 5 May 2025

    Nimforum is a lightweight alternative to Discourse written in Nim. In versions prior to 2.2.0 any forum user can create a new thread/post with an include referencing a file local to the host operating system. Nimforum will render the file if able. This can also be done silently by using NimForum's post "preview" endpoint. Even if NimForum is running as a non-critical user, the forum.json secrets can be stolen. Version 2.2.0 of NimForum includes patches for this vulnerability. Users are advised to upgrade as soon as is possible. There are no known workarounds for this issue.

    Published: 1 Feb 2022
    9.9
    Critical

    CVE-2022-23603

    Last Modified: 5 May 2025

    iTunesRPC-Remastered is a discord rich presence application for use with iTunes & Apple Music. In code before commit 24f43aa user input is not properly sanitized and code injection is possible. Users are advised to upgrade as soon as is possible. There are no known workarounds for this issue.

    Published: 1 Feb 2022
    5.5
    Medium

    CVE-2022-0419

    Last Modified: 21 Nov 2024

    NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0.

    Published: 1 Feb 2022
    6.1
    Medium

    CVE-2022-22818

    Last Modified: 21 Nov 2024

    The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This may lead to XSS.

    Published: 1 Feb 2022
    7.5
    High

    CVE-2022-23833

    Last Modified: 21 Nov 2024

    An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing files.

    Published: 1 Feb 2022
    5.3
    Medium

    CVE-2022-23774

    Last Modified: 21 Nov 2024

    Docker Desktop before 4.4.4 on Windows allows attackers to move arbitrary files.

    Published: 1 Feb 2022
    —
    Unknown

    CVE-2021-3534

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-34981. Reason: This candidate is a reservation duplicate of CVE-2021-34981. Notes: All CVE users should reference CVE-2021-34981 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 1 Feb 2022
    7.8
    High

    CVE-2022-0417

    Last Modified: 3 Nov 2025

    Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2.

    Published: 1 Feb 2022
    9.8
    Critical

    CVE-2022-26520

    Last Modified: 21 Nov 2024

    In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerLevel connection properties. An example situation is that an attacker could create an executable JSP file under a Tomcat web root. NOTE: the vendor's position is that there is no pgjdbc vulnerability; instead, it is a vulnerability for any application to use the pgjdbc driver with untrusted connection properties

    Published: 1 Feb 2022
    6.5
    Medium

    CVE-2022-24197

    Last Modified: 21 Nov 2024

    iText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

    Published: 1 Feb 2022
    6.5
    Medium

    CVE-2021-25097

    Last Modified: 21 Nov 2024

    The LabTools WordPress plugin through 1.0 does not have proper authorisation and CSRF check in place when deleting publications, allowing any authenticated users, such as subscriber to delete arbitrary publication

    Published: 1 Feb 2022
    7.5
    High

    CVE-2021-3859

    Last Modified: 21 Nov 2024

    A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.

    Published: 1 Feb 2022
    7
    High

    CVE-2022-21724

    Last Modified: 5 May 2025

    pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or properties. pgjdbc instantiates plugin instances based on class names provided via `authenticationPluginClassName`, `sslhostnameverifier`, `socketFactory`, `sslfactory`, `sslpasswordcallback` connection properties. However, the driver did not verify if the class implements the expected interface before instantiating the class. This can lead to code execution loaded via arbitrary classes. Users using plugins are advised to upgrade. There are no known workarounds for this issue.

    Published: 1 Feb 2022
    6.5
    Medium

    CVE-2022-24196

    Last Modified: 21 Nov 2024

    iText v7.1.17, up to (exluding)": 7.1.18 and 7.2.2 was discovered to contain an out-of-memory error via the component readStreamBytesRaw, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

    Published: 1 Feb 2022
    6.5
    Medium

    CVE-2022-24198

    Last Modified: 21 Nov 2024

    iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. NOTE: Vendor does not view this as a vulnerability and has not found it to be exploitable.

    Published: 1 Feb 2022
    7.5
    High

    CVE-2022-24266

    Last Modified: 21 Nov 2024

    Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the order_by parameter.

    Published: 31 Jan 2022
    7.5
    High

    CVE-2022-24265

    Last Modified: 21 Nov 2024

    Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=component/menu/&menu_filter=3 parameter.

    Published: 31 Jan 2022
    9.8
    Critical

    CVE-2022-24263

    Last Modified: 21 Nov 2024

    Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.

    Published: 31 Jan 2022
    7.5
    High

    CVE-2022-24264

    Last Modified: 21 Nov 2024

    Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the search_word parameter.

    Published: 31 Jan 2022
    4.8
    Medium

    CVE-2022-23872

    Last Modified: 21 Nov 2024

    Emlog pro v1.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /admin/configure.php via the parameter footer_info.

    Published: 31 Jan 2022
    5.3
    Medium

    CVE-2022-21659

    Last Modified: 5 May 2025

    Flask-AppBuilder is an application development framework, built on top of the Flask web framework. In affected versions there exists a user enumeration vulnerability. This vulnerability allows for a non authenticated user to enumerate existing accounts by timing the response time from the server when you are logging in. Users are advised to upgrade to version 3.4.4 as soon as possible. There are no known workarounds for this issue.

    Published: 31 Jan 2022