CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2021-45223

    Last Modified: 21 Nov 2024

    An issue was discovered in COINS Construction Cloud 11.12. Due to insufficient input neutralization, it is vulnerable to denial of service attacks via forced server crashes.

    Published: 24 Jan 2022
    8.8
    High

    CVE-2021-45222

    Last Modified: 21 Nov 2024

    An issue was discovered in COINS Construction Cloud 11.12. Due to logical flaws in the human ressources interface, it is vulnerable to privilege escalation by HR personnel.

    Published: 24 Jan 2022
    5.4
    Medium

    CVE-2022-21715

    Last Modified: 23 Apr 2025

    CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A cross-site scripting (XSS) vulnerability was found in `API\ResponseTrait` in Codeigniter4 prior to version 4.1.8. Attackers can do XSS attacks if a potential victim is using `API\ResponseTrait`. Version 4.1.8 contains a patch for this vulnerability. There are two potential workarounds available. Users may avoid using `API\ResponseTrait` or `ResourceController` Users may also disable Auto Route and use defined routes only.

    Published: 24 Jan 2022
    7.1
    High

    CVE-2022-21711

    Last Modified: 22 Apr 2025

    elfspirit is an ELF static analysis and injection framework that parses, manipulates, and camouflages ELF files. When analyzing the ELF file format in versions prior to 1.1, there is an out-of-bounds read bug, which can lead to application crashes or information leakage. By constructing a special format ELF file, the information of any address can be leaked. elfspirit version 1.1 contains a patch for this issue.

    Published: 24 Jan 2022
    4.7
    Medium

    CVE-2022-21710

    Last Modified: 22 Apr 2025

    ShortDescription is a MediaWiki extension that provides local short description support. A cross-site scripting (XSS) vulnerability exists in versions prior to 2.3.4. On a wiki that has the ShortDescription enabled, XSS can be triggered on any page or the page with the action=info parameter, which displays the shortdesc property. This is achieved using the wikitext `{{SHORTDESC:<img src=x onerror=alert()>}}`. This issue has a patch in version 2.3.4.

    Published: 24 Jan 2022
    9.8
    Critical

    CVE-2020-17383

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability on Telos Z/IP One devices through 4.0.0r grants an unauthenticated individual root level access to the device's file system. This can be used to identify configuration settings, password hashes for built-in accounts, and the cleartext password for remote configuration of the device through the WebUI.

    Published: 24 Jan 2022
    9.8
    Critical

    CVE-2021-46451

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerabilty exists in Sourcecodester Online Project Time Management System 1.0 via the pid parameter in the load_file function.

    Published: 24 Jan 2022
    9.8
    Critical

    CVE-2021-43420

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Login.php in Sourcecodester Online Payment Hub v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter.

    Published: 24 Jan 2022
    9.8
    Critical

    CVE-2021-41928

    Last Modified: 21 Nov 2024

    SQL injection in Sourcecodester Try My Recipe (Recipe Sharing Website - CMS) 1.0 by oretnom23, allows attackers to execute arbitrary code via the rid parameter to the view_recipe page.

    Published: 24 Jan 2022
    6.1
    Medium

    CVE-2021-42168

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in Sourcecodester Try My Recipe (Recipe Sharing Website - CMS) by oretnom23, allows attackers to gain the PHPSESID or other unspecified impacts via the fullname parameter to the login_registration page.

    Published: 24 Jan 2022
    3.3
    Low

    CVE-2021-35005

    Last Modified: 21 Nov 2024

    This vulnerability allows local attackers to disclose sensitive information on affected installations of TeamViewer. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the TeamViewer service. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated array. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-13818.

    Published: 24 Jan 2022
    9.8
    Critical

    CVE-2022-23126

    Last Modified: 28 May 2025

    TeslaMate before 1.25.1 (when using the default Docker configuration) allows attackers to open doors of Tesla vehicles, start Keyless Driving, and interfere with vehicle operation en route. This occurs because an attacker can leverage Grafana login access to obtain a token for Tesla API calls.

    Published: 24 Jan 2022
    6.1
    Medium

    CVE-2021-41930

    Last Modified: 21 Nov 2024

    Cross site scripting (XSS) vulnerability in Sourcecodester Online Covid Vaccination Scheduler System v1 by oretnom23, allows attackers to execute arbitrary code via the lid parameter to /scheduler/addSchedule.php.

    Published: 24 Jan 2022
    6.1
    Medium

    CVE-2021-41929

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in Sourcecodester The Electric Billing Management System 1.0 by oretnom23, allows attackers to execute arbitrary code via the about page.

    Published: 24 Jan 2022
    9.8
    Critical

    CVE-2021-41660

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Sourcecodester Patient Appointment Scheduler System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password fields to login.php.

    Published: 24 Jan 2022
    9.8
    Critical

    CVE-2021-41659

    Last Modified: 16 Dec 2025

    SQL injection vulnerability in Sourcecodester Banking System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username or password field.

    Published: 24 Jan 2022
    5.4
    Medium

    CVE-2021-41658

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) in Sourcecodester Student Quarterly Grading System by oretnom23, allows attackers to execute arbitrary code via the fullname and username parameters to the users page.

    Published: 24 Jan 2022
    8.4
    High

    CVE-2021-4088

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Data Loss Protection (DLP) ePO extension 11.8.x prior to 11.8.100, 11.7.x prior to 11.7.101, and 11.6.401 allows a remote authenticated attacker to inject unfiltered SQL into the DLP part of the ePO database. This could lead to remote code execution on the ePO server with privilege escalation.

    Published: 24 Jan 2022
    9.8
    Critical

    CVE-2021-41472

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Sourcecodester Simple Membership System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password parameters.

    Published: 24 Jan 2022
    9.8
    Critical

    CVE-2021-41471

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Sourcecodester South Gate Inn Online Reservation System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the email and Password parameters.

    Published: 24 Jan 2022
    9.6
    Critical

    CVE-2021-40909

    Last Modified: 21 Nov 2024

    Cross site scripting (XSS) vulnerability in sourcecodester PHP CRUD without Refresh/Reload using Ajax and DataTables Tutorial v1 by oretnom23, allows remote attackers to execute arbitrary code via the first_name, last_name, and email parameters to /ajax_crud.

    Published: 24 Jan 2022
    9.8
    Critical

    CVE-2021-40908

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Login.php in Sourcecodester Purchase Order Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter.

    Published: 24 Jan 2022
    9.8
    Critical

    CVE-2021-40907

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Sourcecodester Storage Unit Rental Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter to /storage/classes/Login.php.

    Published: 24 Jan 2022
    9.8
    Critical

    CVE-2021-40596

    Last Modified: 18 Dec 2024

    SQL injection vulnerability in Login.php in sourcecodester Online Learning System v2 by oretnom23, allows attackers to execute arbitrary SQL commands via the faculty_id parameter.

    Published: 24 Jan 2022
    5.3
    Medium

    CVE-2022-22296

    Last Modified: 21 Nov 2024

    Sourcecodester Hospital's Patient Records Management System 1.0 is vulnerable to Insecure Permissions via the id parameter in manage_user endpoint. Simply change the value and data of other users can be displayed.

    Published: 24 Jan 2022
    8.8
    High

    CVE-2021-44981

    Last Modified: 21 Nov 2024

    In QuickBox Pro v2.5.8 and below, the config.php file has a variable which takes a GET parameter value and parses it into a shell_exec(''); function without properly sanitizing any shell arguments, therefore remote code execution is possible. Additionally, as the media server is running as root by default attackers can use the sudo command within this shell_exec(''); function, which allows for privilege escalation by means of RCE.

    Published: 24 Jan 2022
    8
    High

    CVE-2022-0269

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) in Packagist yetiforce/yetiforce-crm prior to 6.3.0.

    Published: 24 Jan 2022
    5.5
    Medium

    CVE-2021-3995

    Last Modified: 21 Nov 2024

    A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows an unprivileged local attacker to unmount FUSE filesystems that belong to certain other users who have a UID that is a prefix of the UID of the attacker in its string form. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.

    Published: 24 Jan 2022
    5.5
    Medium

    CVE-2021-3996

    Last Modified: 21 Nov 2024

    A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users' filesystems that are either world-writable themselves (like /tmp) or mounted in a world-writable directory. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.

    Published: 24 Jan 2022
    6.1
    Medium

    CVE-2021-25083

    Last Modified: 21 Nov 2024

    The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outputting it back in an attribute in the settings page, leading to a Reflected Cross-Site Scripting

    Published: 24 Jan 2022
    6.1
    Medium

    CVE-2021-25080

    Last Modified: 21 Nov 2024

    The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved via headers such as CLIENT-IP and X-FORWARDED-FOR, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against logged in admins viewing the created entry

    Published: 24 Jan 2022
    6.1
    Medium

    CVE-2021-25079

    Last Modified: 21 Nov 2024

    The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page

    Published: 24 Jan 2022
    6.1
    Medium

    CVE-2021-25078

    Last Modified: 21 Nov 2024

    The Affiliates Manager WordPress plugin before 2.9.0 does not validate, sanitise and escape the IP address of requests logged by the click tracking feature, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admin viewing the tracked requests.

    Published: 24 Jan 2022
    8.8
    High

    CVE-2021-25076

    Last Modified: 21 Nov 2024

    The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of sanitisation and escaping, this could also lead to Reflected Cross-Site Scripting

    Published: 24 Jan 2022
    6.1
    Medium

    CVE-2021-25074

    Last Modified: 21 Nov 2024

    The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the src parameter before redirecting the user to it, leading to an Open Redirect issue

    Published: 24 Jan 2022
    8.8
    High

    CVE-2021-25073

    Last Modified: 21 Nov 2024

    The WP125 WordPress plugin before 1.5.5 does not have CSRF checks in various action, for example when deleting an ad, allowing attackers to make a logged in admin delete them via a CSRF attack

    Published: 24 Jan 2022
    6.1
    Medium

    CVE-2021-25062

    Last Modified: 21 Nov 2024

    The Orders Tracking for WooCommerce WordPress plugin before 1.1.10 does not sanitise and escape the file_url before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

    Published: 24 Jan 2022
    4.8
    Medium

    CVE-2021-25049

    Last Modified: 21 Nov 2024

    The Mobile Events Manager WordPress plugin before 1.4.4 does not sanitise and escape various of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 24 Jan 2022
    7.2
    High

    CVE-2021-25045

    Last Modified: 21 Nov 2024

    The Asgaros Forum WordPress plugin before 1.15.15 does not validate or escape the forum_id parameter before using it in a SQL statement when editing a forum, leading to an SQL injection issue

    Published: 24 Jan 2022
    6.1
    Medium

    CVE-2021-25035

    Last Modified: 21 Nov 2024

    The Backup and Staging by WP Time Capsule WordPress plugin before 1.22.7 does not sanitise and escape the error parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

    Published: 24 Jan 2022
    6.1
    Medium

    CVE-2021-25031

    Last Modified: 21 Nov 2024

    The Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) WordPress plugin before 9.7.1 does not escape the effects parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

    Published: 24 Jan 2022
    6.1
    Medium

    CVE-2021-25028

    Last Modified: 21 Nov 2024

    The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary redirect issue

    Published: 24 Jan 2022
    6.1
    Medium

    CVE-2021-25017

    Last Modified: 21 Nov 2024

    The Tutor LMS WordPress plugin before 1.9.12 does not escape the search parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

    Published: 24 Jan 2022
    6.1
    Medium

    CVE-2021-25015

    Last Modified: 21 Nov 2024

    The myCred WordPress plugin before 2.4 does not sanitise and escape the search query before outputting it back in the history dashboard page, leading to a Reflected Cross-Site Scripting issue

    Published: 24 Jan 2022
    6.5
    Medium

    CVE-2021-25013

    Last Modified: 21 Nov 2024

    The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure that the block to be deleted belong to the plugin, as a result, any authenticated users, such as subscriber can delete arbitrary posts

    Published: 24 Jan 2022
    6.1
    Medium

    CVE-2021-25008

    Last Modified: 21 Nov 2024

    The Code Snippets WordPress plugin before 2.14.3 does not escape the snippets-safe-mode parameter before outputting it back in attributes, leading to a Reflected Cross-Site Scripting issue

    Published: 24 Jan 2022
    6.5
    Medium

    CVE-2021-24989

    Last Modified: 21 Nov 2024

    The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure that the post to be deleted belongs to the plugin, allowing attackers to make a logged in admin delete arbitrary posts from the blog

    Published: 24 Jan 2022
    6.1
    Medium

    CVE-2021-24985

    Last Modified: 21 Nov 2024

    The Easy Forms for Mailchimp WordPress plugin before 6.8.6 does not sanitise and escape the field_name and field_type parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

    Published: 24 Jan 2022
    6.1
    Medium

    CVE-2021-24976

    Last Modified: 21 Nov 2024

    The Smart SEO Tool WordPress plugin before 3.0.6 does not sanitise and escape the search parameter before outputting it back in an attribute when the TDK optimisation setting is enabled, leading to a Reflected Cross-Site Scripting

    Published: 24 Jan 2022
    5.4
    Medium

    CVE-2021-24974

    Last Modified: 21 Nov 2024

    The Product Feed PRO for WooCommerce WordPress plugin before 11.0.7 does not have authorisation and CSRF check in some of its AJAX actions, allowing any authenticated users to call then, which could lead to Stored Cross-Site Scripting issue (which will be triggered in the admin dashboard) due to the lack of escaping.

    Published: 24 Jan 2022