CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2021-38961

    Last Modified: 21 Nov 2024

    IBM OPENBMC OP910 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 212049.

    Published: 27 Dec 2021
    9.8
    Critical

    CVE-2021-45232

    Last Modified: 21 Nov 2024

    In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some API directly use the interface of framework `gin` thus bypassing the authentication.

    Published: 27 Dec 2021
    7.8
    High

    CVE-2021-45339

    Last Modified: 21 Nov 2024

    Privilege escalation vulnerability in Avast Antivirus prior to 20.4 allows a local user to gain elevated privileges by "hollowing" trusted process which could lead to the bypassing of Avast self-defense.

    Published: 27 Dec 2021
    7.8
    High

    CVE-2021-45338

    Last Modified: 21 Nov 2024

    Multiple privilege escalation vulnerabilities in Avast Antivirus prior to 20.4 allow a local user to gain elevated privileges by calling unnecessarily powerful internal methods of the main antivirus service which could lead to the (1) arbitrary file delete, (2) write and (3) reset security.

    Published: 27 Dec 2021
    8.8
    High

    CVE-2021-45337

    Last Modified: 21 Nov 2024

    Privilege escalation vulnerability in the Self-Defense driver of Avast Antivirus prior to 20.8 allows a local user with SYSTEM privileges to gain elevated privileges by "hollowing" process wsc_proxy.exe which could lead to acquire antimalware (AM-PPL) protection.

    Published: 27 Dec 2021
    8.8
    High

    CVE-2021-45336

    Last Modified: 21 Nov 2024

    Privilege escalation vulnerability in the Sandbox component of Avast Antivirus prior to 20.4 allows a local sandboxed code to gain elevated privileges by using system IPC interfaces which could lead to exit the sandbox and acquire SYSTEM privileges.

    Published: 27 Dec 2021
    8.8
    High

    CVE-2021-45335

    Last Modified: 21 Nov 2024

    Sandbox component in Avast Antivirus prior to 20.4 has an insecure permission which could be abused by local user to control the outcome of scans, and therefore evade detection or delete arbitrary system files.

    Published: 27 Dec 2021
    9.8
    Critical

    CVE-2021-45790

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to arbitrary directory, where attackers can write a cron job to execute commands.

    Published: 27 Dec 2021
    6.5
    Medium

    CVE-2021-45789

    Last Modified: 21 Nov 2024

    An arbitrary file read vulnerability was found in Metersphere v1.15.4, where authenticated users can read any file on the server via the file download function.

    Published: 27 Dec 2021
    8.8
    High

    CVE-2021-45788

    Last Modified: 21 Nov 2024

    Time-based SQL Injection vulnerabilities were found in Metersphere v1.15.4 via the "orders" parameter.

    Published: 27 Dec 2021
    6.1
    Medium

    CVE-2021-45843

    Last Modified: 21 Nov 2024

    glFusion CMS v1.7.9 is affected by a reflected Cross Site Scripting (XSS) vulnerability. The value of the title request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. This input was echoed unmodified in the application's response.

    Published: 27 Dec 2021
    6.5
    Medium

    CVE-2021-24997

    Last Modified: 21 Nov 2024

    The WP Guppy WordPress plugin before 1.3 does not have any authorisation in some of the REST API endpoints, allowing any user to call them and could lead to sensitive information disclosure, such as usernames and chats between users, as well as be able to send messages as an arbitrary user

    Published: 27 Dec 2021
    7.5
    High

    CVE-2021-24998

    Last Modified: 21 Nov 2024

    The Simple JWT Login WordPress plugin before 3.3.0 can be used to create new WordPress user accounts with a randomly generated password. The password is generated using the str_shuffle PHP function that "does not generate cryptographically secure values, and should not be used for cryptographic purposes" according to PHP's documentation.

    Published: 27 Dec 2021
    4.8
    Medium

    CVE-2021-24992

    Last Modified: 21 Nov 2024

    The Smart Floating / Sticky Buttons WordPress plugin before 2.5.5 does not sanitise and escape some parameter before outputting them in attributes and page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 27 Dec 2021
    6.1
    Medium

    CVE-2021-24984

    Last Modified: 21 Nov 2024

    The WPFront User Role Editor WordPress plugin before 3.2.1.11184 does not sanitise and escape the changes-saved parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting

    Published: 27 Dec 2021
    5.4
    Medium

    CVE-2021-24988

    Last Modified: 21 Nov 2024

    The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which could lead to a Stored XSS issue due to the wprss_dismiss_addon_notice AJAX action missing authorisation and CSRF checks, allowing any authenticated users, such as subscriber to call it and set a malicious payload in the addon parameter.

    Published: 27 Dec 2021
    6.1
    Medium

    CVE-2021-24980

    Last Modified: 21 Nov 2024

    The Gwolle Guestbook WordPress plugin before 4.2.0 does not sanitise and escape the gwolle_gb_user_email parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue in an admin page

    Published: 27 Dec 2021
    6.1
    Medium

    CVE-2021-24979

    Last Modified: 21 Nov 2024

    The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

    Published: 27 Dec 2021
    5.4
    Medium

    CVE-2021-24969

    Last Modified: 21 Mar 2025

    The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack of authorisation and CSRF checks in the wpdm_save_template AJAX action, any authenticated users such as subscriber is able to call it and perform Cross-Site Scripting attacks

    Published: 27 Dec 2021
    6.1
    Medium

    CVE-2021-24967

    Last Modified: 21 Nov 2024

    The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead values, which could allow unauthenticated users to perform Cross-Site Scripting attacks against logged in admin viewing the inserted Leads

    Published: 27 Dec 2021
    4.8
    Medium

    CVE-2021-24902

    Last Modified: 21 Nov 2024

    The Typebot | Build beautiful conversational forms WordPress plugin before 1.4.3 does not sanitise and escape the Publish ID setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 27 Dec 2021
    6.1
    Medium

    CVE-2021-24797

    Last Modified: 21 Nov 2024

    The Tickera WordPress plugin before 3.4.8.3 does not properly sanitise and escape the Name fields of booked Events before outputting them in the Orders admin dashboard, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins.

    Published: 27 Dec 2021
    7.2
    High

    CVE-2021-24753

    Last Modified: 21 Nov 2024

    The Rich Reviews by Starfish WordPress plugin before 1.9.6 does not properly validate the orderby GET parameter of the pending reviews page before using it in a SQL statement, leading to an authenticated SQL injection issue

    Published: 27 Dec 2021
    8.8
    High

    CVE-2021-43858

    Last Modified: 21 Nov 2024

    MinIO is a Kubernetes native application for cloud storage. Prior to version `RELEASE.2021-12-27T07-23-18Z`, a malicious client can hand-craft an HTTP API call that allows for updating policy for a user and gaining higher privileges. The patch in version `RELEASE.2021-12-27T07-23-18Z` changes the accepted request body type and removes the ability to apply policy changes through this API. There is a workaround for this vulnerability: Changing passwords can be disabled by adding an explicit `Deny` rule to disable the API for users.

    Published: 27 Dec 2021
    8.2
    High

    CVE-2021-43845

    Last Modified: 4 Nov 2025

    PJSIP is a free and open source multimedia communication library. In version 2.11.1 and prior, if incoming RTCP XR message contain block, the data field is not checked against the received packet size, potentially resulting in an out-of-bound read access. This affects all users that use PJMEDIA and RTCP XR. A malicious actor can send a RTCP XR message with an invalid packet size.

    Published: 27 Dec 2021
    7.8
    High

    CVE-2021-4173

    Last Modified: 3 Nov 2025

    vim is vulnerable to Use After Free

    Published: 27 Dec 2021
    7.8
    High

    CVE-2021-4187

    Last Modified: 3 Nov 2025

    vim is vulnerable to Use After Free

    Published: 27 Dec 2021
    9.8
    Critical

    CVE-2018-25024

    Last Modified: 21 Nov 2024

    An issue was discovered in the actix-web crate before 0.7.15 for Rust. It can unsoundly coerce an immutable reference into a mutable reference, leading to memory corruption.

    Published: 26 Dec 2021
    9.8
    Critical

    CVE-2018-25025

    Last Modified: 21 Nov 2024

    An issue was discovered in the actix-web crate before 0.7.15 for Rust. It can unsoundly extend the lifetime of a string, leading to memory corruption.

    Published: 26 Dec 2021
    9.8
    Critical

    CVE-2018-25026

    Last Modified: 21 Nov 2024

    An issue was discovered in the actix-web crate before 0.7.15 for Rust. It can add the Send marker trait to an object that cannot be sent between threads safely, leading to memory corruption.

    Published: 26 Dec 2021
    7.5
    High

    CVE-2018-25027

    Last Modified: 21 Nov 2024

    An issue was discovered in the libpulse-binding crate before 1.2.1 for Rust. get_format_info can cause a use-after-free.

    Published: 26 Dec 2021
    7.5
    High

    CVE-2018-25028

    Last Modified: 21 Nov 2024

    An issue was discovered in the libpulse-binding crate before 1.2.1 for Rust. get_context can cause a use-after-free.

    Published: 26 Dec 2021
    7.5
    High

    CVE-2019-25054

    Last Modified: 21 Nov 2024

    An issue was discovered in the pnet crate before 0.27.2 for Rust. There is a segmentation fault (upon attempted dereference of an uninitialized descriptor) because of an erroneous IcmpTransportChannelIterator compiler optimization.

    Published: 26 Dec 2021
    7.5
    High

    CVE-2019-25055

    Last Modified: 21 Nov 2024

    An issue was discovered in the libpulse-binding crate before 2.6.0 for Rust. It mishandles a panic that crosses a Foreign Function Interface (FFI) boundary.

    Published: 26 Dec 2021
    7.5
    High

    CVE-2020-36511

    Last Modified: 21 Nov 2024

    An issue was discovered in the bite crate through 2020-12-31 for Rust. read::BiteReadExpandedExt::read_framed_max may read from uninitialized memory locations.

    Published: 26 Dec 2021
    9.8
    Critical

    CVE-2020-36512

    Last Modified: 21 Nov 2024

    An issue was discovered in the buffoon crate through 2020-12-31 for Rust. InputStream::read_exact may read from uninitialized memory locations.

    Published: 26 Dec 2021
    9.8
    Critical

    CVE-2020-36513

    Last Modified: 21 Nov 2024

    An issue was discovered in the acc_reader crate through 2020-12-27 for Rust. read_up_to may read from uninitialized memory locations.

    Published: 26 Dec 2021
    9.8
    Critical

    CVE-2020-36514

    Last Modified: 21 Nov 2024

    An issue was discovered in the acc_reader crate through 2020-12-27 for Rust. fill_buf may read from uninitialized memory locations.

    Published: 26 Dec 2021
    7.5
    High

    CVE-2021-45680

    Last Modified: 21 Nov 2024

    An issue was discovered in the vec-const crate before 2.0.0 for Rust. It tries to construct a Vec from a pointer to a const slice, leading to memory corruption.

    Published: 26 Dec 2021
    7.5
    High

    CVE-2021-45681

    Last Modified: 21 Nov 2024

    An issue was discovered in the derive-com-impl crate before 0.1.2 for Rust. An invalid reference (and memory corruption) can occur because AddRef might not be called before returning a pointer.

    Published: 26 Dec 2021
    9.8
    Critical

    CVE-2021-45682

    Last Modified: 21 Nov 2024

    An issue was discovered in the bronzedb-protocol crate through 2021-01-03 for Rust. ReadKVExt may read from uninitialized memory locations.

    Published: 26 Dec 2021
    9.8
    Critical

    CVE-2021-45683

    Last Modified: 21 Nov 2024

    An issue was discovered in the binjs_io crate through 2021-01-03 for Rust. The Read method may read from uninitialized memory locations.

    Published: 26 Dec 2021
    9.8
    Critical

    CVE-2021-45684

    Last Modified: 21 Nov 2024

    An issue was discovered in the flumedb crate through 2021-01-07 for Rust. read_entry may read from uninitialized memory locations.

    Published: 26 Dec 2021
    9.8
    Critical

    CVE-2021-45685

    Last Modified: 21 Nov 2024

    An issue was discovered in the columnar crate through 2021-01-07 for Rust. ColumnarReadExt::read_typed_vec may read from uninitialized memory locations.

    Published: 26 Dec 2021
    9.8
    Critical

    CVE-2021-45687

    Last Modified: 21 Nov 2024

    An issue was discovered in the raw-cpuid crate before 9.1.1 for Rust. If the serialize feature is used (which is not the the default), a Deserialize operation may lack sufficient validation, leading to memory corruption or a panic.

    Published: 26 Dec 2021
    9.8
    Critical

    CVE-2021-45688

    Last Modified: 30 Sept 2025

    An issue was discovered in the ash crate before 0.33.1 for Rust. util::read_spv may read from uninitialized memory locations.

    Published: 26 Dec 2021
    9.8
    Critical

    CVE-2021-45689

    Last Modified: 21 Nov 2024

    An issue was discovered in the gfx-auxil crate through 2021-01-07 for Rust. gfx_auxil::read_spirv may read from uninitialized memory locations.

    Published: 26 Dec 2021
    9.8
    Critical

    CVE-2021-45690

    Last Modified: 21 Nov 2024

    An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_binary may read from uninitialized memory locations.

    Published: 26 Dec 2021
    9.8
    Critical

    CVE-2021-45691

    Last Modified: 21 Nov 2024

    An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_string may read from uninitialized memory locations.

    Published: 26 Dec 2021
    9.8
    Critical

    CVE-2021-45692

    Last Modified: 21 Nov 2024

    An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_extension_others may read from uninitialized memory locations.

    Published: 26 Dec 2021