CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-45090

    Last Modified: 21 Nov 2024

    Stormshield Endpoint Security before 2.1.2 allows remote code execution.

    Published: 21 Dec 2021
    5.2
    Medium

    CVE-2021-45089

    Last Modified: 21 Nov 2024

    Stormshield Endpoint Security 2.x before 2.1.2 has Incorrect Access Control.

    Published: 21 Dec 2021
    4.3
    Medium

    CVE-2021-45091

    Last Modified: 21 Nov 2024

    Stormshield Endpoint Security from 2.1.0 to 2.1.1 has Incorrect Access Control.

    Published: 21 Dec 2021
    9
    Critical

    CVE-2021-4139

    Last Modified: 21 Nov 2024

    pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 21 Dec 2021
    9.8
    Critical

    CVE-2021-45255

    Last Modified: 21 Nov 2024

    The email parameter from ajax.php of Video Sharing Website 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The application interacted with that domain, indicating that the injected SQL query was executed.

    Published: 21 Dec 2021
    9.8
    Critical

    CVE-2021-45253

    Last Modified: 21 Nov 2024

    The id parameter in view_storage.php from Simple Cold Storage Management System 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The application interacted with that domain, indicating that the injected SQL query was executed.

    Published: 21 Dec 2021
    9.8
    Critical

    CVE-2021-45252

    Last Modified: 21 Nov 2024

    Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications which are manage_topic.php, manage_user.php, and ajax.php. The attacker can be retrieving all information from the database of this system by using this vulnerability.

    Published: 21 Dec 2021
    7.5
    High

    CVE-2021-24981

    Last Modified: 21 Nov 2024

    The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins directory.

    Published: 21 Dec 2021
    6.1
    Medium

    CVE-2021-24956

    Last Modified: 21 Nov 2024

    The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sShowByDate parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

    Published: 21 Dec 2021
    6.1
    Medium

    CVE-2021-24941

    Last Modified: 21 Nov 2024

    The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape the message_id parameter of the get_message_action_row AJAX action before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue

    Published: 21 Dec 2021
    6.1
    Medium

    CVE-2021-24907

    Last Modified: 21 Nov 2024

    The Contact Form, Drag and Drop Form Builder for WordPress plugin before 1.8.0 does not escape the status parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue

    Published: 21 Dec 2021
    9.8
    Critical

    CVE-2021-24849

    Last Modified: 21 Nov 2024

    The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections

    Published: 21 Dec 2021
    8.8
    High

    CVE-2021-24846

    Last Modified: 21 Nov 2024

    The get_query() function of the Ni WooCommerce Custom Order Status WordPress plugin before 1.9.7, used by the niwoocos_ajax AJAX action, available to all authenticated users, does not properly sanitise the sort parameter before using it in a SQL statement, leading to an SQL injection, exploitable by any authenticated users, such as subscriber

    Published: 21 Dec 2021
    8.8
    High

    CVE-2021-24750

    Last Modified: 6 Mar 2026

    The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks

    Published: 21 Dec 2021
    8.1
    High

    CVE-2021-24739

    Last Modified: 21 Nov 2024

    The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arbitrary private posts made by other users via the Carousel Duplication feature

    Published: 21 Dec 2021
    5.4
    Medium

    CVE-2021-24738

    Last Modified: 21 Nov 2024

    The Logo Carousel WordPress plugin before 3.4.2 does not validate and escape the "Logo Margin" carousel option, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks

    Published: 21 Dec 2021
    6.1
    Medium

    CVE-2021-24578

    Last Modified: 21 Nov 2024

    The SportsPress WordPress plugin before 2.7.9 does not sanitise and escape its match_day parameter before outputting back in the Events backend page, leading to a Reflected Cross-Site Scripting issue

    Published: 21 Dec 2021
    7.5
    High

    CVE-2021-45450

    Last Modified: 5 Jun 2026

    In Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.

    Published: 21 Dec 2021
    5.3
    Medium

    CVE-2021-4189

    Last Modified: 17 Dec 2025

    A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. This vulnerability could lead to FTP client scanning ports, which otherwise would not have been possible.

    Published: 21 Dec 2021
    5.5
    Medium

    CVE-2021-45291

    Last Modified: 21 Nov 2024

    The gf_dump_setup function in GPAC 1.0.1 allows malicoius users to cause a denial of service (Invalid memory address dereference) via a crafted file in the MP4Box command.

    Published: 21 Dec 2021
    5.5
    Medium

    CVE-2021-45292

    Last Modified: 21 Nov 2024

    The gf_isom_hint_rtp_read function in GPAC 1.0.1 allows attackers to cause a denial of service (Invalid memory address dereference) via a crafted file in the MP4Box command.

    Published: 21 Dec 2021
    7.5
    High

    CVE-2021-45451

    Last Modified: 21 Nov 2024

    In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.

    Published: 21 Dec 2021
    —
    Unknown

    CVE-2022-22165

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 21 Dec 2021
    —
    Unknown

    CVE-2022-22199

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 21 Dec 2021
    —
    Unknown

    CVE-2022-22200

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 21 Dec 2021
    5.5
    Medium

    CVE-2022-2867

    Last Modified: 21 Nov 2024

    libtiff's tiffcrop utility has a uint32_t underflow that can lead to out of bounds read and write. An attacker who supplies a crafted file to tiffcrop (likely via tricking a user to run tiffcrop on it with certain parameters) could cause a crash or in some cases, further exploitation.

    Published: 21 Dec 2021
    5.5
    Medium

    CVE-2022-2869

    Last Modified: 21 Nov 2024

    libtiff's tiffcrop tool has a uint32_t underflow which leads to out of bounds read and write in the extractContigSamples8bits routine. An attacker who supplies a crafted file to tiffcrop could trigger this flaw, most likely by tricking a user into opening the crafted file with tiffcrop. Triggering this flaw could cause a crash or potentially further exploitation.

    Published: 21 Dec 2021
    5.5
    Medium

    CVE-2021-44917

    Last Modified: 21 Nov 2024

    A Divide by Zero vulnerability exists in gnuplot 5.4 in the boundary3d function in graph3d.c, which could cause a Arithmetic exception and application crash.

    Published: 21 Dec 2021
    5.5
    Medium

    CVE-2021-45297

    Last Modified: 21 Nov 2024

    An infinite loop vulnerability exists in Gpac 1.0.1 in gf_get_bit_size.

    Published: 21 Dec 2021
    —
    Unknown

    CVE-2022-22158

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 21 Dec 2021
    —
    Unknown

    CVE-2020-3709

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 20 Dec 2021
    —
    Unknown

    CVE-2020-3708

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 20 Dec 2021
    —
    Unknown

    CVE-2020-3707

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 20 Dec 2021
    —
    Unknown

    CVE-2020-3706

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 20 Dec 2021
    —
    Unknown

    CVE-2020-3705

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 20 Dec 2021
    —
    Unknown

    CVE-2020-3697

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 20 Dec 2021
    —
    Unknown

    CVE-2020-3682

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 20 Dec 2021
    —
    Unknown

    CVE-2020-3695

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 20 Dec 2021
    —
    Unknown

    CVE-2020-3631

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 20 Dec 2021
    —
    Unknown

    CVE-2020-3627

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 20 Dec 2021
    —
    Unknown

    CVE-2020-16835

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 20 Dec 2021
    —
    Unknown

    CVE-2020-16836

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 20 Dec 2021
    —
    Unknown

    CVE-2020-16834

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 20 Dec 2021
    —
    Unknown

    CVE-2020-16833

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 20 Dec 2021
    —
    Unknown

    CVE-2020-16831

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 20 Dec 2021
    —
    Unknown

    CVE-2020-16832

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 20 Dec 2021
    —
    Unknown

    CVE-2020-16830

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 20 Dec 2021
    —
    Unknown

    CVE-2020-16829

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 20 Dec 2021
    —
    Unknown

    CVE-2020-16827

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 20 Dec 2021
    —
    Unknown

    CVE-2020-16828

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 20 Dec 2021