CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2021-42358

    Last Modified: 13 Feb 2025

    The Contact Form With Captcha WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation in the ~/cfwc-form.php file during contact form submission, which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 1.6.2.

    Published: 29 Nov 2021
    6.5
    Medium

    CVE-2021-39995

    Last Modified: 21 Nov 2024

    Some Huawei products use the OpenHpi software for hardware management. A function that parses data returned by OpenHpi contains an out-of-bounds read vulnerability that could lead to a denial of service. Affected product versions include: eCNS280_TD V100R005C10; eSE620X vESS V100R001C10SPC200, V100R001C20SPC200, V200R001C00SPC300.

    Published: 29 Nov 2021
    9.8
    Critical

    CVE-2021-43691

    Last Modified: 21 Nov 2024

    tripexpress v1.1 is affected by a path manipulation vulnerability in file system/helpers/dompdf/load_font.php. The variable src is coming from $_SERVER["argv"] then there is a path manipulation vulnerability.

    Published: 29 Nov 2021
    6.1
    Medium

    CVE-2021-43692

    Last Modified: 21 Nov 2024

    youtube-php-mirroring (last update Jun 9, 2017) is affected by a Cross Site Scripting (XSS) vulnerability in file ytproxy/index.php.

    Published: 29 Nov 2021
    9.8
    Critical

    CVE-2021-43693

    Last Modified: 21 Nov 2024

    vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php.

    Published: 29 Nov 2021
    6.1
    Medium

    CVE-2021-43695

    Last Modified: 21 Nov 2024

    issabelPBX version 2.11 is affected by a Cross Site Scripting (XSS) vulnerability. In file page.backup_restore.php, the exit function will terminate the script and print the message to the user. The message will contain $_REQUEST without sanitization, then there is a XSS vulnerability.

    Published: 29 Nov 2021
    6.1
    Medium

    CVE-2021-43696

    Last Modified: 21 Nov 2024

    twmap v2.91_v4.33 is affected by a Cross Site Scripting (XSS) vulnerability. In file list.php, the exit function will terminate the script and print the message to the user. The message will contain $_REQUEST then there is a XSS vulnerability.

    Published: 29 Nov 2021
    6.1
    Medium

    CVE-2021-43697

    Last Modified: 21 Nov 2024

    Workerman-ThinkPHP-Redis (last update Mar 16, 2018) is affected by a Cross Site Scripting (XSS) vulnerability. In file Controller.class.php, the exit function will terminate the script and print the message to the user. The message will contain $_GET{C('VAR_JSONP_HANDLER')] then there is a XSS vulnerability.

    Published: 29 Nov 2021
    6.1
    Medium

    CVE-2021-43698

    Last Modified: 21 Nov 2024

    phpWhois (last update Jun 30 2021) is affected by a Cross Site Scripting (XSS) vulnerability. In file example.php, the exit function will terminate the script and print the message to the user. The message will contain $_GET['query'] then there is a XSS vulnerability.

    Published: 29 Nov 2021
    5.4
    Medium

    CVE-2021-24927

    Last Modified: 21 Nov 2024

    The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue

    Published: 29 Nov 2021
    5.4
    Medium

    CVE-2021-24918

    Last Modified: 21 Nov 2024

    The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript on each of its posts and pages.

    Published: 29 Nov 2021
    9.8
    Critical

    CVE-2021-24915

    Last Modified: 21 Nov 2024

    The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform SQL injections attacks, as well as get the list of all users registered on the blog, including their username and email address

    Published: 29 Nov 2021
    6.1
    Medium

    CVE-2021-24908

    Last Modified: 21 Nov 2024

    The Check & Log Email WordPress plugin before 1.0.4 does not escape the d parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

    Published: 29 Nov 2021
    4.8
    Medium

    CVE-2021-24899

    Last Modified: 21 Nov 2024

    The Media-Tags WordPress plugin through 3.2.0.2 does not sanitise and escape any of its Labels settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_htnl capability is disallowed.

    Published: 29 Nov 2021
    7.2
    High

    CVE-2021-24889

    Last Modified: 21 Nov 2024

    The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks

    Published: 29 Nov 2021
    5.4
    Medium

    CVE-2021-24883

    Last Modified: 21 Nov 2024

    The Popup Anything WordPress plugin before 2.0.4 does not escape the Link Text and Button Text fields of Popup, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks

    Published: 29 Nov 2021
    6.1
    Medium

    CVE-2021-24876

    Last Modified: 21 Nov 2024

    The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

    Published: 29 Nov 2021
    7.2
    High

    CVE-2021-24860

    Last Modified: 21 Nov 2024

    The BSK PDF Manager WordPress plugin before 3.1.2 does not validate and escape the orderby and order parameters before using them in a SQL statement, leading to a SQL injection issue

    Published: 29 Nov 2021
    5.4
    Medium

    CVE-2021-24842

    Last Modified: 21 Nov 2024

    The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contributor roles to 1) list private post titles of other users and 2) change the posted date of other users' posts.

    Published: 29 Nov 2021
    5.4
    Medium

    CVE-2021-24822

    Last Modified: 21 Nov 2024

    The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and CSRF checks on some of its AJAX actions (available to authenticated users), which could allow any authenticated users, such as subscriber to call them, and perform Stored Cross-Site Scripting attacks against logged in admin, as well as frontend users due to the lack of sanitisation and escaping in some parameters

    Published: 29 Nov 2021
    4.8
    Medium

    CVE-2021-24811

    Last Modified: 21 Nov 2024

    The Shop Page WP WordPress plugin before 1.2.8 does not sanitise and escape some of the Product fields, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 29 Nov 2021
    4.8
    Medium

    CVE-2021-24768

    Last Modified: 21 Nov 2024

    The WP RSS Aggregator WordPress plugin before 4.19.2 does not properly sanitise and escape the URL to Blacklist field, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html capability is disallowed, which could lead to Cross-Site Scripting issues.

    Published: 29 Nov 2021
    8.8
    High

    CVE-2021-24755

    Last Modified: 17 Oct 2025

    The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL statement, leading to an SQL injection exploitable by any authenticated user

    Published: 29 Nov 2021
    5.4
    Medium

    CVE-2021-24751

    Last Modified: 21 Nov 2024

    The GenerateBlocks WordPress plugin before 1.4.0 does not validate the generateblocks/container block's tagName attribute, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.

    Published: 29 Nov 2021
    4.3
    Medium

    CVE-2021-24749

    Last Modified: 30 Jan 2026

    The URL Shortify WordPress plugin before 1.5.1 does not have CSRF check in place when bulk-deleting links or groups, which could allow attackers to make a logged in admin delete arbitrary link and group via a CSRF attack.

    Published: 29 Nov 2021
    8.8
    High

    CVE-2021-24748

    Last Modified: 21 Nov 2024

    The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET parameters before using them in SQL statements, leading to authenticated SQL injection issues

    Published: 29 Nov 2021
    5.4
    Medium

    CVE-2021-24745

    Last Modified: 21 Nov 2024

    The About Author Box WordPress plugin before 1.0.2 does not sanitise and escape the Social Profiles field values before outputting them in attributes, which could allow user with a role as low as contributor to perform Cross-Site Scripting attacks.

    Published: 29 Nov 2021
    6.1
    Medium

    CVE-2017-20008

    Last Modified: 21 Nov 2024

    The myCred WordPress plugin before 1.7.8 does not sanitise and escape the user parameter before outputting it back in the Points Log admin dashboard, leading to a Reflected Cross-Site Scripting

    Published: 29 Nov 2021
    7.5
    High

    CVE-2021-38283

    Last Modified: 21 Nov 2024

    Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read application log files containing sensitive information via a predictable /log URI.

    Published: 29 Nov 2021
    7.5
    High

    CVE-2021-38147

    Last Modified: 21 Nov 2024

    Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as reports containing sensitive information, because authentication is not required for API access to processexecution/DownloadExcelFile/Domain_Credential_Report_Excel, processexecution/DownloadExcelFile/User_Report_Excel, processexecution/DownloadExcelFile/Process_Report_Excel, processexecution/DownloadExcelFile/Infrastructure_Report_Excel, or processexecution/DownloadExcelFile/Resolver_Report_Excel.

    Published: 29 Nov 2021
    9.8
    Critical

    CVE-2021-44077

    Last Modified: 31 Oct 2025

    Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.

    Published: 29 Nov 2021
    5.3
    Medium

    CVE-2021-32061

    Last Modified: 21 Nov 2024

    S3Scanner before 2.0.2 allows Directory Traversal via a crafted bucket, as demonstrated by a <Key>../ substring in a ListBucketResult element.

    Published: 29 Nov 2021
    6.3
    Medium

    CVE-2021-44964

    Last Modified: 21 Nov 2024

    Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.

    Published: 29 Nov 2021
    6.5
    Medium

    CVE-2021-4147

    Last Modified: 21 Nov 2024

    A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition.

    Published: 29 Nov 2021
    7.8
    High

    CVE-2021-44094

    Last Modified: 21 Nov 2024

    ZrLog 2.2.2 has a remote command execution vulnerability at plugin download function, it could execute any JAR file

    Published: 28 Nov 2021
    9.8
    Critical

    CVE-2021-44093

    Last Modified: 21 Nov 2024

    A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass the original limit, upload the JSP file to get a WebShell

    Published: 28 Nov 2021
    5.4
    Medium

    CVE-2021-4020

    Last Modified: 21 Nov 2024

    janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 27 Nov 2021
    5.6
    Medium

    CVE-2021-23654

    Last Modified: 21 Nov 2024

    This affects all versions of package html-to-csv. When there is a formula embedded in a HTML page, it gets accepted without any validation and the same would be pushed while converting it into a CSV file. Through this a malicious actor can embed or generate a malicious link or execute commands via CSV files.

    Published: 26 Nov 2021
    7.6
    High

    CVE-2021-43785

    Last Modified: 21 Nov 2024

    @joeattardi/emoji-button is a Vanilla JavaScript emoji picker component. In affected versions there are two vectors for XSS attacks: a URL for a custom emoji, and an i18n string. In both of these cases, a value can be crafted such that it can insert a `script` tag into the page and execute malicious code.

    Published: 26 Nov 2021
    7.4
    High

    CVE-2021-43776

    Last Modified: 21 Nov 2024

    Backstage is an open platform for building developer portals. In affected versions the auth-backend plugin allows a malicious actor to trick another user into visiting a vulnerable URL that executes an XSS attack. This attack can potentially allow the attacker to exfiltrate access tokens or other secrets from the user's browser. The default CSP does prevent this attack, but it is expected that some deployments have these policies disabled due to incompatibilities. This is vulnerability is patched in version `0.4.9` of `@backstage/plugin-auth-backend`.

    Published: 26 Nov 2021
    7.7
    High

    CVE-2021-41279

    Last Modified: 21 Nov 2024

    BaserCMS is an open source content management system with a focus on Japanese language support. In affected versions users with upload privilege may upload crafted zip files capable of path traversal on the host operating system. This is a vulnerability that needs to be addressed when the management system is used by an unspecified number of users. If you are eligible, please update to the new version as soon as possible.

    Published: 26 Nov 2021
    9.1
    Critical

    CVE-2021-41243

    Last Modified: 21 Nov 2024

    There is a Potential Zip Slip Vulnerability and OS Command Injection Vulnerability on the management system of baserCMS. Users with permissions to upload files may upload crafted zip files which may execute arbitrary commands on the host operating system. This is a vulnerability that needs to be addressed when the management system is used by an unspecified number of users. If you are eligible, please update to the new version as soon as possible.

    Published: 26 Nov 2021
    6.1
    Medium

    CVE-2021-36919

    Last Modified: 28 Mar 2025

    Multiple Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilities in WordPress Awesome Support plugin (versions <= 6.0.6), vulnerable parameters (&id, &assignee).

    Published: 26 Nov 2021
    5.5
    Medium

    CVE-2021-40833

    Last Modified: 21 Nov 2024

    A vulnerability affecting F-Secure antivirus engine was discovered whereby unpacking UPX file can lead to denial-of-service. The vulnerability can be exploited remotely by an attacker. A successful attack will result in denial-of-service of the antivirus engine.

    Published: 26 Nov 2021
    7.5
    High

    CVE-2021-35533

    Last Modified: 21 Nov 2024

    Improper Input Validation vulnerability in the APDU parser in the Bidirectional Communication Interface (BCI) IEC 60870-5-104 function of Hitachi Energy RTU500 series allows an attacker to cause the receiving RTU500 CMU of which the BCI is enabled to reboot when receiving a specially crafted message. By default, BCI IEC 60870-5-104 function is disabled (not configured). This issue affects: Hitachi Energy RTU500 series CMU Firmware version 12.0.* (all versions); CMU Firmware version 12.2.* (all versions); CMU Firmware version 12.4.* (all versions).

    Published: 26 Nov 2021
    4.8
    Medium

    CVE-2021-36843

    Last Modified: 28 Mar 2025

    Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Floating Social Media Icon plugin (versions <= 4.3.5) Social Media Configuration form. Requires high role user like admin.

    Published: 26 Nov 2021
    7.8
    High

    CVE-2021-26615

    Last Modified: 21 Nov 2024

    ARK library allows attackers to execute remote code via the parameter(path value) of Ark_NormalizeAndDupPAthNameW function because of an integer overflow.

    Published: 26 Nov 2021
    8.1
    High

    CVE-2021-26611

    Last Modified: 21 Nov 2024

    HejHome GKW-IC052 IP Camera contained a hard-coded credentials vulnerability. This issue allows remote attackers to operate the IP Camera.(reboot, factory reset, snapshot etc..)

    Published: 26 Nov 2021
    7.5
    High

    CVE-2020-7881

    Last Modified: 21 Nov 2024

    The vulnerability function is enabled when the streamer service related to the AfreecaTV communicated through web socket using 21201 port. A stack-based buffer overflow leading to remote code execution was discovered in strcpy() operate by "FanTicket" field. It is because of stored data without validation of length.

    Published: 26 Nov 2021
    4.4
    Medium

    CVE-2021-25269

    Last Modified: 21 Nov 2024

    A local administrator could prevent the HMPA service from starting despite tamper protection using an unquoted service path vulnerability in the HMPA component of Sophos Intercept X Advanced and Sophos Intercept X Advanced for Server before version 2.0.23, as well as Sophos Exploit Prevention before version 3.8.3.

    Published: 26 Nov 2021