CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2021-24892

    Last Modified: 21 Nov 2024

    Insecure Direct Object Reference in edit function of Advanced Forms (Free & Pro) before 1.6.9 allows authenticated remote attacker to change arbitrary user's email address and request for reset password, which could lead to take over of WordPress's administrator account. To exploit this vulnerability, an attacker must register to obtain a valid WordPress's user and use such user to authenticate with WordPress in order to exploit the vulnerable edit function.

    Published: 23 Nov 2021
    6.1
    Medium

    CVE-2021-24891

    Last Modified: 21 Nov 2024

    The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue.

    Published: 23 Nov 2021
    4.8
    Medium

    CVE-2021-24888

    Last Modified: 21 Nov 2024

    The ImageBoss WordPress plugin before 3.0.6 does not sanitise and escape its Source Name setting, which could allow high privilege users to perform Cross-Site Scripting attacks

    Published: 23 Nov 2021
    4.8
    Medium

    CVE-2021-24882

    Last Modified: 21 Nov 2024

    The Slideshow Gallery WordPress plugin before 1.7.4 does not sanitise and escape the Slide "Title", "Description", and Gallery "Title" fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

    Published: 23 Nov 2021
    7.2
    High

    CVE-2021-24877

    Last Modified: 21 Nov 2024

    The MainWP Child WordPress plugin before 4.1.8 does not validate the orderby and order parameter before using them in a SQL statement, leading to an SQL injection exploitable by high privilege users such as admin when the Backup and Staging by WP Time Capsule plugin is installed

    Published: 23 Nov 2021
    6.1
    Medium

    CVE-2021-24875

    Last Modified: 21 Nov 2024

    The eCommerce Product Catalog Plugin for WordPress plugin before 3.0.39 does not escape the ic-settings-search parameter before outputting it back in the page in an attribute, leading to a Reflected Cross-Site Scripting issue

    Published: 23 Nov 2021
    6.1
    Medium

    CVE-2021-24873

    Last Modified: 21 Nov 2024

    The Tutor LMS WordPress plugin before 1.9.11 does not sanitise and escape user input before outputting back in attributes in the Student Registration page, leading to a Reflected Cross-Site Scripting issue

    Published: 23 Nov 2021
    4.8
    Medium

    CVE-2021-24830

    Last Modified: 21 Nov 2024

    The Advanced Access Manager WordPress plugin before 6.8.0 does not escape some of its settings when outputting them, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 23 Nov 2021
    5.4
    Medium

    CVE-2021-24812

    Last Modified: 21 Nov 2024

    The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lead to Stored Cross-Site Scripting issues when an admin import a malicious CSV.

    Published: 23 Nov 2021
    5.4
    Medium

    CVE-2021-24729

    Last Modified: 21 Nov 2024

    The Logo Showcase with Slick Slider WordPress plugin before 1.2.4 does not sanitise the Grid Settings, which could allow users with a role as low as Author to perform stored Cross-Site Scripting attacks via post metadata of Grid logo showcase.

    Published: 23 Nov 2021
    4.8
    Medium

    CVE-2021-24713

    Last Modified: 24 Aug 2026

    The Video Lessons Manager WordPress plugin before 1.7.2 and Video Lessons Manager Pro WordPress plugin before 3.5.9 do not properly sanitize and escape values when updating their settings, which could allow high privilege users to perform Cross-Site Scripting attacks

    Published: 23 Nov 2021
    5.7
    Medium

    CVE-2021-24703

    Last Modified: 21 Nov 2024

    The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are already installed.

    Published: 23 Nov 2021
    4.8
    Medium

    CVE-2021-24700

    Last Modified: 21 Nov 2024

    The Forminator WordPress plugin before 1.15.4 does not sanitize and escape the email field label, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

    Published: 23 Nov 2021
    4.3
    Medium

    CVE-2021-24668

    Last Modified: 21 Nov 2024

    The MAZ Loader WordPress plugin before 1.4.1 does not enforce nonce checks, which allows attackers to make administrators delete arbitrary loaders via a CSRF attack

    Published: 23 Nov 2021
    7.5
    High

    CVE-2021-24644

    Last Modified: 21 Nov 2024

    The Images to WebP WordPress plugin before 1.9 does not validate or sanitise the tab parameter before passing it to the include() function, which could lead to a Local File Inclusion issue

    Published: 23 Nov 2021
    8.1
    High

    CVE-2021-24641

    Last Modified: 21 Nov 2024

    The Images to WebP WordPress plugin before 1.9 does not have CSRF checks in place when performing some administrative actions, which could result in modification of plugin settings, Denial-of-Service, as well as arbitrary image conversion

    Published: 23 Nov 2021
    5.3
    Medium

    CVE-2021-38980

    Last Modified: 21 Nov 2024

    IBM Tivoli Key Lifecycle Manager (IBM Security Guardium Key Lifecycle Manager) 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 212786.

    Published: 23 Nov 2021
    7.5
    High

    CVE-2021-38891

    Last Modified: 21 Nov 2024

    IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 209508.

    Published: 23 Nov 2021
    7.5
    High

    CVE-2021-38890

    Last Modified: 21 Nov 2024

    IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 209507.

    Published: 23 Nov 2021
    6.5
    Medium

    CVE-2021-38875

    Last Modified: 21 Nov 2024

    IBM MQ 8.0, 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.1 CD, and 9.2 CD is vulnerable to a denial of service attack caused by an error processing messages. IBM X-Force ID: 208398.

    Published: 23 Nov 2021
    7.5
    High

    CVE-2021-41281

    Last Modified: 21 Nov 2024

    Synapse is a package for Matrix homeservers written in Python 3/Twisted. Prior to version 1.47.1, Synapse instances with the media repository enabled can be tricked into downloading a file from a remote server into an arbitrary directory. No authentication is required for the affected endpoint. The last 2 directories and file name of the path are chosen randomly by Synapse and cannot be controlled by an attacker, which limits the impact. Homeservers with the media repository disabled are unaffected. Homeservers with a federation whitelist are also unaffected, since Synapse will check the remote hostname, including the trailing `../`s, against the whitelist. Server administrators should upgrade to 1.47.1 or later. Server administrators using a reverse proxy could, at the expense of losing media functionality, may block the certain endpoints as a workaround. Alternatively, non-containerized deployments can be adapted to use the hardened systemd config.

    Published: 23 Nov 2021
    8.6
    High

    CVE-2021-43775

    Last Modified: 21 Nov 2024

    Aim is an open-source, self-hosted machine learning experiment tracking tool. Versions of Aim prior to 3.1.0 are vulnerable to a path traversal attack. By manipulating variables that reference files with “dot-dot-slash (../)” sequences and its variations or by using absolute file paths, it may be possible to access arbitrary files and directories stored on file system including application source code or configuration and critical system files. The vulnerability issue is resolved in Aim v3.1.0.

    Published: 23 Nov 2021
    7.8
    High

    CVE-2021-43019

    Last Modified: 23 Apr 2025

    Adobe Creative Cloud version 5.5 (and earlier) are affected by a privilege escalation vulnerability in the resources leveraged by the Setup.exe service. An unauthenticated attacker could leverage this vulnerability to remove files and escalate privileges under the context of SYSTEM . An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability on the product installer. User interaction is required before product installation to abuse this vulnerability.

    Published: 23 Nov 2021
    —
    Unknown

    CVE-2021-44173

    Last Modified: 17 Mar 2025

    Not used

    Published: 23 Nov 2021
    —
    Unknown

    CVE-2021-44174

    Last Modified: 17 Mar 2025

    Not used

    Published: 23 Nov 2021
    —
    Unknown

    CVE-2021-44175

    Last Modified: 17 Mar 2025

    Not used

    Published: 23 Nov 2021
    7.8
    High

    CVE-2021-35052

    Last Modified: 21 Nov 2024

    A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to High.

    Published: 23 Nov 2021
    5.3
    Medium

    CVE-2021-37013

    Last Modified: 21 Nov 2024

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the availability of users is affected.

    Published: 23 Nov 2021
    7.5
    High

    CVE-2021-37006

    Last Modified: 21 Nov 2024

    There is a Improper Preservation of Permissions vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the confidentiality of users is affected.

    Published: 23 Nov 2021
    7.5
    High

    CVE-2021-37010

    Last Modified: 21 Nov 2024

    There is a Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the confidentiality of users is affected.

    Published: 23 Nov 2021
    9.8
    Critical

    CVE-2021-37022

    Last Modified: 21 Nov 2024

    There is a Heap-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause root permission which can be escalated.

    Published: 23 Nov 2021
    6.5
    Medium

    CVE-2021-37023

    Last Modified: 21 Nov 2024

    There is a Improper Access Control vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause media files which can be reads and writes in non-distributed directories on any device on the network..

    Published: 23 Nov 2021
    7.5
    High

    CVE-2021-37024

    Last Modified: 21 Nov 2024

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

    Published: 23 Nov 2021
    7.5
    High

    CVE-2021-37025

    Last Modified: 21 Nov 2024

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

    Published: 23 Nov 2021
    7.5
    High

    CVE-2021-37004

    Last Modified: 21 Nov 2024

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

    Published: 23 Nov 2021
    7.5
    High

    CVE-2021-37012

    Last Modified: 21 Nov 2024

    There is a Data Processing Errors vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

    Published: 23 Nov 2021
    7.5
    High

    CVE-2021-37018

    Last Modified: 21 Nov 2024

    There is a Data Processing Errors vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

    Published: 23 Nov 2021
    7.5
    High

    CVE-2021-37005

    Last Modified: 21 Nov 2024

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

    Published: 23 Nov 2021
    7.5
    High

    CVE-2021-37017

    Last Modified: 21 Nov 2024

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

    Published: 23 Nov 2021
    7.5
    High

    CVE-2021-37026

    Last Modified: 21 Nov 2024

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

    Published: 23 Nov 2021
    7.5
    High

    CVE-2021-37019

    Last Modified: 21 Nov 2024

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

    Published: 23 Nov 2021
    7.5
    High

    CVE-2021-37003

    Last Modified: 21 Nov 2024

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

    Published: 23 Nov 2021
    7.5
    High

    CVE-2021-37015

    Last Modified: 21 Nov 2024

    There is a Out-of-bounds Read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

    Published: 23 Nov 2021
    7.5
    High

    CVE-2021-37008

    Last Modified: 21 Nov 2024

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

    Published: 23 Nov 2021
    9.1
    Critical

    CVE-2021-37016

    Last Modified: 21 Nov 2024

    There is a Out-of-bounds Read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause Information Disclosure or Denial of Service.

    Published: 23 Nov 2021
    7.5
    High

    CVE-2021-37007

    Last Modified: 21 Nov 2024

    There is a Out-of-bounds Read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

    Published: 23 Nov 2021
    7.5
    High

    CVE-2021-37009

    Last Modified: 21 Nov 2024

    There is a Configuration vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the confidentiality of users is affected.

    Published: 23 Nov 2021
    7.5
    High

    CVE-2021-37035

    Last Modified: 21 Nov 2024

    There is a Remote DoS vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the app to exit unexpectedly.

    Published: 23 Nov 2021
    7.5
    High

    CVE-2021-37034

    Last Modified: 21 Nov 2024

    There is an Unstandardized field names in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 23 Nov 2021
    7.5
    High

    CVE-2021-37033

    Last Modified: 21 Nov 2024

    There is an Injection attack vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.

    Published: 23 Nov 2021