CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2021-24851

    Last Modified: 21 Nov 2024

    The Insert Pages WordPress plugin before 3.7.0 allows users with a role as low as Contributor to access content and metadata from arbitrary posts/pages regardless of their author and status (ie private), using a shortcode. Password protected posts/pages are not affected by such issue.

    Published: 17 Nov 2021
    5.4
    Medium

    CVE-2021-24850

    Last Modified: 21 Nov 2024

    The Insert Pages WordPress plugin before 3.7.0 adds a shortcode that prints out other pages' content and custom fields. It can be used by users with a role as low as Contributor to perform Cross-Site Scripting attacks by storing the payload/s in another post's custom fields.

    Published: 17 Nov 2021
    8.8
    High

    CVE-2021-24847

    Last Modified: 21 Nov 2024

    The importFromRedirection AJAX action of the SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 8.2, available to any authenticated user, does not properly sanitise the offset parameter before using it in a SQL statement, leading an SQL injection when the redirection plugin is also installed

    Published: 17 Nov 2021
    4.8
    Medium

    CVE-2021-24841

    Last Modified: 21 Nov 2024

    The Helpful WordPress plugin before 4.4.59 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 17 Nov 2021
    5.4
    Medium

    CVE-2021-24834

    Last Modified: 21 Nov 2024

    The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in the Create Poll - Options module where a user with a role as low as author is allowed to execute arbitrary script code within the context of the application. This vulnerability is due to insufficient validation of custom label parameters - vote button label , results link label and back to vote caption label.

    Published: 17 Nov 2021
    5.4
    Medium

    CVE-2021-24833

    Last Modified: 21 Nov 2024

    The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability, which exists in the Admin preview module where a user with a role as low as author is allowed to execute arbitrary script code within the context of the application. This vulnerability is due to insufficient validation of question and answer text parameters in Create Poll module.

    Published: 17 Nov 2021
    4.8
    Medium

    CVE-2021-24815

    Last Modified: 21 Nov 2024

    The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created Buttons, which could allow a high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 17 Nov 2021
    8.8
    High

    CVE-2021-24804

    Last Modified: 21 Nov 2024

    The Simple JWT Login WordPress plugin before 3.2.1 does not have nonce checks when saving its settings, allowing attackers to make a logged in admin changed them. Settings such as HMAC verification secret, account registering and default user roles can be updated, which could result in site takeover.

    Published: 17 Nov 2021
    6.5
    Medium

    CVE-2021-24802

    Last Modified: 21 Nov 2024

    The Colorful Categories WordPress plugin before 2.0.15 does not enforce nonce checks which could allow attackers to make a logged in admin or editor change taxonomy colors via a CSRF attack

    Published: 17 Nov 2021
    6.1
    Medium

    CVE-2021-24796

    Last Modified: 21 Nov 2024

    The My Tickets WordPress plugin before 1.8.31 does not properly sanitise and escape the Email field of booked tickets before outputting it in the Payment admin dashboard, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins

    Published: 17 Nov 2021
    4.8
    Medium

    CVE-2021-24787

    Last Modified: 21 Nov 2024

    The Client Invoicing by Sprout Invoices WordPress plugin before 19.9.7 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 17 Nov 2021
    4.3
    Medium

    CVE-2021-24776

    Last Modified: 21 Nov 2024

    The WP Performance Score Booster WordPress plugin before 2.1 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

    Published: 17 Nov 2021
    8.8
    High

    CVE-2021-24772

    Last Modified: 21 Nov 2024

    The Stream WordPress plugin before 3.8.2 does not sanitise and validate the order GET parameter from the Stream Records admin dashboard before using it in a SQL statement, leading to an SQL injection issue.

    Published: 17 Nov 2021
    8.8
    High

    CVE-2021-24758

    Last Modified: 21 Nov 2024

    The Email Log WordPress plugin before 2.4.7 does not properly validate, sanitise and escape the "orderby" and "order" GET parameters before using them in SQL statement in the admin dashboard, leading to SQL injections

    Published: 17 Nov 2021
    4.8
    Medium

    CVE-2021-24598

    Last Modified: 21 Nov 2024

    The Testimonial WordPress plugin before 1.6.0 does not escape some testimonial fields which could allow high privilege users to perform Cross Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 17 Nov 2021
    6.5
    Medium

    CVE-2021-43337

    Last Modified: 21 Nov 2024

    SchedMD Slurm 21.08.* before 21.08.4 has Incorrect Access Control. On sites using the new AccountingStoreFlags=job_script and/or job_env options, the access control rules in SlurmDBD may permit users to request job scripts and environment files to which they should not have access.

    Published: 17 Nov 2021
    7.8
    High

    CVE-2021-3939

    Last Modified: 21 Nov 2024

    Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_locale variable, pointing to static storage, to be freed, in the user_change_language_authorized_cb function. This is reachable via the SetLanguage dbus function. This is fixed in versions 0.6.55-0ubuntu12~20.04.5, 0.6.55-0ubuntu13.3, 0.6.55-0ubuntu14.1.

    Published: 17 Nov 2021
    8.2
    High

    CVE-2021-41164

    Last Modified: 25 Aug 2026

    CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.

    Published: 17 Nov 2021
    7.5
    High

    CVE-2021-39920

    Last Modified: 21 Nov 2024

    NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file

    Published: 17 Nov 2021
    7.5
    High

    CVE-2021-39929

    Last Modified: 21 Nov 2024

    Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

    Published: 17 Nov 2021
    5.5
    Medium

    CVE-2021-33480

    Last Modified: 21 Nov 2024

    An use-after-free vulnerability was discovered in gocr through 0.53-20200802 in context_correction() in pgm2asc.c.

    Published: 17 Nov 2021
    7.8
    High

    CVE-2021-33481

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow vulnerability was discovered in gocr through 0.53-20200802 in try_to_divide_boxes() in pgm2asc.c.

    Published: 17 Nov 2021
    7.5
    High

    CVE-2021-39922

    Last Modified: 21 Nov 2024

    Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

    Published: 17 Nov 2021
    7.5
    High

    CVE-2021-39924

    Last Modified: 21 Nov 2024

    Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

    Published: 17 Nov 2021
    7.5
    High

    CVE-2021-39926

    Last Modified: 21 Nov 2024

    Buffer overflow in the Bluetooth HCI_ISO dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file

    Published: 17 Nov 2021
    7.8
    High

    CVE-2021-33479

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow vulnerability was discovered in gocr through 0.53-20200802 in measure_pitch() in pgm2asc.c.

    Published: 17 Nov 2021
    6.5
    Medium

    CVE-2021-3975

    Last Modified: 21 Nov 2024

    A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged client with a read-only connection could use this flaw to perform a denial of service attack by causing the libvirt daemon to crash.

    Published: 17 Nov 2021
    7.5
    High

    CVE-2021-39921

    Last Modified: 21 Nov 2024

    NULL pointer exception in the Modbus dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

    Published: 17 Nov 2021
    7.5
    High

    CVE-2021-39923

    Last Modified: 21 Nov 2024

    Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

    Published: 17 Nov 2021
    7.5
    High

    CVE-2021-39925

    Last Modified: 21 Nov 2024

    Buffer overflow in the Bluetooth SDP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

    Published: 17 Nov 2021
    7.5
    High

    CVE-2021-39928

    Last Modified: 21 Nov 2024

    NULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

    Published: 17 Nov 2021
    3
    Low

    CVE-2021-41190

    Last Modified: 21 Nov 2024

    The OCI Distribution Spec project defines an API protocol to facilitate and standardize the distribution of content. In the OCI Distribution Specification version 1.0.0 and prior, the Content-Type header alone was used to determine the type of document during push and pull operations. Documents that contain both “manifests” and “layers” fields could be interpreted as either a manifest or an index in the absence of an accompanying Content-Type header. If a Content-Type header changed between two pulls of the same digest, a client may interpret the resulting content differently. The OCI Distribution Specification has been updated to require that a mediaType value present in a manifest or index match the Content-Type header used during the push and pull operations. Clients pulling from a registry may distrust the Content-Type header and reject an ambiguous document that contains both “manifests” and “layers” fields or “manifests” and “config” fields if they are unable to update to version 1.0.1 of the spec.

    Published: 17 Nov 2021
    7.8
    High

    CVE-2021-43997

    Last Modified: 21 Nov 2024

    FreeRTOS versions 10.2.0 through 10.4.5 do not prevent non-kernel code from calling the xPortRaisePrivilege internal function to raise privilege. FreeRTOS versions through 10.4.6 do not prevent a third party that has already independently gained the ability to execute injected code to achieve further privilege escalation by branching directly inside a FreeRTOS MPU API wrapper function with a manually crafted stack frame. These issues affect ARMv7-M MPU ports, and ARMv8-M ports with MPU support enabled (i.e. configENABLE_MPU set to 1). These are fixed in V10.5.0 and in V10.4.3-LTS Patch 3.

    Published: 17 Nov 2021
    7
    High

    CVE-2021-4202

    Last Modified: 21 Nov 2024

    A use-after-free flaw was found in nci_request in net/nfc/nci/core.c in NFC Controller Interface (NCI) in the Linux kernel. This flaw could allow a local attacker with user privileges to cause a data race problem while the device is getting removed, leading to a privilege escalation problem.

    Published: 17 Nov 2021
    7.8
    High

    CVE-2021-43011

    Last Modified: 23 Apr 2025

    Adobe Prelude version 10.1 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious M4A file.

    Published: 16 Nov 2021
    7.8
    High

    CVE-2021-43012

    Last Modified: 23 Apr 2025

    Adobe Prelude version 10.1 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious M4A file.

    Published: 16 Nov 2021
    7.8
    High

    CVE-2021-42725

    Last Modified: 21 Nov 2024

    Adobe Bridge version 11.1.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 16 Nov 2021
    7.8
    High

    CVE-2021-42731

    Last Modified: 23 Apr 2025

    Adobe InDesign versions 16.4 (and earlier) are affected by a Buffer Overflow vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Nov 2021
    7.8
    High

    CVE-2021-42723

    Last Modified: 21 Nov 2024

    Adobe Bridge version 11.1.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted SGI file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Nov 2021
    7.8
    High

    CVE-2021-42721

    Last Modified: 21 Nov 2024

    Acrobat Bridge versions 11.1.1 and earlier are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Nov 2021
    7.8
    High

    CVE-2021-43013

    Last Modified: 23 Apr 2025

    Adobe Media Encoder version 15.4.1 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Nov 2021
    7.8
    High

    CVE-2021-42726

    Last Modified: 21 Nov 2024

    Adobe Bridge version 11.1.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 16 Nov 2021
    5.5
    Medium

    CVE-2021-26337

    Last Modified: 21 Nov 2024

    Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA read from invalid DRAM address to SRAM resulting in SMU not servicing further requests.

    Published: 16 Nov 2021
    5.5
    Medium

    CVE-2021-26325

    Last Modified: 21 Nov 2024

    Insufficient input validation in the SNP_GUEST_REQUEST command may lead to a potential data abort error and a denial of service.

    Published: 16 Nov 2021
    5.5
    Medium

    CVE-2021-26330

    Last Modified: 21 Nov 2024

    AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of resources.

    Published: 16 Nov 2021
    5.5
    Medium

    CVE-2021-26327

    Last Modified: 21 Nov 2024

    Insufficient validation of guest context in the SNP Firmware could lead to a potential loss of guest confidentiality.

    Published: 16 Nov 2021
    7.8
    High

    CVE-2020-12944

    Last Modified: 21 Nov 2024

    Insufficient validation of BIOS image length by ASP Firmware could lead to arbitrary code execution.

    Published: 16 Nov 2021
    7.8
    High

    CVE-2021-26323

    Last Modified: 21 Nov 2024

    Failure to validate SEV Commands while SNP is active may result in a potential impact to memory integrity.

    Published: 16 Nov 2021
    7.8
    High

    CVE-2020-12961

    Last Modified: 21 Nov 2024

    A potential vulnerability exists in AMD Platform Security Processor (PSP) that may allow an attacker to zero any privileged register on the System Management Network which may lead to bypassing SPI ROM protections.

    Published: 16 Nov 2021
    7.8
    High

    CVE-2021-26315

    Last Modified: 21 Nov 2024

    When the AMD Platform Security Processor (PSP) boot rom loads, authenticates, and subsequently decrypts an encrypted FW, due to insufficient verification of the integrity of decrypted image, arbitrary code may be executed in the PSP when encrypted firmware images are used.

    Published: 16 Nov 2021