CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-43466

    Last Modified: 21 Nov 2024

    In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution.

    Published: 9 Nov 2021
    5.5
    Medium

    CVE-2021-43519

    Last Modified: 21 Nov 2024

    Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.

    Published: 9 Nov 2021
    5.5
    Medium

    CVE-2021-33098

    Last Modified: 21 Nov 2024

    Improper input validation in the Intel(R) Ethernet ixgbe driver for Linux before version 3.17.3 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 9 Nov 2021
    7.2
    High

    CVE-2020-25719

    Last Modified: 21 Nov 2024

    A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise.

    Published: 9 Nov 2021
    9.8
    Critical

    CVE-2021-27023

    Last Modified: 21 Nov 2024

    A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007

    Published: 9 Nov 2021
    6.5
    Medium

    CVE-2021-27025

    Last Modified: 21 Nov 2024

    A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.

    Published: 9 Nov 2021
    5.9
    Medium

    CVE-2016-2124

    Last Modified: 21 Nov 2024

    A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.

    Published: 9 Nov 2021
    5.5
    Medium

    CVE-2021-42373

    Last Modified: 21 Nov 2024

    A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given

    Published: 9 Nov 2021
    9.8
    Critical

    CVE-2021-20325

    Last Modified: 21 Nov 2024

    Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regression compared to the versions shipped in Red Hat Enterprise Linux 8.4. A user who installs or updates to Red Hat Enterprise Linux 8.5.0 would be vulnerable to the mentioned CVEs, even if they were properly fixed in Red Hat Enterprise Linux 8.4. CVE-2021-20325 was assigned to that Red Hat specific security regression and it does not affect the upstream versions of httpd.

    Published: 9 Nov 2021
    7.2
    High

    CVE-2021-42380

    Last Modified: 3 Nov 2025

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the clrvar function

    Published: 9 Nov 2021
    7.2
    High

    CVE-2021-42384

    Last Modified: 3 Nov 2025

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the handle_special function

    Published: 9 Nov 2021
    5.3
    Medium

    CVE-2021-42374

    Last Modified: 3 Nov 2025

    An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that

    Published: 9 Nov 2021
    7.2
    High

    CVE-2021-42378

    Last Modified: 3 Nov 2025

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_i function

    Published: 9 Nov 2021
    7.2
    High

    CVE-2021-42379

    Last Modified: 3 Nov 2025

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the next_input_file function

    Published: 9 Nov 2021
    7.2
    High

    CVE-2021-42382

    Last Modified: 3 Nov 2025

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_s function

    Published: 9 Nov 2021
    7.2
    High

    CVE-2021-42385

    Last Modified: 3 Nov 2025

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function

    Published: 9 Nov 2021
    7.2
    High

    CVE-2021-42386

    Last Modified: 3 Nov 2025

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the nvalloc function

    Published: 9 Nov 2021
    7.5
    High

    CVE-2021-23192

    Last Modified: 21 Nov 2024

    A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, and chose to fragment it, an attacker could replace later fragments with their own data, bypassing the signature requirements.

    Published: 9 Nov 2021
    5.5
    Medium

    CVE-2021-42376

    Last Modified: 21 Nov 2024

    A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare conditions of filtered command input.

    Published: 9 Nov 2021
    7.2
    High

    CVE-2021-42383

    Last Modified: 23 Apr 2025

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function

    Published: 9 Nov 2021
    6.8
    Medium

    CVE-2021-0146

    Last Modified: 21 Nov 2024

    Hardware allows activation of test or debug logic at runtime for some Intel(R) processors which may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

    Published: 8 Nov 2021
    5.9
    Medium

    CVE-2021-41253

    Last Modified: 21 Nov 2024

    Zydis is an x86/x86-64 disassembler library. Users of Zydis versions v3.2.0 and older that use the string functions provided in `zycore` in order to append untrusted user data to the formatter buffer within their custom formatter hooks can run into heap buffer overflows. Older versions of Zydis failed to properly initialize the string object within the formatter buffer, forgetting to initialize a few fields, leaving their value to chance. This could then in turn cause zycore functions like `ZyanStringAppend` to make incorrect calculations for the new target size, resulting in heap memory corruption. This does not affect the regular uncustomized Zydis formatter, because Zydis internally doesn't use the string functions in zycore that act upon these fields. However, because the zycore string functions are the intended way to work with the formatter buffer for users of the library that wish to extend the formatter, we still consider this to be a vulnerability in Zydis. This bug is patched starting in version 3.2.1. As a workaround, users may refrain from using zycore string functions in their formatter hooks until updating to a patched version.

    Published: 8 Nov 2021
    8.8
    High

    CVE-2020-23572

    Last Modified: 21 Nov 2024

    BEESCMS v4.0 was discovered to contain an arbitrary file upload vulnerability via the component /admin/upload.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file.

    Published: 8 Nov 2021
    6.1
    Medium

    CVE-2021-40261

    Last Modified: 21 Nov 2024

    Multiple Cross Site Scripting (XSS) vulnerabilities exist in SourceCodester CASAP Automated Enrollment System 1.0 via the (1) user_username and (2) category parameters in save_class.php, the (3) firstname, (4) class, and (5) status parameters in student_table.php, the (6) category and (7) class_name parameters in add_class1.php, the (8) fname, (9) mname,(10) lname, (11) address, (12) class, (13) gfname, (14) gmname, (15) glname, (16) rship, (17) status, (18) transport, and (19) route parameters in add_student.php, the (20) fname, (21) mname, (22) lname, (23) address, (24) class, (25) fgname, (26) gmname, (27) glname, (28) rship, (29) status, (30) transport, and (31) route parameters in save_stud.php,the (32) status, (33) fname, and (34) lname parameters in add_user.php, the (35) username, (36) firstname, and (37) status parameters in users.php, the (38) fname, (39) lname, and (40) status parameters in save_user.php, and the (41) activity_log, (42) aprjun, (43) class, (44) janmar, (45) Julsep,(46) octdec, (47) Students and (48) users parameters in table_name.

    Published: 8 Nov 2021
    6.1
    Medium

    CVE-2021-40260

    Last Modified: 21 Nov 2024

    Multiple Cross Site Scripting (XSS) vulnerabilities exist in SourceCodester Tailor Management 1.0 via the (1) eid parameter in (a) partedit.php and (b) customeredit.php, the (2) id parameter in (a) editmeasurement.php and (b) addpayment.php, and the (3) error parameter in index.php.

    Published: 8 Nov 2021
    9.8
    Critical

    CVE-2021-41170

    Last Modified: 21 Nov 2024

    neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures directly into the template engine. As a result values that are callable are executed by the template engine. The issue arises if a value has the same name as a method or function in scope and can therefore be executed either by mistake or maliciously. In theory all users of the package are affected as long as they either deal with direct user input or database values. A multi-step attack on is therefore plausible. Version 1.1.1 has addressed this vulnerability. Unfortunately only working with hardcoded values is safe in prior versions. As this likely defeats the purpose of a template engine, please upgrade.

    Published: 8 Nov 2021
    6.1
    Medium

    CVE-2021-39420

    Last Modified: 21 Nov 2024

    Multiple Cross Site Scripting (XSS) vulnerabilities exist in VFront 0.99.5 via the (1) s parameter in search_all.php and the (2) msg parameter in add.attach.php.

    Published: 8 Nov 2021
    5.4
    Medium

    CVE-2021-40577

    Last Modified: 21 Nov 2024

    A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Enrollment Management System in PHP and PayPal Free Source Code 1.0 in the Add-Users page via the Name parameter.

    Published: 8 Nov 2021
    5.3
    Medium

    CVE-2021-24840

    Last Modified: 21 Nov 2024

    The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of its REST endpoint, without any validation. As a result, private and scheduled posts could be retrieved via a crafted request.

    Published: 8 Nov 2021
    7.2
    High

    CVE-2021-24844

    Last Modified: 21 Nov 2024

    The Affiliates Manager WordPress plugin before 2.8.7 does not validate the orderby parameter before using it in an SQL statement in the admin dashboard, leading to an SQL Injection issue

    Published: 8 Nov 2021
    8.8
    High

    CVE-2021-24835

    Last Modified: 21 Nov 2024

    The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible WordPress plugin before 6.5.12, when used in combination with another WCFM - WooCommerce Multivendor plugin such as WCFM - WooCommerce Multivendor Marketplace, does not escape the withdrawal_vendor parameter before using it in a SQL statement, allowing low privilege users such as Subscribers to perform SQL injection attacks

    Published: 8 Nov 2021
    4.3
    Medium

    CVE-2021-24832

    Last Modified: 21 Nov 2024

    The WP SEO Redirect 301 WordPress plugin before 2.3.2 does not have CSRF in place when deleting redirects, which could allow attackers to make a logged in admin delete them via a CSRF attack

    Published: 8 Nov 2021
    8.8
    High

    CVE-2021-24829

    Last Modified: 21 Nov 2024

    The Visitor Traffic Real Time Statistics WordPress plugin before 3.9 does not validate and escape user input passed to the today_traffic_index AJAX action (available to any authenticated users) before using it in a SQL statement, leading to an SQL injection issue

    Published: 8 Nov 2021
    9.8
    Critical

    CVE-2021-24827

    Last Modified: 21 Nov 2024

    The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthenticated SQL injection issue

    Published: 8 Nov 2021
    4.3
    Medium

    CVE-2021-24816

    Last Modified: 21 Nov 2024

    The Phoenix Media Rename WordPress plugin before 3.4.4 does not have capability checks in its phoenix_media_rename AJAX action, which could allow users with Author roles to rename any uploaded media files, including ones they do not own.

    Published: 8 Nov 2021
    5.4
    Medium

    CVE-2021-24807

    Last Modified: 21 Nov 2024

    The Support Board WordPress plugin before 3.3.5 allows Authenticated (Agent+) users to perform Cross-Site Scripting attacks by placing a payload in the notes field, when an administrator or any authenticated user go to the chat the XSS will be automatically executed.

    Published: 8 Nov 2021
    4.3
    Medium

    CVE-2021-24806

    Last Modified: 21 Nov 2024

    The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could allow attacker to make logged in users such as admin edit and delete arbitrary comment, or the user who made the comment to edit it via a CSRF attack. Attackers could also make logged in users post arbitrary comment.

    Published: 8 Nov 2021
    4.3
    Medium

    CVE-2021-24801

    Last Modified: 21 Nov 2024

    The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX actions, allowing any user to call them and add/edit/delete Surveys. Furthermore, due to the lack of sanitization in the Surveys' Title, this could also lead to Stored Cross-Site Scripting issues

    Published: 8 Nov 2021
    6.1
    Medium

    CVE-2021-24798

    Last Modified: 21 Nov 2024

    The WP Header Images WordPress plugin before 2.0.1 does not sanitise and escape the t parameter before outputting it back in the plugin's settings page, leading to a Reflected Cross-Site Scripting issue

    Published: 8 Nov 2021
    7.2
    High

    CVE-2021-24791

    Last Modified: 21 Nov 2024

    The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" request parameters before using them in a SQL statement when viewing the Snippets admin dashboard, leading to SQL injections

    Published: 8 Nov 2021
    6.5
    Medium

    CVE-2021-24788

    Last Modified: 21 Nov 2024

    The Batch Cat WordPress plugin through 0.3 defines 3 custom AJAX actions, which both require authentication but are available for all roles. As a result, any authenticated user (including simple subscribers) can add/set/delete arbitrary categories to posts.

    Published: 8 Nov 2021
    6.5
    Medium

    CVE-2021-24783

    Last Modified: 21 Nov 2024

    The Post Expirator WordPress plugin before 2.6.0 does not have proper capability checks in place, which could allow users with a role as low as Contributor to schedule deletion of arbitrary posts.

    Published: 8 Nov 2021
    6.5
    Medium

    CVE-2021-24767

    Last Modified: 23 Jan 2026

    The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF when deleting logs, which could allow attacker to make a logged in admin delete them via a CSRF attack

    Published: 8 Nov 2021
    6.5
    Medium

    CVE-2021-24766

    Last Modified: 21 Nov 2024

    The 404 to 301 – Redirect, Log and Notify 404 Errors WordPress plugin before 3.0.9 does not have CSRF check in place when cleaning the logs, which could allow attacker to make a logged in admin delete all of them via a CSRF attack

    Published: 8 Nov 2021
    9.8
    Critical

    CVE-2021-24731

    Last Modified: 21 Nov 2024

    The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection.

    Published: 8 Nov 2021
    6.5
    Medium

    CVE-2021-24721

    Last Modified: 21 Nov 2024

    The Loco Translate WordPress plugin before 2.5.4 mishandles data inputs which get saved to a file, which can be renamed to an extension ending in .php, resulting in authenticated "translator" users being able to inject PHP code into files ending with .php in web accessible locations.

    Published: 8 Nov 2021
    4.8
    Medium

    CVE-2021-24710

    Last Modified: 21 Nov 2024

    The Print-O-Matic WordPress plugin before 2.0.3 does not escape some of its settings before outputting them in attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 8 Nov 2021
    4.8
    Medium

    CVE-2021-24708

    Last Modified: 21 Nov 2024

    The Export any WordPress data to XML/CSV WordPress plugin before 1.3.1 does not escape its Export's Name before outputting it in Manage Exports settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 8 Nov 2021
    4.8
    Medium

    CVE-2021-24706

    Last Modified: 21 Nov 2024

    The Qwizcards – online quizzes and flashcards WordPress plugin before 3.62 does not properly sanitize and escape some of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 8 Nov 2021
    4.8
    Medium

    CVE-2021-24701

    Last Modified: 21 Nov 2024

    The Quiz Tool Lite WordPress plugin through 2.3.15 does not sanitize multiple input fields used when creating or managing quizzes and in other setting options, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 8 Nov 2021