CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2021-24808

    Last Modified: 21 Nov 2024

    The BP Better Messages WordPress plugin before 1.9.9.41 sanitise (with sanitize_text_field) but does not escape the 'subject' parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue

    Published: 1 Nov 2021
    4.3
    Medium

    CVE-2021-24799

    Last Modified: 21 Nov 2024

    The Far Future Expiry Header WordPress plugin before 1.5 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

    Published: 1 Nov 2021
    4.8
    Medium

    CVE-2021-24794

    Last Modified: 21 Nov 2024

    The Connections Business Directory WordPress plugin before 10.4.3 does not escape the Address settings when creating an Entry, which could allow high privilege users to perform Cross-Site Scripting when the unfiltered_html capability is disallowed.

    Published: 1 Nov 2021
    4.8
    Medium

    CVE-2021-24793

    Last Modified: 21 Nov 2024

    The WPeMatico RSS Feed Fetcher WordPress plugin before 2.6.12 does not escape the Feed URL added to a campaign before outputting it in an attribute, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 1 Nov 2021
    4.8
    Medium

    CVE-2021-24789

    Last Modified: 21 Nov 2024

    The Flat Preloader WordPress plugin before 1.5.5 does not escape some of its settings when outputting them in attribute in the frontend, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

    Published: 1 Nov 2021
    4.3
    Medium

    CVE-2021-24781

    Last Modified: 21 Nov 2024

    The Image Source Control WordPress plugin before 2.3.1 allows users with a role as low as Contributor to change arbitrary post meta fields of arbitrary posts (even those they should not be able to edit)

    Published: 1 Nov 2021
    4.8
    Medium

    CVE-2021-24773

    Last Modified: 21 Mar 2025

    The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputting them, allowing high privilege users to perform XSS attacks even when the unfiltered_html capability is disallowed

    Published: 1 Nov 2021
    6.5
    Medium

    CVE-2021-24770

    Last Modified: 21 Nov 2024

    The Stylish Price List WordPress plugin before 6.9.1 does not perform capability checks in its spl_upload_ser_img AJAX action (available to authenticated users), which could allow any authenticated users, such as subscriber, to upload arbitrary images.

    Published: 1 Nov 2021
    5.3
    Medium

    CVE-2021-24757

    Last Modified: 21 Nov 2024

    The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX action (available to both unauthenticated and authenticated users), which could allow unauthenticated users to upload images.

    Published: 1 Nov 2021
    6.5
    Medium

    CVE-2021-24742

    Last Modified: 21 Nov 2024

    The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugin's settings via the rtWLSSettings AJAX action because it uses a nonce for authorisation instead of a capability check.

    Published: 1 Nov 2021
    5.4
    Medium

    CVE-2021-24723

    Last Modified: 21 Nov 2024

    The WP Reactions Lite WordPress plugin before 1.3.6 does not properly sanitize inputs within wp-admin pages, allowing users with sufficient access to inject XSS payloads within /wp-admin/ pages.

    Published: 1 Nov 2021
    4.8
    Medium

    CVE-2021-24722

    Last Modified: 21 Nov 2024

    The Restaurant Menu by MotoPress WordPress plugin before 2.4.2 does not properly sanitize or escape inputs when creating new menu items, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 1 Nov 2021
    8.8
    High

    CVE-2021-24717

    Last Modified: 21 Nov 2024

    The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or perform privilege escalation via Ajax actions.

    Published: 1 Nov 2021
    5.4
    Medium

    CVE-2021-24716

    Last Modified: 21 Nov 2024

    The Modern Events Calendar Lite WordPress plugin before 5.22.3 does not properly sanitize or escape values set by users with access to adjust settings withing wp-admin.

    Published: 1 Nov 2021
    4.8
    Medium

    CVE-2021-24715

    Last Modified: 21 Nov 2024

    The WP Sitemap Page WordPress plugin before 1.7.0 does not properly sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 1 Nov 2021
    5.4
    Medium

    CVE-2021-24685

    Last Modified: 21 Nov 2024

    The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does not sanitise and escape them, which could allow attackers to a make logged in admin change them with a Cross-Site Scripting payload (triggered either in the frontend or backend depending on the payload)

    Published: 1 Nov 2021
    5.4
    Medium

    CVE-2021-24682

    Last Modified: 21 Nov 2024

    The Cool Tag Cloud WordPress plugin before 2.26 does not escape the style attribute of the cool_tag_cloud shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.

    Published: 1 Nov 2021
    4.8
    Medium

    CVE-2021-24624

    Last Modified: 21 Nov 2024

    The MP3 Audio Player for Music, Radio & Podcast by Sonaar WordPress plugin before 2.4.2 does not properly sanitize or escape data in some of its Playlist settings, allowing high privilege users to perform Cross-Site Scripting attacks

    Published: 1 Nov 2021
    4.3
    Medium

    CVE-2021-24572

    Last Modified: 21 Nov 2024

    The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are internally stored as posts. The deletion of a button is not CSRF protected and there is no control to check if the deleted post was a button post. As a result, an attacker could make logged in admins delete arbitrary posts

    Published: 1 Nov 2021
    4.3
    Medium

    CVE-2021-24570

    Last Modified: 21 Nov 2024

    The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use this to make an authenticated admin create a new button. Furthermore, one of the Button field is not escaped before being output in an attribute when editing a Button, leading to a Stored Cross-Site Scripting issue as well.

    Published: 1 Nov 2021
    4.8
    Medium

    CVE-2021-24539

    Last Modified: 21 Nov 2024

    The Coming Soon, Under Construction & Maintenance Mode By Dazzler WordPress plugin before 1.6.7 does not sanitise or escape its description setting when outputting it in the frontend when the Coming Soon mode is enabled, even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue

    Published: 1 Nov 2021
    6.5
    Medium

    CVE-2020-36505

    Last Modified: 21 Nov 2024

    The Delete All Comments Easily WordPress plugin through 1.3 is lacking Cross-Site Request Forgery (CSRF) checks, which could result in an unauthenticated attacker making a logged in admin delete all comments from the blog.

    Published: 1 Nov 2021
    6.5
    Medium

    CVE-2020-36504

    Last Modified: 21 Nov 2024

    The WP-Pro-Quiz WordPress plugin through 0.37 does not have CSRF check in place when deleting a quiz, which could allow an attacker to make a logged in admin delete arbitrary quiz on the blog

    Published: 1 Nov 2021
    8
    High

    CVE-2020-36503

    Last Modified: 21 Nov 2024

    The Connections Business Directory WordPress plugin before 9.7 does not validate or sanitise some connections' fields, which could lead to a CSV injection issue

    Published: 1 Nov 2021
    7.5
    High

    CVE-2018-25019

    Last Modified: 21 Nov 2024

    The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment_process_init() function, which could allow unauthenticated users to upload arbitrary files to the web server

    Published: 1 Nov 2021
    7.5
    High

    CVE-2015-20067

    Last Modified: 21 Nov 2024

    The WP Attachment Export WordPress plugin before 0.2.4 does not have proper access controls, allowing unauthenticated users to download the XML data that holds all the details of attachments/posts on a Wordpress

    Published: 1 Nov 2021
    5.4
    Medium

    CVE-2015-20019

    Last Modified: 21 Nov 2024

    The Content text slider on post WordPress plugin before 6.9 does not sanitise and escape the Title and Message/Content settings, which could lead to Cross-Site Scripting issues

    Published: 1 Nov 2021
    4.3
    Medium

    CVE-2015-10001

    Last Modified: 21 Nov 2024

    The WP-Stats WordPress plugin before 2.52 does not have CSRF check when saving its settings, and did not escape some of them when outputting them, allowing attacker to make logged in high privilege users change them and set Cross-Site Scripting payloads

    Published: 1 Nov 2021
    8.8
    High

    CVE-2021-40348

    Last Modified: 21 Nov 2024

    Spacewalk 2.10, and derivatives such as Uyuni 2021.08, allows code injection. rhn-config-satellite.pl doesn't sanitize the configuration filename used to append Spacewalk-specific key-value pair. The script is intended to be run by the tomcat user account with Sudo, according to the installation setup. This can lead to the ability of an attacker to use --option to append arbitrary code to a root-owned file that eventually will be executed by the system. This is fixed in Uyuni spacewalk-admin 4.3.2-1.

    Published: 1 Nov 2021
    4.3
    Medium

    CVE-2021-41313

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Jira Server and Data Center allow authenticated but non-admin remote attackers to edit email batch configurations via an Improper Authorization vulnerability in the /secure/admin/ConfigureBatching!default.jspa endpoint. The affected versions are before version 8.20.7.

    Published: 1 Nov 2021
    6.5
    Medium

    CVE-2021-20839

    Last Modified: 21 Nov 2024

    Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Entity (XXE) attack to cause a denial of service (DoS) condition to the other servers by processing a specially crafted XML document.

    Published: 1 Nov 2021
    7.5
    High

    CVE-2021-20838

    Last Modified: 21 Nov 2024

    Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Entity (XXE) attack to cause a denial of service (DoS) condition by processing a specially crafted XML document.

    Published: 1 Nov 2021
    5.5
    Medium

    CVE-2021-42917

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in Kodi xbmc up to 19.0, allows attackers to cause a denial of service due to improper length of values passed to istream.

    Published: 1 Nov 2021
    8.3
    High

    CVE-2021-42574

    Last Modified: 21 Nov 2024

    An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be used to craft source code that renders different logic than the logical ordering of tokens ingested by compilers and interpreters. Adversaries can leverage this to encode source code for compilers accepting Unicode such that targeted vulnerabilities are introduced invisibly to human reviewers. NOTE: the Unicode Consortium offers the following alternative approach to presenting this concern. An issue is noted in the nature of international text that can affect applications that implement support for The Unicode Standard and the Unicode Bidirectional Algorithm (all versions). Due to text display behavior when text includes left-to-right and right-to-left characters, the visual order of tokens may be different from their logical order. Additionally, control characters needed to fully support the requirements of bidirectional text can further obfuscate the logical order of tokens. Unless mitigated, an adversary could craft source code such that the ordering of tokens perceived by human reviewers does not match what will be processed by a compiler/interpreter/etc. The Unicode Consortium has documented this class of vulnerability in its document, Unicode Technical Report #36, Unicode Security Considerations. The Unicode Consortium also provides guidance on mitigations for this class of issues in Unicode Technical Standard #39, Unicode Security Mechanisms, and in Unicode Standard Annex #31, Unicode Identifier and Pattern Syntax. Also, the BIDI specification allows applications to tailor the implementation in ways that can mitigate misleading visual reordering in program text; see HL4 in Unicode Standard Annex #9, Unicode Bidirectional Algorithm.

    Published: 1 Nov 2021
    8.3
    High

    CVE-2021-42694

    Last Modified: 21 Nov 2024

    An issue was discovered in the character definitions of the Unicode Specification through 14.0. The specification allows an adversary to produce source code identifiers such as function names using homoglyphs that render visually identical to a target identifier. Adversaries can leverage this to inject code via adversarial identifier definitions in upstream software dependencies invoked deceptively in downstream software. NOTE: the Unicode Consortium offers the following alternative approach to presenting this concern. An issue is noted in the nature of international text that can affect applications that implement support for The Unicode Standard (all versions). Unless mitigated, an adversary could produce source code identifiers using homoglyph characters that render visually identical to but are distinct from a target identifier. In this way, an adversary could inject adversarial identifier definitions in upstream software that are not detected by human reviewers and are invoked deceptively in downstream software. The Unicode Consortium has documented this class of security vulnerability in its document, Unicode Technical Report #36, Unicode Security Considerations. The Unicode Consortium also provides guidance on mitigations for this class of issues in Unicode Technical Standard #39, Unicode Security Mechanisms.

    Published: 1 Nov 2021
    7.5
    High

    CVE-2021-43396

    Last Modified: 21 Nov 2024

    In iconvdata/iso-2022-jp-3.c in the GNU C Library (aka glibc) 2.34, remote attackers can force iconv() to emit a spurious '\0' character via crafted ISO-2022-JP-3 data that is accompanied by an internal state reset. This may affect data integrity in certain iconv() use cases. NOTE: the vendor states "the bug cannot be invoked through user input and requires iconv to be invoked with a NULL inbuf, which ought to require a separate application bug to do so unintentionally. Hence there's no security impact to the bug.

    Published: 1 Nov 2021
    6.5
    Medium

    CVE-2021-41973

    Last Modified: 21 Nov 2024

    In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater.

    Published: 1 Nov 2021
    9.8
    Critical

    CVE-2020-36379

    Last Modified: 21 Nov 2024

    An issue was discovered in the remove function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath parameters.

    Published: 31 Oct 2021
    9.8
    Critical

    CVE-2020-36381

    Last Modified: 21 Nov 2024

    An issue was discovered in the singleCrunch function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath parameters.

    Published: 31 Oct 2021
    9.8
    Critical

    CVE-2020-36380

    Last Modified: 21 Nov 2024

    An issue was discovered in the crunch function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath parameters.

    Published: 31 Oct 2021
    9.8
    Critical

    CVE-2020-36377

    Last Modified: 21 Nov 2024

    An issue was discovered in the dump function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath parameters.

    Published: 31 Oct 2021
    9.8
    Critical

    CVE-2020-36378

    Last Modified: 21 Nov 2024

    An issue was discovered in the packageCmd function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath parameters.

    Published: 31 Oct 2021
    9.8
    Critical

    CVE-2020-36376

    Last Modified: 21 Nov 2024

    An issue was discovered in the list function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via the filePath parameters.

    Published: 31 Oct 2021
    9.8
    Critical

    CVE-2020-26707

    Last Modified: 21 Nov 2024

    An issue was discovered in the add function in Shenzhim AAPTJS 1.3.1 which allows attackers to execute arbitrary code via the filePath parameter.

    Published: 31 Oct 2021
    9.1
    Critical

    CVE-2020-26705

    Last Modified: 21 Nov 2024

    The parseXML function in Easy-XML 0.5.0 was discovered to have a XML External Entity (XXE) vulnerability which allows for an attacker to expose sensitive data or perform a denial of service (DOS) via a crafted external entity entered into the XML content as input.

    Published: 31 Oct 2021
    5.3
    Medium

    CVE-2021-33259

    Last Modified: 21 Nov 2024

    Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query history.

    Published: 31 Oct 2021
    9.1
    Critical

    CVE-2020-25911

    Last Modified: 21 Nov 2024

    A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).

    Published: 31 Oct 2021
    9.1
    Critical

    CVE-2020-25912

    Last Modified: 21 Nov 2024

    A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).

    Published: 31 Oct 2021
    4.6
    Medium

    CVE-2021-43976

    Last Modified: 21 Nov 2024

    In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (who can connect a crafted USB device) to cause a denial of service (skb_over_panic).

    Published: 31 Oct 2021
    5.9
    Medium

    CVE-2021-36808

    Last Modified: 21 Nov 2024

    A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115.

    Published: 30 Oct 2021