CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2021-24615

    Last Modified: 21 Nov 2024

    The Wechat Reward WordPress plugin through 1.7 does not sanitise or escape its QR settings, nor has any CSRF check in place, allowing attackers to make a logged in admin change the settings and perform Cross-Site Scripting attacks.

    Published: 18 Oct 2021
    4.8
    Medium

    CVE-2021-24612

    Last Modified: 21 Nov 2024

    The Sociable WordPress plugin through 4.3.4.1 does not sanitise or escape some of its settings before outputting them in the admins dashboard, allowing high privilege users to perform Cross-Site Scripting attacks against other users even when the unfiltered_html capability is disallowed

    Published: 18 Oct 2021
    6.5
    Medium

    CVE-2021-24595

    Last Modified: 21 Nov 2024

    The Wp Cookie Choice WordPress plugin through 1.1.0 is lacking any CSRF check when saving its options, and do not escape them when outputting them in attributes. As a result, an attacker could make a logged in admin change them to arbitrary values including XSS payloads via a CSRF attack.

    Published: 18 Oct 2021
    4.8
    Medium

    CVE-2021-24516

    Last Modified: 21 Nov 2024

    The PlanSo Forms WordPress plugin through 2.6.3 does not escape the title of its Form before outputting it in attributes, allowing high privilege users such as admin to set XSS payload in it, even when the unfiltered_html is disallowed, leading to an Authenticated Stored Cross-Site Scripting issue.

    Published: 18 Oct 2021
    5.4
    Medium

    CVE-2021-24416

    Last Modified: 21 Nov 2024

    The StreamCast – Radio Player for WordPress plugin before 2.1.1 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode

    Published: 18 Oct 2021
    5.4
    Medium

    CVE-2021-24415

    Last Modified: 21 Nov 2024

    The Polo Video Gallery – Best wordpress video gallery plugin WordPress plugin through 1.2 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode

    Published: 18 Oct 2021
    5.4
    Medium

    CVE-2021-24413

    Last Modified: 21 Nov 2024

    The Easy Twitter Feed WordPress plugin before 1.2 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode

    Published: 18 Oct 2021
    5.4
    Medium

    CVE-2021-24412

    Last Modified: 21 Nov 2024

    The Html5 Audio Player – Audio Player for WordPress plugin before 2.1.3 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode

    Published: 18 Oct 2021
    —
    Unknown

    CVE-2021-3755

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 18 Oct 2021
    8.8
    High

    CVE-2021-42098

    Last Modified: 21 Nov 2024

    An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to bypass permissions via batch custom PowerShell.

    Published: 18 Oct 2021
    6.1
    Medium

    CVE-2020-8291

    Last Modified: 21 Nov 2024

    A link preview rendering issue in Rocket.Chat versions before 3.9 could lead to potential XSS attacks.

    Published: 18 Oct 2021
    9.8
    Critical

    CVE-2021-22961

    Last Modified: 21 Nov 2024

    A code injection vulnerability exists within the firewall software of GlassWire v2.1.167 that could lead to arbitrary code execution from a file in the user path on first execution.

    Published: 18 Oct 2021
    7.8
    High

    CVE-2021-21797

    Last Modified: 21 Nov 2024

    An exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a reference to a timeout object to be stored in two different places. When closed, the document will result in the reference being released twice. This can lead to code execution under the context of the application. An attacker can convince a user to open a document to trigger this vulnerability.

    Published: 18 Oct 2021
    7.8
    High

    CVE-2021-21796

    Last Modified: 21 Nov 2024

    An exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause an object containing the path to a document to be destroyed and then later reused, resulting in a use-after-free vulnerability, which can lead to code execution under the context of the application. An attacker can convince a user to open a document to trigger this vulnerability.

    Published: 18 Oct 2021
    9.8
    Critical

    CVE-2021-38389

    Last Modified: 21 Nov 2024

    Advantech WebAccess versions 9.02 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute code.

    Published: 18 Oct 2021
    9.8
    Critical

    CVE-2021-33023

    Last Modified: 21 Nov 2024

    Advantech WebAccess versions 9.02 and prior are vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute code.

    Published: 18 Oct 2021
    7.8
    High

    CVE-2021-38436

    Last Modified: 21 Nov 2024

    FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project files, which could result in a memory-corruption condition. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.

    Published: 18 Oct 2021
    7.8
    High

    CVE-2021-38438

    Last Modified: 21 Nov 2024

    A use after free vulnerability in FATEK Automation WinProladder versions 3.30 and prior may be exploited when a valid user opens a malformed project file, which may allow arbitrary code execution.

    Published: 18 Oct 2021
    7.8
    High

    CVE-2021-38434

    Last Modified: 21 Nov 2024

    FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project files, which could result in an unexpected sign extension. An attacker could leverage this vulnerability to execute arbitrary code.

    Published: 18 Oct 2021
    3.3
    Low

    CVE-2021-38440

    Last Modified: 21 Nov 2024

    FATEK Automation WinProladder versions 3.30 and prior is vulnerable to an out-of-bounds read, which may allow an attacker to read unauthorized information.

    Published: 18 Oct 2021
    7.8
    High

    CVE-2021-38442

    Last Modified: 21 Nov 2024

    FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project files, which could result in a heap-corruption condition. An attacker could leverage this vulnerability to execute code in the context of the current process.

    Published: 18 Oct 2021
    7.8
    High

    CVE-2021-38426

    Last Modified: 21 Nov 2024

    FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project files, which could result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code.

    Published: 18 Oct 2021
    7.8
    High

    CVE-2021-38430

    Last Modified: 21 Nov 2024

    FATEK Automation WinProladder versions 3.30 and prior proper validation of user-supplied data when parsing project files, which could result in a stack-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code.

    Published: 18 Oct 2021
    7.5
    High

    CVE-2021-38562

    Last Modified: 21 Nov 2024

    Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a timing attack against lib/RT/REST2/Middleware/Auth.pm.

    Published: 18 Oct 2021
    6.1
    Medium

    CVE-2021-42565

    Last Modified: 21 Nov 2024

    myfactory.FMS before 7.1-912 allows XSS via the UID parameter.

    Published: 18 Oct 2021
    6.1
    Medium

    CVE-2021-42566

    Last Modified: 21 Nov 2024

    myfactory.FMS before 7.1-912 allows XSS via the Error parameter.

    Published: 18 Oct 2021
    3.5
    Low

    CVE-2021-36097

    Last Modified: 21 Nov 2024

    Agents are able to lock the ticket without the "Owner" permission. Once the ticket is locked, it could be moved to the queue where the agent has "rw" permissions and gain a full control. This issue affects: OTRS AG OTRS 8.0.x version: 8.0.16 and prior versions.

    Published: 18 Oct 2021
    9.8
    Critical

    CVE-2021-42575

    Last Modified: 21 Nov 2024

    The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.

    Published: 18 Oct 2021
    9.8
    Critical

    CVE-2020-27304

    Last Modified: 21 Nov 2024

    The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file upload form handler, and use parts of the user-controlled filename in the output path, are susceptible to directory traversal

    Published: 18 Oct 2021
    7.5
    High

    CVE-2021-41990

    Last Modified: 21 Nov 2024

    The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.

    Published: 18 Oct 2021
    7.5
    High

    CVE-2021-41991

    Last Modified: 21 Nov 2024

    The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code execution might be a slight possibility.

    Published: 18 Oct 2021
    5.5
    Medium

    CVE-2021-4149

    Last Modified: 21 Nov 2024

    A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to an improper lock operation in btrfs. In this flaw, a user with a local privilege may cause a denial of service (DOS) due to a deadlock problem.

    Published: 18 Oct 2021
    6.1
    Medium

    CVE-2018-16061

    Last Modified: 21 Nov 2024

    Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.

    Published: 15 Oct 2021
    7.5
    High

    CVE-2018-16060

    Last Modified: 21 Nov 2024

    Mitsubishi Electric Europe B.V. SmartRTU devices allow remote attackers to obtain sensitive information (directory listing and source code) via a direct request to the /web URI.

    Published: 15 Oct 2021
    —
    Unknown

    CVE-2022-0003

    Last Modified: 27 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 15 Oct 2021
    9.8
    Critical

    CVE-2021-27561

    Last Modified: 10 Nov 2025

    Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.

    Published: 15 Oct 2021
    8.8
    High

    CVE-2021-29745

    Last Modified: 21 Nov 2024

    IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to priviledge escalation where a lower evel user could have access to the 'New Job' page to which they should not have access to. IBM X-Force ID: 201695.

    Published: 15 Oct 2021
    8.8
    High

    CVE-2021-29679

    Last Modified: 21 Nov 2024

    IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neutralizaing user-contrlled input that could be interpreted a a server-side include (SSI) directive. IBM X-Force ID: 199915.

    Published: 15 Oct 2021
    3.3
    Low

    CVE-2020-4951

    Last Modified: 21 Nov 2024

    IBM Cognos Analytics 11.1.7 and 11.2.0 contains locally cached browser data, that could allow a local attacker to obtain sensitive information.

    Published: 15 Oct 2021
    5.5
    Medium

    CVE-2021-41320

    Last Modified: 30 May 2025

    A technical user has hardcoded credentials in Wallstreet Suite TRM 7.4.83 (64-bit edition) with higher privilege than the average authenticated user. NOTE: the vendor disputes this because the password is not hardcoded (it can be changed during installation or at any later time).

    Published: 15 Oct 2021
    6.1
    Medium

    CVE-2021-40721

    Last Modified: 23 Apr 2025

    Adobe Connect version 11.2.3 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

    Published: 15 Oct 2021
    7.8
    High

    CVE-2021-40731

    Last Modified: 23 Apr 2025

    Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015 (and earlier), and 17.011.30202 (and earlier) is affected by an out-of-bounds write vulnerability when parsing a crafted JPEG2000 file, which could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Oct 2021
    7.8
    High

    CVE-2021-40728

    Last Modified: 23 Apr 2025

    Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015 (and earlier), and 17.011.30202 (and earlier) is affected by a use-after-free vulnerability in the processing of the GetURL function on a global object window that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Oct 2021
    7.8
    High

    CVE-2021-40724

    Last Modified: 21 Nov 2024

    Acrobat Reader for Android versions 21.8.0 (and earlier) are affected by a Path traversal vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Oct 2021
    9.8
    Critical

    CVE-2021-40720

    Last Modified: 21 Nov 2024

    Ops CLI version 2.0.4 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve arbitrary code execution when the checkout_repo function is called on a maliciously crafted file. An attacker can leverage this to execute arbitrary code on the victim machine.

    Published: 15 Oct 2021
    3.3
    Low

    CVE-2021-40730

    Last Modified: 23 Apr 2025

    Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015 (and earlier), and 17.011.30202 (and earlier) is affected by a use-after-free that allow a remote attacker to disclose sensitive information on affected installations of of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPG2000 images.

    Published: 15 Oct 2021
    3.3
    Low

    CVE-2021-40729

    Last Modified: 23 Apr 2025

    Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015 (and earlier), and 17.011.30202 (and earlier) is affected by a out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious PDF file.

    Published: 15 Oct 2021
    6.5
    Medium

    CVE-2021-39864

    Last Modified: 23 Apr 2025

    Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via a Wishlist Share Link. Successful exploitation could lead to unauthorized addition to customer cart by an unauthenticated attacker. Access to the admin console is not required for successful exploitation.

    Published: 15 Oct 2021
    9.8
    Critical

    CVE-2021-38432

    Last Modified: 21 Nov 2024

    FATEK Automation Communication Server Versions 1.13 and prior lacks proper validation of user-supplied data, which could result in a stack-based buffer overflow condition and allow an attacker to remotely execute code.

    Published: 15 Oct 2021
    7.2
    High

    CVE-2021-40998

    Last Modified: 21 Nov 2024

    A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior to 6.8.9-HF1. Aruba has released patches for ClearPass Policy Manager that address this security vulnerability.

    Published: 15 Oct 2021