CVE Feed

    Dashboard / CVE

    9.1
    Critical

    CVE-2021-20034

    Last Modified: 21 Nov 2024

    An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.

    Published: 27 Sept 2021
    9.8
    Critical

    CVE-2021-41558

    Last Modified: 21 Nov 2024

    The set_user extension module before 3.0.0 for PostgreSQL allows ProcessUtility_hook bypass via set_config.

    Published: 27 Sept 2021
    9.8
    Critical

    CVE-2021-37761

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote code execution.

    Published: 27 Sept 2021
    7.5
    High

    CVE-2021-41753

    Last Modified: 21 Nov 2024

    A denial-of-service attack in WPA2, and WPA3-SAE authentication methods in D-Link DIR-X1560, v1.04B04, and DIR-X6060, v1.11B04 allows a remote unauthenticated attacker to disconnect a wireless client via sending specific spoofed SAE authentication frames.

    Published: 27 Sept 2021
    9.8
    Critical

    CVE-2021-40329

    Last Modified: 21 Nov 2024

    The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management.

    Published: 27 Sept 2021
    7.4
    High

    CVE-2021-36134

    Last Modified: 21 Nov 2024

    Out of bounds write vulnerability in the JPEG parsing code of Netop Vision Pro up to and including 9.7.2 allows an adjacent unauthenticated attacker to write to arbitrary memory potentially leading to a Denial of Service (DoS).

    Published: 27 Sept 2021
    6.5
    Medium

    CVE-2021-40712

    Last Modified: 23 Apr 2025

    Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a improper input validation vulnerability via the path parameter. An authenticated attacker can send a malformed POST request to achieve server-side denial of service.

    Published: 27 Sept 2021
    6.1
    Medium

    CVE-2021-40714

    Last Modified: 23 Apr 2025

    Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability via the accesskey parameter. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser

    Published: 27 Sept 2021
    7.8
    High

    CVE-2021-40700

    Last Modified: 21 Nov 2024

    Adobe Premiere Elements version 2021.2235820 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious TIFF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 27 Sept 2021
    7.8
    High

    CVE-2021-40709

    Last Modified: 23 Apr 2025

    Adobe Photoshop versions 21.2.11 (and earlier) and 22.5 (and earlier) are affected by a Buffer Overflow vulnerability when parsing a specially crafted SVG file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 27 Sept 2021
    7.8
    High

    CVE-2021-40701

    Last Modified: 21 Nov 2024

    Adobe Premiere Elements version 2021.2235820 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious m4a file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 27 Sept 2021
    5.8
    Medium

    CVE-2021-39828

    Last Modified: 23 Apr 2025

    Adobe Digital Editions 4.5.11.187646 (and earlier) are affected by a privilege escalation vulnerability in the Digital Editions installer. An authenticated attacker could leverage this vulnerability to escalate privileges. User interaction is required before product installation to abuse this vulnerability.

    Published: 27 Sept 2021
    7.8
    High

    CVE-2021-40703

    Last Modified: 21 Nov 2024

    Adobe Premiere Elements version 2021.2235820 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious m4a file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 27 Sept 2021
    7.8
    High

    CVE-2021-39825

    Last Modified: 21 Nov 2024

    Photoshop Elements versions 2021 build 19.0 (20210304.m.156367) (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious TTF file.

    Published: 27 Sept 2021
    5.9
    Medium

    CVE-2021-40713

    Last Modified: 23 Apr 2025

    Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a improper certificate validation vulnerability in the cold storage component. If an attacker can achieve a man in the middle when the cold server establishes a new certificate, they would be able to harvest sensitive information.

    Published: 27 Sept 2021
    6.5
    Medium

    CVE-2021-39827

    Last Modified: 21 Nov 2024

    Adobe Digital Editions 4.5.11.187646 (and earlier) are affected by an arbitrary file write vulnerability in the Digital Editions installer. An authenticated attacker could leverage this vulnerability to write an arbitrary file to the system. User interaction is required before product installation to abuse this vulnerability.

    Published: 27 Sept 2021
    7.8
    High

    CVE-2021-40702

    Last Modified: 21 Nov 2024

    Adobe Premiere Elements version 2021.2235820 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious psd file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 27 Sept 2021
    7.8
    High

    CVE-2021-39824

    Last Modified: 21 Nov 2024

    Adobe Premiere Elements version 2021.2235820 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious png file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 27 Sept 2021
    5.4
    Medium

    CVE-2021-40711

    Last Modified: 23 Apr 2025

    Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a stored XSS vulnerability when creating Content Fragments. An authenticated attacker can send a malformed POST request to achieve arbitrary code execution. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

    Published: 27 Sept 2021
    7.4
    High

    CVE-2021-28613

    Last Modified: 21 Nov 2024

    Adobe Creative Cloud Desktop Application version 5.4 (and earlier) is affected by a file handling vulnerability that could allow an attacker to arbitrarily overwrite a file. Exploitation of this issue requires local access, administrator privileges and user interaction.

    Published: 27 Sept 2021
    7.8
    High

    CVE-2021-39818

    Last Modified: 21 Nov 2024

    Adobe InCopy version 11.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious TIFF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 27 Sept 2021
    8.6
    High

    CVE-2021-39826

    Last Modified: 21 Nov 2024

    Adobe Digital Editions 4.5.11.187646 (and earlier) are affected by an arbitrary command execution vulnerability. An authenticated attacker could leverage this vulnerability to execute arbitrary commands. User interaction is required to abuse this vulnerability in that a user must open a maliciously crafted .epub file.

    Published: 27 Sept 2021
    7.8
    High

    CVE-2021-39819

    Last Modified: 21 Nov 2024

    Adobe InCopy version 11.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious XML file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 27 Sept 2021
    7.8
    High

    CVE-2021-39823

    Last Modified: 21 Nov 2024

    Adobe svg-native-viewer 8182d14dfad5d1e10f53ed830328d7d9a3cfa96d and earlier versions are affected by a heap buffer overflow vulnerability due to insecure handling of a malicious .svg file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 27 Sept 2021
    6.9
    Medium

    CVE-2021-36845

    Last Modified: 28 Mar 2025

    Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in YITH Maintenance Mode (WordPress plugin) versions <= 1.3.8, there are 46 vulnerable parameters that were missed by the vendor while patching the 1.3.7 version to 1.3.8. Vulnerable parameters: 1 - "Newsletter" tab, &yith_maintenance_newsletter_submit_label parameter: payload should start with a single quote (') symbol to break the context, i.e.: NOTIFY ME' autofocus onfocus=alert(/Visse/);// v=' - this payload will be auto triggered while admin visits this page/tab. 2 - "General" tab issues, vulnerable parameters: &yith_maintenance_message, &yith_maintenance_custom_style, &yith_maintenance_mascotte, &yith_maintenance_title_font[size], &yith_maintenance_title_font[family], &yith_maintenance_title_font[color], &yith_maintenance_paragraph_font[size], &yith_maintenance_paragraph_font[family], &yith_maintenance_paragraph_font[color], &yith_maintenance_border_top. 3 - "Background" tab issues, vulnerable parameters: &yith_maintenance_background_image, &yith_maintenance_background_color. 4 - "Logo" tab issues, vulnerable parameters: &yith_maintenance_logo_image, &yith_maintenance_logo_tagline, &yith_maintenance_logo_tagline_font[size], &yith_maintenance_logo_tagline_font[family], &yith_maintenance_logo_tagline_font[color]. 5 - "Newsletter" tab issues, vulnerable parameters: &yith_maintenance_newsletter_email_font[size], &yith_maintenance_newsletter_email_font[family], &yith_maintenance_newsletter_email_font[color], &yith_maintenance_newsletter_submit_font[size], &yith_maintenance_newsletter_submit_font[family], &yith_maintenance_newsletter_submit_font[color], &yith_maintenance_newsletter_submit_background, &yith_maintenance_newsletter_submit_background_hover, &yith_maintenance_newsletter_title, &yith_maintenance_newsletter_action, &yith_maintenance_newsletter_email_label, &yith_maintenance_newsletter_email_name, &yith_maintenance_newsletter_submit_label, &yith_maintenance_newsletter_hidden_fields. 6 - "Socials" tab issues, vulnerable parameters: &yith_maintenance_socials_facebook, &yith_maintenance_socials_twitter, &yith_maintenance_socials_gplus, &yith_maintenance_socials_youtube, &yith_maintenance_socials_rss, &yith_maintenance_socials_skype, &yith_maintenance_socials_email, &yith_maintenance_socials_behance, &yith_maintenance_socials_dribble, &yith_maintenance_socials_flickr, &yith_maintenance_socials_instagram, &yith_maintenance_socials_pinterest, &yith_maintenance_socials_tumblr, &yith_maintenance_socials_linkedin.

    Published: 27 Sept 2021
    6.9
    Medium

    CVE-2021-36841

    Last Modified: 28 Mar 2025

    Authenticated Stored Cross-Site Scripting (XSS) vulnerability in YITH Maintenance Mode (WordPress plugin) versions <= 1.3.7, vulnerable parameter &yith_maintenance_newsletter_submit_label. Possible even when unfiltered HTML is disallowed by WordPress configuration.

    Published: 27 Sept 2021
    5.9
    Medium

    CVE-2021-36875

    Last Modified: 1 Jul 2025

    Cross-site Scripting (XSS) vulnerability in Stylemix Directory Listings WordPress plugin – uListing allows Reflected XSS.This issue affects Directory Listings WordPress plugin – uListing: from n/a through 2.0.5.

    Published: 27 Sept 2021
    8.6
    High

    CVE-2021-36880

    Last Modified: 28 Mar 2025

    Unauthenticated SQL Injection (SQLi) vulnerability in WordPress uListing plugin (versions <= 2.0.3), vulnerable parameter: custom.

    Published: 27 Sept 2021
    7.1
    High

    CVE-2021-36874

    Last Modified: 28 Mar 2025

    Authenticated Insecure Direct Object References (IDOR) vulnerability in WordPress uListing plugin (versions <= 2.0.5).

    Published: 27 Sept 2021
    4.3
    Medium

    CVE-2021-36877

    Last Modified: 28 Mar 2025

    Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to modify user roles.

    Published: 27 Sept 2021
    5.4
    Medium

    CVE-2021-36876

    Last Modified: 28 Mar 2025

    Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in WordPress uListing plugin (versions <= 2.0.5) as it lacks CSRF checks on plugin administration pages.

    Published: 27 Sept 2021
    9.8
    Critical

    CVE-2021-36879

    Last Modified: 28 Mar 2025

    Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPress configuration allows user registration.

    Published: 27 Sept 2021
    5.4
    Medium

    CVE-2021-24671

    Last Modified: 21 Nov 2024

    The MX Time Zone Clocks WordPress plugin before 3.4.1 does not escape the time_zone attribute of the mxmtzc_time_zone_clocks shortcode, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks

    Published: 27 Sept 2021
    5.4
    Medium

    CVE-2021-24670

    Last Modified: 21 Nov 2024

    The CoolClock WordPress plugin before 4.3.5 does not escape some shortcode attributes, allowing users with a role as low as Contributor toperform Stored Cross-Site Scripting attacks

    Published: 27 Sept 2021
    9.8
    Critical

    CVE-2021-24666

    Last Modified: 21 Nov 2024

    The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by default), which adds the rest route '/services/contributor/(?P<id>[\d]+), takes an 'id' and 'category' parameters as arguments. Both parameters can be used for the SQLi.

    Published: 27 Sept 2021
    4.3
    Medium

    CVE-2021-24661

    Last Modified: 21 Nov 2024

    The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with Contributor roles or higher to read password-protected or private post contents the user is otherwise unable to read, given the post ID.

    Published: 27 Sept 2021
    5.4
    Medium

    CVE-2021-24660

    Last Modified: 21 Nov 2024

    The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's shortcode.

    Published: 27 Sept 2021
    5.4
    Medium

    CVE-2021-24659

    Last Modified: 21 Nov 2024

    The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's block.

    Published: 27 Sept 2021
    6.5
    Medium

    CVE-2021-24652

    Last Modified: 21 Nov 2024

    The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 performs incorrect checks before allowing any logged in user to perform some ajax based requests, allowing any user to modify, delete or add ultp_options values.

    Published: 27 Sept 2021
    5.4
    Medium

    CVE-2021-24643

    Last Modified: 21 Nov 2024

    The WP Map Block WordPress plugin before 1.2.3 does not escape some attributes of the WP Map Block, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

    Published: 27 Sept 2021
    5.4
    Medium

    CVE-2021-24634

    Last Modified: 21 Nov 2024

    The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.3 does not properly sanitise or escape some of the properties of the Recipe Card Block (such as ingredientsLayout, iconSet, steps, ingredients, recipeTitle, or settings), which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.

    Published: 27 Sept 2021
    4.3
    Medium

    CVE-2021-24633

    Last Modified: 21 Nov 2024

    The Countdown Block WordPress plugin before 1.1.2 does not have authorisation in the eb_write_block_css AJAX action, which allows any authenticated user, such as Subscriber, to modify post contents displayed to users.

    Published: 27 Sept 2021
    6.1
    Medium

    CVE-2021-24632

    Last Modified: 21 Nov 2024

    The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.1 does not escape the message parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting issue

    Published: 27 Sept 2021
    4.8
    Medium

    CVE-2021-24610

    Last Modified: 21 Nov 2024

    The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' function only removes script tag with a regex, still allowing other HTML tags and attributes to execute javascript, which could lead to authenticated Stored Cross-Site Scripting issues.

    Published: 27 Sept 2021
    4.8
    Medium

    CVE-2021-24569

    Last Modified: 21 Nov 2024

    The Cookie Notice & Compliance for GDPR / CCPA WordPress plugin before 2.1.2 does not escape the value of its Button Text setting when outputting it in an attribute in the frontend, allowing high privilege users such as admin to perform Cross-Site Scripting even when the unfiltered_html capability is disallowed.

    Published: 27 Sept 2021
    4.3
    Medium

    CVE-2021-36878

    Last Modified: 28 Mar 2025

    Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to update settings.

    Published: 27 Sept 2021
    9.8
    Critical

    CVE-2021-37539

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.

    Published: 27 Sept 2021
    6.5
    Medium

    CVE-2021-26587

    Last Modified: 21 Nov 2024

    A potential DOM-based Cross Site Scripting security vulnerability has been identified in HPE StoreOnce. The vulnerability could be remotely exploited to cause an elevation of privilege leading to partial impact to confidentiality, availability, and integrity. HPE has made the following software update - HPE StoreOnce 4.3.0, to resolve the vulnerability in HPE StoreOnce.

    Published: 27 Sept 2021
    7.5
    High

    CVE-2021-34413

    Last Modified: 21 Nov 2024

    All versions of the Zoom Plugin for Microsoft Outlook for MacOS before 5.3.52553.0918 contain a Time-of-check Time-of-use (TOC/TOU) vulnerability during the plugin installation process. This could allow a standard user to write their own malicious application to the plugin directory, allowing the malicious application to execute in a privileged context.

    Published: 27 Sept 2021
    9.8
    Critical

    CVE-2021-34416

    Last Modified: 21 Nov 2024

    The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360.20210325, Zoom on-premise Meeting Connector MMR before version 4.6.360.20210325, Zoom on-premise Recording Connector before version 3.8.44.20210326, Zoom on-premise Virtual Room Connector before version 4.4.6752.20210326, and Zoom on-premise Virtual Room Connector Load Balancer before version 2.5.5495.20210326 fails to validate input sent in requests to update the network configuration, which could lead to remote command injection on the on-premise image by the web portal administrators.

    Published: 27 Sept 2021