CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2021-32284

    Last Modified: 21 Nov 2024

    An issue was discovered in gravity through 0.8.1. A NULL pointer dereference exists in the function ircode_register_pop_context_protect() located in gravity_ircode.c. It allows an attacker to cause Denial of Service.

    Published: 20 Sept 2021
    7.8
    High

    CVE-2021-32281

    Last Modified: 21 Nov 2024

    An issue was discovered in gravity through 0.8.1. A heap-buffer-overflow exists in the function gnode_function_add_upvalue located in gravity_ast.c. It allows an attacker to cause code Execution.

    Published: 20 Sept 2021
    5.5
    Medium

    CVE-2021-32282

    Last Modified: 21 Nov 2024

    An issue was discovered in gravity through 0.8.1. A NULL pointer dereference exists in the function ircode_add_check() located in gravity_ircode.c. It allows an attacker to cause Denial of Service.

    Published: 20 Sept 2021
    7.8
    High

    CVE-2021-32268

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in function gf_fprintf in os_file.c in gpac before 1.0.1 allows attackers to execute arbitrary code. The fixed version is 1.0.1.

    Published: 20 Sept 2021
    5.5
    Medium

    CVE-2021-32285

    Last Modified: 21 Nov 2024

    An issue was discovered in gravity through 0.8.1. A NULL pointer dereference exists in the function list_iterator_next() located in gravity_core.c. It allows an attacker to cause Denial of Service.

    Published: 20 Sept 2021
    7.8
    High

    CVE-2021-32271

    Last Modified: 21 Nov 2024

    An issue was discovered in gpac through 20200801. A stack-buffer-overflow exists in the function DumpRawUIConfig located in odf_dump.c. It allows an attacker to cause code Execution.

    Published: 20 Sept 2021
    5.5
    Medium

    CVE-2021-32270

    Last Modified: 21 Nov 2024

    An issue was discovered in gpac through 20200801. A NULL pointer dereference exists in the function vwid_box_del located in box_code_base.c. It allows an attacker to cause Denial of Service.

    Published: 20 Sept 2021
    5.5
    Medium

    CVE-2021-32275

    Last Modified: 21 Nov 2024

    An issue was discovered in faust through v2.30.5. A NULL pointer dereference exists in the function CosPrim::computeSigOutput() located in cosprim.hh. It allows an attacker to cause Denial of Service.

    Published: 20 Sept 2021
    5.5
    Medium

    CVE-2021-32269

    Last Modified: 21 Nov 2024

    An issue was discovered in gpac through 20200801. A NULL pointer dereference exists in the function ilst_item_box_dump located in box_dump.c. It allows an attacker to cause Denial of Service.

    Published: 20 Sept 2021
    7.8
    High

    CVE-2021-32274

    Last Modified: 21 Nov 2024

    An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_qmf_synthesis_64 located in sbr_qmf.c. It allows an attacker to cause code Execution.

    Published: 20 Sept 2021
    7.8
    High

    CVE-2021-32277

    Last Modified: 21 Nov 2024

    An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_qmf_analysis_32 located in sbr_qmf.c. It allows an attacker to cause code Execution.

    Published: 20 Sept 2021
    7.8
    High

    CVE-2021-32272

    Last Modified: 21 Nov 2024

    An issue was discovered in faad2 before 2.10.0. A heap-buffer-overflow exists in the function stszin located in mp4read.c. It allows an attacker to cause Code Execution.

    Published: 20 Sept 2021
    5.5
    Medium

    CVE-2021-32276

    Last Modified: 21 Nov 2024

    An issue was discovered in faad2 through 2.10.0. A NULL pointer dereference exists in the function get_sample() located in output.c. It allows an attacker to cause Denial of Service.

    Published: 20 Sept 2021
    7.8
    High

    CVE-2021-32273

    Last Modified: 21 Nov 2024

    An issue was discovered in faad2 through 2.10.0. A stack-buffer-overflow exists in the function ftypin located in mp4read.c. It allows an attacker to cause Code Execution.

    Published: 20 Sept 2021
    7.8
    High

    CVE-2021-32278

    Last Modified: 21 Nov 2024

    An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function lt_prediction located in lt_predict.c. It allows an attacker to cause code Execution.

    Published: 20 Sept 2021
    8.8
    High

    CVE-2021-32265

    Last Modified: 21 Nov 2024

    An issue was discovered in Bento4 through v1.6.0-637. A global-buffer-overflow exists in the function AP4_MemoryByteStream::WritePartial() located in Ap4ByteStream.cpp. It allows an attacker to cause code execution or information disclosure.

    Published: 20 Sept 2021
    8.8
    High

    CVE-2021-38093

    Last Modified: 21 Nov 2024

    Integer Overflow vulnerability in function filter_robert in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.

    Published: 20 Sept 2021
    8.8
    High

    CVE-2021-38094

    Last Modified: 21 Nov 2024

    Integer Overflow vulnerability in function filter_sobel in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.

    Published: 20 Sept 2021
    8.8
    High

    CVE-2021-38092

    Last Modified: 21 Nov 2024

    Integer Overflow vulnerability in function filter_prewitt in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.

    Published: 20 Sept 2021
    —
    Unknown

    CVE-2021-38089

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-22035. Reason: This candidate is a duplicate of CVE-2020-22035. Notes: All CVE users should reference CVE-2020-22035 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 20 Sept 2021
    8.8
    High

    CVE-2021-38090

    Last Modified: 21 Nov 2024

    Integer Overflow vulnerability in function filter16_roberts in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.

    Published: 20 Sept 2021
    8.8
    High

    CVE-2021-38091

    Last Modified: 21 Nov 2024

    Integer Overflow vulnerability in function filter16_sobel in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.

    Published: 20 Sept 2021
    —
    Unknown

    CVE-2020-20900

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-22032. Reason: This candidate is a duplicate of CVE-2020-22032. Notes: All CVE users should reference CVE-2020-22032 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 20 Sept 2021
    —
    Unknown

    CVE-2020-20901

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-22022. Reason: This candidate is a duplicate of CVE-2020-22022. Notes: All CVE users should reference CVE-2020-22022 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 20 Sept 2021
    6.5
    Medium

    CVE-2020-20902

    Last Modified: 21 Nov 2024

    A CWE-125: Out-of-bounds read vulnerability exists in long_term_filter function in g729postfilter.c in FFmpeg 4.2.1 during computation of the denominator of pseudo-normalized correlation R'(0), that could result in disclosure of information.

    Published: 20 Sept 2021
    —
    Unknown

    CVE-2020-20897

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-22035. Reason: This candidate is a duplicate of CVE-2020-22035. Notes: All CVE users should reference CVE-2020-22035 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 20 Sept 2021
    —
    Unknown

    CVE-2020-20899

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-22036. Reason: This candidate is a duplicate of CVE-2020-22036. Notes: All CVE users should reference CVE-2020-22036 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 20 Sept 2021
    8.8
    High

    CVE-2020-20898

    Last Modified: 21 Nov 2024

    Integer Overflow vulnerability in function filter16_prewitt in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.

    Published: 20 Sept 2021
    8.8
    High

    CVE-2020-20896

    Last Modified: 21 Nov 2024

    An issue was discovered in function latm_write_packet in libavformat/latmenc.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts due to a Null pointer dereference.

    Published: 20 Sept 2021
    —
    Unknown

    CVE-2020-20895

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-22028. Reason: This candidate is a duplicate of CVE-2020-22028. Notes: All CVE users should reference CVE-2020-22028 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 20 Sept 2021
    —
    Unknown

    CVE-2020-20894

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-22025. Reason: This candidate is a duplicate of CVE-2020-22025. Notes: All CVE users should reference CVE-2020-22025 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 20 Sept 2021
    —
    Unknown

    CVE-2020-20893

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-22030. Reason: This candidate is a duplicate of CVE-2020-22030. Notes: All CVE users should reference CVE-2020-22030 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 20 Sept 2021
    8.8
    High

    CVE-2020-20892

    Last Modified: 21 Nov 2024

    An issue was discovered in function filter_frame in libavfilter/vf_lenscorrection.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts due to a division by zero.

    Published: 20 Sept 2021
    8.8
    High

    CVE-2020-20891

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in function config_input in libavfilter/vf_gblur.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.

    Published: 20 Sept 2021
    9.8
    Critical

    CVE-2021-40674

    Last Modified: 21 Nov 2024

    An SQL injection vulnerability exists in Wuzhi CMS v4.1.0 via the KeyValue parameter in coreframe/app/order/admin/index.php.

    Published: 20 Sept 2021
    7.2
    High

    CVE-2021-39402

    Last Modified: 21 Nov 2024

    MaianAffiliate v.1.0 is suffers from code injection by adding a new product via the admin panel. The injected payload is reflected on the affiliate main page for all authenticated and unauthenticated visitors.

    Published: 20 Sept 2021
    5.3
    Medium

    CVE-2019-16651

    Last Modified: 21 Nov 2024

    An issue was discovered on Virgin Media Super Hub 3 (based on ARRIS TG2492) devices. Because their SNMP commands have insufficient protection mechanisms, it is possible to use JavaScript and DNS rebinding to leak the WAN IP address of a user (if they are using certain VPN implementations, this would decloak them).

    Published: 20 Sept 2021
    9.8
    Critical

    CVE-2021-24741

    Last Modified: 21 Nov 2024

    The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable by unauthenticated users.

    Published: 20 Sept 2021
    7.2
    High

    CVE-2021-24663

    Last Modified: 21 Nov 2024

    The Simple Schools Staff Directory WordPress plugin through 1.1 does not validate uploaded logo pictures to ensure that are indeed images, allowing high privilege users such as admin to upload arbitrary file like PHP, leading to RCE

    Published: 20 Sept 2021
    6.1
    Medium

    CVE-2021-24657

    Last Modified: 21 Nov 2024

    The Limit Login Attempts WordPress plugin before 4.0.50 does not escape the IP addresses (which can be controlled by attacker via headers such as X-Forwarded-For) of attempted logins before outputting them in the reports table, leading to an Unauthenticated Stored Cross-Site Scripting issue.

    Published: 20 Sept 2021
    5.4
    Medium

    CVE-2021-24640

    Last Modified: 21 Nov 2024

    The WordPress Slider Block Gutenslider plugin before 5.2.0 does not escape the minWidth attribute of a Gutenburg block, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

    Published: 20 Sept 2021
    8.1
    High

    CVE-2021-24639

    Last Modified: 21 Nov 2024

    The OMGF WordPress plugin before 4.5.4 does not enforce path validation, authorisation and CSRF checks in the omgf_ajax_empty_dir AJAX action, which allows any authenticated users to delete arbitrary files or folders on the server.

    Published: 20 Sept 2021
    9.1
    Critical

    CVE-2021-24638

    Last Modified: 21 Nov 2024

    The OMGF WordPress plugin before 4.5.4 does not escape or validate the handle parameter of the REST API, which allows unauthenticated users to perform path traversal and overwrite arbitrary CSS file with Google Fonts CSS, or download fonts uploaded on Google Fonts website.

    Published: 20 Sept 2021
    5.4
    Medium

    CVE-2021-24637

    Last Modified: 21 Nov 2024

    The Google Fonts Typography WordPress plugin before 3.0.3 does not escape and sanitise some of its block settings, allowing users with as role as low as Contributor to perform Stored Cross-Site Scripting attacks via blockType (combined with content), align, color, variant and fontID argument of a Gutenberg block.

    Published: 20 Sept 2021
    8.1
    High

    CVE-2021-24636

    Last Modified: 21 Nov 2024

    The Print My Blog WordPress Plugin before 3.4.2 does not enforce nonce (CSRF) checks, which allows attackers to make logged in administrators deactivate the Print My Blog plugin and delete all saved data for that plugin by tricking them to open a malicious link

    Published: 20 Sept 2021
    5.4
    Medium

    CVE-2021-24635

    Last Modified: 21 Nov 2024

    The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the CSRF nonce displayed for all authenticated users, allowing any authenticated user (such as subscriber) to call them and 1) Get and search through title and content of Draft post, 2) Get title of a password-protected post as well as 3) Upload an image from an URL

    Published: 20 Sept 2021
    5.4
    Medium

    CVE-2021-24618

    Last Modified: 21 Nov 2024

    The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result into a Stored Cross-Site Scripting (XSS). Furthermore, the plugin also does not have any CSRF and capability checks in place when saving such setting, allowing any authenticated user (as low as subscriber), or unauthenticated user via a CSRF vector to update them and perform such attack.

    Published: 20 Sept 2021
    4.8
    Medium

    CVE-2021-24613

    Last Modified: 21 Nov 2024

    The Post Views Counter WordPress plugin before 1.3.5 does not sanitise or escape its Post Views Label settings, which could allow high privilege users to perform Cross-Site Scripting attacks in the frontend even when the unfiltered_html capability is disallowed

    Published: 20 Sept 2021
    4.8
    Medium

    CVE-2021-24609

    Last Modified: 21 Nov 2024

    The WP Mapa Politico Espana WordPress plugin before 3.7.0 does not sanitise or escape some of its settings before outputting them in attributes, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

    Published: 20 Sept 2021
    8.8
    High

    CVE-2021-24606

    Last Modified: 21 Nov 2024

    The Availability Calendar WordPress plugin before 1.2.1 does not escape the category attribute from its shortcode before using it in a SQL statement, leading to a SQL Injection issue, which can be exploited by any user able to add shortcode to posts/pages, such as contributor+

    Published: 20 Sept 2021