CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2021-24604

    Last Modified: 21 Nov 2024

    The Availability Calendar WordPress plugin before 1.2.2 does not sanitise or escape its Category Names before outputting them in page/post where the associated shortcode is embed, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

    Published: 20 Sept 2021
    4.8
    Medium

    CVE-2021-24600

    Last Modified: 21 Nov 2024

    The WP Dialog WordPress plugin through 1.2.5.5 does not sanitise and escape some of its settings before outputting them in pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 20 Sept 2021
    5.4
    Medium

    CVE-2021-24597

    Last Modified: 21 Nov 2024

    The You Shang WordPress plugin through 1.0.1 does not escape its qrcode links settings, which result into Stored Cross-Site Scripting issues in frontend posts and the plugins settings page depending on the payload used

    Published: 20 Sept 2021
    4.8
    Medium

    CVE-2021-24596

    Last Modified: 21 Nov 2024

    The youForms for WordPress plugin through 1.0.5 does not sanitise escape the Button Text field of its Templates, allowing high privilege users (editors and admins) to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 20 Sept 2021
    5.4
    Medium

    CVE-2021-24587

    Last Modified: 21 Nov 2024

    The Splash Header WordPress plugin before 1.20.8 doesn't sanitise and escape some of its settings while outputting them in the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue.

    Published: 20 Sept 2021
    6.5
    Medium

    CVE-2021-24585

    Last Modified: 21 Nov 2024

    The Timetable and Event Schedule WordPress plugin before 2.4.0 outputs the Hashed Password, Username and Email Address (along other less sensitive data) of the user related to the Even Head of the Timeslot in the response when requesting the event Timeslot data with a user with the edit_posts capability. Combined with the other Unauthorised Event Timeslot Modification issue (https://wpscan.com/reports/submissions/4699/) where an arbitrary user ID can be set, this could allow low privilege users with the edit_posts capability (such as author) to retrieve sensitive User data by iterating over the user_id

    Published: 20 Sept 2021
    5.4
    Medium

    CVE-2021-24584

    Last Modified: 21 Nov 2024

    The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when updating a timeslot, allowing any user with the edit_posts capability (contributor+) to update arbitrary timeslot from any events. Furthermore, no CSRF check is in place as well, allowing such attack to be perform via CSRF against a logged in with such capability. In versions before 2.3.19, the lack of sanitisation and escaping in some of the fields, like the descritption could also lead to Stored XSS issues

    Published: 20 Sept 2021
    4.3
    Medium

    CVE-2021-24583

    Last Modified: 21 Nov 2024

    The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when deleting a timeslot, allowing any user with the edit_posts capability (contributor+) to delete arbitrary timeslot from any events. Furthermore, no CSRF check is in place as well, allowing such attack to be performed via CSRF against a logged in with such capability

    Published: 20 Sept 2021
    5.4
    Medium

    CVE-2021-24582

    Last Modified: 21 Nov 2024

    The ThinkTwit WordPress plugin before 1.7.1 did not sanitise or escape its "Consumer key" setting before outputting it its settings page, leading to a Stored Cross-Site Scripting issue.

    Published: 20 Sept 2021
    4.8
    Medium

    CVE-2021-24530

    Last Modified: 21 Nov 2024

    The Alojapro Widget WordPress plugin through 1.1.15 doesn't properly sanitise its Custom CSS settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 20 Sept 2021
    5.4
    Medium

    CVE-2021-24525

    Last Modified: 21 Nov 2024

    The Shortcodes Ultimate WordPress plugin before 5.10.2 allows users with Contributor roles to perform stored XSS via shortcode attributes. Note: the plugin is inconsistent in its handling of shortcode attributes; some do escape, most don't, and there are even some attributes that are insecure by design (like [su_button]'s onclick attribute).

    Published: 20 Sept 2021
    7.2
    High

    CVE-2021-24511

    Last Modified: 21 Nov 2024

    The fetch_product_ajax functionality in the Product Feed on WooCommerce WordPress plugin before 3.3.1.0 uses a `product_id` POST parameter which is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

    Published: 20 Sept 2021
    8.8
    High

    CVE-2021-24404

    Last Modified: 21 Nov 2024

    The options.php file of the WP-Board WordPress plugin through 1.1 beta accepts a postid parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. This is a time based SQLI and in the same function vulnerable parameter is passed twice so if we pass time as 5 seconds it takes 10 seconds to return since the query ran twice.

    Published: 20 Sept 2021
    7.2
    High

    CVE-2021-24403

    Last Modified: 21 Nov 2024

    The Orders functionality in the WordPress Page Contact plugin through 1.0 has an order_id parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. The feature is available to low privilege users such as contributors

    Published: 20 Sept 2021
    7.2
    High

    CVE-2021-24402

    Last Modified: 21 Nov 2024

    The Orders functionality in the WP iCommerce WordPress plugin through 1.1.1 has an `order_id` parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. The feature is available to low privilege users such as contributors

    Published: 20 Sept 2021
    7.2
    High

    CVE-2021-24401

    Last Modified: 21 Nov 2024

    The Edit domain functionality in the WP Domain Redirect WordPress plugin through 1.0 has an `editid` parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

    Published: 20 Sept 2021
    7.2
    High

    CVE-2021-24400

    Last Modified: 21 Nov 2024

    The Edit Role functionality in the Display Users WordPress plugin through 2.0.0 had an `id` parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

    Published: 20 Sept 2021
    7.2
    High

    CVE-2021-24399

    Last Modified: 21 Nov 2024

    The check_order function of The Sorter WordPress plugin through 1.0 uses an `area_id` parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

    Published: 20 Sept 2021
    7.2
    High

    CVE-2021-24398

    Last Modified: 21 Nov 2024

    The Add new scene functionality in the Responsive 3D Slider WordPress plugin through 1.2 uses an id parameter which is not sanitised, escaped or validated before being inserted to a SQL statement, leading to SQL injection. This is a time based SQLI and in the same function vulnerable parameter is passed twice so if we pass time as 5 seconds it takes 10 seconds to return since the query is ran twice.

    Published: 20 Sept 2021
    7.2
    High

    CVE-2021-24397

    Last Modified: 21 Nov 2024

    The edit functionality in the MicroCopy WordPress plugin through 1.1.0 makes a get request to fetch the related option. The id parameter used is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

    Published: 20 Sept 2021
    7.2
    High

    CVE-2021-24396

    Last Modified: 21 Nov 2024

    A pageid GET parameter of the GSEOR – WordPress SEO Plugin WordPress plugin through 1.3 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

    Published: 20 Sept 2021
    7.5
    High

    CVE-2021-40325

    Last Modified: 21 Nov 2024

    Cobbler before 3.3.0 allows authorization bypass for modification of settings.

    Published: 20 Sept 2021
    5.5
    Medium

    CVE-2020-21913

    Last Modified: 21 Nov 2024

    International Components for Unicode (ICU-20850) v66.1 was discovered to contain a use after free bug in the pkg_createWithAssemblyCode function in the file tools/pkgdata/pkgdata.cpp.

    Published: 20 Sept 2021
    7.5
    High

    CVE-2020-26301

    Last Modified: 21 Nov 2024

    ssh2 is client and server modules written in pure JavaScript for node.js. In ssh2 before version 1.4.0 there is a command injection vulnerability. The issue only exists on Windows. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This is fixed in version 1.4.0.

    Published: 20 Sept 2021
    9.8
    Critical

    CVE-2021-40323

    Last Modified: 21 Nov 2024

    Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.

    Published: 20 Sept 2021
    7.5
    High

    CVE-2021-40324

    Last Modified: 21 Nov 2024

    Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.

    Published: 20 Sept 2021
    7.7
    High

    CVE-2021-4435

    Last Modified: 17 Jun 2025

    An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could be executed in unexpected ways.

    Published: 20 Sept 2021
    7.5
    High

    CVE-2020-21468

    Last Modified: 5 Jul 2026

    A segmentation fault in the redis-server component of Redis 5.0.7 leads to a denial of service (DOS). NOTE: the vendor cannot reproduce this issue in a released version, such as 5.0.7.

    Published: 20 Sept 2021
    —
    Unknown

    CVE-2021-23441

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 19 Sept 2021
    7.8
    High

    CVE-2021-41073

    Last Modified: 21 Nov 2024

    loop_rw_iter in fs/io_uring.c in the Linux kernel 5.10 through 5.14.6 allows local users to gain privileges by using IORING_OP_PROVIDE_BUFFERS to trigger a free of a kernel buffer, as demonstrated by using /proc/<pid>/maps for exploitation.

    Published: 19 Sept 2021
    9.8
    Critical

    CVE-2021-41393

    Last Modified: 21 Nov 2024

    Teleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows forgery of SSH host certificates in some situations.

    Published: 18 Sept 2021
    6.5
    Medium

    CVE-2021-41395

    Last Modified: 21 Nov 2024

    Teleport before 6.2.12 and 7.x before 7.1.1 allows attackers to control a database connection string, in some situations, via a crafted database name or username.

    Published: 18 Sept 2021
    5.3
    Medium

    CVE-2021-41394

    Last Modified: 21 Nov 2024

    Teleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows alteration of build artifacts in some situations.

    Published: 18 Sept 2021
    5.3
    Medium

    CVE-2021-3806

    Last Modified: 18 May 2026

    A path traversal vulnerability on Pardus Software Center's "extractArchive" function could allow anyone on the same network to do a man-in-the-middle and write files on the system.

    Published: 18 Sept 2021
    5.5
    Medium

    CVE-2021-3933

    Last Modified: 21 Nov 2024

    An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could cause an invalid bytesPerLine and maxBytesPerLine value, which could lead to problems with application stability or lead to other attack paths.

    Published: 18 Sept 2021
    9.8
    Critical

    CVE-2021-41392

    Last Modified: 21 Nov 2024

    static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal Electron API.

    Published: 17 Sept 2021
    5.4
    Medium

    CVE-2021-41391

    Last Modified: 21 Nov 2024

    In Ericsson ECM before 18.0, it was observed that Security Management Endpoint in User Profile Management Section is vulnerable to stored XSS via a name, leading to session hijacking and full account takeover.

    Published: 17 Sept 2021
    8
    High

    CVE-2021-41390

    Last Modified: 21 Nov 2024

    In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Injection.

    Published: 17 Sept 2021
    8.8
    High

    CVE-2021-41387

    Last Modified: 21 Nov 2024

    seatd-launch in seatd 0.6.x before 0.6.2 allows privilege escalation because it uses execlp and may be installed setuid root.

    Published: 17 Sept 2021
    8.8
    High

    CVE-2020-21548

    Last Modified: 24 Apr 2026

    Libsixel 1.8.3 contains a heap-based buffer overflow in the sixel_encode_highcolor function in tosixel.c.

    Published: 17 Sept 2021
    8.8
    High

    CVE-2020-21547

    Last Modified: 24 Apr 2026

    Libsixel 1.8.2 contains a heap-based buffer overflow in the dither_func_fs function in tosixel.c.

    Published: 17 Sept 2021
    6.3
    Medium

    CVE-2021-39218

    Last Modified: 21 Nov 2024

    Wasmtime is an open source runtime for WebAssembly & WASI. In Wasmtime from version 0.26.0 and before version 0.30.0 is affected by a memory unsoundness vulnerability. There was an invalid free and out-of-bounds read and write bug when running Wasm that uses `externref`s in Wasmtime. To trigger this bug, Wasmtime needs to be running Wasm that uses `externref`s, the host creates non-null `externrefs`, Wasmtime performs a garbage collection (GC), and there has to be a Wasm frame on the stack that is at a GC safepoint where there are no live references at this safepoint, and there is a safepoint with live references earlier in this frame's function. Under this scenario, Wasmtime would incorrectly use the GC stack map for the safepoint from earlier in the function instead of the empty safepoint. This would result in Wasmtime treating arbitrary stack slots as `externref`s that needed to be rooted for GC. At the *next* GC, it would be determined that nothing was referencing these bogus `externref`s (because nothing could ever reference them, because they are not really `externref`s) and then Wasmtime would deallocate them and run `<ExternRef as Drop>::drop` on them. This results in a free of memory that is not necessarily on the heap (and shouldn't be freed at this moment even if it was), as well as potential out-of-bounds reads and writes. Even though support for `externref`s (via the reference types proposal) is enabled by default, unless you are creating non-null `externref`s in your host code or explicitly triggering GCs, you cannot be affected by this bug. We have reason to believe that the effective impact of this bug is relatively small because usage of `externref` is currently quite rare. This bug has been patched and users should upgrade to Wasmtime version 0.30.0. If you cannot upgrade Wasmtime at this time, you can avoid this bug by disabling the reference types proposal by passing `false` to `wasmtime::Config::wasm_reference_types`.

    Published: 17 Sept 2021
    6.3
    Medium

    CVE-2021-39219

    Last Modified: 21 Nov 2024

    Wasmtime is an open source runtime for WebAssembly & WASI. Wasmtime before version 0.30.0 is affected by a type confusion vulnerability. As a Rust library the `wasmtime` crate clearly marks which functions are safe and which are `unsafe`, guaranteeing that if consumers never use `unsafe` then it should not be possible to have memory unsafety issues in their embeddings of Wasmtime. An issue was discovered in the safe API of `Linker::func_*` APIs. These APIs were previously not sound when one `Engine` was used to create the `Linker` and then a different `Engine` was used to create a `Store` and then the `Linker` was used to instantiate a module into that `Store`. Cross-`Engine` usage of functions is not supported in Wasmtime and this can result in type confusion of function pointers, resulting in being able to safely call a function with the wrong type. Triggering this bug requires using at least two `Engine` values in an embedding and then additionally using two different values with a `Linker` (one at the creation time of the `Linker` and another when instantiating a module with the `Linker`). It's expected that usage of more-than-one `Engine` in an embedding is relatively rare since an `Engine` is intended to be a globally shared resource, so the expectation is that the impact of this issue is relatively small. The fix implemented is to change this behavior to `panic!()` in Rust instead of silently allowing it. Using different `Engine` instances with a `Linker` is a programmer bug that `wasmtime` catches at runtime. This bug has been patched and users should upgrade to Wasmtime version 0.30.0. If you cannot upgrade Wasmtime and are using more than one `Engine` in your embedding it's recommended to instead use only one `Engine` for the entire program if possible. An `Engine` is designed to be a globally shared resource that is suitable to have only one for the lifetime of an entire process. If using multiple `Engine`s is required then code should be audited to ensure that `Linker` is only used with one `Engine`.

    Published: 17 Sept 2021
    6.3
    Medium

    CVE-2021-39216

    Last Modified: 21 Nov 2024

    Wasmtime is an open source runtime for WebAssembly & WASI. In Wasmtime from version 0.19.0 and before version 0.30.0 there was a use-after-free bug when passing `externref`s from the host to guest Wasm content. To trigger the bug, you have to explicitly pass multiple `externref`s from the host to a Wasm instance at the same time, either by passing multiple `externref`s as arguments from host code to a Wasm function, or returning multiple `externref`s to Wasm from a multi-value return function defined in the host. If you do not have host code that matches one of these shapes, then you are not impacted. If Wasmtime's `VMExternRefActivationsTable` became filled to capacity after passing the first `externref` in, then passing in the second `externref` could trigger a garbage collection. However the first `externref` is not rooted until we pass control to Wasm, and therefore could be reclaimed by the collector if nothing else was holding a reference to it or otherwise keeping it alive. Then, when control was passed to Wasm after the garbage collection, Wasm could use the first `externref`, which at this point has already been freed. We have reason to believe that the effective impact of this bug is relatively small because usage of `externref` is currently quite rare. The bug has been fixed, and users should upgrade to Wasmtime 0.30.0. If you cannot upgrade Wasmtime yet, you can avoid the bug by disabling reference types support in Wasmtime by passing `false` to `wasmtime::Config::wasm_reference_types`.

    Published: 17 Sept 2021
    7.2
    High

    CVE-2021-41383

    Last Modified: 21 Nov 2024

    setup.cgi on NETGEAR R6020 1.0.0.48 devices allows an admin to execute arbitrary shell commands via shell metacharacters in the ntp_server field.

    Published: 17 Sept 2021
    6.5
    Medium

    CVE-2021-41380

    Last Modified: 21 Nov 2024

    RealVNC Viewer 6.21.406 allows remote VNC servers to cause a denial of service (application crash) via crafted RFB protocol data. NOTE: It is asserted that this issue requires social engineering a user into connecting to a fake VNC Server. The VNC Viewer application they are using will then hang, until terminated, but no memory leak occurs - the resources are freed once the hung process is terminated and the resource usage is constant during the hang. Only the process that is connected to the fake Server is affected. This is an application bug, not a security issue

    Published: 17 Sept 2021
    9.6
    Critical

    CVE-2021-38412

    Last Modified: 21 Nov 2024

    Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Rack device do not require authentication or authentication tokens. This vulnerability could allow an attacker to enable the SNMP service and manipulate the community strings to achieve further control in.

    Published: 17 Sept 2021
    7.8
    High

    CVE-2021-38404

    Last Modified: 23 Apr 2025

    Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in a heap-based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process.

    Published: 17 Sept 2021
    7.8
    High

    CVE-2021-38402

    Last Modified: 23 Apr 2025

    Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could lead to a stack-based buffer overflow while trying to copy to a buffer during font string handling. An attacker could leverage this vulnerability to execute code in the context of the current process.

    Published: 17 Sept 2021
    7.8
    High

    CVE-2021-38406

    Last Modified: 30 Oct 2025

    Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in multiple out-of-bounds write instances. An attacker could leverage this vulnerability to execute code in the context of the current process.

    Published: 17 Sept 2021