CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2020-20672

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in /admin/upload/uploadfile of KiteCMS V1.1 allows attackers to getshell via a crafted PHP file.

    Published: 13 Sept 2021
    8.8
    High

    CVE-2020-20671

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) in KiteCMS V1.1 allows attackers to arbitrarily add an administrator account.

    Published: 13 Sept 2021
    8.8
    High

    CVE-2020-20670

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in /admin/media/upload of ZKEACMS V3.2.0 allows attackers to execute arbitrary code via a crafted HTML file.

    Published: 13 Sept 2021
    8.1
    High

    CVE-2021-41033

    Last Modified: 21 Nov 2024

    In all released versions of Eclipse Equinox, at least until version 4.21 (September 2021), installation can be vulnerable to man-in-the-middle attack if using p2 repos that are HTTP; that can then be exploited to serve incorrect p2 metadata and entirely alter the local installation, particularly by installing plug-ins that may then run malicious code.

    Published: 13 Sept 2021
    7.5
    High

    CVE-2021-41054

    Last Modified: 21 Nov 2024

    tftpd_file.c in atftp through 0.7.4 has a buffer overflow because buffer-size handling does not properly consider the combination of data, OACK, and other options.

    Published: 13 Sept 2021
    5.5
    Medium

    CVE-2021-32139

    Last Modified: 21 Nov 2024

    The gf_isom_vp_config_get function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

    Published: 13 Sept 2021
    5.5
    Medium

    CVE-2021-32138

    Last Modified: 21 Nov 2024

    The DumpTrackInfo function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

    Published: 13 Sept 2021
    —
    Unknown

    CVE-2021-41010

    Last Modified: 7 Nov 2023

    CVE was unused by HPE.

    Published: 13 Sept 2021
    —
    Unknown

    CVE-2021-41007

    Last Modified: 7 Nov 2023

    CVE was unused by HPE.

    Published: 13 Sept 2021
    —
    Unknown

    CVE-2021-41009

    Last Modified: 7 Nov 2023

    CVE was unused by HPE.

    Published: 13 Sept 2021
    —
    Unknown

    CVE-2021-41008

    Last Modified: 7 Nov 2023

    CVE was unused by HPE.

    Published: 13 Sept 2021
    —
    Unknown

    CVE-2021-41006

    Last Modified: 7 Nov 2023

    CVE was unused by HPE.

    Published: 13 Sept 2021
    5.9
    Medium

    CVE-2021-40824

    Last Modified: 21 Nov 2024

    A logic error in the room key sharing functionality of Element Android before 1.2.2 and matrix-android-sdk2 (aka Matrix SDK for Android) before 1.2.2 allows a malicious Matrix homeserver present in an encrypted room to steal room encryption keys (via crafted Matrix protocol messages) that were originally sent by affected Matrix clients participating in that room. This allows the attacker to decrypt end-to-end encrypted messages sent by affected clients.

    Published: 13 Sept 2021
    7.8
    High

    CVE-2021-33362

    Last Modified: 21 Nov 2024

    Stack buffer overflow in the hevc_parse_vps_extension function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.

    Published: 13 Sept 2021
    5.9
    Medium

    CVE-2021-40823

    Last Modified: 21 Nov 2024

    A logic error in the room key sharing functionality of matrix-js-sdk (aka Matrix Javascript SDK) before 12.4.1 allows a malicious Matrix homeserver present in an encrypted room to steal room encryption keys (via crafted Matrix protocol messages) that were originally sent by affected Matrix clients participating in that room. This allows the homeserver to decrypt end-to-end encrypted messages sent by affected clients.

    Published: 13 Sept 2021
    9.8
    Critical

    CVE-2021-3666

    Last Modified: 21 Nov 2024

    body-parser-xml is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

    Published: 13 Sept 2021
    8.8
    High

    CVE-2021-24728

    Last Modified: 21 Nov 2024

    The Membership & Content Restriction – Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, validate or escape its order and orderby parameters before using them in SQL statement, leading to Authenticated SQL Injections in the Members and Payments pages.

    Published: 13 Sept 2021
    8.8
    High

    CVE-2021-24727

    Last Modified: 16 Jan 2026

    The StopBadBots WordPress plugin before 6.60 did not validate or escape the order and orderby GET parameter in some of its admin dashboard pages, leading to Authenticated SQL Injections

    Published: 13 Sept 2021
    8.8
    High

    CVE-2021-24726

    Last Modified: 21 Nov 2024

    The WP Simple Booking Calendar WordPress plugin before 2.0.6 did not escape, validate or sanitise the orderby parameter in its Search Calendars action, before using it in a SQL statement, leading to an authenticated SQL injection issue

    Published: 13 Sept 2021
    4.3
    Medium

    CVE-2021-24725

    Last Modified: 21 Nov 2024

    The Comment Link Remove and Other Comment Tools WordPress plugin before 2.1.6 does not have CSRF check in its 'Delete comments easily', which could allow attackers to make logged in admin delete arbitrary comments

    Published: 13 Sept 2021
    5.4
    Medium

    CVE-2021-24724

    Last Modified: 21 Nov 2024

    The Timetable and Event Schedule by MotoPress WordPress plugin before 2.3.19 does not sanitise some of its parameters, which could allow low privilege users such as author to perform XSS attacks against frontend and backend users when viewing the related event/s

    Published: 13 Sept 2021
    4.8
    Medium

    CVE-2021-24623

    Last Modified: 21 Nov 2024

    The WordPress Advanced Ticket System, Elite Support Helpdesk WordPress plugin before 1.0.64 does not sanitize or escape form values before saving to the database or when outputting, which allows high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 13 Sept 2021
    4.8
    Medium

    CVE-2021-24621

    Last Modified: 21 Nov 2024

    The WP Courses LMS WordPress plugin before 2.0.44 does not sanitise its Video Embed Code, allowing malicious code to be injected in it by high privilege users, even when the unfiltered_html capability is disallowed, which could lead to Stored Cross-Site Scripting issues

    Published: 13 Sept 2021
    8.8
    High

    CVE-2021-24620

    Last Modified: 21 Nov 2024

    The WordPress Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin through 2.2.5 does not check for the uploaded Downloadable Digital product file, allowing any file, such as PHP to be uploaded by an administrator. Furthermore, as there is no CSRF in place, attackers could also make a logged admin upload a malicious PHP file, which would lead to RCE

    Published: 13 Sept 2021
    4.8
    Medium

    CVE-2021-24619

    Last Modified: 21 Nov 2024

    The Per page add to head WordPress plugin through 1.4.4 does not properly sanitise one of its setting, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html capability is disallowed, which could lead to Cross-Site Scripting issues.

    Published: 13 Sept 2021
    4.8
    Medium

    CVE-2021-24614

    Last Modified: 21 Nov 2024

    The Book appointment online WordPress plugin before 1.39 does not sanitise or escape Service Prices before outputting it in the List, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 13 Sept 2021
    5.4
    Medium

    CVE-2021-24605

    Last Modified: 21 Nov 2024

    The create_post_page AJAX action of the Custom Post View Generator WordPress plugin through 0.4.6 (available to authenticated user) does not sanitise or escape user input before outputting it back in the response, leading to a Reflected Cross-Site issue

    Published: 13 Sept 2021
    4.3
    Medium

    CVE-2021-24586

    Last Modified: 21 Nov 2024

    The Per page add to head WordPress plugin before 1.4.4 is lacking any CSRF check when saving its settings, which could allow attackers to make a logged in admin change them. Furthermore, as the plugin allows arbitrary HTML to be inserted in one of the setting (feature mentioned by the plugin), this could lead to Stored XSS issue which will be triggered either in the backend, frontend or both depending on the payload used.

    Published: 13 Sept 2021
    6.1
    Medium

    CVE-2021-24560

    Last Modified: 21 Nov 2024

    The Software License Manager WordPress plugin before 4.4.8 does not sanitise or escape the edit_record parameter before outputting it back in the page in the admin dashboard, leading to a Reflected Cross-Site Scripting issue

    Published: 13 Sept 2021
    5.4
    Medium

    CVE-2021-24523

    Last Modified: 21 Nov 2024

    The Daily Prayer Time WordPress plugin before 2021.08.10 does not sanitise or escape some of its settings before outputting them in the page, leading to Authenticated Stored Cross-Site Scripting issues.

    Published: 13 Sept 2021
    6.1
    Medium

    CVE-2021-24510

    Last Modified: 21 Nov 2024

    The MF Gig Calendar WordPress plugin before 1.2 does not sanitise and escape the id GET parameter before outputting back in the admin dashboard when editing an Event, leading to a reflected Cross-Site Scripting issue

    Published: 13 Sept 2021
    6.1
    Medium

    CVE-2021-24508

    Last Modified: 21 Nov 2024

    The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter in its feed_locator AJAX action (available to both authenticated and unauthenticated users) before outputting a truncated version of it in the admin dashboard, leading to an unauthenticated Stored Cross-Site Scripting issue which will be executed in the context of a logged in administrator.

    Published: 13 Sept 2021
    9.8
    Critical

    CVE-2021-24493

    Last Modified: 21 Nov 2024

    The shopp_upload_file AJAX action of the Shopp WordPress plugin through 1.4, available to both unauthenticated and authenticated user does not have any security measure in place to prevent upload of malicious files, such as PHP, allowing unauthenticated users to upload arbitrary files and leading to RCE

    Published: 13 Sept 2021
    8.8
    High

    CVE-2021-24491

    Last Modified: 21 Nov 2024

    The Fileviewer WordPress plugin through 2.2 does not have CSRF checks in place when performing actions such as upload and delete files. As a result, attackers could make a logged in administrator delete and upload arbitrary files via a CSRF attack

    Published: 13 Sept 2021
    6.8
    Medium

    CVE-2021-24490

    Last Modified: 21 Nov 2024

    The Email Artillery (MASS EMAIL) WordPress plugin through 4.1 does not properly check the uploaded files from the Import Emails feature, allowing arbitrary files to be uploaded. Furthermore, the plugin is also lacking any CSRF check, allowing such issue to be exploited via a CSRF attack as well. However, due to the presence of a .htaccess, denying access to everything in the folder the file is uploaded to, the malicious uploaded file will only be accessible on Web Servers such as Nginx/IIS

    Published: 13 Sept 2021
    4.3
    Medium

    CVE-2021-24431

    Last Modified: 21 Nov 2024

    The Language Bar Flags WordPress plugin through 1.0.8 does not have any CSRF in place when saving its settings and did not sanitise or escape them when generating the flag bar in the frontend. This could allow attackers to make a logged in admin change the settings, and set Cross-Site Scripting payload in them, which will be executed in the frontend for all users

    Published: 13 Sept 2021
    7.2
    High

    CVE-2021-33554

    Last Modified: 21 Nov 2024

    Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

    Published: 13 Sept 2021
    7.2
    High

    CVE-2021-33553

    Last Modified: 21 Nov 2024

    Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

    Published: 13 Sept 2021
    7.2
    High

    CVE-2021-33552

    Last Modified: 21 Nov 2024

    Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

    Published: 13 Sept 2021
    7.2
    High

    CVE-2021-33551

    Last Modified: 21 Nov 2024

    Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

    Published: 13 Sept 2021
    7.2
    High

    CVE-2021-33550

    Last Modified: 21 Nov 2024

    Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

    Published: 13 Sept 2021
    7.2
    High

    CVE-2021-33549

    Last Modified: 21 Nov 2024

    Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the action parameter, which may allow an attacker to remotely execute arbitrary code.

    Published: 13 Sept 2021
    7.2
    High

    CVE-2021-33548

    Last Modified: 21 Nov 2024

    Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

    Published: 13 Sept 2021
    7.2
    High

    CVE-2021-33547

    Last Modified: 21 Nov 2024

    Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the profile parameter which may allow an attacker to remotely execute arbitrary code.

    Published: 13 Sept 2021
    7.2
    High

    CVE-2021-33546

    Last Modified: 21 Nov 2024

    Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the name parameter, which may allow an attacker to remotely execute arbitrary code.

    Published: 13 Sept 2021
    7.2
    High

    CVE-2021-33545

    Last Modified: 21 Nov 2024

    Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the counter parameter which may allow an attacker to remotely execute arbitrary code.

    Published: 13 Sept 2021
    7.2
    High

    CVE-2021-33544

    Last Modified: 21 Nov 2024

    Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

    Published: 13 Sept 2021
    9.8
    Critical

    CVE-2021-33543

    Last Modified: 21 Nov 2024

    Multiple camera devices by UDP Technology, Geutebrück and other vendors allow unauthenticated remote access to sensitive files due to default user authentication settings. This can lead to manipulation of the device and denial of service.

    Published: 13 Sept 2021
    9.8
    Critical

    CVE-2021-38833

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in PHPGurukul Apartment Visitors Management System (AVMS) v. 1.0 allows attackers to execute arbitrary SQL statements and to gain RCE.

    Published: 13 Sept 2021
    5.4
    Medium

    CVE-2021-29643

    Last Modified: 21 Nov 2024

    PRTG Network Monitor before 21.3.69.1333 allows stored XSS via an unsanitized string imported from a User Object in a connected Active Directory instance.

    Published: 13 Sept 2021