CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2021-38327

    Last Modified: 2 May 2025

    The YouTube Video Inserter WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/adminUI/settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.1.0.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-38339

    Last Modified: 2 May 2025

    The Simple Matted Thumbnails WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/simple-matted-thumbnail.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.01.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-38347

    Last Modified: 2 May 2025

    The Custom Website Data WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter found in the ~/views/edit.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.2.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-38355

    Last Modified: 2 May 2025

    The Bug Library WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the successimportcount parameter found in the ~/bug-library.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.3.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-38336

    Last Modified: 2 May 2025

    The Edit Comments XT WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/edit-comments-xt.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.

    Published: 10 Sept 2021
    9.8
    Critical

    CVE-2021-40373

    Last Modified: 21 Nov 2024

    playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then executing that code via the index.php?app=main&inc=core_welcome URI.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-38335

    Last Modified: 2 May 2025

    The Wise Agent Capture Forms WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/WiseAgentCaptureForm.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-38329

    Last Modified: 2 May 2025

    The DJ EmailPublish WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/dj-email-publish.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.7.2.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-38328

    Last Modified: 2 May 2025

    The Notices WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/notices.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 6.1.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-38338

    Last Modified: 2 May 2025

    The Border Loading Bar WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `f` and `t` parameter found in the ~/titan-framework/iframe-googlefont-preview.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.1.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-38331

    Last Modified: 2 May 2025

    The WP-T-Wap WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the posted parameter found in the ~/wap/writer.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.13.2.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-38333

    Last Modified: 2 May 2025

    The WP Scrippets WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/wp-scrippets.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.5.1.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-38352

    Last Modified: 2 May 2025

    The Feedify – Web Push Notifications WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the feedify_msg parameter found in the ~/includes/base.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.1.8.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-38341

    Last Modified: 2 May 2025

    The WooCommerce Payment Gateway Per Category WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/includes/plugin_settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.10.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-38340

    Last Modified: 2 May 2025

    The Wordpress Simple Shop WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the update_row parameter found in the ~/includes/add_product.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-38349

    Last Modified: 2 May 2025

    The Integration of Moneybird for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the error_description parameter found in the ~/templates/wcmb-admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.1.1.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-38353

    Last Modified: 2 May 2025

    The Dropdown and scrollable Text WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the content parameter found in the ~/index.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-38326

    Last Modified: 2 May 2025

    The Post Title Counter WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the notice parameter found in the ~/post-title-counter.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.1.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-38348

    Last Modified: 2 May 2025

    The Advance Search WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the wpas_id parameter found in the ~/inc/admin/views/html-advance-search-admin-options.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.1.2.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-38332

    Last Modified: 2 May 2025

    The On Page SEO + Whatsapp Chat Button Plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.1.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-38337

    Last Modified: 2 May 2025

    The RSVPMaker Excel WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/phpexcel/PHPExcel/Shared/JAMA/docs/download.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.1.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-38330

    Last Modified: 2 May 2025

    The Yet Another bol.com Plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/yabp.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.4.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-38334

    Last Modified: 2 May 2025

    The WP Design Maps & Places WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the filename parameter found in the ~/wpdmp-admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-38350

    Last Modified: 2 May 2025

    The spideranalyse WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the date parameter found in the ~/analyse/index.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.0.1.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-38351

    Last Modified: 2 May 2025

    The OSD Subscribe WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the osd_subscribe_message parameter found in the ~/options/osd_subscribe_options_subscribers.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.3.

    Published: 10 Sept 2021
    4.3
    Medium

    CVE-2021-33011

    Last Modified: 21 Nov 2024

    All versions of the afffected TOYOPUC-PC10 Series,TOYOPUC-Plus Series,TOYOPUC-PC3J/PC2J Series, TOYOPUC-Nano Series products may not be able to properly process an ICMP flood, which may allow an attacker to deny Ethernet communications between affected devices.

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2021-35976

    Last Modified: 21 Nov 2024

    The feature to preview a website in Plesk Obsidian 18.0.0 through 18.0.32 on Linux is vulnerable to reflected XSS via the /plesk-site-preview/ PATH, aka PFSI-62467. The attacker could execute JavaScript code in the victim's browser by using the link to preview sites hosted on the server. Authentication is not required to exploit the vulnerability.

    Published: 10 Sept 2021
    9.8
    Critical

    CVE-2021-3645

    Last Modified: 21 Nov 2024

    merge is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

    Published: 10 Sept 2021
    9.8
    Critical

    CVE-2021-34346

    Last Modified: 21 Nov 2024

    A stack buffer overflow vulnerability has been reported to affect QNAP device running NVR Storage Expansion. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of NVR Storage Expansion: NVR Storage Expansion 1.0.6 ( 2021/08/03 ) and later

    Published: 10 Sept 2021
    9.8
    Critical

    CVE-2021-34345

    Last Modified: 21 Nov 2024

    A stack buffer overflow vulnerability has been reported to affect QNAP device running NVR Storage Expansion. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of NVR Storage Expansion: NVR Storage Expansion 1.0.6 ( 2021/08/03 ) and later

    Published: 10 Sept 2021
    9.8
    Critical

    CVE-2021-34344

    Last Modified: 21 Nov 2024

    A stack buffer overflow vulnerability has been reported to affect QNAP device running QUSBCam2. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QUSBCam2: QTS 4.5.4: QUSBCam2 1.1.4 ( 2021/07/30 ) and later QTS 5.0: QUSBCam2 2.0.1 ( 2021/08/03 ) and later QTS 4.3.6: QUSBCam2 1.1.4 ( 2021/07/30 ) and later QTS 4.3.3: QUSBCam2 1.1.4 ( 2021/08/06 ) and later QuTS hero 4.5.3: QUSBCam2 1.1.4 ( 2021/07/30 ) and later

    Published: 10 Sept 2021
    6
    Medium

    CVE-2021-34343

    Last Modified: 21 Nov 2024

    A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QTS, QuTScloud, QuTS hero: QTS 4.5.4.1715 build 20210630 and later QTS 5.0.0.1716 build 20210701 and later QuTScloud c4.5.6.1755 and later QuTS hero h4.5.4.1771 build 20210825 and later

    Published: 10 Sept 2021
    7.6
    High

    CVE-2021-28816

    Last Modified: 21 Nov 2024

    A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QTS, QuTScloud, QuTS hero: QTS 4.5.4.1715 build 20210630 and later QTS 5.0.0.1716 build 20210701 and later QTS 4.3.3.1693 build 20210624 and later QTS 4.3.6.1750 build 20210730 and later QuTScloud c4.5.6.1755 and later QuTS hero h4.5.4.1771 build 20210825 and later

    Published: 10 Sept 2021
    9.6
    Critical

    CVE-2021-28813

    Last Modified: 21 Nov 2024

    A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism.We have already fixed this vulnerability in the following versions: QSW-M2116P-2T2S 1.0.6 build 210713 and later QGD-1600P: QuNetSwitch 1.0.6.1509 and later QGD-1602P: QuNetSwitch 1.0.6.1509 and later QGD-3014PT: QuNetSwitch 1.0.6.1519 and later

    Published: 10 Sept 2021
    6.1
    Medium

    CVE-2018-19957

    Last Modified: 21 Nov 2024

    A vulnerability involving insufficient HTTP security headers has been reported to affect QNAP NAS running QTS, QuTS hero, and QuTScloud. This vulnerability allows remote attackers to launch privacy and security attacks. We have already fixed this vulnerability in the following versions: QTS 4.5.4.1715 build 20210630 and later QuTS hero h4.5.4.1771 build 20210825 and later QuTScloud c4.5.6.1755 build 20210809 and later

    Published: 10 Sept 2021
    7.5
    High

    CVE-2021-40839

    Last Modified: 21 Nov 2024

    The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabling a remote attack that consumes CPU and memory.

    Published: 10 Sept 2021
    7.5
    High

    CVE-2021-32839

    Last Modified: 3 Nov 2025

    sqlparse is a non-validating SQL parser module for Python. In sqlparse versions 0.4.0 and 0.4.1 there is a regular Expression Denial of Service in sqlparse vulnerability. The regular expression may cause exponential backtracking on strings containing many repetitions of '\r\n' in SQL comments. Only the formatting feature that removes comments from SQL statements is affected by this regular expression. As a workaround don't use the sqlformat.format function with keyword strip_comments=True or the --strip-comments command line flag when using the sqlformat command line tool. The issues has been fixed in sqlparse 0.4.2.

    Published: 10 Sept 2021
    9.9
    Critical

    CVE-2021-3781

    Last Modified: 21 Nov 2024

    A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the context of the ghostscript interpreter. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

    Published: 10 Sept 2021
    7.5
    High

    CVE-2021-3795

    Last Modified: 21 Nov 2024

    semver-regex is vulnerable to Inefficient Regular Expression Complexity

    Published: 10 Sept 2021
    5.4
    Medium

    CVE-2020-19294

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in the /article/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the article comments section.

    Published: 9 Sept 2021
    6.1
    Medium

    CVE-2020-19295

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability in the /weibo/topic component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML.

    Published: 9 Sept 2021
    5.4
    Medium

    CVE-2020-19293

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in the /article/add component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a posted article.

    Published: 9 Sept 2021
    5.4
    Medium

    CVE-2020-19292

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in the /question/ask component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a posted question.

    Published: 9 Sept 2021
    5.4
    Medium

    CVE-2020-19291

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in the /weibo/publishdata component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a posted Weibo.

    Published: 9 Sept 2021
    5.4
    Medium

    CVE-2020-19289

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in the /member/picture/album component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the new album tab.

    Published: 9 Sept 2021
    5.4
    Medium

    CVE-2020-19290

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in the /weibo/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Weibo comment section.

    Published: 9 Sept 2021
    5.4
    Medium

    CVE-2020-19288

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in the /localhost/u component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a private message.

    Published: 9 Sept 2021
    5.4
    Medium

    CVE-2020-19287

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in the /group/post component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the title.

    Published: 9 Sept 2021
    5.4
    Medium

    CVE-2020-19286

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in the /question/detail component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the source field of the editor.

    Published: 9 Sept 2021
    5.4
    Medium

    CVE-2020-19285

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in the /group/apply component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Name text field.

    Published: 9 Sept 2021