CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2021-24568

    Last Modified: 21 Nov 2024

    The AddToAny Share Buttons WordPress plugin before 1.7.46 does not sanitise its Sharing Header setting when outputting it in frontend pages, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 6 Sept 2021
    5.4
    Medium

    CVE-2021-24517

    Last Modified: 21 Nov 2024

    The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2021.18 does not escape some of its settings, allowing high privilege users such as admin to set Cross-Site Scripting payloads in them even when the unfiltered_html capability is disallowed

    Published: 6 Sept 2021
    5.4
    Medium

    CVE-2021-24513

    Last Modified: 21 Nov 2024

    The Form Builder | Create Responsive Contact Forms WordPress plugin before 1.9.8.4 does not sanitise or escape its Form Title, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed

    Published: 6 Sept 2021
    6.1
    Medium

    CVE-2021-24435

    Last Modified: 21 Nov 2024

    The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET parameters before outputting them back in an href attribute, leading to Reflected Cross-Site Scripting issues

    Published: 6 Sept 2021
    7.2
    High

    CVE-2021-24395

    Last Modified: 21 Nov 2024

    The editid GET parameter of the Embed Youtube Video WordPress plugin through 1.0 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

    Published: 6 Sept 2021
    7.2
    High

    CVE-2021-24393

    Last Modified: 21 Nov 2024

    A c GET parameter of the Comment Highlighter WordPress plugin through 0.13 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

    Published: 6 Sept 2021
    7.2
    High

    CVE-2021-24394

    Last Modified: 21 Nov 2024

    An id GET parameter of the Easy Testimonial Manager WordPress plugin through 1.2.0 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection

    Published: 6 Sept 2021
    7.2
    High

    CVE-2021-24392

    Last Modified: 21 Nov 2024

    An id GET parameter of the WordPress Membership SwiftCloud.io WordPress plugin through 1.0 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

    Published: 6 Sept 2021
    8.8
    High

    CVE-2021-24391

    Last Modified: 21 Nov 2024

    An editid GET parameter of the Cashtomer WordPress plugin through 1.0.0 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

    Published: 6 Sept 2021
    7.2
    High

    CVE-2021-24390

    Last Modified: 21 Nov 2024

    A proid GET parameter of the WordPress支付宝Alipay|财付通Tenpay|贝宝PayPal集成插件 WordPress plugin through 3.7.2 is not sanitised, properly escaped or validated before inserting to a SQL statement not delimited by quotes, leading to SQL injection.

    Published: 6 Sept 2021
    8.8
    High

    CVE-2021-24303

    Last Modified: 21 Nov 2024

    The JiangQie Official Website Mini Program WordPress plugin before 1.1.1 does not escape or validate the id GET parameter before using it in SQL statements, leading to SQL injection issues

    Published: 6 Sept 2021
    5.5
    Medium

    CVE-2021-20320

    Last Modified: 21 Nov 2024

    A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a local attacker with special user privilege can circumvent the verifier and may lead to a confidentiality problem.

    Published: 6 Sept 2021
    7.8
    High

    CVE-2021-3770

    Last Modified: 21 Nov 2024

    vim is vulnerable to Heap-based Buffer Overflow

    Published: 6 Sept 2021
    7.5
    High

    CVE-2021-40523

    Last Modified: 21 Nov 2024

    In Contiki 3.0, Telnet option negotiation is mishandled. During negotiation between a server and a client, the server may fail to give the WILL/WONT or DO/DONT response for DO and WILL commands because of improper handling of exception condition, which leads to property violations and denial of service. Specifically, a server sometimes sends no response, because a fixed buffer space is available for all responses and that space may have been exhausted.

    Published: 5 Sept 2021
    7.5
    High

    CVE-2021-40524

    Last Modified: 4 Nov 2025

    In Pure-FTPd before 1.0.50, an incorrect max_filesize quota mechanism in the server allows attackers to upload files of unbounded size, which may lead to denial of service or a server hang. This occurs because a certain greater-than-zero test does not anticipate an initial -1 value. (Versions 1.0.23 through 1.0.49 are affected.)

    Published: 5 Sept 2021
    7.5
    High

    CVE-2021-40516

    Last Modified: 21 Nov 2024

    WeeChat before 3.2.1 allows remote attackers to cause a denial of service (crash) via a crafted WebSocket frame that trigger an out-of-bounds read in plugins/relay/relay-websocket.c in the Relay plugin.

    Published: 5 Sept 2021
    4.2
    Medium

    CVE-2021-23439

    Last Modified: 21 Nov 2024

    This affects the package file-upload-with-preview before 4.2.0. A file containing malicious JavaScript code in the name can be uploaded (a user needs to be tricked into uploading such a file).

    Published: 5 Sept 2021
    5.4
    Medium

    CVE-2021-40509

    Last Modified: 21 Nov 2024

    ViewCommon.java in JForum2 2.7.0 allows XSS via a user signature.

    Published: 4 Sept 2021
    8.8
    High

    CVE-2021-30624

    Last Modified: 21 Nov 2024

    Chromium: CVE-2021-30624 Use after free in Autofill

    Published: 3 Sept 2021
    8.8
    High

    CVE-2021-30623

    Last Modified: 21 Nov 2024

    Chromium: CVE-2021-30623 Use after free in Bookmarks

    Published: 3 Sept 2021
    8.8
    High

    CVE-2021-30622

    Last Modified: 21 Nov 2024

    Chromium: CVE-2021-30622 Use after free in WebApp Installs

    Published: 3 Sept 2021
    6.5
    Medium

    CVE-2021-30621

    Last Modified: 21 Nov 2024

    Chromium: CVE-2021-30621 UI Spoofing in Autofill

    Published: 3 Sept 2021
    8.8
    High

    CVE-2021-30620

    Last Modified: 21 Nov 2024

    Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink

    Published: 3 Sept 2021
    6.5
    Medium

    CVE-2021-30619

    Last Modified: 21 Nov 2024

    Chromium: CVE-2021-30619 UI Spoofing in Autofill

    Published: 3 Sept 2021
    8.8
    High

    CVE-2021-30618

    Last Modified: 21 Nov 2024

    Chromium: CVE-2021-30618 Inappropriate implementation in DevTools

    Published: 3 Sept 2021
    6.5
    Medium

    CVE-2021-30617

    Last Modified: 21 Nov 2024

    Chromium: CVE-2021-30617 Policy bypass in Blink

    Published: 3 Sept 2021
    8.8
    High

    CVE-2021-30616

    Last Modified: 21 Nov 2024

    Chromium: CVE-2021-30616 Use after free in Media

    Published: 3 Sept 2021
    6.5
    Medium

    CVE-2021-30615

    Last Modified: 21 Nov 2024

    Chromium: CVE-2021-30615 Cross-origin data leak in Navigation

    Published: 3 Sept 2021
    8.8
    High

    CVE-2021-30614

    Last Modified: 21 Nov 2024

    Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip

    Published: 3 Sept 2021
    8.8
    High

    CVE-2021-30613

    Last Modified: 21 Nov 2024

    Chromium: CVE-2021-30613 Use after free in Base internals

    Published: 3 Sept 2021
    8.8
    High

    CVE-2021-30612

    Last Modified: 21 Nov 2024

    Chromium: CVE-2021-30612 Use after free in WebRTC

    Published: 3 Sept 2021
    8.8
    High

    CVE-2021-30611

    Last Modified: 21 Nov 2024

    Chromium: CVE-2021-30611 Use after free in WebRTC

    Published: 3 Sept 2021
    8.8
    High

    CVE-2021-30610

    Last Modified: 21 Nov 2024

    Chromium: CVE-2021-30610 Use after free in Extensions API

    Published: 3 Sept 2021
    8.8
    High

    CVE-2021-30609

    Last Modified: 21 Nov 2024

    Chromium: CVE-2021-30609 Use after free in Sign-In

    Published: 3 Sept 2021
    8.8
    High

    CVE-2021-30608

    Last Modified: 21 Nov 2024

    Chromium: CVE-2021-30608 Use after free in Web Share

    Published: 3 Sept 2021
    8.8
    High

    CVE-2021-30607

    Last Modified: 21 Nov 2024

    Chromium: CVE-2021-30607 Use after free in Permissions

    Published: 3 Sept 2021
    8.8
    High

    CVE-2021-30606

    Last Modified: 21 Nov 2024

    Chromium: CVE-2021-30606 Use after free in Blink

    Published: 3 Sept 2021
    5.3
    Medium

    CVE-2021-39193

    Last Modified: 21 Nov 2024

    Frontier is Substrate's Ethereum compatibility layer. Prior to commit number 0b962f218f0cdd796dadfe26c3f09e68f7861b26, a bug in `pallet-ethereum` can cause invalid transactions to be included in the Ethereum block state in `pallet-ethereum` due to not validating the input data size. Any invalid transactions included this way have no possibility to alter the internal Ethereum or Substrate state. The transaction will appear to have be included, but is of no effect as it is rejected by the EVM engine. The impact is further limited by Substrate extrinsic size constraints. A patch is available in commit number 0b962f218f0cdd796dadfe26c3f09e68f7861b26. There are no workarounds aside from applying the patch.

    Published: 3 Sept 2021
    6.1
    Medium

    CVE-2021-40492

    Last Modified: 21 Nov 2024

    A reflected XSS vulnerability exists in multiple pages in version 22 of the Gibbon application that allows for arbitrary execution of JavaScript (gibbonCourseClassID, gibbonPersonID, subpage, currentDate, or allStudents to index.php).

    Published: 3 Sept 2021
    6.5
    Medium

    CVE-2021-39192

    Last Modified: 21 Nov 2024

    Ghost is a Node.js content management system. An error in the implementation of the limits service between versions 4.0.0 and 4.9.4 allows all authenticated users (including contributors) to view admin-level API keys via the integrations API endpoint, leading to a privilege escalation vulnerability. This issue is patched in Ghost version 4.10.0. As a workaround, disable all non-Administrator accounts to prevent API access. It is highly recommended to regenerate all API keys after patching or applying the workaround.

    Published: 3 Sept 2021
    9.8
    Critical

    CVE-2021-40494

    Last Modified: 21 Nov 2024

    A Hardcoded JWT Secret Key in metadata.py in AdaptiveScale LXDUI through 2.1.3 allows attackers to gain admin access to the host system.

    Published: 3 Sept 2021
    7
    High

    CVE-2021-40490

    Last Modified: 13 Aug 2026

    A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13.

    Published: 3 Sept 2021
    7.5
    High

    CVE-2021-23437

    Last Modified: 21 Nov 2024

    The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.

    Published: 3 Sept 2021
    6.5
    Medium

    CVE-2021-40491

    Last Modified: 21 Nov 2024

    The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl.

    Published: 3 Sept 2021
    4.7
    Medium

    CVE-2021-39191

    Last Modified: 21 Nov 2024

    mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In versions prior to 2.4.9.4, the 3rd-party init SSO functionality of mod_auth_openidc was reported to be vulnerable to an open redirect attack by supplying a crafted URL in the `target_link_uri` parameter. A patch in version 2.4.9.4 made it so that the `OIDCRedirectURLsAllowed` setting must be applied to the `target_link_uri` parameter. There are no known workarounds aside from upgrading to a patched version.

    Published: 3 Sept 2021
    6.1
    Medium

    CVE-2021-38642

    Last Modified: 10 Aug 2026

    Microsoft Edge for iOS Spoofing Vulnerability

    Published: 2 Sept 2021
    6.1
    Medium

    CVE-2021-38641

    Last Modified: 10 Aug 2026

    Microsoft Edge for Android Spoofing Vulnerability

    Published: 2 Sept 2021
    5.3
    Medium

    CVE-2021-36930

    Last Modified: 10 Aug 2026

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Published: 2 Sept 2021
    4.6
    Medium

    CVE-2021-26439

    Last Modified: 10 Aug 2026

    Microsoft Edge for Android Information Disclosure Vulnerability

    Published: 2 Sept 2021
    6.1
    Medium

    CVE-2021-26436

    Last Modified: 10 Aug 2026

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Published: 2 Sept 2021