CVE-2021-24568
Last Modified: 21 Nov 2024The AddToAny Share Buttons WordPress plugin before 1.7.46 does not sanitise its Sharing Header setting when outputting it in frontend pages, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2021-24517
Last Modified: 21 Nov 2024The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2021.18 does not escape some of its settings, allowing high privilege users such as admin to set Cross-Site Scripting payloads in them even when the unfiltered_html capability is disallowed
CVE-2021-24513
Last Modified: 21 Nov 2024The Form Builder | Create Responsive Contact Forms WordPress plugin before 1.9.8.4 does not sanitise or escape its Form Title, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed
CVE-2021-24435
Last Modified: 21 Nov 2024The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET parameters before outputting them back in an href attribute, leading to Reflected Cross-Site Scripting issues
CVE-2021-24395
Last Modified: 21 Nov 2024The editid GET parameter of the Embed Youtube Video WordPress plugin through 1.0 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
CVE-2021-24393
Last Modified: 21 Nov 2024A c GET parameter of the Comment Highlighter WordPress plugin through 0.13 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
CVE-2021-24394
Last Modified: 21 Nov 2024An id GET parameter of the Easy Testimonial Manager WordPress plugin through 1.2.0 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection
CVE-2021-24392
Last Modified: 21 Nov 2024An id GET parameter of the WordPress Membership SwiftCloud.io WordPress plugin through 1.0 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
CVE-2021-24391
Last Modified: 21 Nov 2024An editid GET parameter of the Cashtomer WordPress plugin through 1.0.0 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
CVE-2021-24390
Last Modified: 21 Nov 2024A proid GET parameter of the WordPress支付宝Alipay|财付通Tenpay|贝宝PayPal集成插件 WordPress plugin through 3.7.2 is not sanitised, properly escaped or validated before inserting to a SQL statement not delimited by quotes, leading to SQL injection.
CVE-2021-24303
Last Modified: 21 Nov 2024The JiangQie Official Website Mini Program WordPress plugin before 1.1.1 does not escape or validate the id GET parameter before using it in SQL statements, leading to SQL injection issues
CVE-2021-20320
Last Modified: 21 Nov 2024A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a local attacker with special user privilege can circumvent the verifier and may lead to a confidentiality problem.
CVE-2021-3770
Last Modified: 21 Nov 2024vim is vulnerable to Heap-based Buffer Overflow
CVE-2021-40523
Last Modified: 21 Nov 2024In Contiki 3.0, Telnet option negotiation is mishandled. During negotiation between a server and a client, the server may fail to give the WILL/WONT or DO/DONT response for DO and WILL commands because of improper handling of exception condition, which leads to property violations and denial of service. Specifically, a server sometimes sends no response, because a fixed buffer space is available for all responses and that space may have been exhausted.
CVE-2021-40524
Last Modified: 4 Nov 2025In Pure-FTPd before 1.0.50, an incorrect max_filesize quota mechanism in the server allows attackers to upload files of unbounded size, which may lead to denial of service or a server hang. This occurs because a certain greater-than-zero test does not anticipate an initial -1 value. (Versions 1.0.23 through 1.0.49 are affected.)
CVE-2021-40516
Last Modified: 21 Nov 2024WeeChat before 3.2.1 allows remote attackers to cause a denial of service (crash) via a crafted WebSocket frame that trigger an out-of-bounds read in plugins/relay/relay-websocket.c in the Relay plugin.
CVE-2021-23439
Last Modified: 21 Nov 2024This affects the package file-upload-with-preview before 4.2.0. A file containing malicious JavaScript code in the name can be uploaded (a user needs to be tricked into uploading such a file).
CVE-2021-40509
Last Modified: 21 Nov 2024ViewCommon.java in JForum2 2.7.0 allows XSS via a user signature.
CVE-2021-30624
Last Modified: 21 Nov 2024Chromium: CVE-2021-30624 Use after free in Autofill
CVE-2021-30623
Last Modified: 21 Nov 2024Chromium: CVE-2021-30623 Use after free in Bookmarks
CVE-2021-30622
Last Modified: 21 Nov 2024Chromium: CVE-2021-30622 Use after free in WebApp Installs
CVE-2021-30621
Last Modified: 21 Nov 2024Chromium: CVE-2021-30621 UI Spoofing in Autofill
CVE-2021-30620
Last Modified: 21 Nov 2024Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink
CVE-2021-30619
Last Modified: 21 Nov 2024Chromium: CVE-2021-30619 UI Spoofing in Autofill
CVE-2021-30618
Last Modified: 21 Nov 2024Chromium: CVE-2021-30618 Inappropriate implementation in DevTools
CVE-2021-30617
Last Modified: 21 Nov 2024Chromium: CVE-2021-30617 Policy bypass in Blink
CVE-2021-30616
Last Modified: 21 Nov 2024Chromium: CVE-2021-30616 Use after free in Media
CVE-2021-30615
Last Modified: 21 Nov 2024Chromium: CVE-2021-30615 Cross-origin data leak in Navigation
CVE-2021-30614
Last Modified: 21 Nov 2024Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip
CVE-2021-30613
Last Modified: 21 Nov 2024Chromium: CVE-2021-30613 Use after free in Base internals
CVE-2021-30612
Last Modified: 21 Nov 2024Chromium: CVE-2021-30612 Use after free in WebRTC
CVE-2021-30611
Last Modified: 21 Nov 2024Chromium: CVE-2021-30611 Use after free in WebRTC
CVE-2021-30610
Last Modified: 21 Nov 2024Chromium: CVE-2021-30610 Use after free in Extensions API
CVE-2021-30609
Last Modified: 21 Nov 2024Chromium: CVE-2021-30609 Use after free in Sign-In
CVE-2021-30608
Last Modified: 21 Nov 2024Chromium: CVE-2021-30608 Use after free in Web Share
CVE-2021-30607
Last Modified: 21 Nov 2024Chromium: CVE-2021-30607 Use after free in Permissions
CVE-2021-30606
Last Modified: 21 Nov 2024Chromium: CVE-2021-30606 Use after free in Blink
CVE-2021-39193
Last Modified: 21 Nov 2024Frontier is Substrate's Ethereum compatibility layer. Prior to commit number 0b962f218f0cdd796dadfe26c3f09e68f7861b26, a bug in `pallet-ethereum` can cause invalid transactions to be included in the Ethereum block state in `pallet-ethereum` due to not validating the input data size. Any invalid transactions included this way have no possibility to alter the internal Ethereum or Substrate state. The transaction will appear to have be included, but is of no effect as it is rejected by the EVM engine. The impact is further limited by Substrate extrinsic size constraints. A patch is available in commit number 0b962f218f0cdd796dadfe26c3f09e68f7861b26. There are no workarounds aside from applying the patch.
CVE-2021-40492
Last Modified: 21 Nov 2024A reflected XSS vulnerability exists in multiple pages in version 22 of the Gibbon application that allows for arbitrary execution of JavaScript (gibbonCourseClassID, gibbonPersonID, subpage, currentDate, or allStudents to index.php).
CVE-2021-39192
Last Modified: 21 Nov 2024Ghost is a Node.js content management system. An error in the implementation of the limits service between versions 4.0.0 and 4.9.4 allows all authenticated users (including contributors) to view admin-level API keys via the integrations API endpoint, leading to a privilege escalation vulnerability. This issue is patched in Ghost version 4.10.0. As a workaround, disable all non-Administrator accounts to prevent API access. It is highly recommended to regenerate all API keys after patching or applying the workaround.
CVE-2021-40494
Last Modified: 21 Nov 2024A Hardcoded JWT Secret Key in metadata.py in AdaptiveScale LXDUI through 2.1.3 allows attackers to gain admin access to the host system.
CVE-2021-40490
Last Modified: 13 Aug 2026A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13.
CVE-2021-23437
Last Modified: 21 Nov 2024The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.
CVE-2021-40491
Last Modified: 21 Nov 2024The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl.
CVE-2021-39191
Last Modified: 21 Nov 2024mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In versions prior to 2.4.9.4, the 3rd-party init SSO functionality of mod_auth_openidc was reported to be vulnerable to an open redirect attack by supplying a crafted URL in the `target_link_uri` parameter. A patch in version 2.4.9.4 made it so that the `OIDCRedirectURLsAllowed` setting must be applied to the `target_link_uri` parameter. There are no known workarounds aside from upgrading to a patched version.
CVE-2021-38642
Last Modified: 10 Aug 2026Microsoft Edge for iOS Spoofing Vulnerability
CVE-2021-38641
Last Modified: 10 Aug 2026Microsoft Edge for Android Spoofing Vulnerability
CVE-2021-36930
Last Modified: 10 Aug 2026Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2021-26439
Last Modified: 10 Aug 2026Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2021-26436
Last Modified: 10 Aug 2026Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
