CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2021-3728

    Last Modified: 21 Nov 2024

    firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

    Published: 23 Aug 2021
    8.8
    High

    CVE-2021-3693

    Last Modified: 21 Nov 2024

    LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.

    Published: 23 Aug 2021
    4.8
    Medium

    CVE-2021-24658

    Last Modified: 21 Nov 2024

    The Erident Custom Login and Dashboard WordPress plugin before 3.5.9 did not properly sanitise its settings, allowing high privilege users to use XSS payloads in them (even when the unfileted_html is disabled)

    Published: 23 Aug 2021
    8.8
    High

    CVE-2021-24602

    Last Modified: 21 Nov 2024

    The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set themselves as admin via their profile page

    Published: 23 Aug 2021
    4.8
    Medium

    CVE-2021-24574

    Last Modified: 21 Nov 2024

    The Simple Banner WordPress plugin before 2.10.4 does not sanitise and escape one of its settings, allowing high privilege users such as admin to use Cross-Site Scripting payload even when the unfiltered_html capability is disallowed.

    Published: 23 Aug 2021
    5.4
    Medium

    CVE-2021-24571

    Last Modified: 21 Nov 2024

    The HD Quiz WordPress plugin before 1.8.4 does not escape some of its Answers before outputting them in attribute when generating the Quiz, which could lead to Stored Cross-Site Scripting issues

    Published: 23 Aug 2021
    8.8
    High

    CVE-2021-24565

    Last Modified: 21 Nov 2024

    The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings, allowing attacker to make a logged in user with the manage_options change them. Furthermore, the settings are not escaped when output in attributes, leading to a Stored Cross-Site Scripting issue.

    Published: 23 Aug 2021
    5.4
    Medium

    CVE-2021-24564

    Last Modified: 21 Nov 2024

    The WPFront Scroll Top WordPress plugin before 2.0.6.07225 does not sanitise or escape its Image ALT setting before outputting it attributes, leading to an Authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed.

    Published: 23 Aug 2021
    7.5
    High

    CVE-2021-24562

    Last Modified: 21 Nov 2024

    The LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.2 was affected by an IDOR issue, allowing students to see other student answers and grades

    Published: 23 Aug 2021
    5.4
    Medium

    CVE-2021-24561

    Last Modified: 17 Dec 2024

    The WP SMS WordPress plugin before 5.4.13 does not sanitise the "wp_group_name" parameter before outputting it back in the "Groups" page, leading to an Authenticated Stored Cross-Site Scripting issue

    Published: 23 Aug 2021
    5.4
    Medium

    CVE-2021-24558

    Last Modified: 21 Nov 2024

    The pspin_duplicate_post_save_as_new_post function of the Project Status WordPress plugin through 1.6 does not sanitise, validate or escape the post GET parameter passed to it before outputting it in an error message when the related post does not exist, leading to a reflected XSS issue

    Published: 23 Aug 2021
    7.2
    High

    CVE-2021-24557

    Last Modified: 21 Nov 2024

    The update functionality in the rslider_page uses an rs_id POST parameter which is not validated, sanitised or escaped before being inserted in sql query, therefore leading to SQL injection for users having Administrator role.

    Published: 23 Aug 2021
    6.1
    Medium

    CVE-2021-24556

    Last Modified: 21 Nov 2024

    The kento_email_subscriber_ajax AJAX action of the Email Subscriber WordPress plugin through 1.1, does not properly sanitise, validate and escape the submitted subscribe_email and subscribe_name POST parameters, inserting them in the DB and then outputting them back in the Subscriber list (/wp-admin/edit.php?post_type=kes_campaign&page=kento_email_subscriber_list_settings), leading a Stored XSS issue.

    Published: 23 Aug 2021
    7.2
    High

    CVE-2021-24554

    Last Modified: 21 Nov 2024

    The Paytm – Donation Plugin WordPress plugin through 1.3.2 does not sanitise, validate or escape the id GET parameter before using it in a SQL statement when deleting donations, leading to an authenticated SQL injection issue

    Published: 23 Aug 2021
    8.8
    High

    CVE-2021-24555

    Last Modified: 21 Nov 2024

    The daac_delete_booking_callback function, hooked to the daac_delete_booking AJAX action, takes the id POST parameter which is passed into the SQL statement without proper sanitisation, validation or escaping, leading to a SQL Injection issue. Furthermore, the ajax action is lacking any CSRF and capability check, making it available to any authenticated user.

    Published: 23 Aug 2021
    7.2
    High

    CVE-2021-24553

    Last Modified: 21 Nov 2024

    The Timeline Calendar WordPress plugin through 1.2 does not sanitise, validate or escape the edit GET parameter before using it in a SQL statement when editing events, leading to an authenticated SQL injection issue. Other SQL Injections are also present in the plugin

    Published: 23 Aug 2021
    7.2
    High

    CVE-2021-24552

    Last Modified: 21 Nov 2024

    The Simple Events Calendar WordPress plugin through 1.4.0 does not sanitise, validate or escape the event_id POST parameter before using it in a SQL statement when deleting events, leading to an authenticated SQL injection issue

    Published: 23 Aug 2021
    9.8
    Critical

    CVE-2021-24551

    Last Modified: 21 Nov 2024

    The Edit Comments WordPress plugin through 0.3 does not sanitise, validate or escape the jal_edit_comments GET parameter before using it in a SQL statement, leading to a SQL injection issue

    Published: 23 Aug 2021
    7.2
    High

    CVE-2021-24550

    Last Modified: 21 Nov 2024

    The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise, validate or escape the url GET parameter before using it in a SQL statement when retrieving an URL to edit, leading to an authenticated SQL injection issue

    Published: 23 Aug 2021
    4.9
    Medium

    CVE-2021-24549

    Last Modified: 21 Nov 2024

    The AceIDE WordPress plugin through 2.6.2 does not sanitise or validate the user input which is appended to system paths before using it in various actions, such as to read arbitrary files from the server. This allows high privilege users such as administrator to access any file on the web server outside of the blog directory via a path traversal attack.

    Published: 23 Aug 2021
    5.4
    Medium

    CVE-2021-24547

    Last Modified: 21 Nov 2024

    The KN Fix Your Title WordPress plugin through 1.0.1 was vulnerable to Authenticated Stored XSS in the separator field.

    Published: 23 Aug 2021
    4.8
    Medium

    CVE-2021-24533

    Last Modified: 21 Nov 2024

    The Maintenance WordPress plugin before 4.03 does not sanitise or escape some of its settings, allowing high privilege users such as admin to se Cross-Site Scripting payload in them (even when the unfiltered_html capability is disallowed), which will be triggered in the frontend

    Published: 23 Aug 2021
    5.4
    Medium

    CVE-2021-24531

    Last Modified: 21 Nov 2024

    The Charitable – Donation Plugin WordPress plugin before 1.6.51 is affected by an authenticated stored cross-site scripting vulnerability which was found in the add donation feature.

    Published: 23 Aug 2021
    5.4
    Medium

    CVE-2021-24529

    Last Modified: 21 Nov 2024

    The Grid Gallery – Photo Image Grid Gallery WordPress plugin before 1.2.5 does not properly sanitize the title field for image galleries when adding them via the admin dashboard, resulting in an authenticated Stored Cross-Site Scripting vulnerability.

    Published: 23 Aug 2021
    4.8
    Medium

    CVE-2021-24524

    Last Modified: 21 Nov 2024

    The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.12.0 did not escape the Donation Level setting of its Donation Forms, allowing high privilege users to use Cross-Site Scripting payloads in them.

    Published: 23 Aug 2021
    8.8
    High

    CVE-2021-24506

    Last Modified: 21 Nov 2024

    The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape the id attribute of its hero-button shortcode before using it in a SQL statement, allowing users with a role as low as Contributor to perform SQL injection.

    Published: 23 Aug 2021
    7.2
    High

    CVE-2021-24497

    Last Modified: 21 Nov 2024

    The Giveaway WordPress plugin through 1.2.2 is vulnerable to an SQL Injection issue which allows an administrative user to execute arbitrary SQL commands via the $post_id on the options.php page.

    Published: 23 Aug 2021
    5.4
    Medium

    CVE-2021-24486

    Last Modified: 21 Nov 2024

    The Simple Social Media Share Buttons – Social Sharing for Everyone WordPress plugin before 3.2.3 did not escape the align and like_button_size parameters of its SSB shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.

    Published: 23 Aug 2021
    4.6
    Medium

    CVE-2021-33598

    Last Modified: 21 Nov 2024

    A Denial-of-Service (DoS) vulnerability was discovered in all versions of F-Secure Atlant whereby the SAVAPI component used in certain F-Secure products can crash while scanning fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine.

    Published: 23 Aug 2021
    6.1
    Medium

    CVE-2022-1508

    Last Modified: 21 Nov 2024

    An out-of-bounds read flaw was found in the Linux kernel’s io_uring module in the way a user triggers the io_read() function with some special parameters. This flaw allows a local user to read some memory out of bounds.

    Published: 23 Aug 2021
    8.8
    High

    CVE-2021-39291

    Last Modified: 21 Nov 2024

    Certain NetModule devices allow credentials via GET parameters to CLI-PHP. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, NB2810, NB3700, NB3701, NB3710, NB3711, NB3720, and NB3800.

    Published: 23 Aug 2021
    9.8
    Critical

    CVE-2021-39290

    Last Modified: 21 Nov 2024

    Certain NetModule devices allow Limited Session Fixation via PHPSESSID. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, NB2810, NB3700, NB3701, NB3710, NB3711, NB3720, and NB3800.

    Published: 23 Aug 2021
    7.5
    High

    CVE-2021-39289

    Last Modified: 21 Nov 2024

    Certain NetModule devices have Insecure Password Handling (cleartext or reversible encryption), These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, NB2810, NB3700, NB3701, NB3710, NB3711, NB3720, and NB3800.

    Published: 23 Aug 2021
    7.5
    High

    CVE-2021-39245

    Last Modified: 21 Nov 2024

    Hardcoded .htaccess Credentials for getlogs.cgi exist on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices. This affects Nexto NX3003 1.8.11.0, Nexto NX3004 1.8.11.0, Nexto NX3005 1.8.11.0, Nexto NX3010 1.8.3.0, Nexto NX3020 1.8.3.0, Nexto NX3030 1.8.3.0, Nexto NX5100 1.8.11.0, Nexto NX5101 1.8.11.0, Nexto NX5110 1.1.2.8, Nexto NX5210 1.1.2.8, Nexto Xpress XP300 1.8.11.0, Nexto Xpress XP315 1.8.11.0, Nexto Xpress XP325 1.8.11.0, Nexto Xpress XP340 1.8.11.0, and Hadron Xtorm HX3040 1.7.58.0.

    Published: 23 Aug 2021
    8.8
    High

    CVE-2021-39244

    Last Modified: 21 Nov 2024

    Authenticated Semi-Blind Command Injection (via Parameter Injection) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via the getlogs.cgi tcpdump feature. This affects Nexto NX3003 1.8.11.0, Nexto NX3004 1.8.11.0, Nexto NX3005 1.8.11.0, Nexto NX3010 1.8.3.0, Nexto NX3020 1.8.3.0, Nexto NX3030 1.8.3.0, Nexto NX5100 1.8.11.0, Nexto NX5101 1.8.11.0, Nexto NX5110 1.1.2.8, Nexto NX5210 1.1.2.8, Nexto Xpress XP300 1.8.11.0, Nexto Xpress XP315 1.8.11.0, Nexto Xpress XP325 1.8.11.0, Nexto Xpress XP340 1.8.11.0, and Hadron Xtorm HX3040 1.7.58.0.

    Published: 23 Aug 2021
    6.5
    Medium

    CVE-2021-39243

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via any CGI endpoint. This affects Nexto NX3003 1.8.11.0, Nexto NX3004 1.8.11.0, Nexto NX3005 1.8.11.0, Nexto NX3010 1.8.3.0, Nexto NX3020 1.8.3.0, Nexto NX3030 1.8.3.0, Nexto NX5100 1.8.11.0, Nexto NX5101 1.8.11.0, Nexto NX5110 1.1.2.8, Nexto NX5210 1.1.2.8, Nexto Xpress XP300 1.8.11.0, Nexto Xpress XP315 1.8.11.0, Nexto Xpress XP325 1.8.11.0, Nexto Xpress XP340 1.8.11.0, and Hadron Xtorm HX3040 1.7.58.0.

    Published: 23 Aug 2021
    7.5
    High

    CVE-2021-39371

    Last Modified: 21 Nov 2024

    An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the application server filesystem by assigning a path to the entity. OWSLib 0.24.1 may also be affected.

    Published: 23 Aug 2021
    7.5
    High

    CVE-2020-36475

    Last Modified: 21 Nov 2024

    An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). The calculations performed by mbedtls_mpi_exp_mod are not limited; thus, supplying overly large parameters could lead to denial of service when generating Diffie-Hellman key pairs.

    Published: 23 Aug 2021
    7.5
    High

    CVE-2020-36476

    Last Modified: 21 Nov 2024

    An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS). There is missing zeroization of plaintext buffers in mbedtls_ssl_read to erase unused application data from memory.

    Published: 23 Aug 2021
    7.5
    High

    CVE-2020-36478

    Last Modified: 21 Nov 2024

    An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if the parameters do not match in any way, then the certificate should be considered invalid.

    Published: 23 Aug 2021
    7.1
    High

    CVE-2021-35940

    Last Modified: 21 Nov 2024

    An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward to the APR 1.7.x branch, and hence version 1.7.0 regressed compared to 1.6.3 and is vulnerable to the same issue.

    Published: 23 Aug 2021
    5.9
    Medium

    CVE-2020-36477

    Last Modified: 21 Nov 2024

    An issue was discovered in Mbed TLS before 2.24.0. The verification of X.509 certificates when matching the expected common name (the cn argument of mbedtls_x509_crt_verify) with the actual certificate name is mishandled: when the subjecAltName extension is present, the expected name is compared to any name in that extension regardless of its type. This means that an attacker could impersonate a 4-byte or 16-byte domain by getting a certificate for the corresponding IPv4 or IPv6 address (this would require the attacker to control that IP address, though).

    Published: 23 Aug 2021
    6.1
    Medium

    CVE-2021-39368

    Last Modified: 21 Nov 2024

    Canon Oce Print Exec Workgroup 1.3.2 allows XSS via the lang parameter.

    Published: 22 Aug 2021
    5.3
    Medium

    CVE-2021-39367

    Last Modified: 21 Nov 2024

    Canon Oce Print Exec Workgroup 1.3.2 allows Host header injection.

    Published: 22 Aug 2021
    6.1
    Medium

    CVE-2021-39362

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in ReCaptcha Solver 5.7. A response from Anti-Captcha.com, RuCaptcha.com, 2captcha.com, DEATHbyCAPTCHA.com, ImageTyperz.com, or BestCaptchaSolver.com in setCaptchaCode() is inserted into the DOM as HTML, resulting in full control over the user's browser by these servers.

    Published: 22 Aug 2021
    5.9
    Medium

    CVE-2021-39361

    Last Modified: 21 Nov 2024

    In GNOME evolution-rss through 0.3.96, network-soup.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

    Published: 22 Aug 2021
    8.5
    High

    CVE-2021-39153

    Last Modified: 23 May 2025

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream, if using the version out of the box with Java runtime version 14 to 8 or with JavaFX installed. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.

    Published: 22 Aug 2021
    8.1
    High

    CVE-2021-23406

    Last Modified: 21 Nov 2024

    This affects the package pac-resolver before 5.0.0. This can occur when used with untrusted input, due to unsafe PAC file handling. **NOTE:** The fix for this vulnerability is applied in the node-degenerator library, a dependency written by the same maintainer.

    Published: 22 Aug 2021
    8.5
    High

    CVE-2021-39148

    Last Modified: 23 May 2025

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.

    Published: 22 Aug 2021
    8.5
    High

    CVE-2021-39149

    Last Modified: 23 May 2025

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.

    Published: 22 Aug 2021