CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2021-24512

    Last Modified: 21 Nov 2024

    The Video Posts Webcam Recorder WordPress plugin before 3.2.4 has an authenticated reflected cross site scripting (XSS) vulnerability in one of the administrative functions for handling deletion of videos.

    Published: 16 Aug 2021
    5.4
    Medium

    CVE-2021-24471

    Last Modified: 21 Nov 2024

    The YouTube Embed WordPress plugin before 5.2.2 does not validate, escape or sanitise some of its shortcode attributes, leading to Stored XSS issues by 1. using w, h, controls, cc_lang, color, language, start, stop, or style parameter of youtube shortcode, 2. by using style, class, rel, target, width, height, or alt parameter of youtube_thumb shortcode, or 3. by embedding a video whose title or description contains XSS payload (if API key is configured).

    Published: 16 Aug 2021
    6.1
    Medium

    CVE-2021-24466

    Last Modified: 21 Nov 2024

    The Verse-O-Matic WordPress plugin through 4.1.1 does not have any CSRF checks in place, allowing attackers to make logged in administrators do unwanted actions, such as add/edit/delete arbitrary verses and change the settings. Due to the lack of sanitisation in the settings and verses, this could also lead to Stored Cross-Site Scripting issues

    Published: 16 Aug 2021
    5.5
    Medium

    CVE-2021-24445

    Last Modified: 21 Nov 2024

    The My Site Audit WordPress plugin through 1.2.4 does not sanitise or escape the Audit Name field when creating an audit, allowing high privilege users to set JavaScript payloads in them, even when he unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue

    Published: 16 Aug 2021
    6.1
    Medium

    CVE-2021-24410

    Last Modified: 21 Nov 2024

    The తెలుగు బైబిల్ వచనములు WordPress plugin through 1.0 is lacking any CSRF check when saving its settings and verses, and do not sanitise or escape them when outputting them back in the page. This could allow attackers to make a logged in admin change the settings, as well as add malicious verses containing JavaScript code in them, leading to Stored XSS issues

    Published: 16 Aug 2021
    6.1
    Medium

    CVE-2021-24411

    Last Modified: 21 Nov 2024

    The Social Tape WordPress plugin through 1.0 does not have CSRF checks in place when saving its settings, and do not sanitise or escape them before outputting them back in the page, leading to a stored Cross-Site Scripting issue via a CSRF attack

    Published: 16 Aug 2021
    4.3
    Medium

    CVE-2021-24380

    Last Modified: 21 Nov 2024

    The Shantz WordPress QOTD WordPress plugin through 1.2.2 is lacking any CSRF check when updating its settings, allowing attackers to make logged in administrators change them to arbitrary values.

    Published: 16 Aug 2021
    4.9
    Medium

    CVE-2021-24363

    Last Modified: 21 Nov 2024

    The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images/SVG anywhere in the filesystem via a path traversal vector

    Published: 16 Aug 2021
    6.1
    Medium

    CVE-2021-24362

    Last Modified: 21 Nov 2024

    The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded SVG files added to a gallery do not contain malicious content. As a result, users allowed to add images to gallery can upload an SVG file containing JavaScript code, which will be executed when accessing the image directly (ie in the /wp-content/uploads/photo-gallery/ folder), leading to a Cross-Site Scripting (XSS) issue

    Published: 16 Aug 2021
    7.8
    High

    CVE-2021-23422

    Last Modified: 21 Nov 2024

    This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing Inline Tag Command metadata is processed. When an arbitrary OS command is executed, the command output would be included in the HTML output.

    Published: 16 Aug 2021
    5.5
    Medium

    CVE-2021-23423

    Last Modified: 21 Nov 2024

    This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing include, include-code or include-raw block is processed. The contents of arbitrary files could be disclosed in the HTML output.

    Published: 16 Aug 2021
    5.3
    Medium

    CVE-2021-35936

    Last Modified: 21 Nov 2024

    If remote logging is not used, the worker (in the case of CeleryExecutor) or the scheduler (in the case of LocalExecutor) runs a Flask logging server and is listening on a specific port and also binds on 0.0.0.0 by default. This logging server had no authentication and allows reading log files of DAG jobs. This issue affects Apache Airflow < 2.1.2.

    Published: 16 Aug 2021
    7.8
    High

    CVE-2021-3708

    Last Modified: 21 Nov 2024

    D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to OS command injection. An unauthenticated attacker on the local network may exploit this, with CVE-2021-3707, to execute any OS commands on the vulnerable device.

    Published: 16 Aug 2021
    5.5
    Medium

    CVE-2021-3707

    Last Modified: 21 Nov 2024

    D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to unauthorized configuration modification. An unauthenticated attacker on the local network may exploit this, with CVE-2021-3708, to execute any OS commands on the vulnerable device.

    Published: 16 Aug 2021
    7.5
    High

    CVE-2021-38712

    Last Modified: 21 Nov 2024

    OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to block the access via an NGINX configuration file.

    Published: 16 Aug 2021
    5.4
    Medium

    CVE-2021-38713

    Last Modified: 21 Nov 2024

    imgURL 2.31 allows XSS via an X-Forwarded-For HTTP header.

    Published: 16 Aug 2021
    7.5
    High

    CVE-2021-38711

    Last Modified: 21 Nov 2024

    In gitit before 0.15.0.0, the Export feature can be exploited to leak information from files.

    Published: 16 Aug 2021
    5.4
    Medium

    CVE-2021-38708

    Last Modified: 21 Nov 2024

    In ocProducts Composr CMS before 10.0.38, an attacker can inject JavaScript via Comcode for XSS.

    Published: 16 Aug 2021
    6.1
    Medium

    CVE-2021-38709

    Last Modified: 21 Nov 2024

    In ocProducts Composr CMS before 10.0.38, an attacker can inject JavaScript via the staff_messaging messaging system for XSS.

    Published: 16 Aug 2021
    5.3
    Medium

    CVE-2021-26086

    Last Modified: 24 Oct 2025

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1.

    Published: 16 Aug 2021
    8.8
    High

    CVE-2021-3621

    Last Modified: 3 Nov 2025

    A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

    Published: 16 Aug 2021
    3.1
    Low

    CVE-2021-3716

    Last Modified: 21 Nov 2024

    A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_STRUCTURED_REPLY before proxying everything else a client sends to the server, potentially leading the client to terminate the NBD session. The highest threat from this vulnerability is to system availability.

    Published: 16 Aug 2021
    7.8
    High

    CVE-2021-42008

    Last Modified: 21 Nov 2024

    The decode_data function in drivers/net/hamradio/6pack.c in the Linux kernel before 5.13.13 has a slab out-of-bounds write. Input from a process that has the CAP_NET_ADMIN capability can lead to root access.

    Published: 16 Aug 2021
    9
    Critical

    CVE-2021-25955

    Last Modified: 21 Nov 2024

    In “Dolibarr ERP CRM”, WYSIWYG Editor module, v2.8.1 to v13.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the “Private Note” field at “/adherents/note.php?id=1” endpoint. These scripts are executed in a victim’s browser when they open the page containing the vulnerable field. In the worst case, the victim who inadvertently triggers the attack is a highly privileged administrator. The injected scripts can extract the Session ID, which can lead to full Account takeover of the admin and due to other vulnerability (Improper Access Control on Private notes) a low privileged user can update the private notes which could lead to privilege escalation.

    Published: 15 Aug 2021
    5.4
    Medium

    CVE-2021-38699

    Last Modified: 21 Nov 2024

    TastyIgniter 3.0.7 allows XSS via /account, /reservation, /admin/dashboard, and /admin/system_logs.

    Published: 15 Aug 2021
    5.3
    Medium

    CVE-2021-37326

    Last Modified: 21 Nov 2024

    NetSarang Xshell 7 before Build 0077 includes unintended code strings in paste operations.

    Published: 15 Aug 2021
    3.7
    Low

    CVE-2020-36473

    Last Modified: 21 Nov 2024

    UCWeb UC 12.12.3.1219 through 12.12.3.1226 uses cleartext HTTP, and thus man-in-the-middle attackers can discover visited URLs.

    Published: 14 Aug 2021
    7.8
    High

    CVE-2021-21815

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs' Xmill 0.7. Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line. filepattern is passed directly to strcpy copying the path provided by the user into a staticly sized buffer without any length checks resulting in a stack-buffer overflow. An attacker can provide malicious input to trigger this vulnerability.

    Published: 13 Aug 2021
    7.8
    High

    CVE-2021-21813

    Last Modified: 21 Nov 2024

    Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line. filepattern is passed directly to memcpy copying the path provided by the user into a staticly sized buffer without any length checks resulting in a stack-buffer overflow.

    Published: 13 Aug 2021
    7.8
    High

    CVE-2021-21814

    Last Modified: 21 Nov 2024

    Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line. filepattern is passed directly to strlen to determine the ending location of the char* passed in by the user, no checks are done to see if the passed in char* is longer than the staticly sized buffer data is memcpy‘d into, but after the memcpy a null byte is written to what is assumed to be the end of the buffer to terminate the char*, but without length checks, this null write occurs at an arbitrary offset from the buffer. An attacker can provide malicious input to trigger this vulnerability.

    Published: 13 Aug 2021
    7.8
    High

    CVE-2021-21812

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs’ Xmill 0.7. Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line. filepattern is passed directly to strcpy copying the path provided by the user into a static sized buffer without any length checks resulting in a stack-buffer overflow. An attacker can provide malicious input to trigger these vulnerabilities.

    Published: 13 Aug 2021
    —
    Unknown

    CVE-2020-21064

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-15048. Reason: This candidate is a reservation duplicate of CVE-2019-15048. Notes: All CVE users should reference CVE-2019-15048 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 13 Aug 2021
    6.5
    Medium

    CVE-2020-21066

    Last Modified: 21 Nov 2024

    An issue was discovered in Bento4 v1.5.1.0. There is a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a denial of service (program crash), as demonstrated by mp42aac.

    Published: 13 Aug 2021
    10
    Critical

    CVE-2021-37705

    Last Modified: 21 Nov 2024

    OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incomplete authorization check allows an authenticated user from any Azure Active Directory tenant to make authorized API calls to a vulnerable OneFuzz instance. To be vulnerable, a OneFuzz deployment must be both version 2.12.0 or greater and deployed with the non-default --multi_tenant_domain option. This can result in read/write access to private data such as software vulnerability and crash information, security testing tools and proprietary code and symbols. Via authorized API calls, this also enables tampering with existing data and unauthorized code execution on Azure compute resources. This issue is resolved starting in release 2.31.0, via the addition of application-level check of the bearer token's `issuer` against an administrator-configured allowlist. As a workaround users can restrict access to the tenant of a deployed OneFuzz instance < 2.31.0 by redeploying in the default configuration, which omits the `--multi_tenant_domain` option.

    Published: 13 Aug 2021
    9.8
    Critical

    CVE-2021-21829

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem functionality of AT&T Labs’ Xmill 0.7. A specially crafted XMI file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 13 Aug 2021
    9.8
    Critical

    CVE-2021-21830

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&T Labs’ Xmill 0.7. A specially crafted XMI file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 13 Aug 2021
    9.8
    Critical

    CVE-2021-38302

    Last Modified: 21 Nov 2024

    The Newsletter extension through 4.0.0 for TYPO3 allows SQL Injection.

    Published: 13 Aug 2021
    9.1
    Critical

    CVE-2021-34823

    Last Modified: 21 Nov 2024

    The ON24 ScreenShare (aka DesktopScreenShare.app) plugin before 2.0 for macOS allows remote file access via its built-in HTTP server. This allows unauthenticated remote users to retrieve files accessible to the logged-on macOS user. When a remote user sends a crafted HTTP request to the server, it triggers a code path that will download a configuration file from a specified remote machine over HTTP. There is an XXE flaw in processing of this configuration file that allows reading local (to macOS) files and uploading them to remote machines.

    Published: 13 Aug 2021
    7.5
    High

    CVE-2021-38623

    Last Modified: 21 Nov 2024

    The deferred_image_processing (aka Deferred image processing) extension before 1.0.2 for TYPO3 allows Denial of Service via the FAL API because of /var/transient disk consumption.

    Published: 13 Aug 2021
    7.5
    High

    CVE-2021-36793

    Last Modified: 21 Nov 2024

    The routes (aka Extbase Yaml Routes) extension before 2.1.1 for TYPO3, when CsrfTokenViewHelper is used, allows Sensitive Information Disclosure because a session identifier is unsafely present in HTML output.

    Published: 13 Aug 2021
    5.4
    Medium

    CVE-2021-36787

    Last Modified: 21 Nov 2024

    The femanager extension before 5.5.1 and 6.x before 6.3.1 for TYPO3 allows XSS via a crafted SVG document.

    Published: 13 Aug 2021
    7.5
    High

    CVE-2021-36786

    Last Modified: 21 Nov 2024

    The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows Sensitive Data Exposure of API credentials and private keys.

    Published: 13 Aug 2021
    5.4
    Medium

    CVE-2021-36785

    Last Modified: 21 Nov 2024

    The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows XSS.

    Published: 13 Aug 2021
    5.4
    Medium

    CVE-2021-36788

    Last Modified: 21 Nov 2024

    The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS.

    Published: 13 Aug 2021
    7.5
    High

    CVE-2020-18759

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the EPA protocol of Dut Computer Control Engineering Co.'s PLC MAC1100.

    Published: 13 Aug 2021
    9.8
    Critical

    CVE-2020-18758

    Last Modified: 21 Nov 2024

    An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to execute arbitrary code.

    Published: 13 Aug 2021
    7.5
    High

    CVE-2020-18756

    Last Modified: 21 Nov 2024

    An arbitrary memory access vulnerability in the EPA protocol of Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to read the contents of any variable area.

    Published: 13 Aug 2021
    7.5
    High

    CVE-2020-18757

    Last Modified: 21 Nov 2024

    An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to cause persistent denial of service (DOS) via a crafted packet.

    Published: 13 Aug 2021
    7.5
    High

    CVE-2020-18754

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists within Dut Computer Control Engineering Co.'s PLC MAC1100.

    Published: 13 Aug 2021
    9.8
    Critical

    CVE-2020-18753

    Last Modified: 21 Nov 2024

    An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to gain access to the system and escalate privileges via a crafted packet.

    Published: 13 Aug 2021