CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2020-24143

    Last Modified: 21 Nov 2024

    Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker get access to files that are stored outside the web root folder via the njt-tk-download-video parameter.

    Published: 7 Jul 2021
    9.8
    Critical

    CVE-2020-24142

    Last Modified: 21 Nov 2024

    Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the njt-tk-download-video parameter. It can help identify open ports, local network hosts and execute command on services

    Published: 7 Jul 2021
    5.3
    Medium

    CVE-2020-24141

    Last Modified: 21 Nov 2024

    Server-side request forgery in the WP-DownloadManager plugin 1.68.4 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the file_remote parameter to download-add.php. It can help identify open ports, local network hosts and execute command on services

    Published: 7 Jul 2021
    6.5
    Medium

    CVE-2020-24038

    Last Modified: 21 Nov 2024

    myFax version 229 logs sensitive information in the export log module which allows any user to access critical information.

    Published: 7 Jul 2021
    6.5
    Medium

    CVE-2020-20225

    Last Modified: 21 Nov 2024

    Mikrotik RouterOs before 6.47 (stable tree) suffers from an assertion failure vulnerability in the /nova/bin/user process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.

    Published: 7 Jul 2021
    6.1
    Medium

    CVE-2021-35451

    Last Modified: 21 Nov 2024

    In Teradici PCoIP Management Console-Enterprise 20.07.0, an unauthenticated user can inject arbitrary text into user browser via the Web application.

    Published: 7 Jul 2021
    6.5
    Medium

    CVE-2020-20216

    Last Modified: 21 Nov 2024

    Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/graphing process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

    Published: 7 Jul 2021
    6.5
    Medium

    CVE-2020-20215

    Last Modified: 21 Nov 2024

    Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/diskd process. An authenticated remote attacker can cause a Denial of Service due to invalid memory access.

    Published: 7 Jul 2021
    6.5
    Medium

    CVE-2020-20213

    Last Modified: 21 Nov 2024

    Mikrotik RouterOs 6.44.5 (long-term tree) suffers from an stack exhaustion vulnerability in the /nova/bin/net process. An authenticated remote attacker can cause a Denial of Service due to overloading the systems CPU.

    Published: 7 Jul 2021
    6.5
    Medium

    CVE-2020-20212

    Last Modified: 16 Sept 2026

    Mikrotik RouterOs 6.44.5 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/console process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

    Published: 7 Jul 2021
    6.5
    Medium

    CVE-2020-20211

    Last Modified: 16 Sept 2026

    Mikrotik RouterOs 6.44.5 (long-term tree) suffers from an assertion failure vulnerability in the /nova/bin/console process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.

    Published: 7 Jul 2021
    4.3
    Medium

    CVE-2021-22233

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details

    Published: 7 Jul 2021
    6.1
    Medium

    CVE-2021-36212

    Last Modified: 21 Nov 2024

    app/View/SharingGroups/view.ctp in MISP before 2.4.146 allows stored XSS in the sharing groups view.

    Published: 7 Jul 2021
    6.4
    Medium

    CVE-2021-34625

    Last Modified: 21 Nov 2024

    A vulnerability in the saveCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to inject arbitrary web scripts. This issue affects versions 2.2.3 and prior.

    Published: 7 Jul 2021
    4.3
    Medium

    CVE-2021-34627

    Last Modified: 21 Nov 2024

    A vulnerability in the getSelectedMimeTypesByRole function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to view custom extensions added by administrators. This issue affects versions 2.2.3 and prior.

    Published: 7 Jul 2021
    4.3
    Medium

    CVE-2021-34626

    Last Modified: 21 Nov 2024

    A vulnerability in the deleteCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to delete custom extensions added by administrators. This issue affects versions 2.2.3 and prior.

    Published: 7 Jul 2021
    9.8
    Critical

    CVE-2021-34624

    Last Modified: 21 Nov 2024

    A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3. .

    Published: 7 Jul 2021
    9.8
    Critical

    CVE-2021-34621

    Last Modified: 21 Nov 2024

    A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register on sites as an administrator. This issue affects versions 3.0.0 - 3.1.3. .

    Published: 7 Jul 2021
    9.8
    Critical

    CVE-2021-34623

    Last Modified: 21 Nov 2024

    A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3. .

    Published: 7 Jul 2021
    8.8
    High

    CVE-2021-34620

    Last Modified: 21 Nov 2024

    The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Site Scripting and limited Privilege Escalation due to a missing nonce check in the access control function for administrative AJAX actions

    Published: 7 Jul 2021
    9.8
    Critical

    CVE-2021-34622

    Last Modified: 21 Nov 2024

    A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress WordPress plugin made it possible for users to escalate their privileges to that of an administrator while editing their profile. This issue affects versions 3.0.0 - 3.1.3. .

    Published: 7 Jul 2021
    9.8
    Critical

    CVE-2021-25952

    Last Modified: 21 Nov 2024

    Prototype pollution vulnerability in ‘just-safe-set’ versions 1.0.0 through 2.2.1 allows an attacker to cause a denial of service and may lead to remote code execution.

    Published: 7 Jul 2021
    7.1
    High

    CVE-2021-22224

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim

    Published: 7 Jul 2021
    4.7
    Medium

    CVE-2021-22225

    Last Modified: 21 Nov 2024

    Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

    Published: 7 Jul 2021
    4.9
    Medium

    CVE-2021-22230

    Last Modified: 21 Nov 2024

    Improper code rendering while rendering merge requests could be exploited to submit malicious code. This vulnerability affects GitLab CE/EE 9.3 and later through 13.11.6, 13.12.6, and 14.0.2.

    Published: 7 Jul 2021
    6.1
    Medium

    CVE-2021-22227

    Last Modified: 21 Nov 2024

    A reflected cross-site script vulnerability in GitLab before versions 13.11.6, 13.12.6 and 14.0.2 allowed an attacker to send a malicious link to a victim and trigger actions on their behalf if they clicked it

    Published: 7 Jul 2021
    3.5
    Low

    CVE-2021-22231

    Last Modified: 21 Nov 2024

    A denial of service in user's profile page is found starting with GitLab CE/EE 8.0 that allows attacker to reject access to their profile page via using a specially crafted username.

    Published: 7 Jul 2021
    6.1
    Medium

    CVE-2021-26039

    Last Modified: 25 Feb 2026

    An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the imagelist view of com_media leads to a XSS vulnerability.

    Published: 7 Jul 2021
    7.5
    High

    CVE-2021-26038

    Last Modified: 25 Feb 2026

    An issue was discovered in Joomla! 2.5.0 through 3.9.27. Install action in com_installer lack the required hardcoded ACL checks for superusers. A default system is not affected cause the default ACL for com_installer is limited to super users already.

    Published: 7 Jul 2021
    5.3
    Medium

    CVE-2021-26037

    Last Modified: 25 Feb 2026

    An issue was discovered in Joomla! 2.5.0 through 3.9.27. CMS functions did not properly termine existing user sessions when a user's password was changed or the user was blocked.

    Published: 7 Jul 2021
    7.5
    High

    CVE-2021-26036

    Last Modified: 25 Feb 2026

    An issue was discovered in Joomla! 2.5.0 through 3.9.27. Missing validation of input could lead to a broken usergroups table.

    Published: 7 Jul 2021
    6.1
    Medium

    CVE-2021-26035

    Last Modified: 25 Feb 2026

    An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the rules field of the JForm API leads to a XSS vulnerability.

    Published: 7 Jul 2021
    7
    High

    CVE-2022-41222

    Last Modified: 28 May 2025

    mm/mremap.c in the Linux kernel before 5.13.3 has a use-after-free via a stale TLB because an rmap lock is not held during a PUD move.

    Published: 7 Jul 2021
    8.8
    High

    CVE-2021-20780

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in WPCS - WordPress Currency Switcher 1.1.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 7 Jul 2021
    8.8
    High

    CVE-2021-20779

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in WordPress Email Template Designer - WP HTML Mail versions prior to 3.0.8 allows remote attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 7 Jul 2021
    4.3
    Medium

    CVE-2021-20777

    Last Modified: 21 Nov 2024

    Improper authorization in handler for custom URL scheme vulnerability in GU App for Android versions from 4.8.0 to 5.0.2 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App.

    Published: 7 Jul 2021
    9.8
    Critical

    CVE-2021-20776

    Last Modified: 21 Nov 2024

    Improper authentication vulnerability in SCT-40CM01SR and AT-40CM01SR allows an attacker to bypass access restriction and execute an arbitrary command via telnet.

    Published: 7 Jul 2021
    8.8
    High

    CVE-2021-20739

    Last Modified: 21 Nov 2024

    WRC-300FEBK, WRC-F300NF, WRC-733FEBK, WRH-300RD, WRH-300BK, WRH-300SV, WRH-300WH, WRH-H300WH, WRH-H300BK, WRH-300BK-S, and WRH-300WH-S all versions allows an unauthenticated network-adjacent attacker to execute an arbitrary OS command via unspecified vectors.

    Published: 7 Jul 2021
    6.5
    Medium

    CVE-2021-20738

    Last Modified: 21 Nov 2024

    WRC-1167FS-W, WRC-1167FS-B, and WRC-1167FSA all versions allow an unauthenticated network-adjacent attacker to obtain sensitive information via unspecified vectors.

    Published: 7 Jul 2021
    8.3
    High

    CVE-2021-22555

    Last Modified: 30 Dec 2025

    A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

    Published: 7 Jul 2021
    6.5
    Medium

    CVE-2021-3638

    Last Modified: 21 Nov 2024

    An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU. This flaw occurs in the ati_2d_blt() routine while handling MMIO write operations when the guest provides invalid values for the destination display parameters. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service.

    Published: 7 Jul 2021
    6.5
    Medium

    CVE-2021-22144

    Last Modified: 21 Nov 2024

    In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticsearch could create a malicious Grok query that will crash the Elasticsearch node.

    Published: 7 Jul 2021
    6.2
    Medium

    CVE-2021-36217

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-3502. Reason: This candidate is a duplicate of CVE-2021-3502. Notes: All CVE users should reference CVE-2021-3502 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 Jul 2021
    5.5
    Medium

    CVE-2021-3917

    Last Modified: 21 Nov 2024

    A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable access permissions. This flaw allows a local attacker to have read access to potentially sensitive data. The highest threat from this vulnerability is to confidentiality.

    Published: 7 Jul 2021
    5.8
    Medium

    CVE-2021-31810

    Last Modified: 21 Nov 2024

    An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. A malicious FTP server can use the PASV response to trick Net::FTP into connecting back to a given IP address and port. This potentially makes curl extract information about services that are otherwise private and not disclosed (e.g., the attacker can conduct port scans and service banner extractions).

    Published: 7 Jul 2021
    7.4
    High

    CVE-2021-32066

    Last Modified: 21 Nov 2024

    An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. Net::IMAP does not raise an exception when StartTLS fails with an an unknown response, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

    Published: 7 Jul 2021
    5.5
    Medium

    CVE-2021-38203

    Last Modified: 21 Nov 2024

    btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the system space_info.

    Published: 7 Jul 2021
    6.1
    Medium

    CVE-2021-22223

    Last Modified: 21 Nov 2024

    Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link

    Published: 6 Jul 2021
    6.5
    Medium

    CVE-2021-22228

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab affecting all versions before 13.11.6, all versions starting from 13.12 before 13.12.6, and all versions starting from 14.0 before 14.0.2. Improper access control allows unauthorised users to access project details using Graphql.

    Published: 6 Jul 2021
    6.5
    Medium

    CVE-2021-22226

    Last Modified: 21 Nov 2024

    Under certain conditions, some users were able to push to protected branches that were restricted to deploy keys in GitLab CE/EE since version 13.9

    Published: 6 Jul 2021