CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2021-26111

    Last Modified: 21 Nov 2024

    A missing release of memory after effective lifetime vulnerability in FortiSwitch 6.4.0 to 6.4.6, 6.2.0 to 6.2.6, 6.0.0 to 6.0.6, 3.6.11 and below may allow an attacker on an adjacent network to exhaust available memory by sending specifically crafted LLDP/CDP/EDP packets to the device.

    Published: 1 Jun 2021
    6.5
    Medium

    CVE-2020-22042

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak is affected by: memory leak in the link_filter_inouts function in libavfilter/graphparser.c.

    Published: 1 Jun 2021
    2.7
    Low

    CVE-2021-32653

    Last Modified: 21 Nov 2024

    Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server versions prior to 19.0.11, 20.0.10, or 21.0.2 send user IDs to the lookup server even if the user has no fields set to published. The vulnerability is patched in versions 19.0.11, 20.0.10, and 21.0.2; no workarounds outside the updates are known to exist.

    Published: 1 Jun 2021
    6.5
    Medium

    CVE-2020-22041

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_buffersrc_add_frame_flags function in buffersrc.

    Published: 1 Jun 2021
    6.5
    Medium

    CVE-2020-22039

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the inavi_add_ientry function.

    Published: 1 Jun 2021
    6.5
    Medium

    CVE-2020-22038

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_v4l2_m2m_create_context function in v4l2_m2m.c.

    Published: 1 Jun 2021
    6.5
    Medium

    CVE-2020-22037

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in avcodec_alloc_context3 at options.c.

    Published: 1 Jun 2021
    6.5
    Medium

    CVE-2020-22040

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in FFmpeg 4.2 idue to a memory leak in the v_frame_alloc function in frame.c.

    Published: 1 Jun 2021
    8.8
    High

    CVE-2021-32652

    Last Modified: 21 Nov 2024

    Nextcloud Mail is a mail app for the Nextcloud platform. A missing permission check in Nextcloud Mail before 1.4.3 and 1.8.2 allows another authenticated users to access mail metadata of other users. Versions 1.4.3 and 1.8.2 contain patches for this vulnerability; no workarounds other than the patches are known to exist.

    Published: 1 Jun 2021
    8.8
    High

    CVE-2020-22036

    Last Modified: 21 Nov 2024

    A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_intra at libavfilter/vf_bwdif.c, which might lead to memory corruption and other potential consequences.

    Published: 1 Jun 2021
    8.8
    High

    CVE-2020-22035

    Last Modified: 21 Nov 2024

    A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in get_block_row at libavfilter/vf_bm3d.c, which might lead to memory corruption and other potential consequences.

    Published: 1 Jun 2021
    8.8
    High

    CVE-2021-32924

    Last Modified: 21 Nov 2024

    Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because the IPS\cms\modules\front\pages\_builder::previewBlock method interacts unsafely with the IPS\_Theme::runProcessFunction method.

    Published: 1 Jun 2021
    3.1
    Low

    CVE-2021-32651

    Last Modified: 21 Nov 2024

    OneDev is a development operations platform. If the LDAP external authentication mechanism is enabled in OneDev versions 4.4.1 and prior, an attacker can manipulate a user search filter to send forged queries to the application and explore the LDAP tree using Blind LDAP Injection techniques. The specific payload depends on how the User Search Filter property is configured in OneDev. This issue was fixed in version 4.4.2.

    Published: 1 Jun 2021
    4.8
    Medium

    CVE-2020-27377

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability was discovered in the Administrator panel on the 'Setting News' module on CMS Made Simple 2.2.14 which allows an attacker to execute arbitrary web scripts.

    Published: 1 Jun 2021
    5.4
    Medium

    CVE-2020-26693

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability was discovered in pfSense 2.4.5-p1 which allows an authenticated attacker to execute arbitrary web scripts via exploitation of the load_balancer_monitor.php function.

    Published: 1 Jun 2021
    5.4
    Medium

    CVE-2021-31643

    Last Modified: 21 Nov 2024

    An XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and Webpass due to a lack of sanitization on the component if.cgi - username parameter.

    Published: 1 Jun 2021
    6.5
    Medium

    CVE-2021-31642

    Last Modified: 21 Nov 2024

    A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC. The vulnerability can be explored by sending an unexpected integer (> 32 bits) on the page parameter that will crash the web portal and making it unavailable until a reboot of the device.

    Published: 1 Jun 2021
    8.8
    High

    CVE-2020-26670

    Last Modified: 21 Nov 2024

    A vulnerability has been discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary commands through a crafted request sent to the server via the 'Create a New Setting' function.

    Published: 1 Jun 2021
    5.4
    Medium

    CVE-2020-26669

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability was discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary web scripts or HTML via the page content to site/index.php/admin/pages/update.

    Published: 1 Jun 2021
    8.8
    High

    CVE-2020-26668

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability was discovered in /core/feeds/custom.php in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to inject a malicious SQL query to the applications via the 'Create New Feed' function.

    Published: 1 Jun 2021
    6.1
    Medium

    CVE-2021-31641

    Last Modified: 21 Nov 2024

    An unauthenticated XSS vulnerability exists in several IoT devices from CHIYU Technology, including BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, BF-MINI-W, and SEMAC due to a lack of sanitization when the HTTP 404 message is generated.

    Published: 1 Jun 2021
    7.8
    High

    CVE-2021-29740

    Last Modified: 21 Nov 2024

    IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.3 system core component is affected by a format string security vulnerability. An attacker could execute arbitrary code in the context of process memory, potentially escalating their system privileges and taking control over the entire system with root access. IBM X-Force ID: 201474.

    Published: 1 Jun 2021
    7.5
    High

    CVE-2021-28091

    Last Modified: 21 Nov 2024

    Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.

    Published: 1 Jun 2021
    5.5
    Medium

    CVE-2021-23021

    Last Modified: 21 Nov 2024

    The Nginx Controller 3.x before 3.7.0 agent configuration file /etc/controller-agent/agent.conf is world readable with current permission bits set to 644.

    Published: 1 Jun 2021
    5.5
    Medium

    CVE-2021-23020

    Last Modified: 21 Nov 2024

    The NAAS 3.x before 3.10.0 API keys were generated using an insecure pseudo-random string and hashing algorithm which could lead to predictable keys.

    Published: 1 Jun 2021
    7.8
    High

    CVE-2021-23019

    Last Modified: 21 Nov 2024

    The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt file that is included in the NGINX support package.

    Published: 1 Jun 2021
    7.4
    High

    CVE-2021-23018

    Last Modified: 21 Nov 2024

    Intra-cluster communication does not use TLS. The services within the NGINX Controller 3.x before 3.4.0 namespace are using cleartext protocols inside the cluster.

    Published: 1 Jun 2021
    7.5
    High

    CVE-2020-1920

    Last Modified: 21 Nov 2024

    A regular expression denial of service (ReDoS) vulnerability in the validateBaseUrl function can cause the application to use excessive resources, become unresponsive, or crash. This was introduced in react-native version 0.59.0 and fixed in version 0.64.1.

    Published: 1 Jun 2021
    5.4
    Medium

    CVE-2021-24322

    Last Modified: 21 Nov 2024

    The Database Backup for WordPress plugin before 2.4 did not escape the backup_recipient POST parameter in before output it back in the attribute of an HTML tag, leading to a Stored Cross-Site Scripting issue.

    Published: 1 Jun 2021
    4.8
    Medium

    CVE-2021-24330

    Last Modified: 21 Nov 2024

    The Funnel Builder by CartFlows – Create High Converting Sales Funnels For WordPress plugin before 1.6.13 did not sanitise its facebook_pixel_id and google_analytics_id settings, allowing high privilege users to set XSS payload in them, which will either be executed on pages generated by the plugin, or the whole website depending on the settings used.

    Published: 1 Jun 2021
    4.8
    Medium

    CVE-2021-24331

    Last Modified: 21 Nov 2024

    The Smooth Scroll Page Up/Down Buttons WordPress plugin before 1.4 did not properly sanitise and validate its settings, such as psb_distance, psb_buttonsize, psb_speed, only validating them client side. This could allow high privilege users (such as admin) to set XSS payloads in them

    Published: 1 Jun 2021
    6.2
    Medium

    CVE-2021-24328

    Last Modified: 21 Nov 2024

    The WP Login Security and History WordPress plugin through 1.0 did not have CSRF check when saving its settings, not any sanitisation or validation on them. This could allow attackers to make logged in administrators change the plugin's settings to arbitrary values, and set XSS payloads on them as well

    Published: 1 Jun 2021
    5.4
    Medium

    CVE-2021-24329

    Last Modified: 21 Nov 2024

    The WP Super Cache WordPress plugin before 1.7.3 did not properly sanitise its wp_cache_location parameter in its settings, which could lead to a Stored Cross-Site Scripting issue.

    Published: 1 Jun 2021
    6.5
    Medium

    CVE-2021-24333

    Last Modified: 21 Nov 2024

    The Content Copy Protection & Prevent Image Save WordPress plugin through 1.3 does not check for CSRF when saving its settings, not perform any validation and sanitisation on them, allowing attackers to make a logged in administrator set arbitrary XSS payloads in them.

    Published: 1 Jun 2021
    6.1
    Medium

    CVE-2021-24335

    Last Modified: 21 Nov 2024

    The Car Repair Services & Auto Mechanic WordPress theme before 4.0 did not properly sanitise its serviceestimatekey search parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting issue

    Published: 1 Jun 2021
    5.4
    Medium

    CVE-2021-24334

    Last Modified: 21 Nov 2024

    The Instant Images – One Click Unsplash Uploads WordPress plugin before 4.4.0.1 did not properly validate and sanitise its unsplash_download_w and unsplash_download_h parameter settings (/wp-admin/upload.php?page=instant-images), only validating them client side before saving them, leading to a Stored Cross-Site Scripting issue.

    Published: 1 Jun 2021
    7.2
    High

    CVE-2021-24312

    Last Modified: 21 Nov 2024

    The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of WP Super Cache WordPress plugin before 1.7.3 result in RCE because they allow input of '$' and '\n'. This is due to an incomplete fix of CVE-2021-24209.

    Published: 1 Jun 2021
    6.1
    Medium

    CVE-2021-24316

    Last Modified: 21 Nov 2024

    The search feature of the Mediumish WordPress theme through 1.0.47 does not properly sanitise it's 's' GET parameter before output it back the page, leading to the Cross-SIte Scripting issue.

    Published: 1 Jun 2021
    6.1
    Medium

    CVE-2021-24317

    Last Modified: 21 Nov 2024

    The Listeo WordPress theme before 1.6.11 did not properly sanitise some parameters in its Search, Booking Confirmation and Personal Message pages, leading to Cross-Site Scripting issues

    Published: 1 Jun 2021
    6.5
    Medium

    CVE-2021-24318

    Last Modified: 21 Nov 2024

    The Listeo WordPress theme before 1.6.11 did not ensure that the Post/Page and Booking to delete belong to the user making the request, allowing any authenticated users to delete arbitrary page/post and booking via an IDOR vector.

    Published: 1 Jun 2021
    6.1
    Medium

    CVE-2021-24320

    Last Modified: 21 Nov 2024

    The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise and escape its listing_list_view, bt_bb_listing_field_my_lat, bt_bb_listing_field_my_lng, bt_bb_listing_field_distance_value, bt_bb_listing_field_my_lat_default, bt_bb_listing_field_keyword, bt_bb_listing_field_location_autocomplete, bt_bb_listing_field_price_range_from and bt_bb_listing_field_price_range_to parameter in ints listing page, leading to reflected Cross-Site Scripting issues.

    Published: 1 Jun 2021
    5.4
    Medium

    CVE-2021-24313

    Last Modified: 21 Nov 2024

    The WP Prayer WordPress plugin before 1.6.2 provides the functionality to store requested prayers/praises and list them on a WordPress website. These stored prayer/praise requests can be listed by using the WP Prayer engine. An authenticated WordPress user with any role can fill in the form to request a prayer. The form to request prayers or praises have several fields. The 'prayer request' and 'praise request' fields do not use proper input validation and can be used to store XSS payloads.

    Published: 1 Jun 2021
    5.4
    Medium

    CVE-2021-24319

    Last Modified: 21 Nov 2024

    The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise its post_excerpt parameter before outputting it back in the shop/my-account/bello-listing-endpoint/ page, leading to a Cross-Site Scripting issue

    Published: 1 Jun 2021
    9.8
    Critical

    CVE-2021-24321

    Last Modified: 21 Nov 2024

    The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, bt_bb_listing_field_my_lng, listing_list_view and bt_bb_listing_field_my_lat parameters before using them in a SQL statement, leading to SQL Injection issues

    Published: 1 Jun 2021
    4.8
    Medium

    CVE-2021-24310

    Last Modified: 21 Nov 2024

    The Photo Gallery by 10Web - Mobile-Friendly Image Gallery WordPress plugin before 1.5.67 did not properly sanitise the gallery title, allowing high privilege users to create one with XSS payload in it, which will be triggered when another user will view the gallery list or the affected gallery in the admin dashboard. This is due to an incomplete fix of CVE-2019-16117

    Published: 1 Jun 2021
    8.8
    High

    CVE-2021-24311

    Last Modified: 21 Nov 2024

    The wp_ajax_upload-remote-file AJAX action of the External Media WordPress plugin before 1.0.34 was vulnerable to arbitrary file uploads via any authenticated users.

    Published: 1 Jun 2021
    5.4
    Medium

    CVE-2021-24309

    Last Modified: 21 Nov 2024

    The "Schedule Name" input in the Weekly Schedule WordPress plugin before 3.4.3 general options did not properly sanitize input, allowing a user to inject javascript code using the <script> HTML tags and cause a stored XSS issue

    Published: 1 Jun 2021
    9.1
    Critical

    CVE-2021-27828

    Last Modified: 21 Nov 2024

    SQL injection in In4Suite ERP 3.2.74.1370 allows attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.

    Published: 1 Jun 2021
    5.4
    Medium

    CVE-2021-25932

    Last Modified: 21 Nov 2024

    In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to Stored Cross-Site Scripting, since the function `validateFormInput()` performs improper validation checks on the input sent to the `userID` parameter. Due to this flaw an attacker could inject an arbitrary script which will be stored in the database.

    Published: 1 Jun 2021
    6.6
    Medium

    CVE-2021-33181

    Last Modified: 21 Nov 2024

    Server-Side Request Forgery (SSRF) vulnerability in webapi component in Synology Video Station before 2.4.10-1632 allows remote authenticated users to send arbitrary request to intranet resources via unspecified vectors.

    Published: 1 Jun 2021