CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2020-19109

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_edit.php, which could let a remote malicious user execute arbitrary code.

    Published: 5 May 2021
    9.8
    Critical

    CVE-2020-19108

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in Online Book Store v1.0 via the pubid parameter to bookPerPub.php, which could let a remote malicious user execute arbitrary code.

    Published: 5 May 2021
    9.8
    Critical

    CVE-2020-19107

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in Online Book Store v1.0 via the isbn parameter to edit_book.php, which could let a remote malicious user execute arbitrary code.

    Published: 5 May 2021
    7.5
    High

    CVE-2021-31409

    Last Modified: 21 Nov 2024

    Unsafe validation RegEx in EmailValidator component in com.vaadin:vaadin-compatibility-server versions 8.0.0 through 8.12.4 (Vaadin versions 8.0.0 through 8.12.4) allows attackers to cause uncontrolled resource consumption by submitting malicious email addresses.

    Published: 5 May 2021
    7.2
    High

    CVE-2021-24254

    Last Modified: 21 Nov 2024

    The College publisher Import WordPress plugin through 0.1 does not check for the uploaded CSV file to import, allowing high privilege users to upload arbitrary files, such as PHP, leading to RCE. Due to the lack of CSRF check, the issue could also be exploited via a CSRF attack.

    Published: 5 May 2021
    5.4
    Medium

    CVE-2021-24250

    Last Modified: 21 Nov 2024

    The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from lack of sanitisation in the label of the Form Fields, leading to Authenticated Stored Cross-Site Scripting issues across various pages of the plugin.

    Published: 5 May 2021
    5.4
    Medium

    CVE-2021-24246

    Last Modified: 21 Nov 2024

    The Workscout Core WordPress plugin before 1.3.4, used by the WorkScout Theme did not sanitise the chat messages sent via the workscout_send_message_chat AJAX action, leading to Stored Cross-Site Scripting and Cross-Frame Scripting issues

    Published: 5 May 2021
    5.4
    Medium

    CVE-2021-24247

    Last Modified: 21 Nov 2024

    The Contact Form Check Tester WordPress plugin through 1.0.2 settings are visible to all registered users in the dashboard and are lacking any sanitisation. As a result, any registered user, such as subscriber, can leave an XSS payload in the plugin settings, which will be triggered by any user visiting them, and could allow for privilege escalation. The vendor decided to close the plugin.

    Published: 5 May 2021
    7.2
    High

    CVE-2021-24248

    Last Modified: 21 Nov 2024

    The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 did not properly check for imported files, forbidding certain extension via a blacklist approach, allowing administrator to import an archive with a .php4 inside for example, leading to RCE

    Published: 5 May 2021
    6.5
    Medium

    CVE-2021-24249

    Last Modified: 21 Nov 2024

    The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator export files, which could then be downloaded by the attacker to get access to PII, such as email, home addresses etc

    Published: 5 May 2021
    7.2
    High

    CVE-2021-24252

    Last Modified: 21 Nov 2024

    The Event Banner WordPress plugin through 1.3 does not verify the uploaded image file, allowing admin accounts to upload arbitrary files, such as .exe, .php, or others executable, leading to RCE. Due to the lack of CSRF check, the issue can also be used via such vector to achieve the same result, or via a LFI as authorisation checks are missing (but would require WP to be loaded)

    Published: 5 May 2021
    4.3
    Medium

    CVE-2021-24251

    Last Modified: 21 Nov 2024

    The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator update arbitrary payment history, such as change their status (from pending to completed to example)

    Published: 5 May 2021
    8.8
    High

    CVE-2021-24253

    Last Modified: 21 Nov 2024

    The Classyfrieds WordPress plugin through 3.8 does not properly check the uploaded file when an authenticated user adds a listing, only checking the content-type in the request. This allows any authenticated user to upload arbitrary PHP files via the Add Listing feature of the plugin, leading to RCE.

    Published: 5 May 2021
    8.8
    High

    CVE-2021-24179

    Last Modified: 21 Nov 2024

    The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator import files. As the plugin also did not validate uploaded files, it could lead to RCE.

    Published: 5 May 2021
    6.1
    Medium

    CVE-2021-24214

    Last Modified: 21 Nov 2024

    The OpenID Connect Generic Client WordPress plugin 3.8.0 and 3.8.1 did not sanitise the login error when output back in the login form, leading to a reflected Cross-Site Scripting issue. This issue does not require authentication and can be exploited with the default configuration.

    Published: 5 May 2021
    6.1
    Medium

    CVE-2021-24245

    Last Modified: 21 Nov 2024

    The Stop Spammers WordPress plugin before 2021.9 did not escape user input when blocking requests (such as matching a spam word), outputting it in an attribute after sanitising it to remove HTML tags, which is not sufficient and lead to a reflected Cross-Site Scripting issue.

    Published: 5 May 2021
    8.8
    High

    CVE-2021-24178

    Last Modified: 21 Nov 2024

    The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 suffered from Cross-Site Request Forgery issues, allowing an attacker to make a logged in administrator add, edit or delete form fields, which could also lead to Stored Cross-Site Scripting issues.

    Published: 5 May 2021
    9.8
    Critical

    CVE-2021-24236

    Last Modified: 21 Nov 2024

    The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Content-Type in the request to forbid dangerous files. This allows unauthenticated attackers to upload arbitrary files by using a valid image Content-Type along with a PHP filename and code, leading to RCE.

    Published: 5 May 2021
    5.4
    Medium

    CVE-2021-24243

    Last Modified: 21 Nov 2024

    An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.6 did not have capability checks nor sanitization, allowing low privilege users (subscriber+) to call it and set XSS payloads, which will be triggered in all backend pages.

    Published: 5 May 2021
    6.5
    Medium

    CVE-2021-24244

    Last Modified: 21 Nov 2024

    An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.8 did not have capability checks, allowing low privilege users, such as subscribers, to update the license options (key, email).

    Published: 5 May 2021
    5.3
    Medium

    CVE-2021-32062

    Last Modified: 21 Nov 2024

    MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 does not properly enforce the MS_MAP_NO_PATH and MS_MAP_PATTERN restrictions that are intended to control the locations from which a mapfile may be loaded (with MapServer CGI).

    Published: 5 May 2021
    6.1
    Medium

    CVE-2021-24274

    Last Modified: 21 Nov 2024

    The Ultimate Maps by Supsystic WordPress plugin before 1.2.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

    Published: 5 May 2021
    6.1
    Medium

    CVE-2021-24276

    Last Modified: 21 Nov 2024

    The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

    Published: 5 May 2021
    6.1
    Medium

    CVE-2021-24293

    Last Modified: 21 Nov 2024

    In the eCommerce module of the NextGEN Gallery Pro WordPress plugin before 3.1.11, there is an action to call get_cart_items via photocrati_ajax , after that the settings[shipping_address][name] is able to inject malicious javascript.

    Published: 5 May 2021
    6.1
    Medium

    CVE-2021-24275

    Last Modified: 21 Nov 2024

    The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

    Published: 5 May 2021
    5.4
    Medium

    CVE-2021-24266

    Last Modified: 21 Nov 2024

    The “The Plus Addons for Elementor Page Builder Lite” WordPress Plugin before 2.0.6 has four widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

    Published: 5 May 2021
    5.4
    Medium

    CVE-2021-24268

    Last Modified: 21 Nov 2024

    The “JetWidgets For Elementor” WordPress Plugin before 1.0.9 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

    Published: 5 May 2021
    5.4
    Medium

    CVE-2021-24269

    Last Modified: 21 Nov 2024

    The “Sina Extension for Elementor” WordPress Plugin before 3.3.12 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

    Published: 5 May 2021
    5.4
    Medium

    CVE-2021-24270

    Last Modified: 21 Nov 2024

    The “DeTheme Kit for Elementor” WordPress Plugin before 1.5.5.5 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

    Published: 5 May 2021
    5.4
    Medium

    CVE-2021-24271

    Last Modified: 21 Nov 2024

    The “Ultimate Addons for Elementor” WordPress Plugin before 1.30.0 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

    Published: 5 May 2021
    4.3
    Medium

    CVE-2021-24272

    Last Modified: 21 Nov 2024

    The fitness calculators WordPress plugin before 1.9.6 add calculators for Water intake, BMI calculator, protein Intake, and Body Fat and was lacking CSRF check, allowing attackers to make logged in users perform unwanted actions, such as change the calculator headers. Due to the lack of sanitisation, this could also lead to a Stored Cross-Site Scripting issue

    Published: 5 May 2021
    5.4
    Medium

    CVE-2021-24273

    Last Modified: 21 Nov 2024

    The “Clever Addons for Elementor” WordPress Plugin before 2.1.0 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

    Published: 5 May 2021
    5.4
    Medium

    CVE-2021-24265

    Last Modified: 21 Nov 2024

    The “Rife Elementor Extensions & Templates” WordPress Plugin before 1.1.6 has a widget that is vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method.

    Published: 5 May 2021
    5.4
    Medium

    CVE-2021-24267

    Last Modified: 21 Nov 2024

    The “All-in-One Addons for Elementor – WidgetKit” WordPress Plugin before 2.3.10 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

    Published: 5 May 2021
    5.4
    Medium

    CVE-2021-24257

    Last Modified: 21 Nov 2024

    The “Premium Addons for Elementor” WordPress Plugin before 4.2.8 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

    Published: 5 May 2021
    5.4
    Medium

    CVE-2021-24262

    Last Modified: 21 Nov 2024

    The “WooLentor – WooCommerce Elementor Addons + Builder” WordPress Plugin before 1.8.6 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

    Published: 5 May 2021
    5.4
    Medium

    CVE-2021-24258

    Last Modified: 21 Nov 2024

    The Elements Kit Lite and Elements Kit Pro WordPress Plugins before 2.2.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

    Published: 5 May 2021
    5.4
    Medium

    CVE-2021-24259

    Last Modified: 21 Nov 2024

    The “Elementor Addon Elements” WordPress Plugin before 1.11.2 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

    Published: 5 May 2021
    5.4
    Medium

    CVE-2021-24260

    Last Modified: 21 Nov 2024

    The “Livemesh Addons for Elementor” WordPress Plugin before 6.8 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

    Published: 5 May 2021
    5.4
    Medium

    CVE-2021-24264

    Last Modified: 21 Nov 2024

    The “Image Hover Effects – Elementor Addon” WordPress Plugin before 1.3.4 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

    Published: 5 May 2021
    5.4
    Medium

    CVE-2021-24261

    Last Modified: 21 Nov 2024

    The “HT Mega – Absolute Addons for Elementor Page Builder” WordPress Plugin before 1.5.7 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

    Published: 5 May 2021
    5.4
    Medium

    CVE-2021-24263

    Last Modified: 21 Nov 2024

    The “Elementor Addons – PowerPack Addons for Elementor” WordPress Plugin before 2.3.2 for WordPress has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

    Published: 5 May 2021
    5.4
    Medium

    CVE-2021-24255

    Last Modified: 21 Nov 2024

    The Essential Addons for Elementor Lite WordPress Plugin before 4.5.4 has two widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, both via a similar method.

    Published: 5 May 2021
    5.4
    Medium

    CVE-2021-24256

    Last Modified: 21 Nov 2024

    The “Elementor – Header, Footer & Blocks Template” WordPress Plugin before 1.5.8 has two widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

    Published: 5 May 2021
    5.8
    Medium

    CVE-2021-29490

    Last Modified: 21 Nov 2024

    Jellyfin is a free software media system that provides media from a dedicated server to end-user devices via multiple apps. Verions prior to 10.7.3 vulnerable to unauthenticated Server-Side Request Forgery (SSRF) attacks via the imageUrl parameter. This issue potentially exposes both internal and external HTTP servers or other resources available via HTTP `GET` that are visible from the Jellyfin server. The vulnerability is patched in version 10.7.3. As a workaround, disable external access to the API endpoints `/Items/*/RemoteImages/Download`, `/Items/RemoteSearch/Image` and `/Images/Remote` via reverse proxy, or limit to known-friendly IPs.

    Published: 5 May 2021
    7.5
    High

    CVE-2021-29101

    Last Modified: 10 Apr 2025

    ArcGIS GeoEvent Server versions 10.8.1 and below has a read-only directory path traversal vulnerability that could allow an unauthenticated, remote attacker to perform directory traversal attacks and read arbitrary files on the system.

    Published: 5 May 2021
    6.3
    Medium

    CVE-2021-31411

    Last Modified: 21 Nov 2024

    Insecure temporary directory usage in frontend build functionality of com.vaadin:flow-server versions 2.0.9 through 2.5.2 (Vaadin 14.0.3 through Vaadin 14.5.2), 3.0 prior to 6.0 (Vaadin 15 prior to 19), and 6.0.0 through 6.0.5 (Vaadin 19.0.0 through 19.0.4) allows local users to inject malicious code into frontend resources during application rebuilds.

    Published: 5 May 2021
    7.8
    High

    CVE-2021-20401

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.3 and 7.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196075.

    Published: 5 May 2021
    6.1
    Medium

    CVE-2021-20397

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 196017.

    Published: 5 May 2021
    8.1
    High

    CVE-2020-5013

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.3 and 7.4 may vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 193245.

    Published: 5 May 2021