CVE Feed

    Dashboard / CVE

    4.9
    Medium

    CVE-2021-28191

    Last Modified: 21 Nov 2024

    The Firmware update function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28190

    Last Modified: 21 Nov 2024

    The specific function in ASUS BMC’s firmware Web management page (Generate new certificate function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28189

    Last Modified: 21 Nov 2024

    The SMTP configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28188

    Last Modified: 21 Nov 2024

    The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28187

    Last Modified: 21 Nov 2024

    The specific function in ASUS BMC’s firmware Web management page (Generate new SSL certificate) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28186

    Last Modified: 21 Nov 2024

    The specific function in ASUS BMC’s firmware Web management page (ActiveX configuration-2 acquisition) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28185

    Last Modified: 21 Nov 2024

    The specific function in ASUS BMC’s firmware Web management page (ActiveX configuration-1 acquisition) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28184

    Last Modified: 21 Nov 2024

    The Active Directory configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28183

    Last Modified: 21 Nov 2024

    The specific function in ASUS BMC’s firmware Web management page (Web License configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28182

    Last Modified: 21 Nov 2024

    The Web Service configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28181

    Last Modified: 21 Nov 2024

    The specific function in ASUS BMC’s firmware Web management page (Remote video configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28180

    Last Modified: 21 Nov 2024

    The specific function in ASUS BMC’s firmware Web management page (Audit log configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28179

    Last Modified: 21 Nov 2024

    The specific function in ASUS BMC’s firmware Web management page (Media support configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28178

    Last Modified: 21 Nov 2024

    The UEFI configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28177

    Last Modified: 21 Nov 2024

    The LDAP configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28176

    Last Modified: 21 Nov 2024

    The DNS configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021
    4.9
    Medium

    CVE-2021-28175

    Last Modified: 21 Nov 2024

    The Radius configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

    Published: 6 Apr 2021
    4.3
    Medium

    CVE-2021-30144

    Last Modified: 21 Nov 2024

    The Dashboard plugin through 1.0.2 for GLPI allows remote low-privileged users to bypass access control on viewing information about the last ten events, the connected users, and the users in the tech category. For example, plugins/dashboard/front/main2.php can be used.

    Published: 6 Apr 2021
    7.5
    High

    CVE-2021-30130

    Last Modified: 21 Nov 2024

    phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification.

    Published: 6 Apr 2021
    6.1
    Medium

    CVE-2021-30151

    Last Modified: 21 Nov 2024

    Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.

    Published: 6 Apr 2021
    4.3
    Medium

    CVE-2021-30156

    Last Modified: 21 Nov 2024

    An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Special:Contributions can leak that a "hidden" user exists.

    Published: 6 Apr 2021
    7.5
    High

    CVE-2021-30141

    Last Modified: 21 Nov 2024

    Module/Settings/UserExport.php in Friendica through 2021.01 allows settings/userexport to be used by anonymous users, as demonstrated by an attempted access to an array offset on a value of type null, and excessive memory consumption. NOTE: the vendor states "the feature still requires a valid authentication cookie even if the route is accessible to non-logged users.

    Published: 5 Apr 2021
    9.8
    Critical

    CVE-2021-20307

    Last Modified: 21 Nov 2024

    Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~rc2+dfsg-3 and earlier can lead to read and write arbitrary memory values.

    Published: 5 Apr 2021
    9.8
    Critical

    CVE-2021-20308

    Last Modified: 21 Nov 2024

    Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-2017-9181.

    Published: 5 Apr 2021
    7.5
    High

    CVE-2020-19595

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in Core FTP Server v2 Build 697, via a crafted username.

    Published: 5 Apr 2021
    9.8
    Critical

    CVE-2020-19596

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in Core FTP Server v1.2 Build 583, via a crafted username.

    Published: 5 Apr 2021
    9.8
    Critical

    CVE-2021-24212

    Last Modified: 21 Nov 2024

    The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site which by default will end up in wp-content/uploads/hstmp.

    Published: 5 Apr 2021
    6.1
    Medium

    CVE-2021-24210

    Last Modified: 21 Nov 2024

    There is an open redirect in the PhastPress WordPress plugin before 1.111 that allows an attacker to malform a request to a page with the plugin and then redirect the victim to a malicious page. There is also a support comment from another user one year ago (https://wordpress.org/support/topic/phast-php-used-for-remote-fetch/) that says that the php involved in the request only go to whitelisted pages but it's possible to redirect the victim to any domain.

    Published: 5 Apr 2021
    5.4
    Medium

    CVE-2021-24211

    Last Modified: 12 Aug 2025

    The WordPress Related Posts plugin through 3.6.4 contains an authenticated (admin+) stored XSS vulnerability in the title field on the settings page. By exploiting that an attacker will be able to execute JavaScript code in the user's browser.

    Published: 5 Apr 2021
    5.4
    Medium

    CVE-2021-24202

    Last Modified: 21 Nov 2024

    In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes/widgets/heading.php) accepts a ‘header_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request with this parameter set to ‘script’ and combined with a ‘title’ parameter containing JavaScript, which will then be executed when the saved page is viewed or previewed.

    Published: 5 Apr 2021
    5.4
    Medium

    CVE-2021-24203

    Last Modified: 21 Nov 2024

    In the Elementor Website Builder WordPress plugin before 3.1.4, the divider widget (includes/widgets/divider.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request with this parameter set to ‘script’ and combined with a ‘text’ parameter containing JavaScript, which will then be executed when the saved page is viewed or previewed.

    Published: 5 Apr 2021
    5.4
    Medium

    CVE-2021-24205

    Last Modified: 21 Nov 2024

    In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes/widgets/icon-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request containing JavaScript in the ‘title_size’ parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.

    Published: 5 Apr 2021
    5.4
    Medium

    CVE-2021-24206

    Last Modified: 21 Nov 2024

    In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes/widgets/image-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request containing JavaScript in the ‘title_size’ parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.

    Published: 5 Apr 2021
    4.3
    Medium

    CVE-2021-24207

    Last Modified: 21 Nov 2024

    By default, the WP Page Builder WordPress plugin before 1.2.4 allows subscriber-level users to edit and make changes to any and all posts pages - user roles must be specifically blocked from editing posts and pages.

    Published: 5 Apr 2021
    5.4
    Medium

    CVE-2021-24204

    Last Modified: 21 Nov 2024

    In the Elementor Website Builder WordPress plugin before 3.1.4, the accordion widget (includes/widgets/accordion.php) accepts a ‘title_html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request containing JavaScript in the ‘title_html_tag’ parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.

    Published: 5 Apr 2021
    7.2
    High

    CVE-2021-24209

    Last Modified: 21 Nov 2024

    The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in the WP Super Cache Settings -> Cache Location option. Direct access to the wp-cache-config.php file is not prohibited, so this vulnerability can be exploited for a web shell injection.

    Published: 5 Apr 2021
    5.4
    Medium

    CVE-2021-24201

    Last Modified: 21 Nov 2024

    In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes/elements/column.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request containing JavaScript in the ‘html_tag’ parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.

    Published: 5 Apr 2021
    5.4
    Medium

    CVE-2021-24208

    Last Modified: 21 Nov 2024

    The editor of the WP Page Builder WordPress plugin before 1.2.4 allows lower-privileged users to insert unfiltered HTML, including JavaScript, into pages via the “Raw HTML” widget and the “Custom HTML” widgets (though the custom HTML widget requires sending a crafted request - it appears that this widget uses some form of client side validation but not server side validation), all of which are added via the “page_builder_data” parameter when performing the “wppb_page_save” AJAX action. It is also possible to insert malicious JavaScript via the “wppb_page_css” parameter (this can be done by closing out the style tag and opening a script tag) when performing the “wppb_page_save” AJAX action.

    Published: 5 Apr 2021
    5.4
    Medium

    CVE-2021-24177

    Last Modified: 24 Mar 2025

    In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint /wp-admin/admin.php?page=wp_file_manager_properties when a payload is submitted on the User-Agent parameter. The payload is then reflected back on the web application response.

    Published: 5 Apr 2021
    5.4
    Medium

    CVE-2021-24180

    Last Modified: 21 Nov 2024

    Unvalidated input and lack of output encoding within the Related Posts for WordPress plugin before 2.0.4 lead to a Reflected Cross-Site Scripting (XSS) vulnerability within the 'lang' GET parameter while editing a post, triggered when users with the capability of editing posts access a malicious URL.

    Published: 5 Apr 2021
    5.4
    Medium

    CVE-2021-24187

    Last Modified: 21 Nov 2024

    The setting page of the SEO Redirection Plugin - 301 Redirect Manager WordPress plugin before 6.4 is vulnerable to reflected Cross-Site Scripting (XSS) as user input is not properly sanitised before being output in an attribute.

    Published: 5 Apr 2021
    5.4
    Medium

    CVE-2021-24196

    Last Modified: 21 Nov 2024

    The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the ‘token_error’ parameter can be controlled by users and it is directly echoed without being sanitized

    Published: 5 Apr 2021
    6.5
    Medium

    CVE-2021-24181

    Last Modified: 21 Nov 2024

    The tutor_mark_answer_as_correct AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploited by students.

    Published: 5 Apr 2021
    6.5
    Medium

    CVE-2021-24182

    Last Modified: 21 Nov 2024

    The tutor_quiz_builder_get_answers_by_question AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.

    Published: 5 Apr 2021
    6.5
    Medium

    CVE-2021-24183

    Last Modified: 21 Nov 2024

    The tutor_quiz_builder_get_question_form AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.

    Published: 5 Apr 2021
    8.8
    High

    CVE-2021-24184

    Last Modified: 21 Nov 2024

    Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unprotected, allowing students to modify course information and elevate their privileges among many other actions.

    Published: 5 Apr 2021
    6.5
    Medium

    CVE-2021-24185

    Last Modified: 21 Nov 2024

    The tutor_place_rating AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploited by students.

    Published: 5 Apr 2021
    6.5
    Medium

    CVE-2021-24186

    Last Modified: 21 Nov 2024

    The tutor_answering_quiz_question/get_answer_by_id function pair from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.

    Published: 5 Apr 2021
    7.5
    High

    CVE-2021-24170

    Last Modified: 21 Nov 2024

    The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functionality to users with the upload_files capability. This included password hashes, hashed user activation keys, usernames, emails, and other less sensitive information.

    Published: 5 Apr 2021
    5.4
    Medium

    CVE-2021-24176

    Last Modified: 21 Nov 2024

    The JH 404 Logger WordPress plugin through 1.1 doesn't sanitise the referer and path of 404 pages, when they are output in the dashboard, which leads to executing arbitrary JavaScript code in the WordPress dashboard.

    Published: 5 Apr 2021