CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2021-24168

    Last Modified: 21 Nov 2024

    The Easy Contact Form Pro WordPress plugin before 1.1.1.9 did not properly sanitise the text fields (such as Email Subject, Email Recipient, etc) when creating or editing a form, leading to an authenticated (author+) stored cross-site scripting issue. This could allow medium privilege accounts (such as author and editor) to perform XSS attacks against high privilege ones like administrator.

    Published: 5 Apr 2021
    9.8
    Critical

    CVE-2021-24171

    Last Modified: 25 Nov 2024

    The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions such as .php. It was possible to bypass this and upload a file with a PHP extension by embedding a "blocked" extension within another "blocked" extension in the "wcuf_file_name" parameter. It was also possible to perform a double extension attack and upload files to a different location via path traversal using the "wcuf_current_upload_session_id" parameter.

    Published: 5 Apr 2021
    4.3
    Medium

    CVE-2021-24172

    Last Modified: 21 Nov 2024

    The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the DB, plugins, and current .

    Published: 5 Apr 2021
    6.1
    Medium

    CVE-2021-24173

    Last Modified: 21 Nov 2024

    The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as update the plugin's options, leading to a Stored Cross-Site Scripting issue.

    Published: 5 Apr 2021
    8.1
    High

    CVE-2021-24174

    Last Modified: 21 Nov 2024

    The Database Backups WordPress plugin through 1.2.2.6 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the database, change the plugin's settings and delete backups.

    Published: 5 Apr 2021
    9.8
    Critical

    CVE-2021-24175

    Last Modified: 21 Nov 2024

    The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to bypass authentication, allowing unauthenticated users to log in as any user (including admin) by just providing the related username, as well as create accounts with arbitrary roles, such as admin. These issues can be exploited even if registration is disabled, and the Login widget is not active.

    Published: 5 Apr 2021
    6.1
    Medium

    CVE-2021-24169

    Last Modified: 21 Nov 2024

    This Advanced Order Export For WooCommerce WordPress plugin before 3.1.8 helps you to easily export WooCommerce order data. The tab parameter in the Admin Panel is vulnerable to reflected XSS.

    Published: 5 Apr 2021
    8.8
    High

    CVE-2021-24162

    Last Modified: 21 Nov 2024

    In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into importing all new settings. These settings could be modified to include malicious JavaScript, therefore allowing an attacker to inject payloads that could aid in further infection of the site.

    Published: 5 Apr 2021
    4.3
    Medium

    CVE-2021-24164

    Last Modified: 21 Nov 2024

    In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to trigger the action, wp_ajax_nf_oauth, and retrieve the connection url needed to establish a connection. They could also retrieve the client_id for an already established OAuth connection.

    Published: 5 Apr 2021
    5.4
    Medium

    CVE-2021-24166

    Last Modified: 21 Nov 2024

    The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 had no nonce protection making it possible for attackers to craft a request to disconnect a site's OAuth connection.

    Published: 5 Apr 2021
    8.8
    High

    CVE-2021-24159

    Last Modified: 21 Nov 2024

    Due to the lack of sanitization and lack of nonce protection on the custom CSS feature, an attacker could craft a request to inject malicious JavaScript on a site using the Contact Form 7 Style WordPress plugin through 3.1.9. If an attacker successfully tricked a site’s administrator into clicking a link or attachment, then the request could be sent and the CSS settings would be successfully updated to include malicious JavaScript.

    Published: 5 Apr 2021
    8.8
    High

    CVE-2021-24160

    Last Modified: 21 Nov 2024

    In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ directory. These files could then be accessed via the front end of the site to trigger remote code execution and ultimately allow an attacker to execute commands to further infect a WordPress site.

    Published: 5 Apr 2021
    8.8
    High

    CVE-2021-24161

    Last Modified: 21 Nov 2024

    In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into uploading a zip archive containing malicious PHP files. The attacker could then access those files to achieve remote code execution and further infect the targeted site.

    Published: 5 Apr 2021
    6.1
    Medium

    CVE-2021-24165

    Last Modified: 21 Nov 2024

    In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect parameter and no protection in place.

    Published: 5 Apr 2021
    7.5
    High

    CVE-2021-24167

    Last Modified: 21 Nov 2024

    When visiting a site running Web-Stat < 1.4.0, the "wts_web_stat_load_init" function used the visitor’s browser to send an XMLHttpRequest request to https://wts2.one/ajax.htm?action=lookup_WP_account.

    Published: 5 Apr 2021
    8.8
    High

    CVE-2021-24163

    Last Modified: 21 Nov 2024

    The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it have any nonce protection, therefore making it possible for low-level users, such as subscribers, to install and activate the SendWP Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 and retrieve the client_secret key needed to establish the SendWP connection while also installing the SendWP plugin.

    Published: 5 Apr 2021
    6.5
    Medium

    CVE-2021-24158

    Last Modified: 21 Nov 2024

    Orbit Fox by ThemeIsle has a feature to add a registration form to both the Elementor and Beaver Builder page builders functionality. As part of the registration form, administrators can choose which role to set as the default for users upon registration. This field is hidden from view for lower-level users, however, they can still supply the user_role parameter to update the default role for registration.

    Published: 5 Apr 2021
    6.1
    Medium

    CVE-2021-24152

    Last Modified: 21 Nov 2024

    The "All Subscribers" setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting.

    Published: 5 Apr 2021
    4.9
    Medium

    CVE-2021-24154

    Last Modified: 21 Nov 2024

    The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrary files on the web server, such as /etc/passwd

    Published: 5 Apr 2021
    7.2
    High

    CVE-2021-24155

    Last Modified: 21 Nov 2024

    The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high privilege users (admin+) to upload arbitrary files, including PHP ones, leading to RCE.

    Published: 5 Apr 2021
    5.4
    Medium

    CVE-2021-24156

    Last Modified: 21 Nov 2024

    Stored Cross-Site Scripting vulnerabilities in Testimonial Rotator 3.0.3 allow low privileged users (Contributor) to inject arbitrary JavaScript code or HTML without approval. This could lead to privilege escalation

    Published: 5 Apr 2021
    7.5
    High

    CVE-2021-24150

    Last Modified: 21 Nov 2024

    The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request Forgery (SSRF).

    Published: 5 Apr 2021
    5.4
    Medium

    CVE-2021-24153

    Last Modified: 21 Nov 2024

    A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had built-in blacklist filters which were blacklisting Parenthesis as well as several functions such as alert but bypasses were found.

    Published: 5 Apr 2021
    5.4
    Medium

    CVE-2021-24157

    Last Modified: 21 Nov 2024

    Orbit Fox by ThemeIsle has a feature to add custom scripts to the header and footer of a page or post. There were no checks to verify that a user had the unfiltered_html capability prior to saving the script tags, thus allowing lower-level users to inject scripts that could potentially be malicious.

    Published: 5 Apr 2021
    5.4
    Medium

    CVE-2020-4997

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192914

    Published: 5 Apr 2021
    5.4
    Medium

    CVE-2020-4792

    Last Modified: 21 Nov 2024

    IBM Edge 4.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 189441.

    Published: 5 Apr 2021
    6.1
    Medium

    CVE-2021-30109

    Last Modified: 21 Nov 2024

    Froala Editor 3.2.6 is affected by Cross Site Scripting (XSS). Under certain conditions, a base64 crafted string leads to persistent Cross-site scripting (XSS) vulnerability within the hyperlink creation module.

    Published: 5 Apr 2021
    8.8
    High

    CVE-2021-30055

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in Knowage Suite version 7.1 exists in the documentexecution/url analytics driver component via the 'par_year' parameter when running a report.

    Published: 5 Apr 2021
    5.4
    Medium

    CVE-2021-30056

    Last Modified: 21 Nov 2024

    Knowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in /restful-services/publish via the 'EXEC_FROM' parameter that can lead to data leakage.

    Published: 5 Apr 2021
    4.8
    Medium

    CVE-2021-30057

    Last Modified: 21 Nov 2024

    A stored HTML injection vulnerability exists in Knowage Suite version 7.1. An attacker can inject arbitrary HTML in "/restful-services/2.0/analyticalDrivers" via the 'LABEL' and 'NAME' parameters.

    Published: 5 Apr 2021
    6.1
    Medium

    CVE-2021-30058

    Last Modified: 21 Nov 2024

    Knowage Suite before 7.4 is vulnerable to cross-site scripting (XSS). An attacker can inject arbitrary external script in '/knowagecockpitengine/api/1.0/pages/execute' via the 'SBI_HOST' parameter.

    Published: 5 Apr 2021
    9.6
    Critical

    CVE-2021-29996

    Last Modified: 21 Nov 2024

    Mark Text through 0.16.3 allows attackers arbitrary command execution. This could lead to Remote Code Execution (RCE) by opening .md files containing a mutation Cross Site Scripting (XSS) payload.

    Published: 5 Apr 2021
    7.8
    High

    CVE-2021-29261

    Last Modified: 21 Nov 2024

    The unofficial Svelte extension before 104.8.0 for Visual Studio Code allows attackers to execute arbitrary code via a crafted workspace configuration.

    Published: 5 Apr 2021
    7.8
    High

    CVE-2021-28832

    Last Modified: 21 Nov 2024

    VSCodeVim before 1.19.0 allows attackers to execute arbitrary code via a crafted workspace configuration.

    Published: 5 Apr 2021
    6.1
    Medium

    CVE-2020-17453

    Last Modified: 21 Nov 2024

    WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.

    Published: 5 Apr 2021
    7.5
    High

    CVE-2021-28965

    Last Modified: 21 Nov 2024

    The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing.

    Published: 5 Apr 2021
    4.3
    Medium

    CVE-2021-20306

    Last Modified: 21 Nov 2024

    A flaw was found in the BPMN editor in version jBPM 7.51.0.Final. Any authenticated user from any project can see the name of Ruleflow Groups from other projects, despite the user not having access to those projects. The highest threat from this vulnerability is to confidentiality.

    Published: 5 Apr 2021
    6.5
    Medium

    CVE-2021-3482

    Last Modified: 21 Nov 2024

    A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetadata() in jp2image.cpp can lead to a heap-based buffer overflow via a crafted JPG image containing malicious EXIF data.

    Published: 5 Apr 2021
    7.8
    High

    CVE-2021-30184

    Last Modified: 12 Jan 2025

    GNU Chess 6.2.7 allows attackers to execute arbitrary code via crafted PGN (Portable Game Notation) data. This is related to a buffer overflow in the use of a .tmp.epd temporary file in the cmd_pgnload and cmd_pgnreplay functions in frontend/cmd.cc.

    Published: 4 Apr 2021
    7.8
    High

    CVE-2021-3483

    Last Modified: 21 Nov 2024

    A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted twice into a doubly-linked list, leading to a use-after-free when one of these devices is removed. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. Versions before kernel 5.12-rc6 are affected

    Published: 4 Apr 2021
    7.3
    High

    CVE-2021-30127

    Last Modified: 21 Nov 2024

    TerraMaster F2-210 devices through 2021-04-03 use UPnP to make the admin web server accessible over the Internet on TCP port 8181, which is arguably inconsistent with the "It is only available on the local network" documentation. NOTE: manually editing /etc/upnp.json provides a partial but undocumented workaround.

    Published: 3 Apr 2021
    4.3
    Medium

    CVE-2021-21533

    Last Modified: 21 Nov 2024

    Wyse Management Suite versions up to 3.2 contains a vulnerability wherein a malicious authenticated user can cause a denial of service in the job status retrieval page, also affecting other users that would have normally access to the same subset of job details

    Published: 2 Apr 2021
    5
    Medium

    CVE-2021-21532

    Last Modified: 21 Nov 2024

    Dell Wyse ThinOS 8.6 MR9 contains remediation for an improper management server validation vulnerability that could be potentially exploited to redirect a client to an attacker-controlled management server, thus allowing the attacker to change the device configuration or certificate file.

    Published: 2 Apr 2021
    3.8
    Low

    CVE-2021-21529

    Last Modified: 21 Nov 2024

    Dell System Update (DSU) 1.9 and earlier versions contain a denial of service vulnerability. A local authenticated malicious user with low privileges may potentially exploit this vulnerability to cause the system to run out of memory by running multiple instances of the vulnerable application.

    Published: 2 Apr 2021
    6.1
    Medium

    CVE-2021-30074

    Last Modified: 21 Nov 2024

    docsify 4.12.1 is affected by Cross Site Scripting (XSS) because the search component does not appropriately encode Code Blocks and mishandles the " character.

    Published: 2 Apr 2021
    9.8
    Critical

    CVE-2020-27600

    Last Modified: 21 Nov 2024

    HNAP1/control/SetMasterWLanSettings.php in D-Link D-Link Router DIR-846 DIR-846 A1_100.26 allows remote attackers to execute arbitrary commands via shell metacharacters in the ssid0 or ssid1 parameter.

    Published: 2 Apr 2021
    4.3
    Medium

    CVE-2020-21590

    Last Modified: 21 Nov 2024

    Directory traversal in coreframe/app/template/admin/index.php in WUZHI CMS 4.1.0 allows attackers to list files in arbitrary directories via the dir parameter.

    Published: 2 Apr 2021
    5.5
    Medium

    CVE-2020-21588

    Last Modified: 21 Nov 2024

    Buffer overflow in Core FTP LE v2.2 allows local attackers to cause a denial or service (crash) via a long string in the Setup->Users->Username editbox.

    Published: 2 Apr 2021
    9.8
    Critical

    CVE-2020-21585

    Last Modified: 21 Nov 2024

    Vulnerability in emlog v6.0.0 allows user to upload webshells via zip plugin module.

    Published: 2 Apr 2021
    9.8
    Critical

    CVE-2021-30072

    Last Modified: 21 Nov 2024

    An issue was discovered in prog.cgi on D-Link DIR-878 1.30B08 devices. Because strcat is misused, there is a stack-based buffer overflow that does not require authentication.

    Published: 2 Apr 2021