8.8
    High

    CVE-2021-25642

    Last Modified: 21 Nov 2024

    ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An attacker having access to ZooKeeper can run arbitrary commands as YARN user by exploiting this. Users should upgrade to Apache Hadoop 2.10.2, 3.2.4, 3.3.4 or later (containing YARN-11126) if ZKConfigurationStore is used.

    Published:25 Aug 2022
    9.8
    Critical

    CVE-2021-25641

    Last Modified: 21 Nov 2024

    Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on. But for Dubbo versions before 2.7.8 or 2.6.9, an attacker can choose which serialization id the Provider will use by tampering with the byte preamble flags, aka, not following the server's instruction. This means that if a weak deserializer such as the Kryo and FST are somehow in code scope (e.g. if Kryo is somehow a part of a dependency), a remote unauthenticated attacker can tell the Provider to use the weak deserializer, and then proceed to exploit it.

    Published:29 May 2021
    4
    Medium

    CVE-2021-25461

    Last Modified: 21 Nov 2024

    An improper length check in APAService prior to SMR Sep-2021 Release 1 results in stack based Buffer Overflow.

    Published:9 Sept 2021
    8.6
    High

    CVE-2021-25374

    Last Modified: 21 Nov 2024

    An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 2.4.83.9 in Android O(8.1) and below, and 3.9.00.9 in Android P(9.0) and above allows remote attackers to access a user data related with Samsung Account.

    Published:9 Apr 2021
    4.4
    Medium

    CVE-2021-25337

    Last Modified: 30 Oct 2025

    Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files.

    Published:4 Mar 2021
    9.8
    Critical

    CVE-2021-25281

    Last Modified: 21 Nov 2024

    An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attacker can remotely run any wheel modules on the master.

    Published:25 Feb 2021
    7.8
    High

    CVE-2021-25253

    Last Modified: 21 Nov 2024

    An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a resource used by the service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published:13 Apr 2021
    8.1
    High

    CVE-2021-25162

    Last Modified: 16 Jul 2021

    A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba Instant 8.7.x: 8.7.1.1 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.

    Source:Aleph Security
    Published:30 Mar 2021
    6.1
    Medium

    CVE-2021-25161

    Last Modified: 16 Jul 2021

    A remote cross-site scripting (xss) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba Instant 8.7.x: 8.7.1.1 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.

    Source:Aleph Security
    Published:30 Mar 2021
    4.9
    Medium

    CVE-2021-25160

    Last Modified: 16 Jul 2021

    A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba Instant 8.7.x: 8.7.1.1 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.

    Source:Aleph Security
    Published:30 Mar 2021
    6.5
    Medium

    CVE-2021-25159

    Last Modified: 16 Jul 2021

    A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba Instant 8.7.x: 8.7.1.1 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.

    Source:Aleph Security
    Published:30 Mar 2021
    5.9
    Medium

    CVE-2021-25158

    Last Modified: 16 Jul 2021

    A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba Instant 8.7.x: 8.7.1.1 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.

    Source:Aleph Security
    Published:30 Mar 2021
    4.9
    Medium

    CVE-2021-25157

    Last Modified: 16 Jul 2021

    A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.6 and below; Aruba Instant 8.7.x: 8.7.1.0 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.

    Source:Aleph Security
    Published:30 Mar 2021
    4.9
    Medium

    CVE-2021-25156

    Last Modified: 16 Jul 2021

    A remote arbitrary directory create vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.6 and below; Aruba Instant 8.7.x: 8.7.1.0 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.

    Source:Aleph Security
    Published:30 Mar 2021
    6.5
    Medium

    CVE-2021-25155

    Last Modified: 16 Jul 2021

    A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.6 and below; Aruba Instant 8.7.x: 8.7.1.0 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.

    Source:Aleph Security
    Published:30 Mar 2021
    8.1
    High

    CVE-2021-25094

    Last Modified: 18 Apr 2025

    The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rogue zip file which is uncompressed under the WordPress's upload directory. By adding a PHP shell with a filename starting with a dot ".", this can bypass extension control implemented in the plugin. Moreover, there is a race condition in the zip extraction process which makes the shell file live long enough on the filesystem to be callable by an attacker.

    Source:Milad karimi
    Published:25 Apr 2022
    8.8
    High

    CVE-2021-25076

    Last Modified: 21 Feb 2022

    The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of sanitisation and escaping, this could also lead to Reflected Cross-Site Scripting

    Source:Ron Jost
    Published:24 Jan 2022
    9.8
    Critical

    CVE-2021-25032

    Last Modified: 21 Nov 2024

    The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation and CSRF checks when updating the plugin's settings via the init hook, and does not ensure that the options to be updated belong to the plugin. As a result, unauthenticated attackers could update arbitrary blog options, such as the default role and make any new registered user with an administrator role.

    Published:10 Jan 2022
    9.8
    Critical

    CVE-2021-25003

    Last Modified: 21 Nov 2024

    The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE

    Published:14 Mar 2022
    4.9
    Medium

    CVE-2021-24966

    Last Modified: 16 Feb 2022

    The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitrary files on the web server, including those outside of the blog folder

    Source:Ceylan BOZOĞULLARINDAN
    Published:14 Mar 2022
    8.8
    High

    CVE-2021-24959

    Last Modified: 21 Nov 2024

    The WP Email Users WordPress plugin through 1.7.6 does not escape the data_raw parameter in the weu_selected_users_1 AJAX action, available to any authenticated users, allowing them to perform SQL injection attacks.

    Published:14 Mar 2022
    9.8
    Critical

    CVE-2021-24946

    Last Modified: 27 Jan 2022

    The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue

    Source:Ron Jost
    Published:13 Dec 2021
    9.8
    Critical

    CVE-2021-24931

    Last Modified: 10 Feb 2022

    The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an SQL injection.

    Source:Ron Jost
    Published:6 Dec 2021
    6.1
    Medium

    CVE-2021-24926

    Last Modified: 2 Feb 2022

    The Domain Check WordPress plugin before 1.0.17 does not sanitise and escape the domain parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue

    Source:Ceylan BOZOĞULLARINDAN
    Published:1 Feb 2022
    7.5
    High

    CVE-2021-24917

    Last Modified: 21 Nov 2024

    The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.

    Published:6 Dec 2021
    4.8
    Medium

    CVE-2021-24904

    Last Modified: 27 Jan 2022

    The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the background of a calculator, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Source:Ceylan BOZOĞULLARINDAN
    Published:14 Feb 2022
    4.8
    Medium

    CVE-2021-24901

    Last Modified: 8 Feb 2022

    The Security Audit WordPress plugin through 1.0.0 does not sanitise and escape the Data Id setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Source:Shweta Mahajan
    Published:28 Feb 2022
    6.1
    Medium

    CVE-2021-24891

    Last Modified: 21 Nov 2024

    The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue.

    Published:23 Nov 2021
    9.6
    Critical

    CVE-2021-24884

    Last Modified: 21 Nov 2024

    The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img>,<a> and<button>.This could allow an unauthenticated, remote attacker to exploit a HTML-injection byinjecting a malicous link. The HTML-injection may trick authenticated users to follow the link. If the Link gets clicked, Javascript code can be executed. The vulnerability is due to insufficient sanitization of the "data-frmverify" tag for links in the web-based entry inspection page of affected systems. A successful exploitation incomibantion with CSRF could allow the attacker to perform arbitrary actions on an affected system with the privileges of the user. These actions include stealing the users account by changing their password or allowing attackers to submit their own code through an authenticated user resulting in Remote Code Execution. If an authenticated user who is able to edit Wordpress PHP Code in any kind, clicks the malicious link, PHP code can be edited.

    Published:25 Oct 2021
    7.2
    High

    CVE-2021-24862

    Last Modified: 27 Jan 2022

    The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injection issue

    Source:Ron Jost
    Published:10 Jan 2022
    5.4
    Medium

    CVE-2021-24807

    Last Modified: 21 Nov 2024

    The Support Board WordPress plugin before 3.3.5 allows Authenticated (Agent+) users to perform Cross-Site Scripting attacks by placing a payload in the notes field, when an administrator or any authenticated user go to the chat the XSS will be automatically executed.

    Published:8 Nov 2021
    7.2
    High

    CVE-2021-24786

    Last Modified: 2 Feb 2022

    The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue

    Source:Ron Jost
    Published:3 Jan 2022
    9.8
    Critical

    CVE-2021-24762

    Last Modified: 21 Feb 2022

    The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection.

    Source:Ron Jost
    Published:1 Feb 2022
    8.8
    High

    CVE-2021-24750

    Last Modified: 5 Jan 2022

    The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks

    Source:Ron Jost
    Published:21 Dec 2021
    9.8
    Critical

    CVE-2021-24741

    Last Modified: 21 Nov 2024

    The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable by unauthenticated users.

    Published:20 Sept 2021
    6.1
    Medium

    CVE-2021-24719

    Last Modified: 19 Oct 2021

    The Enfold Enfold WordPress theme before 4.8.4 was vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability is present on Enfold versions previous than 4.8.4 which use Avia Page Builder.

    Source:David Álvarez Robles
    Published:11 Oct 2021
    4.8
    Medium

    CVE-2021-24664

    Last Modified: 15 Nov 2021

    The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_field() but does not escape them before outputting in attributes, resulting in Stored Cross-Site Scripting issues.

    Source:Davide Taraschi
    Published:8 Nov 2021
    8.1
    High

    CVE-2021-24647

    Last Modified: 21 Nov 2024

    The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username

    Published:8 Nov 2021
    4.8
    Medium

    CVE-2021-24610

    Last Modified: 28 Sept 2021

    The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' function only removes script tag with a regex, still allowing other HTML tags and attributes to execute javascript, which could lead to authenticated Stored Cross-Site Scripting issues.

    Source:Nosa Shandy
    Published:27 Sept 2021
    8.8
    High

    CVE-2021-24581

    Last Modified: 11 May 2022

    The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin does not have CSRF check in place when saving its settings, allowing the issue to be exploited via a CSRF attack.

    Source:Abisheik M
    Published:30 Aug 2021
    6.1
    Medium

    CVE-2021-24563

    Last Modified: 12 Jan 2022

    The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly

    Source:Veshraj Ghimire
    Published:11 Oct 2021
    5.4
    Medium

    CVE-2021-24545

    Last Modified: 21 Nov 2024

    The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone visit a post in the frontend made by such user. As a result, user with a role as low as author could perform Cross-Site Scripting attacks against users, which could potentially lead to privilege escalation when an admin view the related post/s.

    Published:11 Oct 2021
    9.8
    Critical

    CVE-2021-24507

    Last Modified: 21 Nov 2024

    The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both unauthenticated and authenticated user) before using them in SQL statement, leading to an SQL Injection issues

    Published:9 Aug 2021
    9.8
    Critical

    CVE-2021-24499

    Last Modified: 9 Jun 2023

    The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks, or validate that the request is from a valid user in any other way. The endpoints allowed for uploading arbitrary files to the uploads/workreap-temp directory. Uploaded files were neither sanitized nor validated, allowing an unauthenticated visitor to upload executable code such as php scripts.

    Source:Mohammad Hossein Khanaki
    Published:9 Aug 2021
    6.1
    Medium

    CVE-2021-24488

    Last Modified: 2 Feb 2022

    The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading to Reflected Cross-Site Scripting issues

    Source:0xB9
    Published:2 Aug 2021
    4.8
    Medium

    CVE-2021-24444

    Last Modified: 25 Oct 2021

    The TaxoPress – Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its Taxonomy description field, allowing high privilege users to set JavaScript payload in them even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue.

    Source:Akash Patil
    Published:2 Aug 2021
    6.5
    Medium

    CVE-2021-24405

    Last Modified: 30 Mar 2022

    The Easy Cookies Policy WordPress plugin through 1.6.2 is lacking any capability and CSRF check when saving its settings, allowing any authenticated users (such as subscriber) to change them. If users can't register, this can be done through CSRF. Furthermore, the cookie banner setting is not sanitised or validated before being output in all pages of the frontend and the backend settings one, leading to a Stored Cross-Site Scripting issue.

    Source:0xB9
    Published:6 Jul 2021
    5.4
    Medium

    CVE-2021-24383

    Last Modified: 23 Jun 2021

    The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue

    Source:Mohammed Adam
    Published:21 Jun 2021
    8.8
    High

    CVE-2021-24356

    Last Modified: 21 Nov 2024

    In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, a lack of capability checks and insufficient nonce check on the AJAX action, simple301redirects/admin/activate_plugin, made it possible for authenticated users to activate arbitrary plugins installed on vulnerable sites.

    Published:14 Jun 2021
    5.4
    Medium

    CVE-2021-24308

    Last Modified: 28 May 2021

    The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.1 is not properly sanitised when output in the About section of the profile page, leading to a stored Cross-Site Scripting issue. This could allow low privilege users (such as students) to elevate their privilege via an XSS attack when an admin will view their profile.

    Source:Captain_hook
    Published:24 May 2021