8.8
    High

    CVE-2021-24307

    Last Modified: 21 Nov 2024

    The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticated users with "aioseo_tools_settings" privilege (most of the time admin) to execute arbitrary code on the underlying host. Users can restore plugin's configuration by uploading a backup .ini file in the section "Tool > Import/Export". However, the plugin attempts to unserialize values of the .ini file. Moreover, the plugin embeds Monolog library which can be used to craft a gadget chain and thus trigger system command execution.

    Published:24 May 2021
    6.1
    Medium

    CVE-2021-24300

    Last Modified: 2 Feb 2022

    The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-Site Scripting issue

    Source:0xB9
    Published:24 May 2021
    6.1
    Medium

    CVE-2021-24299

    Last Modified: 24 May 2021

    The ReDi Restaurant Reservation WordPress plugin before 21.0426 provides the functionality to let users make restaurant reservations. These reservations are stored and can be listed on an 'Upcoming' page provided by the plugin. An unauthenticated user can fill in the form to make a restaurant reservation. The form to make a restaurant reservation field called 'Comment' does not use proper input validation and can be used to store XSS payloads. The XSS payloads will be executed when the plugin user goes to the 'Upcoming' page, which is an external website https://upcoming.reservationdiary.eu/ loaded in an iframe, and the stored reservation with XSS payload is loaded.

    Source:Bastijn Ouwendijk
    Published:17 May 2021
    6.1
    Medium

    CVE-2021-24287

    Last Modified: 28 Oct 2021

    The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue

    Source:0xB9
    Published:14 May 2021
    6.1
    Medium

    CVE-2021-24286

    Last Modified: 22 Oct 2021

    The settings page of the Redirect 404 to parent WordPress plugin before 1.3.1 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue

    Source:0xB9
    Published:14 May 2021
    6.1
    Medium

    CVE-2021-24276

    Last Modified: 28 Sept 2021

    The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

    Source:0xB9
    Published:5 May 2021
    6.1
    Medium

    CVE-2021-24275

    Last Modified: 28 Sept 2021

    The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

    Source:0xB9
    Published:5 May 2021
    6.1
    Medium

    CVE-2021-24274

    Last Modified: 28 Sept 2021

    The Ultimate Maps by Supsystic WordPress plugin before 1.2.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

    Source:0xB9
    Published:5 May 2021
    4.3
    Medium

    CVE-2021-24272

    Last Modified: 23 Sept 2021

    The fitness calculators WordPress plugin before 1.9.6 add calculators for Water intake, BMI calculator, protein Intake, and Body Fat and was lacking CSRF check, allowing attackers to make logged in users perform unwanted actions, such as change the calculator headers. Due to the lack of sanitisation, this could also lead to a Stored Cross-Site Scripting issue

    Source:0xB9
    Published:5 May 2021
    5.4
    Medium

    CVE-2021-24247

    Last Modified: 2 Feb 2022

    The Contact Form Check Tester WordPress plugin through 1.0.2 settings are visible to all registered users in the dashboard and are lacking any sanitisation. As a result, any registered user, such as subscriber, can leave an XSS payload in the plugin settings, which will be triggered by any user visiting them, and could allow for privilege escalation. The vendor decided to close the plugin.

    Source:0xB9
    Published:5 May 2021
    6.1
    Medium

    CVE-2021-24245

    Last Modified: 19 May 2021

    The Stop Spammers WordPress plugin before 2021.9 did not escape user input when blocking requests (such as matching a spam word), outputting it in an attribute after sanitising it to remove HTML tags, which is not sufficient and lead to a reflected Cross-Site Scripting issue.

    Source:Hosein Vita
    Published:5 May 2021
    8.1
    High

    CVE-2021-24174

    Last Modified: 11 Jun 2021

    The Database Backups WordPress plugin through 1.2.2.6 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the database, change the plugin's settings and delete backups.

    Source:0xB9
    Published:5 Apr 2021
    6.1
    Medium

    CVE-2021-24169

    Last Modified: 23 Sept 2021

    This Advanced Order Export For WooCommerce WordPress plugin before 3.1.8 helps you to easily export WooCommerce order data. The tab parameter in the Admin Panel is vulnerable to reflected XSS.

    Source:0xB9
    Published:5 Apr 2021
    8.8
    High

    CVE-2021-24160

    Last Modified: 21 Nov 2024

    In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ directory. These files could then be accessed via the front end of the site to trigger remote code execution and ultimately allow an attacker to execute commands to further infect a WordPress site.

    Published:5 Apr 2021
    7.2
    High

    CVE-2021-24155

    Last Modified: 5 Jul 2021

    The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high privilege users (admin+) to upload arbitrary files, including PHP ones, leading to RCE.

    Source:Ron Jost
    Published:5 Apr 2021
    7.5
    High

    CVE-2021-24146

    Last Modified: 2 Jul 2021

    Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example.

    Source:Ron Jost
    Published:18 Mar 2021
    7.2
    High

    CVE-2021-24145

    Last Modified: 2 Jul 2021

    Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing PHP ones to be uploaded by administrator by using the 'text/csv' content-type in the request.

    Source:Ron Jost
    Published:18 Mar 2021
    5.5
    Medium

    CVE-2021-24098

    Last Modified: 21 Nov 2024

    Windows Console Driver Denial of Service Vulnerability

    Published:25 Feb 2021
    7.8
    High

    CVE-2021-24096

    Last Modified: 21 Nov 2024

    Windows Kernel Elevation of Privilege Vulnerability

    Published:25 Feb 2021
    7.8
    High

    CVE-2021-24092

    Last Modified: 21 Nov 2024

    Microsoft Defender Elevation of Privilege Vulnerability

    Published:25 Feb 2021
    7.5
    High

    CVE-2021-24086

    Last Modified: 21 Nov 2024

    Windows TCP/IP Denial of Service Vulnerability

    Published:25 Feb 2021
    6.5
    Medium

    CVE-2021-24085

    Last Modified: 21 Nov 2024

    Microsoft Exchange Server Spoofing Vulnerability

    Published:25 Feb 2021
    5.5
    Medium

    CVE-2021-24084

    Last Modified: 21 Nov 2024

    Windows Mobile Device Management Information Disclosure Vulnerability

    Published:25 Feb 2021
    9.8
    Critical

    CVE-2021-24040

    Last Modified: 13 Sept 2021

    Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input, resulting in remote code execution or similar risks. This issue affects ParlAI prior to v1.1.0.

    Source:Abhiram V
    Published:10 Sept 2021
    7.5
    High

    CVE-2021-24027

    Last Modified: 21 Nov 2024

    A cache configuration issue prior to WhatsApp for Android v2.21.4.18 and WhatsApp Business for Android v2.21.4.18 may have allowed a third party with access to the device’s external storage to read cached TLS material.

    Published:6 Apr 2021
    8.1
    High

    CVE-2021-24019

    Last Modified: 21 Nov 2024

    An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below may allow an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that session ID (via other, hypothetical attacks)

    Published:6 Oct 2021
    6.3
    Medium

    CVE-2021-24006

    Last Modified: 21 Nov 2024

    An improper access control vulnerability in FortiManager versions 6.4.0 to 6.4.3 may allow an authenticated attacker with a restricted user profile to access the SD-WAN Orchestrator panel via directly visiting its URL.

    Published:6 Sept 2021
    5.9
    Medium

    CVE-2021-23841

    Last Modified: 21 Nov 2024

    The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is maliciously constructed). This may subsequently result in a NULL pointer deref and a crash leading to a potential denial of service attack. The function X509_issuer_and_serial_hash() is never directly called by OpenSSL itself so applications are only vulnerable if they use this function directly and they use it on certificates that may have been obtained from untrusted sources. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x).

    Published:16 Feb 2021
    7.5
    High

    CVE-2021-23840

    Last Modified: 16 Apr 2026

    Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output length value will be negative. This could cause applications to behave incorrectly or crash. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x).

    Published:16 Feb 2021
    7.5
    High

    CVE-2021-23797

    Last Modified: 21 Nov 2024

    All versions of package http-server-node are vulnerable to Directory Traversal via use of --path-as-is.

    Published:17 Dec 2021
    8.1
    High

    CVE-2021-23758

    Last Modified: 26 Aug 2026

    All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

    Published:3 Dec 2021
    9.8
    Critical

    CVE-2021-23639

    Last Modified: 21 Nov 2024

    The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matter to parse front matter content, without disabling the JS engine.

    Published:10 Dec 2021
    Low

    CVE-2021-23410

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published:21 Jul 2021
    8.1
    High

    CVE-2021-23394

    Last Modified: 21 Nov 2024

    The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP.

    Published:13 Jun 2021
    5.6
    Medium

    CVE-2021-23383

    Last Modified: 21 Nov 2024

    The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.

    Published:12 Apr 2021
    5.6
    Medium

    CVE-2021-23369

    Last Modified: 21 Nov 2024

    The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

    Published:12 Apr 2021
    3.3
    Low

    CVE-2021-23358

    Last Modified: 3 Nov 2025

    The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.

    Published:29 Mar 2021
    7.2
    High

    CVE-2021-23337

    Last Modified: 21 Nov 2024

    Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

    Published:15 Feb 2021
    7.5
    High

    CVE-2021-23132

    Last Modified: 25 Feb 2026

    An issue was discovered in Joomla! 3.0.0 through 3.9.24. com_media allowed paths that are not intended for image uploads

    Published:4 Mar 2021
    7.7
    High

    CVE-2021-23017

    Last Modified: 11 Jul 2022

    A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.

    Source:Mohammed Alshehri
    Published:25 May 2021
    9.8
    Critical

    CVE-2021-22986

    Last Modified: 2 Apr 2021

    On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

    Source:Al1ex
    Published:31 Mar 2021
    9.8
    Critical

    CVE-2021-22941

    Last Modified: 3 Nov 2025

    Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.

    Published:23 Sept 2021
    3.7
    Low

    CVE-2021-22924

    Last Modified: 9 Jun 2025

    libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing wrong connections.File paths are, or can be, case sensitive on many systems but not all, and caneven vary depending on used file systems.The comparison also didn't include the 'issuer cert' which a transfer can setto qualify how to verify the server certificate.

    Published:21 Jul 2021
    9.8
    Critical

    CVE-2021-22911

    Last Modified: 28 Oct 2021

    A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE.

    Source:enox
    Published:27 May 2021
    10
    Critical

    CVE-2021-22893

    Last Modified: 30 Oct 2025

    Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild.

    Published:23 Apr 2021
    7.5
    High

    CVE-2021-22880

    Last Modified: 21 Nov 2024

    The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS) vulnerability. Carefully crafted input can cause the input validation in the `money` type of the PostgreSQL adapter in Active Record to spend too much time in a regular expression, resulting in the potential for a DoS attack. This only impacts Rails applications that are using PostgreSQL along with money type columns that take user input.

    Published:11 Feb 2021
    6.1
    Medium

    CVE-2021-22873

    Last Modified: 21 Nov 2024

    Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php delivery scripts. Such open redirects had previously been available by design to allow third party ad servers to track such metrics when delivering ads. However, third party click tracking via redirects is not a viable option anymore, leading to such open redirect functionality being removed and reclassified as a vulnerability.

    Published:21 Jan 2021
    9.8
    Critical

    CVE-2021-22681

    Last Modified: 6 Mar 2026

    Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.

    Published:3 Mar 2021
    6.6
    Medium

    CVE-2021-22600

    Last Modified: 24 Oct 2025

    A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755

    Published:15 Dec 2021
    7.5
    High

    CVE-2021-22569

    Last Modified: 21 Apr 2025

    An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.

    Published:6 Jan 2022