|
196091
|
5.4 |
MEDIUM
Network
|
admincolumns
|
admin_columns
|
The Admin Columns WordPress plugin Free before 4.3.2 and Pro before 5.5.2 allowed to configure individual columns for tables. Each column had a type. The type "Custom Field" allowed to choose an arbi…
|
-
|
CVE-2021-24365
|
2024-11-21 14:52 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196092
|
8.8 |
HIGH
Network
|
fortinet
|
fortimail
|
An improper neutralization of special elements used in an OS Command vulnerability in the administrative interface of FortiMail before 6.4.4 may allow an authenticated attacker to execute unauthorize…
|
CWE-78
OS Command
|
CVE-2021-24015
|
2024-11-21 14:52 |
2021-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196093
|
6.5 |
MEDIUM
Network
|
fortinet
|
fortimail
|
Multiple Path traversal vulnerabilities in the Webmail of FortiMail before 6.4.4 may allow a regular user to obtain unauthorized access to files and data via specifically crafted web requests.
|
CWE-22
Path Traversal
|
CVE-2021-24013
|
2024-11-21 14:52 |
2021-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196094
|
9.8 |
CRITICAL
Network
|
fortinet
|
fortimail
|
A missing cryptographic step in the implementation of the hash digest algorithm in FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthenticated attacker to tamper with signed U…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2021-24020
|
2024-11-21 14:52 |
2021-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196095
|
9.8 |
CRITICAL
Network
|
fortinet
|
fortimail
|
Multiple improper neutralization of special elements of SQL commands vulnerabilities in FortiMail before 6.4.4 may allow a non-authenticated attacker to execute unauthorized code or commands via spec…
|
CWE-89
SQL Injection
|
CVE-2021-24007
|
2024-11-21 14:52 |
2021-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196096
|
6.1 |
MEDIUM
Network
|
chimpgroup
|
foodbakery
|
The WP Foodbakery WordPress plugin before 2.2, used in the FoodBakery WordPress theme before 2.2 did not properly sanitize the foodbakery_radius parameter before outputting it back in the response, l…
|
-
|
CVE-2021-24389
|
2024-11-21 14:52 |
2021-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196097
|
6.1 |
MEDIUM
Network
|
contempothemes
|
real_estate_7
|
The WP Pro Real Estate 7 WordPress theme before 3.1.1 did not properly sanitise the ct_community parameter in its search listing page before outputting it back in it, leading to a reflected Cross-Sit…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24387
|
2024-11-21 14:52 |
2021-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196098
|
5.4 |
MEDIUM
Network
|
kubiq
|
wp_svg_images
|
The WP SVG images WordPress plugin before 3.4 did not sanitise the SVG files uploaded, which could allow low privilege users such as author+ to upload a malicious SVG and then perform XSS attacks by …
|
-
|
CVE-2021-24386
|
2024-11-21 14:52 |
2021-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196099
|
5.4 |
MEDIUM
Network
|
e4j
|
vikrentcar_car_rental_management_system
|
In the VikRentCar Car Rental Management System WordPress plugin before 1.1.7, there is a custom filed option by which we can manage all the fields that the users will have to fill in before saving th…
|
-
|
CVE-2021-24388
|
2024-11-21 14:52 |
2021-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196100
|
9.8 |
CRITICAL
Network
|
beardev
|
joomsport
|
The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unserialised user input from the shattr POST parameter…
|
-
|
CVE-2021-24384
|
2024-11-21 14:52 |
2021-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|