|
195071
|
8.0 |
HIGH
Adjacent
|
mcafee
|
database_security
|
Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authenticated attacker to create a reverse shell with administrator privileges on th…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-23895
|
2024-11-21 14:52 |
2021-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195072
|
8.8 |
HIGH
Adjacent
|
mcafee
|
database_security
|
Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote unauthenticated attacker to create a reverse shell with administrator privileges on …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-23894
|
2024-11-21 14:52 |
2021-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195073
|
6.1 |
MEDIUM
Network
|
smartdatasoft
|
car_repair_services_\&_auto_mechanic
|
The Car Repair Services & Auto Mechanic WordPress theme before 4.0 did not properly sanitise its serviceestimatekey search parameter before outputting it back in the page, leading to a reflected Cros…
|
-
|
CVE-2021-24335
|
2024-11-21 14:52 |
2021-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195074
|
5.4 |
MEDIUM
Network
|
connekthq
|
instant_images_-_one_click_unsplash_uploads
|
The Instant Images – One Click Unsplash Uploads WordPress plugin before 4.4.0.1 did not properly validate and sanitise its unsplash_download_w and unsplash_download_h parameter settings (/wp-admin/up…
|
-
|
CVE-2021-24334
|
2024-11-21 14:52 |
2021-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195075
|
6.5 |
MEDIUM
Network
|
content_copy_protection_\&_prevent_image_save_project
|
content_copy_protection_\&_prevent_image_save
|
The Content Copy Protection & Prevent Image Save WordPress plugin through 1.3 does not check for CSRF when saving its settings, not perform any validation and sanitisation on them, allowing attackers…
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2021-24333
|
2024-11-21 14:52 |
2021-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195076
|
4.8 |
MEDIUM
Network
|
smooth_scroll_page_up\/down_buttons_project
|
smooth_scroll_page_up\/down_buttons
|
The Smooth Scroll Page Up/Down Buttons WordPress plugin before 1.4 did not properly sanitise and validate its settings, such as psb_distance, psb_buttonsize, psb_speed, only validating them client si…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24331
|
2024-11-21 14:52 |
2021-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195077
|
4.8 |
MEDIUM
Network
|
cartflows
|
cartflows
|
The Funnel Builder by CartFlows – Create High Converting Sales Funnels For WordPress plugin before 1.6.13 did not sanitise its facebook_pixel_id and google_analytics_id settings, allowing high privil…
|
-
|
CVE-2021-24330
|
2024-11-21 14:52 |
2021-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195078
|
5.4 |
MEDIUM
Network
|
automattic
|
wp_super_cache
|
The WP Super Cache WordPress plugin before 1.7.3 did not properly sanitise its wp_cache_location parameter in its settings, which could lead to a Stored Cross-Site Scripting issue.
|
-
|
CVE-2021-24329
|
2024-11-21 14:52 |
2021-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195079
|
6.2 |
MEDIUM
Network
|
clogica
|
wp_login_security_and_history
|
The WP Login Security and History WordPress plugin through 1.0 did not have CSRF check when saving its settings, not any sanitisation or validation on them. This could allow attackers to make logged …
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2021-24328
|
2024-11-21 14:52 |
2021-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195080
|
5.4 |
MEDIUM
Network
|
deliciousbrains
|
database_backup
|
The Database Backup for WordPress plugin before 2.4 did not escape the backup_recipient POST parameter in before output it back in the attribute of an HTML tag, leading to a Stored Cross-Site Scripti…
|
-
|
CVE-2021-24322
|
2024-11-21 14:52 |
2021-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|