|
194971
|
5.4 |
MEDIUM
Network
|
king-theme
|
kingcomposer
|
The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creating profile, allowing any authenticated users to create arbitrary ones, with Cros…
|
-
|
CVE-2021-25048
|
2024-11-21 14:54 |
2022-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194972
|
6.1 |
MEDIUM
Network
|
inpsyde
|
akismet_privacy_policies
|
The WordPress plugin through 2.0.1 does not sanitise and escape the translation parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
|
-
|
CVE-2021-25071
|
2024-11-21 14:54 |
2022-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194973
|
9.8 |
CRITICAL
Network
|
stopbadbots
|
block_and_stop_bad_bots
|
The Block Bad Bots WordPress plugin before 6.88 does not properly sanitise and escape the User Agent before using it in a SQL statement to record logs, leading to an SQL Injection issue
|
-
|
CVE-2021-25070
|
2024-11-21 14:54 |
2022-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194974
|
7.2 |
HIGH
Network
|
dpl
|
sync_woocommerce_product_feed_to_google_shopping
|
The Sync WooCommerce Product feed to Google Shopping WordPress plugin through 1.2.4 uses the 'feed_id' POST parameter which is not properly sanitized for use in a SQL statement, leading to a SQL inje…
|
-
|
CVE-2021-25068
|
2024-11-21 14:54 |
2022-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194975
|
7.2 |
HIGH
Network
|
wow-company
|
wow_countdowns
|
The Wow Countdowns WordPress plugin through 3.1.2 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection.
|
-
|
CVE-2021-25064
|
2024-11-21 14:54 |
2022-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194976
|
6.1 |
MEDIUM
Network
|
popozure
|
pz-linkcard
|
The Pz-LinkCard WordPress plugin through 2.4.4.4 does not sanitise and escape multiple parameters before outputting them back in admin dashboard pages, leading to Reflected Cross-Site Scripting issues
|
-
|
CVE-2021-25012
|
2024-11-21 14:54 |
2022-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194977
|
5.3 |
MEDIUM
Network
|
b4after
|
osmapper
|
The OSMapper WordPress plugin through 2.1.5 contains an AJAX action to delete a plugin related post type named 'map' and is registered with the wp_ajax_nopriv prefix, making it available to unauthent…
|
CWE-352 CWE-862
Origin Validation Error Missing Authorization
|
CVE-2021-24978
|
2024-11-21 14:54 |
2022-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194978
|
8.8 |
HIGH
Network
|
iptanus
|
wordpress_file_upload_pro wordpress_file_upload
|
The WordPress File Upload Free and Pro WordPress plugins before 4.16.3 allow users with a role as low as Contributor to perform path traversal via a shortcode argument, which can then be used to uplo…
|
CWE-22
Path Traversal
|
CVE-2021-24962
|
2024-11-21 14:54 |
2022-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194979
|
6.8 |
MEDIUM
Network
|
isc fedoraproject netapp siemens juniper
|
bind fedora h300s_firmware h500s_firmware h700s_firmware h300e_firmware h500e_firmware h700e_firmware h410s_firmware h410c_firmware sinec_ins junos
|
BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0,…
|
CWE-444
HTTP Request Smuggling
|
CVE-2021-25220
|
2024-11-21 14:54 |
2022-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194980
|
6.1 |
MEDIUM
Network
|
squirrly
|
seo_plugin_by_squirrly_seo
|
The SEO Plugin by Squirrly SEO WordPress plugin before 11.1.12 does not escape the type parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripti…
|
-
|
CVE-2021-25019
|
2024-11-21 14:54 |
2022-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|