|
194951
|
7.2 |
HIGH
Network
|
export_users_with_meta_project
|
export_users_with_meta
|
The Export Users With Meta WordPress plugin before 0.6.5 did not escape the list of roles to export before using them in a SQL statement in the export functionality, available to admins, leading to a…
|
-
|
CVE-2021-24451
|
2024-11-21 14:53 |
2021-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194952
|
6.1 |
MEDIUM
Network
|
tielabs
|
jannah
|
The Jannah WordPress theme before 5.4.5 did not properly sanitize the 'query' POST parameter in its tie_ajax_search AJAX action, leading to a Reflected Cross-site Scripting (XSS) vulnerability.
|
-
|
CVE-2021-24407
|
2024-11-21 14:53 |
2021-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194953
|
6.1 |
MEDIUM
Network
|
gvectors
|
wpforo_forum
|
The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect issue after a successful login. Such issue could …
|
-
|
CVE-2021-24406
|
2024-11-21 14:53 |
2021-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194954
|
6.5 |
MEDIUM
Network
|
izsoft
|
easy_cookies_policy
|
The Easy Cookies Policy WordPress plugin through 1.6.2 is lacking any capability and CSRF check when saving its settings, allowing any authenticated users (such as subscriber) to change them. If user…
|
NVD-CWE-Other
|
CVE-2021-24405
|
2024-11-21 14:53 |
2021-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194955
|
7.2 |
HIGH
Network
|
benjaminrojas
|
wp_editor
|
The WP Editor WordPress plugin before 1.2.7 did not sanitise or validate its setting fields leading to an authenticated (admin+) blind SQL injection issue via an arbitrary parameter when making a req…
|
CWE-89
SQL Injection
|
CVE-2021-24151
|
2024-11-21 14:52 |
2024-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194956
|
6.1 |
MEDIUM
Network
|
mozilla
|
bleach
|
A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags style, title, noscript, script, textarea, noframes, iframe, or xmp in allowed ta…
|
CWE-79
Cross-site Scripting
|
CVE-2021-23980
|
2024-11-21 14:52 |
2023-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194957
|
8.8 |
HIGH
Network
|
fortinet
|
fortiwan
|
Multiple improper neutralization of special elements used in an OS command vulnerabilities (CWE-78) in the Web GUI of FortiWAN before 4.5.9 may allow an authenticated attacker to execute arbitrary co…
|
CWE-78
OS Command
|
CVE-2021-24009
|
2024-11-21 14:52 |
2022-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194958
|
7.2 |
HIGH
Network
|
servmask
|
one-stop_wp_migration
|
The All-in-One WP Migration WordPress plugin before 7.41 does not validate uploaded files' extension, which allows administrators to upload PHP files on their site, even on multisite installations.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-24216
|
2024-11-21 14:52 |
2022-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194959
|
9.1 |
CRITICAL
Network
|
whatsapp
|
whatsapp whatsapp_business
|
A missing bound check in RTCP flag parsing code prior to WhatsApp for Android v2.21.23.2, WhatsApp Business for Android v2.21.23.2, WhatsApp for iOS v2.21.230.6, WhatsApp Business for iOS 2.21.230.7,…
|
CWE-125
Out-of-bounds Read
|
CVE-2021-24043
|
2024-11-21 14:52 |
2022-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194960
|
9.8 |
CRITICAL
Network
|
facebook
|
hermes
|
By passing invalid javascript code where await and yield were called upon non-async and non-generator getter/setter functions, Hermes would invoke generator functions and error out on invalid await/y…
|
CWE-843
Type Confusion
|
CVE-2021-24044
|
2024-11-21 14:52 |
2022-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|