|
196281
|
4.3 |
MEDIUM
Network
|
shantz_wordpress_qotd_project
|
shantz_wordpress_qotd
|
The Shantz WordPress QOTD WordPress plugin through 1.2.2 is lacking any CSRF check when updating its settings, allowing attackers to make logged in administrators change them to arbitrary values.
|
CWE-352
Origin Validation Error
|
CVE-2021-24380
|
2024-11-21 14:52 |
2021-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196282
|
4.9 |
MEDIUM
Network
|
10web
|
photo_gallery
|
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put i…
|
-
|
CVE-2021-24363
|
2024-11-21 14:52 |
2021-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196283
|
6.1 |
MEDIUM
Network
|
10web
|
photo_gallery
|
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded SVG files added to a gallery do not contain malicious content. As a result, user…
|
-
|
CVE-2021-24362
|
2024-11-21 14:52 |
2021-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196284
|
6.1 |
MEDIUM
Network
|
tagdiv
|
newsmag
|
The Newsmag WordPress theme before 5.0 does not sanitise the td_block_id parameter in its td_ajax_block AJAX action, leading to an unauthenticated Reflected Cross-site Scripting (XSS) vulnerability.
|
-
|
CVE-2021-24304
|
2024-11-21 14:52 |
2021-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196285
|
6.1 |
MEDIUM
Network
|
fortinet
|
fortisandbox
|
Multiple instances of improper neutralization of input during web page generation vulnerabilities in FortiSandbox before 4.0.0 may allow an unauthenticated attacker to perform an XSS attack via speci…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24014
|
2024-11-21 14:52 |
2021-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196286
|
8.8 |
HIGH
Adjacent
|
fortinet
|
fortios
|
A buffer underwrite vulnerability in the firmware verification routine of FortiOS before 7.0.1 may allow an attacker located in the adjacent network to potentially execute arbitrary code via a specif…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-24018
|
2024-11-21 14:52 |
2021-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196287
|
6.5 |
MEDIUM
Network
|
fortinet
|
fortisandbox
|
Improper limitation of a pathname to a restricted directory vulnerabilities in FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated user to obtain unauthorized access …
|
CWE-22
Path Traversal
|
CVE-2021-24010
|
2024-11-21 14:52 |
2021-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196288
|
2.7 |
LOW
Network
|
carrcommunications
|
rsvpmaker
|
The Import feature of the RSVPMaker WordPress plugin before 8.7.3 (/wp-admin/tools.php?page=rsvpmaker_export_screen) takes an URL input and calls curl on it, without first validating it to ensure it'…
|
-
|
CVE-2021-24371
|
2024-11-21 14:52 |
2021-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196289
|
9.8 |
CRITICAL
Network
|
facebook
|
hhvm folly
|
Passing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds write on the heap with the possibility of remote code execution. This issue affect…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2021-24036
|
2024-11-21 14:52 |
2021-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196290
|
4.4 |
MEDIUM
Local
|
fortinet
|
fortimanager fortianalyzer
|
A buffer overflow vulnerability in FortiAnalyzer CLI 6.4.5 and below, 6.2.7 and below, 6.0.x and FortiManager CLI 6.4.5 and below, 6.2.7 and below, 6.0.x may allow an authenticated, local attacker to…
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-24022
|
2024-11-21 14:52 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|