|
196561
|
4.9 |
MEDIUM
Network
|
themeeditor
|
theme_editor
|
The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrary files on the web …
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2021-24154
|
2024-11-21 14:52 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196562
|
5.4 |
MEDIUM
Network
|
yoast
|
yoast_seo
|
A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had built-in blacklist filters which were blacklisting Parenthesis as well as several …
|
CWE-79
Cross-site Scripting
|
CVE-2021-24153
|
2024-11-21 14:52 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196563
|
6.1 |
MEDIUM
Network
|
sygnoos
|
popup_builder
|
The "All Subscribers" setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting.
|
CWE-79
Cross-site Scripting
|
CVE-2021-24152
|
2024-11-21 14:52 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196564
|
7.5 |
HIGH
Network
|
likebtn-like-button_project
|
likebtn-like-button
|
The LikeBtn WordPress Like Button Rating ? LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request Forgery (SSRF).
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-24150
|
2024-11-21 14:52 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196565
|
6.1 |
MEDIUM
Network
|
devolutions
|
devolutions_server
|
An issue was discovered in Devolutions Server before 2020.3. There is a cross-site scripting (XSS) vulnerability in entries of type Document.
|
CWE-79
Cross-site Scripting
|
CVE-2021-23925
|
2024-11-21 14:52 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196566
|
7.5 |
HIGH
Network
|
devolutions
|
devolutions_server
|
An issue was discovered in Devolutions Server before 2020.3. There is an exposure of sensitive information in diagnostic files.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2021-23924
|
2024-11-21 14:52 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196567
|
8.1 |
HIGH
Network
|
devolutions
|
devolutions_server
|
An issue was discovered in Devolutions Server before 2020.3. There is Broken Authentication with Windows domain users.
|
CWE-287
Improper Authentication
|
CVE-2021-23923
|
2024-11-21 14:52 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196568
|
5.4 |
MEDIUM
Network
|
devolutions
|
remote_desktop_manager
|
An issue was discovered in Devolutions Remote Desktop Manager before 2020.2.12. There is a cross-site scripting (XSS) vulnerability in webviews.
|
CWE-79
Cross-site Scripting
|
CVE-2021-23922
|
2024-11-21 14:52 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196569
|
9.1 |
CRITICAL
Network
|
devolutions
|
devolutions_server
|
An issue was discovered in Devolutions Server before 2020.3. There is broken access control on Password List entry elements.
|
NVD-CWE-Other
|
CVE-2021-23921
|
2024-11-21 14:52 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196570
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
Mozilla developers reported memory safety bugs present in Firefox 86. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-23988
|
2024-11-21 14:52 |
2021-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|