|
196931
|
5.4 |
MEDIUM
Network
|
kubiq
|
wp_svg_images
|
The WP SVG images WordPress plugin before 3.4 did not sanitise the SVG files uploaded, which could allow low privilege users such as author+ to upload a malicious SVG and then perform XSS attacks by …
|
-
|
CVE-2021-24386
|
2024-11-21 14:52 |
2021-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196932
|
5.4 |
MEDIUM
Network
|
e4j
|
vikrentcar_car_rental_management_system
|
In the VikRentCar Car Rental Management System WordPress plugin before 1.1.7, there is a custom filed option by which we can manage all the fields that the users will have to fill in before saving th…
|
-
|
CVE-2021-24388
|
2024-11-21 14:52 |
2021-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196933
|
9.8 |
CRITICAL
Network
|
beardev
|
joomsport
|
The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unserialised user input from the shattr POST parameter…
|
-
|
CVE-2021-24384
|
2024-11-21 14:52 |
2021-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196934
|
9.8 |
CRITICAL
Network
|
stockware
|
motor
|
Lack of authentication or validation in motor_load_more, motor_gallery_load_more, motor_quick_view and motor_project_quick_view AJAX handlers of the Motor WordPress theme before 3.1.0 allows an unaut…
|
-
|
CVE-2021-24375
|
2024-11-21 14:52 |
2021-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196935
|
7.5 |
HIGH
Network
|
fortinet
|
fortiauthenticator
|
Usage of hard-coded cryptographic keys to encrypt configuration files and debug logs in FortiAuthenticator versions before 6.3.0 may allow an attacker with access to the files or the CLI configuratio…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2021-24005
|
2024-11-21 14:52 |
2021-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196936
|
8.8 |
HIGH
Network
|
mozilla
|
thunderbird firefox firefox_esr
|
When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and allowed arbitrary commands to be sent to the FTP server. Th…
|
CWE-74
Injection
|
CVE-2021-24002
|
2024-11-21 14:52 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196937
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
A compromised content process could have performed session history manipulations it should not have been able to due to testing infrastructure that was not restricted to testing-only configurations. …
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2021-24001
|
2024-11-21 14:52 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196938
|
3.1 |
LOW
Network
|
mozilla
|
firefox
|
A race condition with requestPointerLock() and setTimeout() could have resulted in a user interacting with one tab when they believed they were on a separate tab. In conjunction with certain elements…
|
CWE-362
Race Condition
|
CVE-2021-24000
|
2024-11-21 14:52 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196939
|
8.8 |
HIGH
Network
|
mozilla
|
thunderbird firefox firefox_esr
|
If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges that should not be granted to web content. This vul…
|
CWE-269 CWE-697
Improper Privilege Management Incorrect Comparison
|
CVE-2021-23999
|
2024-11-21 14:52 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196940
|
6.5 |
MEDIUM
Network
|
mozilla
|
thunderbird firefox firefox_esr
|
Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Fir…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2021-23998
|
2024-11-21 14:52 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|