|
197241
|
9.8 |
CRITICAL
Network
|
facebook
|
parlai
|
Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input, resulting in remote code execution or similar ris…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-24040
|
2024-11-21 14:52 |
2021-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197242
|
8.8 |
HIGH
Network
|
fortinet
|
fortimanager
|
An improper access control vulnerability in FortiManager versions 6.4.0 to 6.4.3 may allow an authenticated attacker with a restricted user profile to access the SD-WAN Orchestrator panel via directl…
|
NVD-CWE-Other
|
CVE-2021-24006
|
2024-11-21 14:52 |
2021-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197243
|
7.2 |
HIGH
Network
|
geekwebsolution
|
embed_youtube_video
|
The editid GET parameter of the Embed Youtube Video WordPress plugin through 1.0 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
|
CWE-89
SQL Injection
|
CVE-2021-24395
|
2024-11-21 14:52 |
2021-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197244
|
7.2 |
HIGH
Network
|
easy_testimonial_manager_project
|
easy_testimonial_manager
|
An id GET parameter of the Easy Testimonial Manager WordPress plugin through 1.2.0 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection
|
CWE-89
SQL Injection
|
CVE-2021-24394
|
2024-11-21 14:52 |
2021-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197245
|
7.2 |
HIGH
Network
|
comment_highlighter_project
|
comment_highlighter
|
A c GET parameter of the Comment Highlighter WordPress plugin through 0.13 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
|
CWE-89
SQL Injection
|
CVE-2021-24393
|
2024-11-21 14:52 |
2021-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197246
|
7.2 |
HIGH
Network
|
swiftcrm
|
club-management-software
|
An id GET parameter of the WordPress Membership SwiftCloud.io WordPress plugin through 1.0 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injectio…
|
CWE-89
SQL Injection
|
CVE-2021-24392
|
2024-11-21 14:52 |
2021-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197247
|
8.8 |
HIGH
Network
|
cashtomer_project
|
cashtomer
|
An editid GET parameter of the Cashtomer WordPress plugin through 1.0.0 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
|
CWE-89
SQL Injection
|
CVE-2021-24391
|
2024-11-21 14:52 |
2021-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197248
|
7.2 |
HIGH
Network
|
alipay_project
|
alipay
|
A proid GET parameter of the WordPress???Alipay|???Tenpay|??PayPal???? WordPress plugin through 3.7.2 is not sanitised, properly escaped or validated before inserting to a SQL statement not delimited…
|
-
|
CVE-2021-24390
|
2024-11-21 14:52 |
2021-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197249
|
8.8 |
HIGH
Network
|
jiangqie
|
official_website_mini_program
|
The JiangQie Official Website Mini Program WordPress plugin before 1.1.1 does not escape or validate the id GET parameter before using it in SQL statements, leading to SQL injection issues
|
CWE-89
SQL Injection
|
CVE-2021-24303
|
2024-11-21 14:52 |
2021-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197250
|
7.8 |
HIGH
Local
|
oculus
|
desktop
|
Due to a bug with management of handles in OVRServiceLauncher.exe, an attacker could expose a privileged process handle to an unprivileged process, leading to local privilege escalation. This issue a…
|
CWE-269
Improper Privilege Management
|
CVE-2021-24038
|
2024-11-21 14:52 |
2021-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|