|
197401
|
6.1 |
MEDIUM
Network
|
tielabs
|
jannah
|
The Jannah WordPress theme before 5.4.5 did not properly sanitize the 'query' POST parameter in its tie_ajax_search AJAX action, leading to a Reflected Cross-site Scripting (XSS) vulnerability.
|
-
|
CVE-2021-24407
|
2024-11-21 14:53 |
2021-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197402
|
6.1 |
MEDIUM
Network
|
gvectors
|
wpforo_forum
|
The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect issue after a successful login. Such issue could …
|
-
|
CVE-2021-24406
|
2024-11-21 14:53 |
2021-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197403
|
6.5 |
MEDIUM
Network
|
izsoft
|
easy_cookies_policy
|
The Easy Cookies Policy WordPress plugin through 1.6.2 is lacking any capability and CSRF check when saving its settings, allowing any authenticated users (such as subscriber) to change them. If user…
|
NVD-CWE-Other
|
CVE-2021-24405
|
2024-11-21 14:53 |
2021-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197404
|
7.2 |
HIGH
Network
|
benjaminrojas
|
wp_editor
|
The WP Editor WordPress plugin before 1.2.7 did not sanitise or validate its setting fields leading to an authenticated (admin+) blind SQL injection issue via an arbitrary parameter when making a req…
|
CWE-89
SQL Injection
|
CVE-2021-24151
|
2024-11-21 14:52 |
2024-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197405
|
6.1 |
MEDIUM
Network
|
mozilla
|
bleach
|
A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags style, title, noscript, script, textarea, noframes, iframe, or xmp in allowed ta…
|
CWE-79
Cross-site Scripting
|
CVE-2021-23980
|
2024-11-21 14:52 |
2023-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197406
|
8.8 |
HIGH
Network
|
fortinet
|
fortiwan
|
Multiple improper neutralization of special elements used in an OS command vulnerabilities (CWE-78) in the Web GUI of FortiWAN before 4.5.9 may allow an authenticated attacker to execute arbitrary co…
|
CWE-78
OS Command
|
CVE-2021-24009
|
2024-11-21 14:52 |
2022-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197407
|
7.2 |
HIGH
Network
|
servmask
|
one-stop_wp_migration
|
The All-in-One WP Migration WordPress plugin before 7.41 does not validate uploaded files' extension, which allows administrators to upload PHP files on their site, even on multisite installations.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-24216
|
2024-11-21 14:52 |
2022-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197408
|
9.1 |
CRITICAL
Network
|
whatsapp
|
whatsapp whatsapp_business
|
A missing bound check in RTCP flag parsing code prior to WhatsApp for Android v2.21.23.2, WhatsApp Business for Android v2.21.23.2, WhatsApp for iOS v2.21.230.6, WhatsApp Business for iOS 2.21.230.7,…
|
CWE-125
Out-of-bounds Read
|
CVE-2021-24043
|
2024-11-21 14:52 |
2022-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197409
|
9.8 |
CRITICAL
Network
|
facebook
|
hermes
|
By passing invalid javascript code where await and yield were called upon non-async and non-generator getter/setter functions, Hermes would invoke generator functions and error out on invalid await/y…
|
CWE-843
Type Confusion
|
CVE-2021-24044
|
2024-11-21 14:52 |
2022-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197410
|
5.3 |
MEDIUM
Network
|
ray-ban
|
stories_rw4003_65582v_48-23_firmware stories_rw4002_601\/71_50-22_firmware stories_rw4005_656013_51-20_firmware stories_rw4005_6563m3_51-20_firmware
|
A logic flaw in Ray-Ban® Stories device software allowed some parameters like video capture duration limit to be modified through the Facebook View application. This issue affected versions of device…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2021-24046
|
2024-11-21 14:52 |
2022-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|