Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-24188 | 1 Wp-buy | 1 Wp Content Copy Protection \& No Right Click | 2022-08-30 | 6.5 MEDIUM | 8.8 HIGH |
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Content Copy Protection & No Right Click WordPress plugin before 3.1.5, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE. | |||||
CVE-2021-24164 | 1 Ninjaforms | 1 Ninja Forms | 2022-08-30 | 4.0 MEDIUM | 4.3 MEDIUM |
In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to trigger the action, wp_ajax_nf_oauth, and retrieve the connection url needed to establish a connection. They could also retrieve the client_id for an already established OAuth connection. | |||||
CVE-2021-24158 | 1 Themeisle | 1 Orbit Fox | 2022-08-30 | 3.5 LOW | 6.5 MEDIUM |
Orbit Fox by ThemeIsle has a feature to add a registration form to both the Elementor and Beaver Builder page builders functionality. As part of the registration form, administrators can choose which role to set as the default for users upon registration. This field is hidden from view for lower-level users, however, they can still supply the user_role parameter to update the default role for registration. | |||||
CVE-2021-22957 | 1 Ui | 1 Unifi Protect | 2022-08-30 | 6.8 MEDIUM | 8.8 HIGH |
A Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allows a malicious actor who has convinced a privileged user to access a URL with malicious code to take over said user’s account.This vulnerability is fixed in UniFi Protect application Version 1.20.0 and later. | |||||
CVE-2021-23019 | 1 F5 | 1 Nginx Controller | 2022-08-30 | 6.9 MEDIUM | 7.8 HIGH |
The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt file that is included in the NGINX support package. | |||||
CVE-2021-24146 | 1 Webnus | 1 Modern Events Calendar Lite | 2022-08-30 | 5.0 MEDIUM | 7.5 HIGH |
Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example. | |||||
CVE-2020-29450 | 1 Atlassian | 2 Confluence Data Center, Confluence Server | 2022-08-30 | 4.0 MEDIUM | 6.5 MEDIUM |
Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the avatar upload feature. The affected versions are before version 7.2.0. | |||||
CVE-2021-22952 | 1 Ui | 1 Unifi Talk | 2022-08-30 | 6.5 MEDIUM | 8.8 HIGH |
A vulnerability found in UniFi Talk application V1.12.3 and earlier permits a malicious actor who has already gained access to a network to subsequently control Talk device(s) assigned to said network if they are not yet adopted. This vulnerability is fixed in UniFi Talk application V1.12.5 and later. | |||||
CVE-2021-22941 | 1 Citrix | 1 Sharefile Storagezones Controller | 2022-08-30 | 10.0 HIGH | 9.8 CRITICAL |
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller. | |||||
CVE-2021-22911 | 1 Rocket.chat | 1 Rocket.chat | 2022-08-30 | 7.5 HIGH | 9.8 CRITICAL |
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE. | |||||
CVE-2021-24163 | 1 Ninjaforms | 1 Ninja Forms | 2022-08-30 | 6.5 MEDIUM | 8.8 HIGH |
The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it have any nonce protection, therefore making it possible for low-level users, such as subscribers, to install and activate the SendWP Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 and retrieve the client_secret key needed to establish the SendWP connection while also installing the SendWP plugin. | |||||
CVE-2022-36749 | 2022-08-30 | N/A | N/A | ||
RPi-Jukebox-RFID v2.3.0 was discovered to contain a command injection vulnerability via the component /htdocs/utils/Files.php. This vulnerability is exploited via a crafted payload injected into the file name of an uploaded file. | |||||
CVE-2022-27560 | 2022-08-30 | N/A | N/A | ||
HCL VersionVault Express exposes administrator credentials. | |||||
CVE-2022-31232 | 2022-08-30 | N/A | N/A | ||
SmartFabric storage software version 1.0.0 contains a Command-Injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to gain access and perform actions on the affected system. | |||||
CVE-2021-24027 | 1 Whatsapp | 2 Whatsapp, Whatsapp Business | 2022-08-30 | 5.0 MEDIUM | 7.5 HIGH |
A cache configuration issue prior to WhatsApp for Android v2.21.4.18 and WhatsApp Business for Android v2.21.4.18 may have allowed a third party with access to the device’s external storage to read cached TLS material. | |||||
CVE-2021-22917 | 1 Brave | 1 Browser | 2022-08-30 | 4.3 MEDIUM | 6.5 MEDIUM |
Brave Browser Desktop between versions 1.17 and 1.20 is vulnerable to information disclosure by way of DNS requests in Tor windows not flowing through Tor if adblocking was enabled. | |||||
CVE-2021-22916 | 1 Brave | 1 Brave | 2022-08-30 | 4.3 MEDIUM | 5.9 MEDIUM |
In Brave Desktop between versions 1.17 and 1.26.60, when adblocking is enabled and a proxy browser extension is installed, the CNAME adblocking feature issues DNS requests that used the system DNS settings instead of the extension's proxy settings, resulting in possible information disclosure. | |||||
CVE-2021-22882 | 1 Ui | 4 Unifi Cloud Key Plus, Unifi Dream Machine Pro, Unifi Network Video Recorder and 1 more | 2022-08-30 | 5.0 MEDIUM | 7.5 HIGH |
UniFi Protect before v1.17.1 allows an attacker to use spoofed cameras to perform a denial-of-service attack that may cause the UniFi Protect controller to crash. | |||||
CVE-2021-22907 | 1 Citrix | 1 Workspace | 2022-08-30 | 7.2 HIGH | 7.8 HIGH |
An improper access control vulnerability exists in Citrix Workspace App for Windows potentially allows privilege escalation in CR versions prior to 2105 and 1912 LTSR prior to CU4. | |||||
CVE-2021-22900 | 1 Pulsesecure | 1 Pulse Connect Secure | 2022-08-30 | 6.5 MEDIUM | 7.2 HIGH |
A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface. |