Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-44114 | 1 Stock Management System Project | 1 Stock Management System | 2022-02-04 | 3.5 LOW | 4.8 MEDIUM |
Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Stock Management System in PHP/OOP 1.0, which allows remote malicious users to execute arbitrary remote code execution via create user function. | |||||
CVE-2021-46101 | 1 Gitforwindows | 1 Git | 2022-02-04 | 5.0 MEDIUM | 7.5 HIGH |
In Git for windows through 2.34.1 when using git pull to update the local warehouse, git.cmd can be run directly. | |||||
CVE-2021-24868 | 1 Bplugins | 1 Document Embedder | 2022-02-04 | 4.0 MEDIUM | 4.3 MEDIUM |
The Document Embedder WordPress plugin before 1.7.9 contains a AJAX action endpoint, which could allow any authenticated user, such as subscriber to enumerate the title of arbitrary private and draft posts. | |||||
CVE-2021-24919 | 1 Wickedplugins | 1 Wicked Folders | 2022-02-04 | 6.5 MEDIUM | 8.8 HIGH |
The Wicked Folders WordPress plugin before 2.8.10 does not sanitise and escape the folder_id parameter before using it in a SQL statement in the wicked_folders_save_sort_order AJAX action, available to any authenticated user. leading to an SQL injection | |||||
CVE-2021-24937 | 1 Asset Cleanup\ | 1 Page Speed Booster Project | 2022-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not escape the wpacu_selected_sub_tab_area parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting issue | |||||
CVE-2021-24975 | 1 Nextscripts | 1 Social Networks Auto Poster | 2022-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.24 does not sanitise and escape logged requests before outputting them in the related admin dashboard, leading to an Unauthenticated Stored Cross-Site Scripting issue | |||||
CVE-2021-24926 | 1 Domaincheckplugin | 1 Domain Check | 2022-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
The Domain Check WordPress plugin before 1.0.17 does not sanitise and escape the domain parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue | |||||
CVE-2021-24944 | 1 Cusmin | 1 Absolutely Glamorous Custom Admin | 2022-02-04 | 3.5 LOW | 4.8 MEDIUM |
The Custom Dashboard & Login Page WordPress plugin before 7.0 does not sanitise some of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |||||
CVE-2021-24983 | 1 Asset Cleanup\ | 1 Page Speed Booster Project | 2022-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not sanitise and escape POSted parameters sent to the wpassetcleanup_fetch_active_plugins_icons AJAX action (available to admin users), leading to a Reflected Cross-Site Scripting issue | |||||
CVE-2021-24934 | 1 Yellowpencil | 1 Visual Css Style Editor | 2022-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
The Visual CSS Style Editor WordPress plugin before 7.5.4 does not sanitise and escape the wyp_page_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue | |||||
CVE-2021-40042 | 1 Huawei | 8 Cloudengine 12800, Cloudengine 12800 Firmware, Cloudengine 5800 and 5 more | 2022-02-04 | 4.0 MEDIUM | 6.5 MEDIUM |
There is a release of invalid pointer vulnerability in some Huawei products, successful exploit may cause the process and service abnormal. Affected product versions include: CloudEngine 12800 V200R019C10SPC800, V200R019C10SPC900; CloudEngine 5800 V200R019C10SPC800, V200R020C00SPC600; CloudEngine 6800 versions V200R019C10SPC800, V200R019C10SPC900, V200R020C00SPC600, V300R020C00SPC200; CloudEngine 7800 V200R019C10SPC800. | |||||
CVE-2021-43510 | 1 Simple Client Management System Project | 1 Simple Client Management System | 2022-02-04 | 7.5 HIGH | 9.8 CRITICAL |
SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php. | |||||
CVE-2021-43509 | 1 Simple Client Management System Project | 1 Simple Client Management System | 2022-02-04 | 7.5 HIGH | 9.8 CRITICAL |
SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the id parameter in view-service.php. | |||||
CVE-2021-25072 | 1 Nextscripts | 1 Social Networks Auto Poster | 2022-02-04 | 4.3 MEDIUM | 6.5 MEDIUM |
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.25 does not have CSRF check in place when deleting items, allowing attacker to make a logged in admin delete arbitrary posts via a CSRF attack | |||||
CVE-2021-25089 | 1 Updraftplus | 1 Updraftplus | 2022-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.69 does not sanitise and escape the updraft_restore parameter before outputting it back in the Restore page, leading to a Reflected Cross-Site Scripting | |||||
CVE-2021-25085 | 1 Pluginus | 1 Woocommerce Products Filter | 2022-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
The WOOF WordPress plugin before 1.2.6.3 does not sanitise and escape the woof_redraw_elements before outputing back in an admin page, leading to a Reflected Cross-Site Scripting | |||||
CVE-2021-25091 | 1 Link Library Project | 1 Link Library | 2022-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting | |||||
CVE-2021-25092 | 1 Link Library Project | 1 Link Library | 2022-02-04 | 4.3 MEDIUM | 6.5 MEDIUM |
The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library settings, allowing attackers to make a logged in admin reset arbitrary settings via a CSRF attack | |||||
CVE-2021-25093 | 1 Link Library Project | 1 Link Library | 2022-02-04 | 5.0 MEDIUM | 7.5 HIGH |
The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauthenticated users to delete arbitrary links via a crafted request | |||||
CVE-2022-22919 | 1 Adenza | 1 Axiomsl Controllerview | 2022-02-04 | 5.8 MEDIUM | 6.1 MEDIUM |
Adenza AxiomSL ControllerView through 10.8.1 allows redirection for SSO login URLs. |