Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24840 1 Codesupply 1 Squaretype 2021-11-12 5.0 MEDIUM 5.3 MEDIUM
The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of its REST endpoint, without any validation. As a result, private and scheduled posts could be retrieved via a crafted request.
CVE-2021-24835 1 Wclovers 1 Frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible 2021-11-12 6.5 MEDIUM 8.8 HIGH
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible WordPress plugin before 6.5.12, when used in combination with another WCFM - WooCommerce Multivendor plugin such as WCFM - WooCommerce Multivendor Marketplace, does not escape the withdrawal_vendor parameter before using it in a SQL statement, allowing low privilege users such as Subscribers to perform SQL injection attacks
CVE-2021-24832 1 Wp Seo Redirect 301 Project 1 Wp Seo Redirect 301 2021-11-12 4.3 MEDIUM 4.3 MEDIUM
The WP SEO Redirect 301 WordPress plugin before 2.3.2 does not have CSRF in place when deleting redirects, which could allow attackers to make a logged in admin delete them via a CSRF attack
CVE-2020-23888 1 Wildbit-soft 1 Wildbit Viewer 2021-11-12 4.3 MEDIUM 5.5 MEDIUM
A User Mode Write AV in Editor!TMethodImplementationIntercept+0x53f6c3 of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted psd file.
CVE-2020-23889 1 Wildbit-soft 1 Wildbit Viewer 2021-11-12 4.3 MEDIUM 5.5 MEDIUM
A User Mode Write AV starting at Editor!TMethodImplementationIntercept+0x4189c6 of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted ico file.
CVE-2020-28137 1 Genexis 2 Platinum 4410, Platinum 4410 Firmware 2021-11-12 7.1 HIGH 6.5 MEDIUM
Cross site request forgery (CSRF) in Genexis Platinum 4410 V2-1.28, allows attackers to cause a denial of service by continuously restarting the router.
CVE-2021-41038 1 Eclipse 1 Theia 2021-11-12 4.3 MEDIUM 6.1 MEDIUM
In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().
CVE-2020-23902 1 Wildbit-soft 1 Wildbit Viewer 2021-11-12 4.3 MEDIUM 5.5 MEDIUM
A buffer overflow in WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tga file. Related to Data from Faulting Address may be used as a return value starting at Editor!TMethodImplementationIntercept+0x528a3.
CVE-2021-41427 1 Beeline 2 Smart Box, Smart Box Firmware 2021-11-12 4.3 MEDIUM 6.1 MEDIUM
Beeline Smart Box 2.0.38 is vulnerable to Cross Site Scripting (XSS) via the choose_mac parameter to setup.cgi.
CVE-2021-41426 1 Beeline 2 Smart Box, Smart Box Firmware 2021-11-12 6.8 MEDIUM 8.8 HIGH
Beeline Smart box 2.0.38 is vulnerable to Cross Site Request Forgery (CSRF) via mgt_end_user.htm.
CVE-2021-40519 1 Airangel 10 Hsmx-app-100, Hsmx-app-1000, Hsmx-app-1000 Firmware and 7 more 2021-11-12 6.4 MEDIUM 10.0 CRITICAL
Airangel HSMX Gateway devices through 5.2.04 have Hard-coded Database Credentials.
CVE-2020-23876 1 Science-miner 1 Pdf2xml 2021-11-12 5.0 MEDIUM 7.5 HIGH
pdf2xml v2.0 was discovered to contain a memory leak in the function TextPage::testLinkedText.
CVE-2020-23872 1 Science-miner 1 Pdf2xml 2021-11-12 5.0 MEDIUM 7.5 HIGH
A NULL pointer dereference in the function TextPage::restoreState of pdf2xml v2.0 allows attackers to cause a denial of service (DoS).
CVE-2020-23877 1 Science-miner 1 Pdf2xml 2021-11-12 7.5 HIGH 9.8 CRITICAL
pdf2xml v2.0 was discovered to contain a stack buffer overflow in the component getObjectStream.
CVE-2020-23878 1 Flowpaper 1 Pdf2json 2021-11-12 7.5 HIGH 9.8 CRITICAL
pdf2json v0.71 was discovered to contain a stack buffer overflow in the component XRef::fetch.
CVE-2020-23879 1 Flowpaper 1 Pdf2json 2021-11-12 5.0 MEDIUM 7.5 HIGH
pdf2json v0.71 was discovered to contain a NULL pointer dereference in the component ObjectStream::getObject.
CVE-2021-40521 1 Airangel 10 Hsmx-app-100, Hsmx-app-1000, Hsmx-app-1000 Firmware and 7 more 2021-11-12 10.0 HIGH 9.8 CRITICAL
Airangel HSMX Gateway devices through 5.2.04 allow Remote Code Execution.
CVE-2021-40517 1 Airangel 10 Hsmx-app-100, Hsmx-app-1000, Hsmx-app-1000 Firmware and 7 more 2021-11-12 3.5 LOW 5.4 MEDIUM
Airangel HSMX Gateway devices through 5.2.04 is vulnerable to stored Cross Site Scripting. XSS Payload is placed in the name column of the updates table using database access.
CVE-2021-42026 1 Mendix 1 Mendix 2021-11-12 4.0 MEDIUM 4.3 MEDIUM
A vulnerability has been identified in Mendix Applications using Mendix 8 (All versions < V8.18.13), Mendix Applications using Mendix 9 (All versions < V9.6.2). Applications built with affected versions of Mendix Studio Pro do not properly control read access for certain client actions. This could allow authenticated attackers to retrieve the changedDate attribute of arbitrary objects, even when they don't have read access to them.
CVE-2020-23884 1 Nomacs 1 Nomacs 2021-11-12 4.3 MEDIUM 5.5 MEDIUM
A buffer overflow in Nomacs v3.15.0 allows attackers to cause a denial of service (DoS) via a crafted MNG file.