LiveActive security incident?Get immediate response
CVE archive

June 2021

Browse CVE records published in June 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1730 matching CVEs · Page 28 of 35.

Unknown · CVSS Not scored

CVE-2021-24334: Instant Images WordPress Plugin < 4.4.0.1 - Authenticated Stored XSS & XFS

The Instant Images – One Click Unsplash Uploads WordPress plugin before 4.4.0.1 did not properly validate and sanitise its unsplash_download_w and unsplash_download_h parameter settings (/wp-admin/upload.php?page=instant-images), only validating them client side before saving them, leading to a Stored Cross-Site Scripting issue.

Published Jun 1, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-24337: Video Embed <= 1.0 - Authenticated (subscriber+) SQL Injection

The id GET parameter of one of the Video Embed WordPress plugin through 1.0's page (available via forced browsing) is not sanitised, validated or escaped before being used in a SQL statement, allowing low privilege users, such as subscribers, to perform SQL injection.

Published Jun 7, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-24340: WP Statistics < 13.0.8 - Unauthenticated SQL Injection

The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been accessible to administrator only, was also available to any visitor, including unauthenticated ones.

Published Jun 7, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-24331: Smooth Scroll Page Up/Down Buttons < 1.4 - Authenticated Stored XSS

The Smooth Scroll Page Up/Down Buttons WordPress plugin before 1.4 did not properly sanitise and validate its settings, such as psb_distance, psb_buttonsize, psb_speed, only validating them client side. This could allow high privilege users (such as admin) to set XSS payloads in them

Published Jun 1, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-24321: Bello < 1.6.0 - Unauthenticated Blind SQL Injection

The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, bt_bb_listing_field_my_lng, listing_list_view and bt_bb_listing_field_my_lat parameters before using them in a SQL statement, leading to SQL Injection issues

Published Jun 1, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-24310: Photo Gallery < 1.5.67 - Authenticated Stored Cross-Site Scripting via Gallery Title

The Photo Gallery by 10Web - Mobile-Friendly Image Gallery WordPress plugin before 1.5.67 did not properly sanitise the gallery title, allowing high privilege users to create one with XSS payload in it, which will be triggered when another user will view the gallery list or the affected gallery in the admin dashboard. This is due to an incomplete fix of CVE-2019-16117

Published Jun 1, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-24330: Funnel Builder by CartFlows < 1.6.13 - Authenticated Stored XSS via FB Pixel ID and Google Analytics ID

The Funnel Builder by CartFlows – Create High Converting Sales Funnels For WordPress plugin before 1.6.13 did not sanitise its facebook_pixel_id and google_analytics_id settings, allowing high privilege users to set XSS payload in them, which will either be executed on pages generated by the plugin, or the whole website depending on the settings used.

Published Jun 1, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-24037: A use after free in hermes, while emitting certain error messages, prior to commit d86e185e485b6330216dee8e...

A use after free in hermes, while emitting certain error messages, prior to commit d86e185e485b6330216dee8e854455c694e3a36e allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.

Published Jun 15, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-24000: A race condition with requestPointerLock() and setTimeout() could have resulted in a user interacting with...

A race condition with requestPointerLock() and setTimeout() could have resulted in a user interacting with one tab when they believed they were on a separate tab. In conjunction with certain elements (such as &lt;input type="file"&gt;) this could have led to an attack where a user was confused about the origin of the webpage and potentially disclosed information they did not intend to. This vulnerability affects Firefox < 88.

Published Jun 24, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-23992: Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature.

Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key, by either replacing the original user ID, or by adding another user ID. If Thunderbird imports and accepts the crafted key, the Thunderbird user may falsely conclude that the false user ID belongs to the correspondent. This vulnerability affects Thunderbird < 78.9.1.

Published Jun 24, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-23991: If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity peri...

If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet been imported, an attacker may send an email containing a crafted version of Alice's key with an invalid subkey, Thunderbird might subsequently attempt to use the invalid subkey, and will fail to send encrypted email to Alice. This vulnerability affects Thunderbird < 78.9.1.

Published Jun 24, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-23993: An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent.

An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key with a subkey that has an invalid self signature, and the Thunderbird user imports the crafted key, then Thunderbird may try to use the invalid subkey, but the RNP library rejects it from being used, causing encryption to fail. This vulnerability affects Thunderbird < 78.9.1.

Published Jun 24, 2021 · Updated Aug 3, 2024

Low · CVSS 3.2

CVE-2021-23896: Cleartext Transmission of Sensitive Information in McAfee DBSec

Cleartext Transmission of Sensitive Information vulnerability in the administrator interface of McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to view the unencrypted password of the McAfee Insights Server used to pass data to the Insights Server. This user is restricted to only have access to DBSec data in the Insights Server.

Published Jun 2, 2021 · Updated Aug 3, 2024

Critical · CVSS 9

CVE-2021-23895: Authorized deserialization of untrusted data in McAfee DBSec

Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authenticated attacker to create a reverse shell with administrator privileges on the DBSec server via carefully constructed Java serialized object sent to the DBSec server.

Published Jun 2, 2021 · Updated Aug 3, 2024

Critical · CVSS 9.6

CVE-2021-23894: Unauthorized deserialization of untrusted data in McAfee DBSec

Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote unauthenticated attacker to create a reverse shell with administrator privileges on the DBSec server via carefully constructed Java serialized object sent to the DBSec server.

Published Jun 2, 2021 · Updated Aug 3, 2024

High · CVSS 8.1

CVE-2021-23205: Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator to alter...

Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator to alter the configuration of Controllers and other hardware items beyond their privilege. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 versions prior to 8.30.1359 (MR3); 8.20 versions prior to 8.20.1259 (MR5); version 8.10 and prior versions.

Published Jun 11, 2021 · Updated Aug 3, 2024

Critical · CVSS 9.9

CVE-2021-23230: A SQL Injection vulnerability in the OPCUA interface of Gallagher Command Centre allows a remote unprivileg...

A SQL Injection vulnerability in the OPCUA interface of Gallagher Command Centre allows a remote unprivileged Command Centre Operator to modify Command Centre databases undetected. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 versions prior to 8.30.1359 (MR3); 8.20 versions prior to 8.20.1259 (MR5); 8.10 versions prior to 8.10.1284 (MR7); version 8.00 and prior versions.

Published Jun 11, 2021 · Updated Aug 3, 2024

Medium · CVSS 6.5

CVE-2021-23136: Improper Authorization vulnerability in Gallagher Command Centre Server allows macro overrides to be perfor...

Improper Authorization vulnerability in Gallagher Command Centre Server allows macro overrides to be performed by an unprivileged Command Centre Operator. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 versions prior to 8.30.1359 (MR3); 8.20 versions prior to 8.20.1259 (MR5); version 8.10 and prior versions.

Published Jun 11, 2021 · Updated Aug 3, 2024

Critical · CVSS 9.9

CVE-2021-23140: Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be mo...

Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Command Centre Operator. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 versions prior to 8.30.1359 (MR3); 8.20 versions prior to 8.20.1259 (MR5); version 8.10 and prior versions.

Published Jun 11, 2021 · Updated Aug 3, 2024