Unknown · CVSS Not scored
A cross-site request forgery (CSRF) vulnerability in the Cron job tab in EasyCorp ZenTao 12.5.3 allows attackers to update the fields of a Cron job.
Published Aug 31, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The SAS Admin portal of Mitel MiCollab before 9.2 FP2 could allow an unauthenticated attacker to access (view and modify) user data by injecting arbitrary directory paths due to improper URL validation, aka Directory Traversal.
Published Aug 13, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The Join Meeting page of Mitel MiCollab Web Client before 9.2 FP2 could allow an attacker to access (view and modify) user data by executing arbitrary code due to insufficient input validation, aka Cross-Site Scripting (XSS).
Published Aug 13, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
PuppetDB logging included potentially sensitive system information.
Published Aug 30, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
NetApp Cloud Manager versions prior to 3.9.9 log sensitive information that is available only to authenticated users. Customers with auto-upgrade enabled should already be on a fixed version while customers using on-prem connectors with auto-upgrade disabled are advised to upgrade to a fixed version.
Published Aug 6, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
NetApp Cloud Manager versions prior to 3.9.9 log sensitive information when an Active Directory connection fails. The logged information is available only to authenticated users. Customers with auto-upgrade enabled should already be on a fixed version while customers using on-prem connectors with auto-upgrade disabled are advised to upgrade to a fixed version.
Published Aug 6, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed by an internal certificate authority to not be properly validated. This issue only affects clients that are configured to utilize Tenable.sc as the vulnerability data source.
Published Aug 30, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export.
Published Aug 30, 2021 · Updated Aug 3, 2024
High · CVSS 8.1
This vulnerability is caused by the lack of validation of input values for specific functions if WISA Smart Wing CMS. Remote attackers can use this vulnerability to leak all files in the server without logging in system.
Published Aug 17, 2022 · Updated Aug 3, 2024
High · CVSS 7.5
An improper input validation vulnerability in the service of ezPDFReader allows attacker to execute arbitrary command. This issue occurred when the ezPDF launcher received and executed crafted input values through JSON-RPC communication.
Published Aug 5, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A potential security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software. The vulnerability could be remotely exploited to disclose sensitive information. HPE has made software updates available to resolve the vulnerability in the HPE Edgeline Infrastructure Manager (EIM).
Published Aug 5, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An attacker having access to ZooKeeper can run arbitrary commands as YARN user by exploiting this. Users should upgrade to Apache Hadoop 2.10.2, 3.2.4, 3.3.4 or later (containing YARN-11126) if ZKConfigurationStore is used.
Published Aug 25, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A vulnerability has been identified in Automation License Manager 5 (All versions), Automation License Manager 6 (All versions < V6.0 SP9 Update 2). Sending specially crafted packets to port 4410/tcp of an affected system could lead to extensive memory being consumed and as such could cause a denial-of-service preventing legitimate users from using the system.
Published Aug 10, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause local file inclusion in webview.
Published Aug 5, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Improper access control vulnerability in Smart Touch Call prior to version 1.0.0.5 allows arbitrary webpage loading in webview.
Published Aug 5, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An IV reuse vulnerability in keymaster prior to SMR AUG-2021 Release 1 allows decryption of custom keyblob with privileged process.
Published Aug 5, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Unprotected component vulnerability in Samsung Internet prior to version 14.2 allows untrusted application to access internal files in Samsung Internet.
Published Aug 5, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause arbitrary webpage loading in webview.
Published Aug 5, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A use after free vulnerability in conn_gadget driver prior to SMR AUG-2021 Release 1 allows malicious action by an attacker.
Published Aug 5, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Local privilege vulnerability in Yandex Browser for Windows prior to 21.9.0.390 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating files in directory with insecure permissions during Yandex Browser update process.
Published Aug 17, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the tk0 parameter from the tp_translation AJAX action, leading to Stored Cross-Site Scripting, which will trigger in the admin dashboard of the plugin. The minimum role needed to perform such attack depends on the plugin "Who can translate ?" setting.
Published Aug 22, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the a parameter via an AJAX action (available to both unauthenticated and authenticated users when the curl library is installed) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue
Published Aug 22, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The Transposh WordPress Translation WordPress plugin before 1.0.8 does not have CSRF check in its tp_translation AJAX action, which could allow attackers to make authorised users add a translation. Given the lack of sanitisation in the tk0 parameter, this could lead to a Stored Cross-Site Scripting issue which will be executed in the context of a logged in admin
Published Aug 22, 2022 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The WP Video Lightbox WordPress plugin before 1.9.3 does not escape the attributes of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks
Published Aug 30, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A stored cross-site scripting vulnerability has been discovered in : Simply Gallery Blocks with Lightbox (Version – 2.2.0 & below). The vulnerability exists in the Lightbox functionality where a user with low privileges is allowed to execute arbitrary script code within the context of the application. This vulnerability is due to insufficient validation of image parameters in meta data.
Published Aug 30, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The Erident Custom Login and Dashboard WordPress plugin before 3.5.9 did not properly sanitise its settings, allowing high privilege users to use XSS payloads in them (even when the unfileted_html is disabled)
Published Aug 23, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and successimportcount GET parameters before outputting them back in an admin page, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator
Published Aug 2, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The Simple Banner WordPress plugin before 2.10.4 does not sanitise and escape one of its settings, allowing high privilege users such as admin to use Cross-Site Scripting payload even when the unfiltered_html capability is disallowed.
Published Aug 23, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set themselves as admin via their profile page
Published Aug 23, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The Side Menu Lite WordPress plugin before 2.2.6 does not sanitise user input from the List page in the admin dashboard before using it in SQL statement, leading to a SQL Injection issue
Published Aug 30, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings, allowing attacker to make a logged in user with the manage_options change them. Furthermore, the settings are not escaped when output in attributes, leading to a Stored Cross-Site Scripting issue.
Published Aug 23, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The PhoneTrack Meu Site Manager WordPress plugin through 0.1 does not sanitise or escape its "php_id" setting before outputting it back in an attribute in the page, leading to a stored Cross-Site Scripting issue.
Published Aug 16, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The WPFront Scroll Top WordPress plugin before 2.0.6.07225 does not sanitise or escape its Image ALT setting before outputting it attributes, leading to an Authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed.
Published Aug 23, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The bt_bb_get_grid AJAX action of the Bold Page Builder WordPress plugin before 3.1.6 passes user input into the unserialize() function without any validation or sanitisation, which could lead to a PHP Object Injection. Even though the plugin did not contain a suitable gadget to fully exploit the issue, other installed plugins on the blog could allow such issue to be exploited and lead to RCE in some cases.
Published Aug 30, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The Simple Events Calendar WordPress plugin through 1.4.0 does not sanitise, validate or escape the event_id POST parameter before using it in a SQL statement when deleting events, leading to an authenticated SQL injection issue
Published Aug 23, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both unauthenticated and authenticated user) before using them in SQL statement, leading to an SQL Injection issues
Published Aug 9, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The WP SMS WordPress plugin before 5.4.13 does not sanitise the "wp_group_name" parameter before outputting it back in the "Groups" page, leading to an Authenticated Stored Cross-Site Scripting issue
Published Aug 23, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The Business Hours Indicator WordPress plugin before 2.3.5 does not sanitise or escape its 'Now closed message" setting when outputting it in the backend and frontend, leading to an Authenticated Stored Cross-Site Scripting issue
Published Aug 30, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin does not have CSRF check in place when saving its settings, allowing the issue to be exploited via a CSRF attack.
Published Aug 30, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The HD Quiz WordPress plugin before 1.8.4 does not escape some of its Answers before outputting them in attribute when generating the Quiz, which could lead to Stored Cross-Site Scripting issues
Published Aug 23, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The daac_delete_booking_callback function, hooked to the daac_delete_booking AJAX action, takes the id POST parameter which is passed into the SQL statement without proper sanitisation, validation or escaping, leading to a SQL Injection issue. Furthermore, the ajax action is lacking any CSRF and capability check, making it available to any authenticated user.
Published Aug 23, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The pspin_duplicate_post_save_as_new_post function of the Project Status WordPress plugin through 1.6 does not sanitise, validate or escape the post GET parameter passed to it before outputting it in an error message when the related post does not exist, leading to a reflected XSS issue
Published Aug 23, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The Light Messages WordPress plugin through 1.0 is lacking CSRF check when updating it's settings, and is not sanitising its Message Content in them (even with the unfiltered_html disallowed). As a result, an attacker could make a logged in admin update the settings to arbitrary values, and set a Cross-Site Scripting payload in the Message Content. Depending on the options set, the XSS payload can be triggered either in the backend only (in the plugin's settings), or both frontend and backend.
Published Aug 16, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.2 was affected by an IDOR issue, allowing students to see other student answers and grades
Published Aug 23, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The Mimetic Books WordPress plugin through 0.2.13 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS) in the "Default Publisher ID" field on the plugin's settings page.
Published Aug 16, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The Sitewide Notice WP WordPress plugin before 2.3 does not sanitise some of its settings before outputting them in frontend pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Published Aug 30, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The KN Fix Your Title WordPress plugin through 1.0.1 was vulnerable to Authenticated Stored XSS in the separator field.
Published Aug 23, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The update functionality in the rslider_page uses an rs_id POST parameter which is not validated, sanitised or escaped before being inserted in sql query, therefore leading to SQL injection for users having Administrator role.
Published Aug 23, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The Paytm – Donation Plugin WordPress plugin through 1.3.2 does not sanitise, validate or escape the id GET parameter before using it in a SQL statement when deleting donations, leading to an authenticated SQL injection issue
Published Aug 23, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The Timeline Calendar WordPress plugin through 1.2 does not sanitise, validate or escape the edit GET parameter before using it in a SQL statement when editing events, leading to an authenticated SQL injection issue. Other SQL Injections are also present in the plugin
Published Aug 23, 2021 · Updated Aug 3, 2024