Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total664
Critical42
High116
Medium490
Reset
Showing 661-664 of 664 records
Threat Entry Updated 2024-11-21

CVE-2021-24180 - Before 2 Plugin

Unvalidated input and lack of output encoding within the Related Posts for WordPress plugin before 2.0.4 lead to a Reflected Cross-Site Scripting (XSS) vulnerability within the 'lang' GET parameter while editing a post, triggered when users with the capability of editing posts access a malicious URL.

PLUGIN Before 2

CVE-2021-24180

MEDIUM CVSS 5.4 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24170 - Before 2 Plugin

The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functionality to users with the upload_files capability. This included password hashes, hashed user activation keys, usernames, emails, and other less sensitive information.

PLUGIN Before 2

CVE-2021-24170

HIGH CVSS 7.5 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24150 - Before 2 Plugin

The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request Forgery (SSRF).

PLUGIN Before 2

CVE-2021-24150

HIGH CVSS 7.5 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24154 - Before 2 Plugin

The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrary files on the web server, such as /etc/passwd

PLUGIN Before 2

CVE-2021-24154

MEDIUM CVSS 4.9 2021-04-05
Scroll to top