Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 1241-1249 of 1249 records
Threat Entry Updated 2024-11-21

CVE-2021-24222 - Wp Curriculo Vitae Free Plugin

The WP-Curriculo Vitae Free WordPress plugin through 6.3 suffers from an arbitrary file upload issue in page where the [formCadastro] is embed. The form allows unauthenticated user to register and submit files for their profile picture as well as resume, without any file extension restriction, leading to RCE.

PLUGIN Wp Curriculo Vitae Free

CVE-2021-24222

CRITICAL CVSS 9.8 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24215 - Proper Access Control Vulnerability Was Discovered In The Controlled Admin Access Plugin

An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the website customization functionality and global CMS settings, like /wp-admin/customization.php and /wp-admin/options.php, can lead to a complete compromise of the target resource.

PLUGIN Proper Access Control Vulnerability Was Discovered In The Controlled Admin Access

CVE-2021-24215

CRITICAL CVSS 9.8 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24220 - Rise By Thrive Themes

Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, FocusBlog by Thrive Themes WordPress theme before 2.0.0, Squared by Thrive Themes WordPress theme before 2.0.0, Voice WordPress theme before 2.0.0, Performag by Thrive Themes WordPress theme before 2.0.0, Pressive by Thrive Themes WordPress theme before 2.0.0, Storied by Thrive Themes WordPress theme before 2.0.0 register a REST API endpoint to compress images using the Kraken…

THEME Rise By Thrive Themes

CVE-2021-24220

CRITICAL CVSS 9.1 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24212 - Woocommerce Help Scout Plugin

The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site which by default will end up in wp-content/uploads/hstmp.

PLUGIN Woocommerce Help Scout

CVE-2021-24212

CRITICAL CVSS 9.8 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24175 - Plus Addons For Elementor Page Builder Plugin

The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to bypass authentication, allowing unauthenticated users to log in as any user (including admin) by just providing the related username, as well as create accounts with arbitrary roles, such as admin. These issues can be exploited even if registration is disabled, and the Login widget is not active.

PLUGIN Plus Addons For Elementor Page Builder

CVE-2021-24175

CRITICAL CVSS 9.8 2021-04-05
Threat Entry Updated 2024-11-25

CVE-2021-24171 - Woocommerce Upload Files Plugin

The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions such as .php. It was possible to bypass this and upload a file with a PHP extension by embedding a "blocked" extension within another "blocked" extension in the "wcuf_file_name" parameter. It was also possible to perform a double extension attack and upload files to a different location via path traversal using the "wcuf_current_upload_session_id" parameter.

PLUGIN Woocommerce Upload Files

CVE-2021-24171

CRITICAL CVSS 9.8 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24139 - Photo Gallery Plugin

Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter.

PLUGIN Photo Gallery

CVE-2021-24139

CRITICAL CVSS 9.8 2021-03-18
Threat Entry Updated 2024-11-21

CVE-2021-3120 - Yith Woocommerce Gift Cards Plugin

An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers to achieve remote code execution on the operating system in the security context of the web server. In order to exploit this vulnerability, an attacker must be able to place a valid Gift Card product into the shopping cart. An uploaded file is placed at a predetermined path on the web server with a user-specified filename and extension. This occurs because the ywgc-upload-picture parameter can have a .php value even…

PLUGIN Yith Woocommerce Gift Cards

CVE-2021-3120

CRITICAL CVSS 9.8 2021-02-22
Scroll to top