Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,047
Critical0
High3,047
Medium0
Reset
Showing 3041-3047 of 3047 records
Threat Entry Updated 2024-11-21

CVE-2021-24132 - Slider By 10web Plugin

The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functionalities of the plugin were vulnerable, allowing a high privileged user (Admin), or medium one such as Contributor+ (if "Role Options" is turn on for other users) to perform a SQL Injection attacks.

PLUGIN Slider By 10web

CVE-2021-24132

HIGH CVSS 8.8 2021-03-18
Threat Entry Updated 2024-11-21

CVE-2021-24123 - Arbitrary File Upload In The Powerpress Plugin

Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.8, did not verify some of the uploaded feed images (such as the ones from Podcast Artwork section), allowing high privilege accounts (admin+) being able to upload arbitrary files, such as php, leading to RCE.

PLUGIN Arbitrary File Upload In The Powerpress

CVE-2021-24123

HIGH CVSS 7.2 2021-03-18
Scroll to top