Latest CVE Feed
-
8.5
HIGHCVE-2021-39147
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is a... Read more
- Published: Aug. 23, 2021
- Modified: May. 23, 2025
-
7.5
HIGHCVE-2022-40151
Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a deni... Read more
- Published: Sep. 16, 2022
- Modified: May. 23, 2025
-
7.5
HIGHCVE-2022-40152
Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This e... Read more
- Published: Sep. 16, 2022
- Modified: May. 23, 2025
-
8.2
HIGHCVE-2022-41966
XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate the application with a stack overflow error, resulting in a denial of service only via manipulation the processed input stream. The at... Read more
- Published: Dec. 28, 2022
- Modified: May. 23, 2025
-
6.5
MEDIUMCVE-2021-39140
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload result... Read more
- Published: Aug. 23, 2021
- Modified: May. 23, 2025
-
8.5
HIGHCVE-2021-39153
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream, if using the... Read more
Affected Products : fedora debian_linux snapmanager communications_cloud_native_core_policy webcenter_portal xstream communications_unified_inventory_management utilities_framework communications_cloud_native_core_automated_test_suite communications_billing_and_revenue_management_elastic_charging_engine +4 more products- Published: Aug. 23, 2021
- Modified: May. 23, 2025
-
8.5
HIGHCVE-2021-39149
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is a... Read more
- Published: Aug. 23, 2021
- Modified: May. 23, 2025
-
8.5
HIGHCVE-2021-39151
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is a... Read more
- Published: Aug. 23, 2021
- Modified: May. 23, 2025
-
8.5
HIGHCVE-2021-39144
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is a... Read more
- Actively Exploited
- Published: Aug. 23, 2021
- Modified: May. 23, 2025
-
4.7
MEDIUMCVE-2025-0522
The LikeBot WordPress plugin through 0.85 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.... Read more
Affected Products : likebot- Published: Feb. 06, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.5
HIGHCVE-2021-39146
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is a... Read more
- Published: Aug. 23, 2021
- Modified: May. 23, 2025
-
8.5
HIGHCVE-2021-39148
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is a... Read more
- Published: Aug. 23, 2021
- Modified: May. 23, 2025
-
8.5
HIGHCVE-2021-39150
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input st... Read more
- Published: Aug. 23, 2021
- Modified: May. 23, 2025
-
8.5
HIGHCVE-2021-39152
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input st... Read more
- Published: Aug. 23, 2021
- Modified: May. 23, 2025
-
8.5
HIGHCVE-2021-39154
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is a... Read more
- Published: Aug. 23, 2021
- Modified: May. 23, 2025
-
8.8
HIGHCVE-2022-30550
An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can be applied to passdb definitions. ... Read more
- Published: Jul. 17, 2022
- Modified: May. 23, 2025
-
7.1
HIGHCVE-2024-13352
The Legull WordPress plugin through 1.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more
Affected Products : legull- Published: Feb. 07, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-13492
The Guten Free Options WordPress plugin through 0.9.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more
Affected Products : guten_free_options- Published: Feb. 07, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2024-55416
DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticated user to click on a link, arbitrary Javascript can be executed.... Read more
Affected Products : voyager- Published: Jan. 30, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2024-55417
DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /admin/media/upload. An authenticated user can upload a web shell causing arbitrary code execution on the server.... Read more
Affected Products : voyager- Published: Jan. 30, 2025
- Modified: May. 23, 2025
- Vuln Type: Authentication