Latest CVE Feed
-
9.8
CRITICALCVE-2021-21350
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the processed input stream. No user is affect... Read more
Affected Products : fedora debian_linux weblogic_server communications_policy_management oncommand_insight jmeter retail_xstore_point_of_service webcenter_portal xstream activemq +7 more products- Published: Mar. 23, 2021
- Modified: May. 23, 2025
-
8.6
HIGHCVE-2021-21349
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating... Read more
Affected Products : fedora debian_linux communications_policy_management oncommand_insight jmeter retail_xstore_point_of_service webcenter_portal xstream activemq banking_platform +8 more products- Published: Mar. 23, 2021
- Modified: May. 23, 2025
-
7.8
HIGHCVE-2021-21348
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return. No user is affected... Read more
Affected Products : fedora debian_linux communications_policy_management oncommand_insight jmeter retail_xstore_point_of_service webcenter_portal xstream activemq banking_platform +7 more products- Published: Mar. 23, 2021
- Modified: May. 23, 2025
-
9.8
CRITICALCVE-2021-21347
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed inp... Read more
Affected Products : fedora debian_linux weblogic_server communications_policy_management oncommand_insight jmeter retail_xstore_point_of_service webcenter_portal xstream activemq +7 more products- Published: Mar. 23, 2021
- Modified: May. 23, 2025
-
7.2
HIGHCVE-2025-0924
The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 5.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenti... Read more
Affected Products : wp_activity_log- Published: Feb. 17, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2021-21346
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed inp... Read more
Affected Products : fedora debian_linux communications_policy_management oncommand_insight jmeter retail_xstore_point_of_service webcenter_portal xstream activemq banking_platform +7 more products- Published: Mar. 23, 2021
- Modified: May. 23, 2025
-
9.9
CRITICALCVE-2021-21345
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed... Read more
Affected Products : fedora debian_linux peoplesoft_enterprise_peopletools communications_policy_management oncommand_insight jmeter retail_xstore_point_of_service webcenter_portal xstream activemq +7 more products- Published: Mar. 23, 2021
- Modified: May. 23, 2025
-
9.8
CRITICALCVE-2021-21344
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed inp... Read more
Affected Products : fedora debian_linux communications_policy_management oncommand_insight jmeter retail_xstore_point_of_service webcenter_portal xstream activemq banking_platform +7 more products- Published: Mar. 23, 2021
- Modified: May. 23, 2025
-
7.1
HIGHCVE-2024-13626
The VR-Frases (collect & share quotes) WordPress plugin through 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admi... Read more
Affected Products : vr-frases- Published: Feb. 17, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2021-21343
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream c... Read more
Affected Products : fedora debian_linux communications_policy_management oncommand_insight jmeter retail_xstore_point_of_service webcenter_portal xstream activemq banking_platform +6 more products- Published: Mar. 23, 2021
- Modified: May. 23, 2025
-
9.1
CRITICALCVE-2021-21342
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream c... Read more
Affected Products : fedora debian_linux communications_policy_management oncommand_insight jmeter retail_xstore_point_of_service webcenter_portal xstream activemq banking_platform +6 more products- Published: Mar. 23, 2021
- Modified: May. 23, 2025
-
7.5
HIGHCVE-2021-21341
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of ... Read more
Affected Products : fedora debian_linux oncommand_insight jmeter retail_xstore_point_of_service webcenter_portal xstream activemq banking_platform communications_unified_inventory_management +4 more products- Published: Mar. 23, 2021
- Modified: May. 23, 2025
-
4.7
MEDIUMCVE-2024-13627
The OWL Carousel Slider WordPress plugin through 2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more
Affected Products : owl_carousel_slider- Published: Feb. 17, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Scripting
-
9.1
CRITICALCVE-2021-21351
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input str... Read more
Affected Products : fedora debian_linux communications_policy_management oncommand_insight jmeter retail_xstore_point_of_service webcenter_portal xstream activemq banking_platform +7 more products- Published: Mar. 23, 2021
- Modified: May. 23, 2025
-
6.5
MEDIUMCVE-2024-13356
The DSGVO All in one for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6. This is due to missing or incorrect nonce validation in the user_remove_form.php file. This makes it possible for unaut... Read more
Affected Products : dsgvo_all_in_one_for_wp- Published: Feb. 04, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.4
MEDIUMCVE-2024-13733
The SKT Blocks – Gutenberg based Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's skt-blocks/post-carousel block in all versions up to, and including, 1.7 due to insufficient input sanitization and output esc... Read more
Affected Products : skt_blocks- Published: Feb. 04, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-24804
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentation for bundle ID's, it must contain only alphanumeric c... Read more
Affected Products : mobile_security_framework- Published: Feb. 05, 2025
- Modified: May. 23, 2025
- Vuln Type: Misconfiguration
-
8.5
HIGHCVE-2025-24805
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. A local user with minimal privileges is able to make use of an access token for materia... Read more
Affected Products : mobile_security_framework- Published: Feb. 05, 2025
- Modified: May. 23, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2013-7285
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. ... Read more
- Published: May. 15, 2019
- Modified: May. 23, 2025
-
9.3
HIGHCVE-2020-26217
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone usin... Read more
- Published: Nov. 16, 2020
- Modified: May. 23, 2025