Show filters
237 Total Results
Displaying 81-90 of 237
Sort by:
Attacker Value
Unknown

CVE-2021-24427

Disclosure Date: July 12, 2021 (last updated February 23, 2025)
The W3 Total Cache WordPress plugin before 2.1.3 did not sanitise or escape some of its CDN settings, allowing high privilege users to use JavaScript in them, which will be output in the page, leading to an authenticated Stored Cross-Site Scripting issue
Attacker Value
Unknown

CVE-2021-23390

Disclosure Date: July 12, 2021 (last updated February 23, 2025)
The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
Attacker Value
Unknown

CVE-2021-23389

Disclosure Date: July 12, 2021 (last updated February 23, 2025)
The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
Attacker Value
Unknown

CVE-2020-15732

Disclosure Date: June 22, 2021 (last updated February 22, 2025)
Improper Certificate Validation vulnerability in the Online Threat Prevention module as used in Bitdefender Total Security allows an attacker to potentially bypass HTTP Strict Transport Security (HSTS) checks. This issue affects: Bitdefender Total Security versions prior to 25.0.7.29. Bitdefender Internet Security versions prior to 25.0.7.29. Bitdefender Antivirus Plus versions prior to 25.0.7.29.
Attacker Value
Unknown

CVE-2021-23872

Disclosure Date: May 12, 2021 (last updated February 22, 2025)
Privilege Escalation vulnerability in the File Lock component of McAfee Total Protection (MTP) prior to 16.0.32 allows a local user to gain elevated privileges by manipulating a symbolic link in the IOCTL interface.
Attacker Value
Unknown

CVE-2021-23891

Disclosure Date: May 12, 2021 (last updated February 22, 2025)
Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.32 allows a local user to gain elevated privileges by impersonating a client token which could lead to the bypassing of MTP self-defense.
Attacker Value
Unknown

CVE-2021-23344

Disclosure Date: March 04, 2021 (last updated February 22, 2025)
The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set.
Attacker Value
Unknown

CVE-2021-23874

Disclosure Date: February 10, 2021 (last updated February 22, 2025)
Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP self-defense.
Attacker Value
Unknown

CVE-2021-23876

Disclosure Date: February 10, 2021 (last updated February 22, 2025)
Bypass Remote Procedure call in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and perform arbitrary file modification as the SYSTEM user potentially causing Denial of Service via executing carefully constructed malware.
Attacker Value
Unknown

CVE-2021-23873

Disclosure Date: February 10, 2021 (last updated February 22, 2025)
Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and perform arbitrary file deletion as the SYSTEM user potentially causing Denial of Service via manipulating Junction link, after enumerating certain files, at a specific time.