13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-4328
狮子鱼CMS Web Database
6.3
MEDIUM
EPSS
0.4%
2021 CWE-89 1 PoC

A vulnerability has been found in 狮子鱼CMS and classified as critical. Affected by this vulnerability is the function goods_detail of the file ApiController.class.php. The manipulation of the argument goods_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The associated identifier of this vulnerability is VDB-222223.

CVE-2021-2057
Retail Customer Management and Segmentation Foundation Web Database
6.3
MEDIUM
EPSS
0.3%
2021 1 PoC

Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Internal Operations). The supported version that is affected is 19.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Customer Management and Segmentation Foundation. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Retail Customer Management and Segmentation Foundation accessible data as well as unauthorized read access to

CVE-2021-23400
nodemailer Web
6.3
MEDIUM
EPSS
0.5%
2021 2 PoCs

The package nodemailer before 6.6.1 are vulnerable to HTTP Header Injection if unsanitized user input that may contain newlines and carriage returns is passed into an address object.

CVE-2021-3983
kevinpapst/kimai2 Web
6.3
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-4242
BR270n Web
6.3
MEDIUM
EPSS
10.5%
2021 CWE-707 2 PoCs

A vulnerability was found in Sapido BR270n, BRC76n, GR297 and RB1732 and classified as critical. Affected by this issue is some unknown functionality of the file ip/syscmd.htm. The manipulation leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-214592.

CVE-2021-3904
getgrav/grav Web
6.3
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

grav is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-27909
Mautic Web ⚡ nuclei
6.3
MEDIUM
EPSS
18.7%
2021 CWE-79 0 PoCs

For Mautic versions prior to 3.3.4/4.0.0, there is an XSS vulnerability on Mautic's password reset page where a vulnerable parameter, "bundle," in the URL could allow an attacker to execute Javascript code. The attacker would be required to convince or trick the target into clicking a password reset URL with the vulnerable parameter utilized.

CVE-2021-23327
apexcharts Web
6.3
MEDIUM
EPSS
0.3%
2021 2 PoCs

The package apexcharts before 3.24.0 are vulnerable to Cross-site Scripting (XSS) via lack of sanitization of graph legend fields.

CVE-2021-4018
snipe/snipe-it Web
6.3
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2017-20142
Movie Portal Script Web Database
6.3
MEDIUM
EPSS
0.2%
2017 CWE-89 2 PoCs

A vulnerability classified as critical was found in Itech Movie Portal Script 7.36. This vulnerability affects unknown code of the file /artist-display.php. The manipulation of the argument act leads to sql injection (Union). The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2017-20131
News Portal Web Database
6.3
MEDIUM
EPSS
0.3%
2017 CWE-89 2 PoCs

A vulnerability was found in Itech News Portal 6.28. It has been classified as critical. Affected is an unknown function of the file /news-portal-script/information.php. The manipulation of the argument inf leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2017-20078
Hindu Matrimonial Script Web
6.3
MEDIUM
EPSS
0.3%
2017 CWE-269 2 PoCs

A vulnerability classified as critical has been found in Hindu Matrimonial Script. Affected is an unknown function of the file /admin/featured.php. The manipulation leads to improper privilege management. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2017-20077
Hindu Matrimonial Script Web
6.3
MEDIUM
EPSS
0.3%
2017 CWE-269 2 PoCs

A vulnerability was found in Hindu Matrimonial Script. It has been rated as critical. This issue affects some unknown processing of the file /admin/success_story.php. The manipulation leads to improper privilege management. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2017-20079
Hindu Matrimonial Script Web
6.3
MEDIUM
EPSS
0.3%
2017 CWE-269 2 PoCs

A vulnerability classified as critical was found in Hindu Matrimonial Script. Affected by this vulnerability is an unknown functionality of the file /admin/photo.php. The manipulation leads to improper privilege management. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2017-20075
Hindu Matrimonial Script Web
6.3
MEDIUM
EPSS
0.3%
2017 CWE-269 2 PoCs

A vulnerability was found in Hindu Matrimonial Script. It has been classified as critical. This affects an unknown part of the file /admin/payment.php. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2017-20137
B2B Script Web Database
6.3
MEDIUM
EPSS
0.3%
2017 CWE-89 2 PoCs

A vulnerability was found in Itech B2B Script 4.28. It has been rated as critical. This issue affects some unknown processing of the file /catcompany.php. The manipulation of the argument token with the input 704667c6a1e7ce56d3d6fa748ab6d9af3fd7' AND 6539=6539 AND 'Fakj'='Fakj leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2017-20080
Hindu Matrimonial Script Web
6.3
MEDIUM
EPSS
0.3%
2017 CWE-269 1 PoC

A vulnerability, which was classified as critical, has been found in Hindu Matrimonial Script. Affected by this issue is some unknown functionality of the file /admin/googleads.php. The manipulation leads to improper privilege management. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2017-20103
Kama Click Counter Plugin Web Database
6.3
MEDIUM
EPSS
0.2%
2017 CWE-89 2 PoCs

A vulnerability classified as critical has been found in Kama Click Counter Plugin up to 3.4.8. This affects an unknown part of the file wp-admin/admin.php. The manipulation of the argument order_by/order with the input ASC%2c(select*from(select(sleep(2)))a) leads to sql injection (Blind). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.4.9 is able to address this issue. It is recommended to upgrade the affected component.

CVE-2017-20130
Real Estate Script Web Database
6.3
MEDIUM
EPSS
0.3%
2017 CWE-89 1 PoC

A vulnerability was found in Itech Real Estate Script 3.12. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /real-estate-script/search_property.php. The manipulation of the argument property_for leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2017-20134
Freelancer Script Web Database
6.3
MEDIUM
EPSS
0.3%
2017 CWE-89 2 PoCs

A vulnerability, which was classified as critical, has been found in Itech Freelancer Script 5.13. Affected by this issue is some unknown functionality of the file /category.php. The manipulation of the argument sk leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.