3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-24701
Quiz Tool Lite Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Quiz Tool Lite WordPress plugin through 2.3.15 does not sanitize multiple input fields used when creating or managing quizzes and in other setting options, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2021-28148
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
5.7%
2021 2 PoCs

One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication. This allows any unauthenticated user to send an unlimited number of requests to the endpoint, leading to a denial of service (DoS) attack against a Grafana Enterprise instance.

CVE-2021-37833
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
11.6%
2021 1 PoC

A reflected cross-site scripting (XSS) vulnerability exists in multiple pages in version 3.0.2 of the Hotel Druid application that allows for arbitrary execution of JavaScript commands.

CVE-2021-33966
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Cross site scripting (XSS) vulnerability in spotweb 1.4.9, allows authenticated attackers to execute arbitrary code via crafted GET request to the login page.

CVE-2021-24799
Far Future Expiry Header Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The Far Future Expiry Header WordPress plugin before 1.5 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVE-2021-27940
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

resources/public/js/orchestrator.js in openark orchestrator before 3.2.4 allows XSS via the orchestrator-msg parameter.

CVE-2021-25013
Qubely – Advanced Gutenberg Blocks Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-862 1 PoC

The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure that the block to be deleted belong to the plugin, as a result, any authenticated users, such as subscriber can delete arbitrary posts

CVE-2021-42567
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
48.9%
2021 0 PoCs

Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints.

CVE-2021-45348
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An Arbitrary File Deletion vulnerability exists in SourceCodester Attendance Management System v1.0 via the csv parameter in admin/pageUploadCSV.php, which can cause a Denial of Service (crash).

CVE-2021-24688
Orange Form Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-284 1 PoC

The Orange Form WordPress plugin through 1.0.1 does not have any authorisation and CSRF checks in all of its AJAX calls, for example the or_delete_filed one which is available to both unauthenticated and authenticated users could allow attackers to delete arbitrary posts.The AJAX calls performing actions on posts also do not ensure that the post belong to them (or that they are allowed to perform such action on it)

CVE-2021-24784
WP Admin Logo Changer Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The WP Admin Logo Changer WordPress plugin through 1.0 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin update them via a CSRF attack.

CVE-2021-29394
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote authenticated users to change the password of any targeted user accounts via lack of proper authorization in the user-controlled "userID" parameter of the HTTP POST request.

CVE-2021-30146
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Seafile 7.0.5 (2019) allows Persistent XSS via the "share of library functionality."

CVE-2021-24680
WP Travel Engine – Travel and Tour Booking Plugin Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The WP Travel Engine WordPress plugin before 5.3.1 does not escape the Description field in the Trip Destination/Activities/Trip Type and Pricing Category pages, allowing users with a role as low as editor to perform Stored Cross-Site Scripting attacks, even when the unfiltered_html capability is disallowed

CVE-2021-27931
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
89.4%
2021 0 PoCs

LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XXE via an API request to PageControllerXml.jsp. One can send a request crafted with an XXE payload and achieve outcomes such as reading local server files or denial of service.

CVE-2021-24357
Best Image Gallery & Responsive Photo Gallery – FooGallery Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

In the Best Image Gallery & Responsive Photo Gallery – FooGallery WordPress plugin before 2.0.35, the Custom CSS field of each gallery is not properly sanitised or validated before being being output in the page where the gallery is embed, leading to a stored Cross-Site Scripting issue.

CVE-2021-27670
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.8%
2021 0 PoCs

Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.

CVE-2021-32158
Software Genérico Web
N/A
UNKNOWN
EPSS
8.1%
2021 1 PoC

A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Upload and Download feature.

CVE-2021-24382
Smart Slider 3 Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The Smart Slider 3 Free and pro WordPress plugins before 3.5.0.9 did not sanitise the Project Name before outputting it back in the page, leading to a Stored Cross-Site Scripting issue. By default, only administrator users could access the affected functionality, limiting the exploitability of the vulnerability. However, some WordPress admins may allow lesser privileged users to access the plugin's functionality, in which case, privilege escalation could be performed.