3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-22939
Node Web
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-295 3 PoCs

If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.

CVE-2021-24182
Tutor LMS – eLearning and online course solution Web Database Windows
N/A
UNKNOWN
EPSS
7.6%
2021 CWE-89 1 PoC

The tutor_quiz_builder_get_answers_by_question AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.

CVE-2021-25327
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 3 PoCs

Skyworth Digital Technology RN510 V.3.1.0.4 contains a cross-site request forgery (CSRF) vulnerability in /cgi-bin/net-routeadd.asp and /cgi-bin/sec-urlfilter.asp. Missing CSRF protection in devices can lead to XSRF, as the above pages are vulnerable to cross-site scripting (XSS).

CVE-2021-24565
Contact Form 7 Captcha Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings, allowing attacker to make a logged in user with the manage_options change them. Furthermore, the settings are not escaped when output in attributes, leading to a Stored Cross-Site Scripting issue.

CVE-2021-24980
Gwolle Guestbook Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Gwolle Guestbook WordPress plugin before 4.2.0 does not sanitise and escape the gwolle_gb_user_email parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue in an admin page

CVE-2021-24275
Popup by Supsystic Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.9%
2021 CWE-79 2 PoCs

The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

CVE-2021-24127
ThirstyAffiliates Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-79 1 PoC

Unvalidated input and lack of output encoding in the ThirstyAffiliates Affiliate Link Manager WordPress plugin, versions before 3.9.3, was vulnerable to authenticated Stored Cross-Site Scripting (XSS), which could lead to privilege escalation.

CVE-2021-27672
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

SQL Injection in the "admin_boxes.ajax.php" component of Tribal Systems Zenario CMS v8.8.52729 allows remote attackers to obtain sesnitive database information by injecting SQL commands into the "cID" parameter when creating a new HTML component.

CVE-2021-20659
SolarView Compact Web
N/A
UNKNOWN
EPSS
1.6%
2021 1 PoC

SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecified vectors. If the file is PHP script, an attacker may execute arbitrary code.

CVE-2021-24174
Database Backups Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-352 2 PoCs

The Database Backups WordPress plugin through 1.2.2.6 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the database, change the plugin's settings and delete backups.

CVE-2021-24679
Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Bitcoin / AltCoin Payment Gateway for WooCommerce WordPress plugin before 1.6.1 does not escape the 's' GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting issue

CVE-2021-24935
WP Google Fonts Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The WP Google Fonts WordPress plugin before 3.1.5 does not escape the googlefont_ajax_name and googlefont_ajax_family parameter of the googlefont_action AJAx action (available to any authenticated user) before outputing them in attributes, leading Reflected Cross-Site Scripting issues

CVE-2021-31934
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

OX App Suite 7.10.4 and earlier allows XSS via a crafted contact object (payload in the position or company field) that is mishandled in the App Suite UI on a smartphone.

CVE-2021-38702
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
34.8%
2021 3 PoCs

Cyberoam NetGenie C0101B1-20141120-NG11VO devices through 2021-08-14 allow tweb/ft.php?u=[XSS] attacks.

CVE-2021-31584
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.4%
2021 3 PoCs

Sipwise C5 NGCP www_csc version 3.6.4 up to and including platform NGCP CE mr3.8.13 allows call/click2dial CSRF attacks for actions with administrative privileges.

CVE-2021-24425
Floating Notification Bar, Sticky Menu on Scroll, and Sticky Header for Any Theme – myStickymenu Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Floating Notification Bar, Sticky Menu on Scroll, and Sticky Header for Any Theme – myStickymenu WordPress plugin before 2.5.2 does not sanitise or escape its Bar Text settings, allowing hight privilege users to use malicious JavaScript in it, leading to a Stored Cross-Site Scripting issue, which will be triggered in the plugin's setting, as well as all front-page of the blog (when the Welcome bar is active)

CVE-2021-46427
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.2%
2021 2 PoCs

An SQL Injection vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 via the message parameter in Master.php.

CVE-2021-24368
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or escape its result_id parameter when displaying an existing quiz result page, leading to a reflected Cross-Site Scripting issue. This could allow for privilege escalation by inducing a logged in admin to open a malicious link

CVE-2021-3346
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Foris before 101.1.1, as used in Turris OS, lacks certain HTML escaping in the login template.

CVE-2021-40096
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via modification of the authorisationUrl in some integration configurations.