3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-24935
WP Google Fonts Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The WP Google Fonts WordPress plugin before 3.1.5 does not escape the googlefont_ajax_name and googlefont_ajax_family parameter of the googlefont_action AJAx action (available to any authenticated user) before outputing them in attributes, leading Reflected Cross-Site Scripting issues

CVE-2021-46013
Software Genérico Web
N/A
UNKNOWN
EPSS
2.4%
2021 1 PoC

An unrestricted file upload vulnerability exists in Sourcecodester Free school management software 1.0. An attacker can leverage this vulnerability to enable remote code execution on the affected web server. Once a php webshell containing "<?php system($_GET["cmd"]); ?>" gets uploaded it is saved into /uploads/exam_question/ directory, and is accessible by all users.

CVE-2021-25053
WP Coder – add custom html, css and js code Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.

CVE-2021-31934
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

OX App Suite 7.10.4 and earlier allows XSS via a crafted contact object (payload in the position or company field) that is mishandled in the App Suite UI on a smartphone.

CVE-2021-38702
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
34.8%
2021 3 PoCs

Cyberoam NetGenie C0101B1-20141120-NG11VO devices through 2021-08-14 allow tweb/ft.php?u=[XSS] attacks.

CVE-2021-24164
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-200 1 PoC

In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to trigger the action, wp_ajax_nf_oauth, and retrieve the connection url needed to establish a connection. They could also retrieve the client_id for an already established OAuth connection.

CVE-2021-20152
Trendnet AC2600 TEW-827DRU Web
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

Trendnet AC2600 TEW-827DRU version 2.08B01 lacks proper authentication to the bittorrent functionality. If enabled, anyone is able to visit and modify settings and files via the Bittorent web client by visiting: http://192.168.10.1:9091/transmission/web/

CVE-2021-31584
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.4%
2021 3 PoCs

Sipwise C5 NGCP www_csc version 3.6.4 up to and including platform NGCP CE mr3.8.13 allows call/click2dial CSRF attacks for actions with administrative privileges.

CVE-2021-24425
Floating Notification Bar, Sticky Menu on Scroll, and Sticky Header for Any Theme – myStickymenu Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Floating Notification Bar, Sticky Menu on Scroll, and Sticky Header for Any Theme – myStickymenu WordPress plugin before 2.5.2 does not sanitise or escape its Bar Text settings, allowing hight privilege users to use malicious JavaScript in it, leading to a Stored Cross-Site Scripting issue, which will be triggered in the plugin's setting, as well as all front-page of the blog (when the Welcome bar is active)

CVE-2021-46427
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.2%
2021 2 PoCs

An SQL Injection vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 via the message parameter in Master.php.

CVE-2021-24368
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or escape its result_id parameter when displaying an existing quiz result page, leading to a reflected Cross-Site Scripting issue. This could allow for privilege escalation by inducing a logged in admin to open a malicious link

CVE-2021-3346
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Foris before 101.1.1, as used in Turris OS, lacks certain HTML escaping in the login template.

CVE-2021-40096
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via modification of the authorisationUrl in some integration configurations.

CVE-2021-24725
Comment Link Remove and Other Comment Tools Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 2 PoCs

The Comment Link Remove and Other Comment Tools WordPress plugin before 2.1.6 does not have CSRF check in its 'Delete comments easily', which could allow attackers to make logged in admin delete arbitrary comments

CVE-2021-42169
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.0%
2021 1 PoC

The Simple Payroll System with Dynamic Tax Bracket in PHP using SQLite Free Source Code (by: oretnom23 ) is vulnerable from remote SQL-Injection-Bypass-Authentication for the admin account. The parameter (username) from the login form is not protected correctly and there is no security and escaping from malicious payloads.

CVE-2021-28924
Software Genérico Web
N/A
UNKNOWN
EPSS
52.4%
2021 1 PoC

Self Authenticated XSS in Nagios Network Analyzer before 2.4.2 via the nagiosna/groups/queries page.

CVE-2021-24628
Wow Forms – create any form with custom style Web Database Windows
N/A
UNKNOWN
EPSS
1.0%
2021 CWE-89 2 PoCs

The Wow Forms WordPress plugin through 3.1.3 does not sanitise or escape a 'did' GET parameter before using it in a SQL statement, when deleting a form in the admin dashboard, leading to an authenticated SQL injection

CVE-2021-24757
Stylish Price List Web Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-863 1 PoC

The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX action (available to both unauthenticated and authenticated users), which could allow unauthenticated users to upload images.

CVE-2021-24802
Colorful Categories Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The Colorful Categories WordPress plugin before 2.0.15 does not enforce nonce checks which could allow attackers to make a logged in admin or editor change taxonomy colors via a CSRF attack

CVE-2021-24706
Qwizcards – online quizzes and flashcards Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Qwizcards – online quizzes and flashcards WordPress plugin before 3.62 does not properly sanitize and escape some of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.