3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-31761
Software Genérico Web
N/A
UNKNOWN
EPSS
82.3%
2021 4 PoCs

Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process feature.

CVE-2021-24571
HD Quiz Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The HD Quiz WordPress plugin before 1.8.4 does not escape some of its Answers before outputting them in attribute when generating the Quiz, which could lead to Stored Cross-Site Scripting issues

CVE-2021-28924
Software Genérico Web
N/A
UNKNOWN
EPSS
52.4%
2021 1 PoC

Self Authenticated XSS in Nagios Network Analyzer before 2.4.2 via the nagiosna/groups/queries page.

CVE-2021-24986
Post Grid Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-79 1 PoC

The Post Grid WordPress plugin before 2.1.16 does not escape the keyword parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in pages containing a Post Grid with a search form

CVE-2021-24822
Stylish Cost Calculator Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and CSRF checks on some of its AJAX actions (available to authenticated users), which could allow any authenticated users, such as subscriber to call them, and perform Stored Cross-Site Scripting attacks against logged in admin, as well as frontend users due to the lack of sanitisation and escaping in some parameters

CVE-2021-24621
WP Courses LMS Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The WP Courses LMS WordPress plugin before 2.0.44 does not sanitise its Video Embed Code, allowing malicious code to be injected in it by high privilege users, even when the unfiltered_html capability is disallowed, which could lead to Stored Cross-Site Scripting issues

CVE-2021-46780
Easy Google Maps Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Easy Google Maps WordPress plugin before 1.9.32 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting

CVE-2021-24628
Wow Forms – create any form with custom style Web Database Windows
N/A
UNKNOWN
EPSS
1.0%
2021 CWE-89 2 PoCs

The Wow Forms WordPress plugin through 3.1.3 does not sanitise or escape a 'did' GET parameter before using it in a SQL statement, when deleting a form in the admin dashboard, leading to an authenticated SQL injection

CVE-2021-24757
Stylish Price List Web Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-863 1 PoC

The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX action (available to both unauthenticated and authenticated users), which could allow unauthenticated users to upload images.

CVE-2021-24802
Colorful Categories Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The Colorful Categories WordPress plugin before 2.0.15 does not enforce nonce checks which could allow attackers to make a logged in admin or editor change taxonomy colors via a CSRF attack

CVE-2021-24706
Qwizcards – online quizzes and flashcards Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Qwizcards – online quizzes and flashcards WordPress plugin before 3.62 does not properly sanitize and escape some of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2021-27969
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Dolphin CMS 7.4.2 is vulnerable to stored XSS via the Page Builder "width" parameter.

CVE-2021-37803
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An SQL Injection vulnerability exists in Sourcecodester Online Covid Vaccination Scheduler System 1.0 via the username in lognin.php .

CVE-2021-30862
iTunes U Web
N/A
UNKNOWN
EPSS
2.2%
2021 2 PoCs

A validation issue was addressed with improved input sanitization. This issue is fixed in iTunes U 3.8.3. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.

CVE-2021-25111
English WordPress Admin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.8%
2021 CWE-601 1 PoC

The English WordPress Admin WordPress plugin before 1.5.2 does not validate the admin_custom_language_return_url before redirecting users o it, leading to an open redirect issue

CVE-2021-43960
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Lorensbergs Connect2 3.13.7647.20190 is affected by an XSS vulnerability. Exploitation requires administrator privileges and is performed through the Wizard editor of the application. The attack requires an administrator to go into the Wizard editor and enter an XSS payload within the Page title, Page Instructions, Text before, Text after, or Text on side box. Once this has been done, the administrator must click save and finally wait until any user of the application performs a booking for rental items in the booking area of the application, where the XSS triggers. NOTE: another perspective i

CVE-2021-36160
Apache HTTP Server Web
N/A
UNKNOWN
EPSS
4.7%
2021 CWE-125 2 PoCs

A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive).

CVE-2021-43436
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

MartDevelopers Inc iResturant v1.0 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed.

CVE-2021-24133
ActiveCampaign Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

Lack of CSRF checks in the ActiveCampaign WordPress plugin, versions before 8.0.2, on its Settings form, which could allow attacker to make a logged-in administrator change API Credentials to attacker's account.

CVE-2021-25756
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains IntelliJ IDEA before 2020.2, HTTP links were used for several remote repositories instead of HTTPS.