3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-24962
WordPress File Upload Web Windows
N/A
UNKNOWN
EPSS
1.7%
2021 CWE-22 2 PoCs

The WordPress File Upload Free and Pro WordPress plugins before 4.16.3 allow users with a role as low as Contributor to perform path traversal via a shortcode argument, which can then be used to upload a PHP code disguised as an image inside the auto-loaded directory of the plugin, resulting in arbitrary code execution.

CVE-2021-28840
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2021 1 PoC

Null Pointer Dereference vulnerability exists in D-Link DAP-2310 2.07.RC031, DAP-2330 1.07.RC028, DAP-2360 2.07.RC043, DAP-2553 3.06.RC027, DAP-2660 1.13.RC074, DAP-2690 3.16.RC100, DAP-2695 1.17.RC063, DAP-3320 1.01.RC014 and DAP-3662 1.01.RC022 in the upload_config function of sbin/httpd binary. When the binary handle the specific HTTP GET request, the content in upload_file variable is NULL in the upload_config function then the strncasecmp would take NULL as first argument, and incur the NULL pointer dereference vulnerability.

CVE-2021-24618
Donate With QRCode Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-79 1 PoC

The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result into a Stored Cross-Site Scripting (XSS). Furthermore, the plugin also does not have any CSRF and capability checks in place when saving such setting, allowing any authenticated user (as low as subscriber), or unauthenticated user via a CSRF vector to update them and perform such attack.

CVE-2021-24909
ACF Photo Gallery Field Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-79 1 PoC

The ACF Photo Gallery Field WordPress plugin before 1.7.5 does not sanitise and escape the post parameter in the includes/acf_photo_gallery_metabox_edit.php file before outputing back in an attribute, leading to a Reflected Cross-Site Scripting issue

CVE-2021-24523
Daily Prayer Time Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The Daily Prayer Time WordPress plugin before 2021.08.10 does not sanitise or escape some of its settings before outputting them in the page, leading to Authenticated Stored Cross-Site Scripting issues.

CVE-2021-24769
Permalink Manager Lite Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 1 PoC

The Permalink Manager Lite WordPress plugin before 2.2.13.1 does not validate and escape the orderby parameter before using it in a SQL statement in the Permalink Manager page, leading to a SQL Injection

CVE-2021-24196
Social Slider Widget Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 2 PoCs

The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the ‘token_error’ parameter can be controlled by users and it is directly echoed without being sanitized

CVE-2021-25061
WP Booking System – Booking Calendar Web Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-79 1 PoC

The WP Booking System WordPress plugin before 2.0.15 was affected by a reflected xss in wp-booking-system on the wpbs-calendars admin page.

CVE-2021-24861
Quotes Collection Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 1 PoC

The Quotes Collection WordPress plugin through 2.5.2 does not validate and escape the bulkcheck parameter before using it in a SQL statement, leading to a SQL injection

CVE-2021-40875
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
83.0%
2021 1 PoC

Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat actor can access the /files.md5 file on the client side of a Gurock TestRail application, disclosing a full list of application files and the corresponding file paths. The corresponding file paths can be tested, and in some cases, result in the disclosure of hardcoded credentials, API keys, or other sensitive data.

CVE-2021-41696
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An authentication bypass (account takeover) vulnerability exists in Premiumdatingscript 4.2.7.7 due to a weak password reset mechanism in requests\user.php.

CVE-2021-25082
Popup Builder – Create highly converting, mobile friendly marketing popups. Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
29.7%
2021 CWE-22 1 PoC

The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR

CVE-2021-24325
404 SEO Redirection Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The tab parameter of the settings page of the 404 SEO Redirection WordPress plugin through 1.3 is vulnerable to a reflected Cross-Site Scripting (XSS) issue as user input is not properly sanitised or escaped before being output in an attribute.

CVE-2021-24302
Hana Flv Player Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-79 1 PoC

The Hana Flv Player WordPress plugin through 3.1.3 is vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) vulnerability within the 'Default Skin' field.

CVE-2021-40374
Software Genérico Web
N/A
UNKNOWN
EPSS
1.9%
2021 1 PoC

A stored cross-site scripting (XSS) vulnerability was identified in Apperta Foundation OpenEyes 3.5.1. Updating a patient's details allows remote attackers to inject arbitrary web script or HTML via the Address1 parameter. This JavaScript then executes when the patient profile is loaded, which could be used in a XSS attack.

CVE-2021-24631
Unlimited PopUps Web Database Windows
N/A
UNKNOWN
EPSS
1.0%
2021 CWE-89 2 PoCs

The Unlimited PopUps WordPress plugin through 4.5.3 does not sanitise or escape the did GET parameter before using it in a SQL statement, available to users as low as editor, leading to an authenticated SQL Injection

CVE-2021-25032
PublishPress Capabilities – User Role Access, Editor Permissions, Admin Menus Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
81.9%
2021 CWE-352 2 PoCs

The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation and CSRF checks when updating the plugin's settings via the init hook, and does not ensure that the options to be updated belong to the plugin. As a result, unauthenticated attackers could update arbitrary blog options, such as the default role and make any new registered user with an administrator role.

CVE-2021-24788
Batch Cat Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-863 1 PoC

The Batch Cat WordPress plugin through 0.3 defines 3 custom AJAX actions, which both require authentication but are available for all roles. As a result, any authenticated user (including simple subscribers) can add/set/delete arbitrary categories to posts.

CVE-2021-3298
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?action=edit address1 parameter.

CVE-2021-42183
Software Genérico Web
N/A
UNKNOWN
EPSS
44.6%
2021 1 PoC

MasaCMS 7.2.1 is affected by a path traversal vulnerability in /index.cfm/_api/asset/image/.