3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-41696
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An authentication bypass (account takeover) vulnerability exists in Premiumdatingscript 4.2.7.7 due to a weak password reset mechanism in requests\user.php.

CVE-2021-25082
Popup Builder – Create highly converting, mobile friendly marketing popups. Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
29.7%
2021 CWE-22 1 PoC

The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR

CVE-2021-24933
Dynamic Widgets Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Dynamic Widgets WordPress plugin through 1.5.16 does not escape the prefix parameter before outputting it back in an attribute when using the term_tree AJAX action (available to any authenticated users), leading to a Reflected Cross-Site Scripting issue

CVE-2021-24325
404 SEO Redirection Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The tab parameter of the settings page of the 404 SEO Redirection WordPress plugin through 1.3 is vulnerable to a reflected Cross-Site Scripting (XSS) issue as user input is not properly sanitised or escaped before being output in an attribute.

CVE-2021-24302
Hana Flv Player Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-79 1 PoC

The Hana Flv Player WordPress plugin through 3.1.3 is vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) vulnerability within the 'Default Skin' field.

CVE-2021-40374
Software Genérico Web
N/A
UNKNOWN
EPSS
1.9%
2021 1 PoC

A stored cross-site scripting (XSS) vulnerability was identified in Apperta Foundation OpenEyes 3.5.1. Updating a patient's details allows remote attackers to inject arbitrary web script or HTML via the Address1 parameter. This JavaScript then executes when the patient profile is loaded, which could be used in a XSS attack.

CVE-2021-24631
Unlimited PopUps Web Database Windows
N/A
UNKNOWN
EPSS
1.0%
2021 CWE-89 2 PoCs

The Unlimited PopUps WordPress plugin through 4.5.3 does not sanitise or escape the did GET parameter before using it in a SQL statement, available to users as low as editor, leading to an authenticated SQL Injection

CVE-2021-25032
PublishPress Capabilities – User Role Access, Editor Permissions, Admin Menus Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
81.9%
2021 CWE-352 2 PoCs

The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation and CSRF checks when updating the plugin's settings via the init hook, and does not ensure that the options to be updated belong to the plugin. As a result, unauthenticated attackers could update arbitrary blog options, such as the default role and make any new registered user with an administrator role.

CVE-2021-24788
Batch Cat Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-863 1 PoC

The Batch Cat WordPress plugin through 0.3 defines 3 custom AJAX actions, which both require authentication but are available for all roles. As a result, any authenticated user (including simple subscribers) can add/set/delete arbitrary categories to posts.

CVE-2021-3298
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?action=edit address1 parameter.

CVE-2021-42183
Software Genérico Web
N/A
UNKNOWN
EPSS
44.6%
2021 1 PoC

MasaCMS 7.2.1 is affected by a path traversal vulnerability in /index.cfm/_api/asset/image/.

CVE-2021-45967
Software Genérico Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
92.6%
2021 1 PoC

An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints.

CVE-2021-24448
User Registration & User Profile – Profile Builder Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.8 does not sanitise or escape its 'Modify default Redirect Delay timer' setting, allowing high privilege users to use JavaScript code in it, even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue

CVE-2021-41282
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
91.3%
2021 2 PoCs

diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data about the routes set in the firewall. The data is retrieved by executing the netstat utility, and then its output is parsed via the sed utility. Although the common protection mechanisms against command injection (i.e., the usage of the escapeshellarg function for the arguments) are used, it is still possible to inject sed-specific code and write an arbitrary file in an arbitrary location.

CVE-2021-45416
Software Genérico Web
N/A
UNKNOWN
EPSS
23.1%
2021 2 PoCs

Reflected Cross-site scripting (XSS) vulnerability in RosarioSIS 8.2.1 allows attackers to inject arbitrary HTML via the search_term parameter in the modules/Scheduling/Courses.php script.

CVE-2021-35515
Apache Commons Compress Web
N/A
UNKNOWN
EPSS
1.2%
2021 CWE-834 4 PoCs

When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.

CVE-2021-26929
Software Genérico Web
N/A
UNKNOWN
EPSS
1.5%
2021 2 PoCs

An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library before 2.3.7 is used). The attacker can send a plain text e-mail message, with JavaScript encoded as a link or email that is mishandled by preProcess in Text2html.php, because bespoke use of \x00\x00\x00 and \x01\x01\x01 interferes with XSS defenses.

CVE-2021-43506
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

An SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the password parameter in Login.php.

CVE-2021-24177
File Manager Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint /wp-admin/admin.php?page=wp_file_manager_properties when a payload is submitted on the User-Agent parameter. The payload is then reflected back on the web application response.

CVE-2021-21123
Chrome Web
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.