3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-36090
Apache Commons Compress Web
N/A
UNKNOWN
EPSS
0.7%
2021 CWE-130 4 PoCs

When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.

CVE-2021-43728
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Pix-Link MiNi Router 28K.MiniRouter.20190211 was discovered to contain a stored cross-site scripting (XSS) vulnerability due to an unsanitized SSID parameter.

CVE-2021-46068
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.7%
2021 1 PoC

A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the My Account Section in login panel.

CVE-2021-24466
Verse-O-Matic Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-79 1 PoC

The Verse-O-Matic WordPress plugin through 4.1.1 does not have any CSRF checks in place, allowing attackers to make logged in administrators do unwanted actions, such as add/edit/delete arbitrary verses and change the settings. Due to the lack of sanitisation in the settings and verses, this could also lead to Stored Cross-Site Scripting issues

CVE-2021-30224
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Cross Site Request Forgery (CSRF) in Rukovoditel v2.8.3 allows attackers to create an admin user with an arbitrary credentials.

CVE-2021-24837
Passster Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The Passster WordPress plugin before 3.5.5.8 does not escape the area parameter of its shortcode, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

CVE-2021-43506
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

An SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the password parameter in Login.php.

CVE-2021-24177
File Manager Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint /wp-admin/admin.php?page=wp_file_manager_properties when a payload is submitted on the User-Agent parameter. The payload is then reflected back on the web application response.

CVE-2021-21123
Chrome Web
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.

CVE-2021-25004
SEUR Oficial Web Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-552 1 PoC

The SEUR Oficial WordPress plugin before 1.7.2 creates a PHP file with a random name when installed, even though it is used for support purposes, it allows to download any file from the web server without restriction after knowing the URL and a password than an administrator can see in the plugin settings page.

CVE-2021-36352
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Stored cross-site scripting (XSS) vulnerability in Care2x Hospital Information Management 2.7 Alpha. The vulnerability has found POST requests in /modules/registration_admission/patient_register.php page with "name_middle", "addr_str", "station", "name_maiden", "name_2", "name_3" parameters.

CVE-2021-38706
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

messages_load.php in ClinicCases 7.3.3 suffers from a blind SQL injection vulnerability, which allows low-privileged attackers to execute arbitrary SQL commands through a vulnerable parameter.

CVE-2021-24266
The Plus Addons for Elementor Page Builder Lite Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The “The Plus Addons for Elementor Page Builder Lite” WordPress Plugin before 2.0.6 has four widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

CVE-2021-42763
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Couchbase Server before 6.6.3 and 7.x before 7.0.2 stores Sensitive Information in Cleartext. The issue occurs when the cluster manager forwards a HTTP request from the pluggable UI (query workbench etc) to the specific service. In the backtrace, the Basic Auth Header included in the HTTP request, has the "@" user credentials of the node processing the UI request.

CVE-2021-24595
Wp Cookie Choice Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-352 1 PoC

The Wp Cookie Choice WordPress plugin through 1.1.0 is lacking any CSRF check when saving its options, and do not escape them when outputting them in attributes. As a result, an attacker could make a logged in admin change them to arbitrary values including XSS payloads via a CSRF attack.

CVE-2021-35503
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Afian FileRun 2021.03.26 allows stored XSS via an HTTP X-Forwarded-For header that is mishandled when rendering Activity Logs.

CVE-2021-24959
WP Email Users Web Database Windows
N/A
UNKNOWN
EPSS
39.4%
2021 CWE-89 2 PoCs

The WP Email Users WordPress plugin through 1.7.6 does not escape the data_raw parameter in the weu_selected_users_1 AJAX action, available to any authenticated users, allowing them to perform SQL injection attacks.

CVE-2021-42669
Software Genérico Web
N/A
UNKNOWN
EPSS
44.2%
2021 3 PoCs

A file upload vulnerability exists in Sourcecodester Engineers Online Portal in PHP via dashboard_teacher.php, which allows changing the avatar through teacher_avatar.php. Once an avatar gets uploaded it is getting uploaded to the /admin/uploads/ directory, and is accessible by all users. By uploading a php webshell containing "<?php system($_GET["cmd"]); ?>" the attacker can execute commands on the web server with - /admin/uploads/php-webshell?cmd=id.

CVE-2021-24648
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The RegistrationMagic WordPress plugin before 5.0.1.9 does not sanitise and escape the rm_search_value parameter before outputting back in an attribute, leading to a Reflected Cross-Site Scripting

CVE-2021-24588
SMS Alert Order Notifications – WooCommerce Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page.