3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-3150
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

A cross-site scripting (XSS) vulnerability on the Delete Personal Data page in Cryptshare Server before 4.8.0 allows an attacker to inject arbitrary web script or HTML via the user name. The issue is fixed with the version 4.8.1

CVE-2021-24605
Custom Post View Generator Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The create_post_page AJAX action of the Custom Post View Generator WordPress plugin through 0.4.6 (available to authenticated user) does not sanitise or escape user input before outputting it back in the response, leading to a Reflected Cross-Site issue

CVE-2021-38704
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.0%
2021 1 PoC

Multiple reflected cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow unauthenticated attackers to introduce arbitrary JavaScript by crafting a malicious URL. This can result in account takeover via session token theft.

CVE-2021-39275
Apache HTTP Server Web
N/A
UNKNOWN
EPSS
37.7%
2021 2 PoCs

ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.

CVE-2021-24153
Yoast SEO Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-79 1 PoC

A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had built-in blacklist filters which were blacklisting Parenthesis as well as several functions such as alert but bypasses were found.

CVE-2021-38152
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

index.php/appointment/insert_patient_add_appointment in Chikitsa Patient Management System 2.0.0 allows XSS.

CVE-2021-26795
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

A SQL Injection vulnerability in /appliance/shiftmgn.php in TalariaX sendQuick Alert Plus Server Admin 4.3 before 8HF11 allows attackers to obtain sensitive information via a Roster Time to Roster Management.

CVE-2021-24924
Email Log Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Email Log WordPress plugin before 2.4.8 does not escape the d parameter before outputting it back in an attribute in the Log page, leading to a Reflected Cross-Site Scripting issue

CVE-2021-41782
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.

CVE-2021-24603
Site Reviews Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Site Reviews WordPress plugin before 5.13.1 does not sanitise some of its Review Details when adding a review as an admin, which could allow them to perform Cross-Site Scripting attacks when the unfiltered_html is disallowed

CVE-2021-29295
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Null Pointer Dereference vulnerability exists in D-Link DSP-W215 1.10, which could let a remote malicious user cause a denial of servie via usr/bin/lighttpd. It could be triggered by sending an HTTP request without URL in the start line directly to the device. NOTE: The DSP-W215 and all hardware revisions is considered End of Life and as such this issue will not be patched

CVE-2021-0474
Android Web
N/A
UNKNOWN
EPSS
3.9%
2021 2 PoCs

In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-177611958

CVE-2021-25020
CAOS | Host Google Analytics Locally Web Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-22 1 PoC

The CAOS | Host Google Analytics Locally WordPress plugin before 4.1.9 does not validate the cache directory setting, allowing high privilege users to use a path traversal vector and delete arbitrary folders when uninstalling the plugin

CVE-2021-3427
Deluge-web Web
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-79 1 PoC

The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. The the data from torrent files is not properly sanitised as it's interpreted directly as HTML. Someone who supplies the user with a malicious torrent file can execute arbitrary Javascript code in the context of the user's browser session.

CVE-2021-26549
Software Genérico Web
N/A
UNKNOWN
EPSS
1.4%
2021 3 PoCs

An XSS issue was discovered in SmartFoxServer 2.17.0. Input passed to the AdminTool console is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML code in a user's browser session in context of an affected site.

CVE-2021-25077
Store Toolkit for WooCommerce Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Store Toolkit for WooCommerce WordPress plugin before 2.3.2 does not sanitise and escape the tab parameter before outputting it back in an admin page in an error message, leading to a Reflected Cross-Site Scripting

CVE-2021-24267
All-in-One Addons for Elementor – WidgetKit Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The “All-in-One Addons for Elementor – WidgetKit” WordPress Plugin before 2.3.10 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

CVE-2021-24500
Workreap Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-283 2 PoCs

Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object references that were not validated. This allows an attacker to trick a logged in user to submit a POST request to the vulnerable site, potentially modifying or deleting arbitrary objects on the target site.

CVE-2021-24538
Current Book Web Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-79 1 PoC

The Current Book WordPress plugin through 1.0.1 does not sanitize user input when an authenticated user adds Author or Book Title, then does not escape these values when outputting to the browser leading to an Authenticated Stored XSS Cross-Site Scripting issue.

CVE-2021-28088
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Cross-site scripting (XSS) in modules/content/admin/content.php in ImpressCMS profile 1.4.2 allows remote attackers to inject arbitrary web script or HTML parameters through the "Display Name" field.