3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-32162
Software Genérico Web
N/A
UNKNOWN
EPSS
8.0%
2021 1 PoC

A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 through the File Manager feature.

CVE-2021-24150
Like Button Rating ♥ LikeBtn Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
46.3%
2021 CWE-918 1 PoC

The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request Forgery (SSRF).

CVE-2021-25073
WP125 Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The WP125 WordPress plugin before 1.5.5 does not have CSRF checks in various action, for example when deleting an ad, allowing attackers to make a logged in admin delete them via a CSRF attack

CVE-2021-32099
Software Genérico Web Database
N/A
UNKNOWN
EPSS
52.6%
2021 6 PoCs

A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileged session via the /include/chart_generator.php session_id parameter, leading to a login bypass.

CVE-2021-24378
Autoptimize Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Autoptimize WordPress plugin before 2.7.8 does not check for malicious files such as .html in the archive uploaded via the 'Import Settings' feature. As a result, it is possible for a high privilege user to upload a malicious file containing JavaScript code inside an archive which will execute when a victim visits index.html inside the plugin directory.

CVE-2021-25033
WordPress Newsletter Plugin – Noptin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2021 CWE-601 1 PoC

The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the user to its given value, leading to an open redirect issue

CVE-2021-25864
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
57.0%
2021 0 PoCs

node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in file hue-magic.js, to fetch an arbitrary file.

CVE-2021-29055
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Firtstname parameter to the Update Account form in student_profile.php.

CVE-2021-38841
Software Genérico Web
N/A
UNKNOWN
EPSS
5.3%
2021 3 PoCs

Remote Code Execution can occur in Simple Water Refilling Station Management System 1.0 via the System Logo option on the system_info page in classes/SystemSettings.php with an update_settings action.

CVE-2021-24824
Custom Content Shortcode Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-863 1 PoC

The [field] shortcode included with the Custom Content Shortcode WordPress plugin before 4.0.1, allows authenticated users with a role as low as contributor, to access arbitrary post metadata. This could lead to sensitive data disclosure, for example when used in combination with WooCommerce, the email address of orders can be retrieved

CVE-2021-24393
Comment Highlighter Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 2 PoCs

A c GET parameter of the Comment Highlighter WordPress plugin through 0.13 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

CVE-2021-38757
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php.

CVE-2021-41871
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An issue was discovered in Socomec REMOTE VIEW PRO 2.0.41.4. Improper validation of input into the username field makes it possible to place a stored XSS payload. This is executed if an administrator views the System Event Log.

CVE-2021-27352
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An open redirect vulnerability in Ilch CMS version 2.1.42 allows attackers to redirect users to an attacker's site after a successful login.

CVE-2021-43198
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains TeamCity before 2021.1.2, stored XSS is possible.

CVE-2021-24671
MX Time Zone Clocks Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The MX Time Zone Clocks WordPress plugin before 3.4.1 does not escape the time_zone attribute of the mxmtzc_time_zone_clocks shortcode, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks

CVE-2021-45026
Software Genérico Web
N/A
UNKNOWN
EPSS
3.3%
2021 2 PoCs

ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cross Site Scripting (XSS).

CVE-2021-24511
Product Feed on WooCommerce for Google, Awin, Shareasale, Bing, and More Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 2 PoCs

The fetch_product_ajax functionality in the Product Feed on WooCommerce WordPress plugin before 3.3.1.0 uses a `product_id` POST parameter which is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

CVE-2021-27695
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbitrary web script or HTML via any "Add" sections, such as Add Card Building & Floor, or others in the Name and Code Parameters.

CVE-2021-43742
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

CMSimple 5.4 is vulnerable to Cross Site Scripting (XSS) via the file upload feature.