3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-24518
WPFront Notification Bar Web Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-79 2 PoCs

The WPFront Notification Bar WordPress plugin before 2.0.0.07176 does not sanitise or escape its Custom CSS setting, allowing high privilege users such as admin to set XSS payload in it even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue

CVE-2021-24976
Smart SEO Tool – SEO优化插件 Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Smart SEO Tool WordPress plugin before 3.0.6 does not sanitise and escape the search parameter before outputting it back in an attribute when the TDK optimisation setting is enabled, leading to a Reflected Cross-Site Scripting

CVE-2021-44593
Software Genérico Web Database
N/A
UNKNOWN
EPSS
6.4%
2021 4 PoCs

Simple College Website 1.0 is vulnerable to unauthenticated file upload & remote code execution via UNION-based SQL injection in the username parameter on /admin/login.php.

CVE-2021-31693
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The 10Web Photo Gallery plugin through 1.5.68 for WordPress allows XSS via album_gallery_id_0, bwg_album_search_0, and type_0 for bwg_frontend_data. NOTE: other parameters are covered by CVE-2021-24291, CVE-2021-25041, and CVE-2021-46889. NOTE: VMware information, previously connected to this CVE ID because of a typo, is at CVE-2022-31693.

CVE-2021-24225
Advanced Booking Calendar Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Advanced Booking Calendar WordPress plugin before 1.6.7 did not sanitise the calId GET parameter in the "Seasons & Calendars" page before outputing it in an A tag, leading to a reflected XSS issue

CVE-2021-35265
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.3%
2021 0 PoCs

A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attackers to inject arbitrary web script to a page.

CVE-2021-46360
Software Genérico Web
N/A
UNKNOWN
EPSS
4.2%
2021 1 PoC

Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrary code via uploading a PHP shell through /adminzone/index.php?page=admin-commandr.

CVE-2021-26691
Apache HTTP Server Web
N/A
UNKNOWN
EPSS
47.8%
2021 CWE-122 3 PoCs

In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow

CVE-2021-25118
Yoast SEO Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
35.3%
2021 CWE-200 1 PoC

The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints which could help an attacker identify other vulnerabilities or help during the exploitation of other identified vulnerabilities.

CVE-2021-24317
Listeo Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 2 PoCs

The Listeo WordPress theme before 1.6.11 did not properly sanitise some parameters in its Search, Booking Confirmation and Personal Message pages, leading to Cross-Site Scripting issues

CVE-2021-27799
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2021 1 PoC

ean_leading_zeroes in backend/upcean.c in Zint Barcode Generator 2.9.1 has a stack-based buffer overflow that is reachable from the C API through an application that includes the Zint Barcode Generator library code.

CVE-2021-24920
StatCounter – Free Real Time Visitor Stats Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The StatCounter WordPress plugin before 2.0.7 does not sanitise and escape the Project ID and Secure Code settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2021-28002
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which allows remote attackers to execute arbitrary code via a crafted payload entered into the URL field. The vulnerability is triggered by users visiting the 'Articles' page.

CVE-2021-24599
Email Encoder – Protect Email Addresses Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Email Encoder – Protect Email Addresses WordPress plugin before 2.1.2 has an endpoint that requires no authentication and will render a user supplied value in the HTML response without escaping or sanitizing the data.

CVE-2021-28935
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

CMS Made Simple (CMSMS) 2.2.15 allows authenticated XSS via the /admin/addbookmark.php script through the Site Admin > My Preferences > Title field.

CVE-2021-23922
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An issue was discovered in Devolutions Remote Desktop Manager before 2020.2.12. There is a cross-site scripting (XSS) vulnerability in webviews.

CVE-2021-43159
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
2.5%
2021 1 PoC

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the setSessionTime function in /cgi-bin/luci/api/common..

CVE-2021-46108
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2021 2 PoCs

D-Link DSL-2730E CT-20131125 devices allow XSS via the username parameter to the password page in the maintenance configuration.

CVE-2021-25090
Portfolio Gallery, Product Catalog – Grid KIT Portfolio Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Portfolio Gallery, Product Catalog WordPress plugin before 2.1.0 does not have authorisation and CSRF checks in various functions related to AJAX actions, allowing any authenticated users, such as subscriber, to call them. Due to the lack of sanitisation and escaping, it could also allows attackers to perform Cross-Site Scripting attacks on pages where a Portfolio is embed

CVE-2021-24878
SupportCandy – Helpdesk & Support Ticket System Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The SupportCandy WordPress plugin before 2.2.7 does not sanitise and escape the query string before outputting it back in pages with the [wpsc_create_ticket] shortcode embed, leading to a Reflected Cross-Site Scripting issue