3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-41317
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

XSS Hunter Express before 2021-09-17 does not properly enforce authentication requirements for paths.

CVE-2021-22132
Elasticsearch Web Database
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-522 1 PoC

Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2

CVE-2021-43574
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
29.2%
2021 1 PoC

WebAdmin Control Panel in Atmail 6.5.0 (a version released in 2012) allows XSS via the format parameter to the default URI. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2021-27338
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Faraday Edge before 3.7 allows XSS via the network/create/ page and its network name parameter.

CVE-2021-24736
Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files WordPress plugin before 1.6.57 does not sanitise and escape some of its settings before outputting them in attributes, which could lead to Stored Cross-Site Scripting issues.

CVE-2021-31682
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
41.1%
2021 1 PoC

The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for reflected XSS attacks due to the operatorlocale GET parameter not being sanitized. This issue impacts versions 6.5 and below. This issue works by passing in a basic XSS payload to a vulnerable GET parameter that is reflected in the output without sanitization.

CVE-2021-24785
Great Quotes Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Great Quotes WordPress plugin through 1.0.0 does not sanitise and escape the Quote and Author fields of its Quotes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

CVE-2021-23928
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

OX App Suite through 7.10.3 allows XSS via the ajax/apps/manifests query string.

CVE-2021-25076
WP User Frontend – Membership, Profile, Registration & Post Submission Plugin for WordPress Web Database Windows
N/A
UNKNOWN
EPSS
52.3%
2021 CWE-89 5 PoCs

The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of sanitisation and escaping, this could also lead to Reflected Cross-Site Scripting

CVE-2021-3164
Software Genérico Web
N/A
UNKNOWN
EPSS
20.8%
2021 1 PoC

ChurchRota 2.6.4 is vulnerable to authenticated remote code execution. The user does not need to have file upload permission in order to upload and execute an arbitrary file via a POST request to resources.php.

CVE-2021-3351
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

OpenPLC runtime V3 through 2016-03-14 allows stored XSS via the Device Name to the web server's Add New Device page.

CVE-2021-24965
Five Star Restaurant Reservations – WordPress Booking Plugin Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Scripting attacks against logged in admins

CVE-2021-25101
Anti-Malware Security and Brute-Force Firewall Web Networking Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.94 does not sanitise and escape the POST data before outputting it back in attributes of an admin page, leading to a Reflected Cross-Site scripting. Due to the presence of specific parameter value, available to admin users, this can only be exploited by an admin against another admin user.

CVE-2021-24904
Mortgage Calculators WP Web Windows
N/A
UNKNOWN
EPSS
3.0%
2021 CWE-79 1 PoC

The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the background of a calculator, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2021-24751
GenerateBlocks DevOps Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The GenerateBlocks WordPress plugin before 1.4.0 does not validate the generateblocks/container block's tagName attribute, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.

CVE-2021-45281
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

QuickBox Pro v2.4.8 contains a cross-site scripting (XSS) vulnerability at "adminuseredit.php?usertoedit=XSS", as the user supplied input for the value of this parameter is not properly sanitized.

CVE-2021-25120
Easy Social Feed Pro Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
25.6%
2021 CWE-79 1 PoC

The Easy Social Feed Free and Pro WordPress plugins before 6.2.7 do not sanitise some of their parameters used via AJAX actions before outputting them back in the response, leading to Reflected Cross-Site Scripting issues

CVE-2021-27320
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
26.7%
2021 2 PoCs

Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.

CVE-2021-46398
Software Genérico Web
N/A
UNKNOWN
EPSS
10.3%
2021 7 PoCs

A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilege and get access to the filesystem via a malicious HTML webpage that is sent to the victim. An admin can run commands using the FileBrowser and hence it leads to RCE.

CVE-2021-24611
Keyword Meta Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The Keyword Meta WordPress plugin through 3.0 does not sanitise of escape its settings before outputting them back in the page after they are saved, allowing for Cross-Site Scripting issues. Furthermore, it is also lacking any CSRF check, allowing attacker to make a logged in high privilege user save arbitrary setting via a CSRF attack.