3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-24413
Easy Twitter Feed Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Easy Twitter Feed WordPress plugin before 1.2 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode

CVE-2021-24427
W3 Total Cache Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The W3 Total Cache WordPress plugin before 2.1.3 did not sanitise or escape some of its CDN settings, allowing high privilege users to use JavaScript in them, which will be output in the page, leading to an authenticated Stored Cross-Site Scripting issue

CVE-2021-25101
Anti-Malware Security and Brute-Force Firewall Web Networking Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.94 does not sanitise and escape the POST data before outputting it back in attributes of an admin page, leading to a Reflected Cross-Site scripting. Due to the presence of specific parameter value, available to admin users, this can only be exploited by an admin against another admin user.

CVE-2021-24904
Mortgage Calculators WP Web Windows
N/A
UNKNOWN
EPSS
3.0%
2021 CWE-79 1 PoC

The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the background of a calculator, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2021-24751
GenerateBlocks DevOps Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The GenerateBlocks WordPress plugin before 1.4.0 does not validate the generateblocks/container block's tagName attribute, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.

CVE-2021-45281
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

QuickBox Pro v2.4.8 contains a cross-site scripting (XSS) vulnerability at "adminuseredit.php?usertoedit=XSS", as the user supplied input for the value of this parameter is not properly sanitized.

CVE-2021-25120
Easy Social Feed Pro Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
25.6%
2021 CWE-79 1 PoC

The Easy Social Feed Free and Pro WordPress plugins before 6.2.7 do not sanitise some of their parameters used via AJAX actions before outputting them back in the response, leading to Reflected Cross-Site Scripting issues

CVE-2021-27320
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
26.7%
2021 2 PoCs

Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.

CVE-2021-46398
Software Genérico Web
N/A
UNKNOWN
EPSS
10.3%
2021 7 PoCs

A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilege and get access to the filesystem via a malicious HTML webpage that is sent to the victim. An admin can run commands using the FileBrowser and hence it leads to RCE.

CVE-2021-24611
Keyword Meta Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The Keyword Meta WordPress plugin through 3.0 does not sanitise of escape its settings before outputting them back in the page after they are saved, allowing for Cross-Site Scripting issues. Furthermore, it is also lacking any CSRF check, allowing attacker to make a logged in high privilege user save arbitrary setting via a CSRF attack.

CVE-2021-31812
Apache PDFBox Web
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-834 4 PoCs

In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.

CVE-2021-29002
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

A stored cross-site scripting (XSS) vulnerability in Plone CMS 5.2.3 exists in site-controlpanel via the "form.widgets.site_title" parameter.

CVE-2021-33818
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

An issue was discovered in UniFi Protect G3 FLEX Camera Version UVC.v4.30.0.67. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. Then the web server is denial-of-service.

CVE-2021-24859
User meta shortcodes Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-284 1 PoC

The User Meta Shortcodes WordPress plugin through 0.5 registers a shortcode that allows any user with a role as low as contributor to access other users metadata by specifying the user login as a parameter. This makes the WP instance vulnerable to data extrafiltration, including password hashes

CVE-2021-24809
BP Better Messages Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-352 1 PoC

The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_better_messages_leave_chat, bp_better_messages_join_chat, bp_messages_leave_thread, bp_messages_mute_thread, bp_messages_unmute_thread, bp_better_messages_add_user_to_thread, bp_better_messages_exclude_user_from_thread. This could allow attackers to make logged in users do unwanted actions

CVE-2021-26303
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the user-profile.php Full Name field.

CVE-2021-41492
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

Multiple SQL Injection vulnerabilities exist in Sourcecodester Simple Cashiering System (POS) 1.0 via the (1) Product Code in the pos page in cashiering. (2) id parameter in manage_products and the (3) t paramater in actions.php.

CVE-2021-33616
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

RSA Archer 6.x through 6.9 SP1 P4 (6.9.1.4) allows stored XSS.

CVE-2021-41847
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

An issue was discovered in 3xLogic Infinias Access Control through 6.7.10708.0, affecting physical security. Users with login credentials assigned to a specific zone can send modified HTTP GET and POST requests, allowing them to view user data such as personal information and Prox card credentials. Also, an authorized user of one zone can send API requests to unlock electronic locks associated with zones they are unauthorized to have access to. They can also create new user logins for zones they were not authorized to access, including the root zone of the software.

CVE-2021-24910
Transposh WordPress Translation Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
14.6%
2021 CWE-79 1 PoC

The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the a parameter via an AJAX action (available to both unauthenticated and authenticated users when the curl library is installed) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue