3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-26810
Software Genérico Web
N/A
UNKNOWN
EPSS
34.3%
2021 1 PoC

D-link DIR-816 A2 v1.10 is affected by a remote code injection vulnerability. An HTTP request parameter can be used in command string construction in the handler function of the /goform/dir_setWanWifi, which can lead to command injection via shell metacharacters in the statuscheckpppoeuser parameter.

CVE-2021-43528
Thunderbird Web
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level privileges, but could be used as a stepping stone to further an attack with other vulnerabilities. This vulnerability affects Thunderbird < 91.4.0.

CVE-2021-20073
Racom MIDGE Firmware Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for cross-site request forgeries.

CVE-2021-35478
Software Genérico Web
N/A
UNKNOWN
EPSS
49.2%
2021 2 PoCs

Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. All parameters used for filtering are affected. This affects users who open a crafted link or third-party web page.

CVE-2021-3441
HP OfficeJet 7110 Wide Format ePrinter Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross-Site Scripting (XSS).

CVE-2021-20748
Retty App Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Retty App for Android versions prior to 4.8.13 and Retty App for iOS versions prior to 4.11.14 uses a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtained by analyzing data in the app.

CVE-2021-46080
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

A Cross Site Request Forgery (CSRF) vulnerability exists in Vehicle Service Management System 1.0. An successful CSRF attacks leads to Stored Cross Site Scripting Vulnerability.

CVE-2021-25043
WOOCS – Currency Switcher for WooCommerce. Professional and Free multi currency plugin – Pay in selected currency Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The WOOCS WordPress plugin before 1.3.7.3 does not sanitise and escape the custom_prices parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue

CVE-2021-25281
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.8%
2021 2 PoCs

An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attacker can remotely run any wheel modules on the master.

CVE-2021-37542
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains TeamCity before 2020.2.3, XSS was possible.

CVE-2021-25106
Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages WordPress plugin before 2.7.1 does not check for authorisation and has a flawed CSRF logic when saving its settings, allowing any authenticated users, such as subscriber, to update them. Furthermore, due to the lack of sanitisation and escaping, it could lead to Stored Cross-Site Scripting

CVE-2021-45380
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.7%
2021 0 PoCs

AppCMS 2.0.101 has a XSS injection vulnerability in \templates\m\inc_head.php

CVE-2021-24693
Simple Download Monitor Web Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-79 1 PoC

The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputting it in some pages, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. Given the that XSS is triggered even when the Download is in a review state, contributor could make JavaScript code execute in a context of a reviewer such as admin and make them create a rogue admin account, or install a malicious plugin

CVE-2021-44117
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2021 2 PoCs

A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/sitevariables/delete/4.

CVE-2021-37330
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Laravel Booking System Booking Core 2.0 is vulnerable to Cross Site Scripting (XSS). The Avatar upload in the My Profile section could be exploited to upload a malicious SVG file which contains Javascript. Now if another user/admin views the profile and clicks to view his avatar, an XSS will trigger.

CVE-2021-45815
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Quectel UC20 UMTS/HSPA+ UC20 6.3.14 is affected by a Cross Site Scripting (XSS) vulnerability.

CVE-2021-24478
Bookshelf Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The Bookshelf WordPress plugin through 2.0.4 does not sanitise or escape its "Paypal email address" setting before outputting it in the page, leading to an authenticated Stored Cross-Site Scripting issue

CVE-2021-3509
ceph-dashboard Web
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-79 1 PoC

A flaw was found in Red Hat Ceph Storage 4, in the Dashboard component. In response to CVE-2020-27839, the JWT token was moved from localStorage to an httpOnly cookie. However, token cookies are used in the body of the HTTP response for the documentation, which again makes it available to XSS.The greatest threat to the system is for confidentiality, integrity, and availability.

CVE-2021-27513
Software Genérico Web
N/A
UNKNOWN
EPSS
44.4%
2021 2 PoCs

The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files because it relies on "le filtre userside."

CVE-2021-36654
Software Genérico Web
N/A
UNKNOWN
EPSS
2.6%
2021 1 PoC

CMSuno 1.7 is vulnerable to an authenticated stored cross site scripting in modifying the filename parameter (tgo) while updating the theme.