3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-24451
Export Users With Meta Web Database Windows
N/A
UNKNOWN
EPSS
1.0%
2021 CWE-89 1 PoC

The Export Users With Meta WordPress plugin before 0.6.5 did not escape the list of roles to export before using them in a SQL statement in the export functionality, available to admins, leading to an authenticated SQL Injection.

CVE-2021-24447
WP Image Zoom Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-22 1 PoC

The WP Image Zoom WordPress plugin before 1.47 did not validate its tab parameter before using it in the include_once() function, leading to a local file inclusion issue in the admin dashboard

CVE-2021-45815
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Quectel UC20 UMTS/HSPA+ UC20 6.3.14 is affected by a Cross Site Scripting (XSS) vulnerability.

CVE-2021-24478
Bookshelf Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The Bookshelf WordPress plugin through 2.0.4 does not sanitise or escape its "Paypal email address" setting before outputting it in the page, leading to an authenticated Stored Cross-Site Scripting issue

CVE-2021-3509
ceph-dashboard Web
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-79 1 PoC

A flaw was found in Red Hat Ceph Storage 4, in the Dashboard component. In response to CVE-2020-27839, the JWT token was moved from localStorage to an httpOnly cookie. However, token cookies are used in the body of the HTTP response for the documentation, which again makes it available to XSS.The greatest threat to the system is for confidentiality, integrity, and availability.

CVE-2021-27513
Software Genérico Web
N/A
UNKNOWN
EPSS
44.4%
2021 2 PoCs

The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files because it relies on "le filtre userside."

CVE-2021-36654
Software Genérico Web
N/A
UNKNOWN
EPSS
2.6%
2021 1 PoC

CMSuno 1.7 is vulnerable to an authenticated stored cross site scripting in modifying the filename parameter (tgo) while updating the theme.

CVE-2021-24812
BetterLinks – Shorten, Track and Manage any URL Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lead to Stored Cross-Site Scripting issues when an admin import a malicious CSV.

CVE-2021-24336
FlightLog Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 2 PoCs

The FlightLog WordPress plugin through 3.0.2 does not sanitise, validate or escape various POST parameters before using them a SQL statement, leading to SQL injections exploitable by editor and administrator users

CVE-2021-45086
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js.

CVE-2021-28382
Software Genérico Web
N/A
UNKNOWN
EPSS
18.0%
2021 1 PoC

Zoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious user details from AD.

CVE-2021-28006
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Web Based Quiz System 1.0 is affected by cross-site scripting (XSS) in admin.php through the options parameter.

CVE-2021-33849
Zoho CRM Lead Magnet Web
N/A
UNKNOWN
EPSS
2.2%
2021 2 PoCs

A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser is connected to a trusted website. The attack targets your application's users and not the application itself while using your application as the attack's vehicle. The XSS payload executes whenever the user changes the form values or deletes a created form in Zoho CRM Lead Magnet Version 1.7.2.4.

CVE-2021-24175
The Plus Addons for Elementor Page Builder Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
89.6%
2021 CWE-287 2 PoCs

The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to bypass authentication, allowing unauthenticated users to log in as any user (including admin) by just providing the related username, as well as create accounts with arbitrary roles, such as admin. These issues can be exploited even if registration is disabled, and the Login widget is not active.

CVE-2021-28420
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via alerts.php and the "from_time" parameter.

CVE-2021-38153
Apache Kafka Web
N/A
UNKNOWN
EPSS
1.2%
2021 CWE-203 3 PoCs

Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0.

CVE-2021-24911
Transposh WordPress Translation Web Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-79 1 PoC

The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the tk0 parameter from the tp_translation AJAX action, leading to Stored Cross-Site Scripting, which will trigger in the admin dashboard of the plugin. The minimum role needed to perform such attack depends on the plugin "Who can translate ?" setting.

CVE-2021-24793
WPeMatico RSS Feed Fetcher Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.6.12 does not escape the Feed URL added to a campaign before outputting it in an attribute, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2021-33831
Software Genérico Web
N/A
UNKNOWN
EPSS
8.0%
2021 1 PoC

api/account/register in the TH Wildau COVID-19 Contact Tracing application through 2021-09-01 has Incorrect Access Control. An attacker can interfere with tracing of infection chains by creating 500 random users within 2500 seconds.

CVE-2021-24287
Select All Categories and Taxonomies, Change Checkbox to Radio Buttons Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
22.3%
2021 CWE-79 2 PoCs

The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue