3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-36654
Software Genérico Web
N/A
UNKNOWN
EPSS
2.6%
2021 1 PoC

CMSuno 1.7 is vulnerable to an authenticated stored cross site scripting in modifying the filename parameter (tgo) while updating the theme.

CVE-2021-38374
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 4 PoCs

OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL.

CVE-2021-28382
Software Genérico Web
N/A
UNKNOWN
EPSS
18.0%
2021 1 PoC

Zoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious user details from AD.

CVE-2021-28006
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Web Based Quiz System 1.0 is affected by cross-site scripting (XSS) in admin.php through the options parameter.

CVE-2021-33849
Zoho CRM Lead Magnet Web
N/A
UNKNOWN
EPSS
2.2%
2021 2 PoCs

A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser is connected to a trusted website. The attack targets your application's users and not the application itself while using your application as the attack's vehicle. The XSS payload executes whenever the user changes the form values or deletes a created form in Zoho CRM Lead Magnet Version 1.7.2.4.

CVE-2021-24175
The Plus Addons for Elementor Page Builder Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
89.6%
2021 CWE-287 2 PoCs

The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to bypass authentication, allowing unauthenticated users to log in as any user (including admin) by just providing the related username, as well as create accounts with arbitrary roles, such as admin. These issues can be exploited even if registration is disabled, and the Login widget is not active.

CVE-2021-28420
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via alerts.php and the "from_time" parameter.

CVE-2021-38153
Apache Kafka Web
N/A
UNKNOWN
EPSS
1.2%
2021 CWE-203 3 PoCs

Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0.

CVE-2021-24911
Transposh WordPress Translation Web Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-79 1 PoC

The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the tk0 parameter from the tp_translation AJAX action, leading to Stored Cross-Site Scripting, which will trigger in the admin dashboard of the plugin. The minimum role needed to perform such attack depends on the plugin "Who can translate ?" setting.

CVE-2021-24793
WPeMatico RSS Feed Fetcher Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.6.12 does not escape the Feed URL added to a campaign before outputting it in an attribute, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2021-33831
Software Genérico Web
N/A
UNKNOWN
EPSS
8.0%
2021 1 PoC

api/account/register in the TH Wildau COVID-19 Contact Tracing application through 2021-09-01 has Incorrect Access Control. An attacker can interfere with tracing of infection chains by creating 500 random users within 2500 seconds.

CVE-2021-24287
Select All Categories and Taxonomies, Change Checkbox to Radio Buttons Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
22.3%
2021 CWE-79 2 PoCs

The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue

CVE-2021-42224
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2021 3 PoCs

SQL Injection vulnerability exists in IFSC Code Finder Project 1.0 via the searchifsccode POST parameter in /search.php.

CVE-2021-22696
Apache CXF Web
N/A
UNKNOWN
EPSS
2.0%
2021 CWE-918 2 PoCs

CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR)). Instead of sending a JWT token as a "request" parameter, the spec also supports specifying a URI from which to retrieve a JWT token from via the "request_uri" parameter. CXF was not validating the "request_uri" parameter (apart from ensuring it uses "https) and was making a REST request to the parameter in the request to retrieve a token. This means that CXF was vulnerable to DDos attacks on the

CVE-2021-38296
Apache Spark Web
N/A
UNKNOWN
EPSS
2.1%
2021 CWE-294 1 PoC

Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for full encryption key recovery. After an initial interactive attack, this would allow someone to decrypt plaintext traffic offline. Note that this does not affect security mechanisms controlled by "spark.authenticate.enableSaslEncryption", "spark.io.encryption.enabled", "spark.ssl", "spark.ui.strictTransportSecurity". Update to Apache Spark 3.1.3 or later

CVE-2021-24711
Software License Manager Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The del_reistered_domains AJAX action of the Software License Manager WordPress plugin before 4.5.1 does not have any CSRF checks, and is vulnerable to a CSRF attack

CVE-2021-24476
Steam Group Viewer Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The Steam Group Viewer WordPress plugin through 2.1 does not sanitise or escape its "Steam Group Address" settings before outputting it in the page, leading to an authenticated Stored Cross-Site Scripting issue

CVE-2021-30133
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

A cross-site scripting (XSS) vulnerability in CloverDX Server 5.9.0, CloverDX 5.8.1, CloverDX 5.7.0, and earlier allows remote attackers to inject arbitrary web script or HTML via the sessionToken parameter of multiple methods in Simple HTTP API. This is resolved in 5.9.1 and 5.10.

CVE-2021-42077
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.8%
2021 2 PoCs

PHP Event Calendar before 2021-09-03 allows SQL injection, as demonstrated by the /server/ajax/user_manager.php username parameter. This can be used to execute SQL statements directly on the database, allowing an adversary in some cases to completely compromise the database system. It can also be used to bypass the login form.

CVE-2021-38603
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2021 2 PoCs

PluXML 5.8.7 allows core/admin/profil.php stored XSS via the Information field.