3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-24389
WP Foodbakery Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
13.9%
2021 CWE-79 1 PoC

The WP Foodbakery WordPress plugin before 2.2, used in the FoodBakery WordPress theme before 2.2 did not properly sanitize the foodbakery_radius parameter before outputting it back in the response, leading to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability.

CVE-2021-38377
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results.

CVE-2021-26078
Jira Server Web
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from version 8.14.0 before version 8.16.1 allows remote attackers inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability.

CVE-2021-41652
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database.

CVE-2021-33963
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
4.0%
2021 1 PoC

China Mobile An Lianbao WF-1 v1.0.1 router web interface through /api/ZRMacClone/mac_addr_clone receives parameters by POST request, and the parameter macType has a command injection vulnerability. An attacker can use the vulnerability to execute remote commands.

CVE-2021-24989
Accept Donations with PayPal Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure that the post to be deleted belongs to the plugin, allowing attackers to make a logged in admin delete arbitrary posts from the blog

CVE-2021-24316
Mediumish Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
57.4%
2021 CWE-79 2 PoCs

The search feature of the Mediumish WordPress theme through 1.0.47 does not properly sanitise it's 's' GET parameter before output it back the page, leading to the Cross-SIte Scripting issue.

CVE-2021-27200
Software Genérico Web
N/A
UNKNOWN
EPSS
3.0%
2021 1 PoC

In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The code parameter is easily predicted from the time of day.

CVE-2021-24630
Schreikasten Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-89 2 PoCs

The Schreikasten WordPress plugin through 0.14.18 does not sanitise or escape the id GET parameter before using it in SQL statements in the comments dashboard from various actions, leading to authenticated SQL Injections which can be exploited by users as low as author

CVE-2021-24457
Portfolio Responsive Gallery Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The get_portfolios() and get_portfolio_attributes() functions in the class-portfolio-responsive-gallery-list-table.php and class-portfolio-responsive-gallery-attributes-list-table.php files of the Portfolio Responsive Gallery WordPress plugin before 1.1.8 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

CVE-2021-31152
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
1.4%
2021 2 PoCs

Multilaser Router AC1200 V02.03.01.45_pt contains a cross-site request forgery (CSRF) vulnerability. An attacker can enable remote access, change passwords, and perform other actions through misconfigured requests, entries, and headers.

CVE-2021-24813
Events Made Easy Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Events Made Easy WordPress plugin before 2.2.24 does not sanitise and escape Custom Field Names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2021-24923
Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape the sib-statistics-date parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue

CVE-2021-24730
Logo Showcase with Slick Slider – Logo Carousel, Logo Slider & Logo Grid Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-862 1 PoC

The Logo Showcase with Slick Slider WordPress plugin before 1.2.5 does not have CSRF and authorisation checks in the lswss_save_attachment_data AJAX action, allowing any authenticated users, such as Subscriber, to change title, description, alt text, and URL of arbitrary uploaded media.

CVE-2021-43512
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered in FlightRadar24 v8.9.0, v8.10.0, v8.10.2, v8.10.3, v8.10.4 for Android, allows attackers to cause unspecified consequences due to being able to decompile a local application and extract their API keys.

CVE-2021-35043
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2021 4 PoCs

OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with &#00058 as the replacement for the : character.

CVE-2021-24305
Target First Plugin Web Windows
N/A
UNKNOWN
EPSS
2.3%
2021 CWE-79 1 PoC

The Target First WordPress Plugin v2.0, also previously known as Watcheezy, suffers from a critical unauthenticated stored XSS vulnerability. An attacker could change the licence key value through a POST on any URL with the 'weeWzKey' parameter that will be save as the 'weeID option and is not sanitized.

CVE-2021-36646
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.2%
2021 0 PoCs

A Cross Site Scrtpting (XSS) vulnerability in KodExplorer 4.45 allows remote attackers to run arbitrary code via /index.php page.