3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-47872
SEO Panel Web Database
7.0
HIGH
EPSS
0.0%
2021 CWE-89 1 PoC

SEO Panel versions prior to 4.9.0 contain a blind SQL injection vulnerability in the archive.php page that allows authenticated attackers to manipulate database queries through the 'order_col' parameter. Attackers can use sqlmap to exploit the vulnerability and extract database information by injecting malicious SQL code into the order column parameter.

CVE-2021-47776
Umbraco Web
6.9
MEDIUM
EPSS
0.0%
2021 CWE-918 1 PoC

Umbraco CMS v8.14.1 contains a server-side request forgery vulnerability that allows attackers to manipulate baseUrl parameters in multiple dashboard and help controller endpoints. Attackers can craft malicious requests to the GetContextHelpForPage, GetRemoteDashboardContent, and GetRemoteDashboardCss endpoints to trigger unauthorized server-side requests to external hosts.

CVE-2021-47754
Arunna Web
6.9
MEDIUM
EPSS
0.0%
2021 CWE-352 1 PoC

Arunna 1.0.0 contains a cross-site request forgery vulnerability that allows attackers to manipulate user profile settings without authentication. Attackers can craft a malicious form to change user details, including passwords, email, and administrative privileges by tricking authenticated users into submitting the form.

CVE-2021-41174
grafana DevOps Web ⚡ nuclei
6.9
MEDIUM
EPSS
87.7%
2021 CWE-79 0 PoCs

Grafana is an open-source platform for monitoring and observability. In affected versions if an attacker is able to convince a victim to visit a URL referencing a vulnerable page, arbitrary JavaScript content may be executed within the context of the victim's browser. The user visiting the malicious link must be unauthenticated and the link must be for a page that contains the login button in the menu bar. The url has to be crafted to exploit AngularJS rendering and contain the interpolation binding for AngularJS expressions. AngularJS uses double curly braces for interpolation binding: {{ }}

CVE-2021-47703
OpenBMCS Web Networking
6.9
MEDIUM
EPSS
0.1%
2021 CWE-918 2 PoCs

OpenBMCS 2.4 contains an unauthenticated SSRF vulnerability that allows attackers to bypass firewalls and initiate service and network enumeration on the internal network through the affected application, allowing hijacking of current sessions. Attackers can specify an external domain in the 'ip' parameter to force the application to make an HTTP request to an arbitrary destination host.

CVE-2021-47723
STVS ProVision Web
6.9
MEDIUM
EPSS
0.0%
2021 CWE-352 2 PoCs

STVS ProVision 5.9.10 contains a cross-site request forgery vulnerability that allows attackers to perform actions with administrative privileges by exploiting unvalidated HTTP requests. Attackers can visit malicious web sites to trigger the forge request, allowing them to create new admin users.

CVE-2021-47800
b2evolution Web
6.9
MEDIUM
EPSS
0.0%
2021 CWE-352 1 PoC

b2evolution 7.2.2 contains a cross-site request forgery vulnerability that allows attackers to modify admin account details without authentication. Attackers can craft a malicious HTML form to submit unauthorized changes to user profiles by tricking victims into loading a specially crafted webpage.

CVE-2021-22238
GitLab DevOps Web
6.8
MEDIUM
EPSS
1.2%
2021 1 PoC

An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature in issues.

CVE-2021-3866
zulip/zulip Web
6.8
MEDIUM
EPSS
0.6%
2021 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip more than and including 44f935695d452cc3fb16845a0c6af710438b153d and prior to 3eb2791c3e9695f7d37ffe84e0c2184fae665cb6.

CVE-2021-3879
snipe/snipe-it Web
6.8
MEDIUM
EPSS
0.5%
2021 CWE-79 1 PoC

snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-29484
Ghost Web ⚡ nuclei
6.8
MEDIUM
EPSS
57.0%
2021 CWE-79 1 PoC

Ghost is a Node.js CMS. An unused endpoint added during the development of 4.0.0 has left sites vulnerable to untrusted users gaining access to Ghost Admin. Attackers can gain access by getting logged in users to click a link containing malicious code. Users do not need to enter credentials and may not know they've visited a malicious site. Ghost(Pro) has already been patched. We can find no evidence that the issue was exploited on Ghost(Pro) prior to the patch being added. Self-hosters are impacted if running Ghost a version between 4.0.0 and 4.3.2. Immediate action should be taken to secure

CVE-2021-43991
Kentico Xperience XMS Web
6.8
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

The Kentico Xperience CMS version 13.0 – 13.0.43 is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability (also known as Stored or Second-Order XSS). Persistent XSS vulnerabilities occur when the application stores and retrieves client supplied data without proper handling of dangerous content. This type of XSS vulnerability is exploited by submitting malicious script content to the application which is then retrieved and executed by other application users. The attacker could exploit this to conduct a range of attacks against users of the affected application such as session hij

CVE-2021-4103
vanessa219/vditor Web
6.8
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 1.0.34.

CVE-2021-2414
Communications Session Border Controller Web Database
6.8
MEDIUM
EPSS
0.4%
2021 1 PoC

Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications (component: Routing). Supported versions that are affected are 8.4 and 9.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Session Border Controller. While the vulnerability is in Oracle Communications Session Border Controller, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communi

CVE-2021-2151
PeopleSoft Enterprise PT PeopleTools Web Database
6.7
MEDIUM
EPSS
0.4%
2021 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and

CVE-2021-3812
pi-hole/adminlte Web
6.7
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-23814
unisharp/laravel-filemanager Web
6.7
MEDIUM
EPSS
2.1%
2021 CWE-94 3 PoCs

This affects versions of the package unisharp/laravel-filemanager before 2.6.2. The upload() function does not sufficiently validate the file type when uploading. An attacker may be able to reproduce the following steps: 1. Install a package with a web Laravel application. 2. Navigate to the Upload window 3. Upload an image file, then capture the request 4. Edit the request contents with a malicious file (webshell) 5. Enter the path of file uploaded on URL - Remote Code Execution **Note:** Prevention for bad extensions can be done by using a whitelist in the config file(lfm.php). Correspon

CVE-2021-3811
pi-hole/adminlte Web
6.7
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-4175
livehelperchat/livehelperchat Web
6.6
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-4179
livehelperchat/livehelperchat Web
6.6
MEDIUM
EPSS
0.1%
2021 CWE-79 1 PoC

livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')