3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-2275
Applications Manager Web Database
6.5
MEDIUM
EPSS
1.3%
2021 1 PoC

Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: View Reports). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Applications Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Applications Manager acce

CVE-2021-45667
Software Genérico Web
6.5
MEDIUM
EPSS
0.4%
2021 1 PoC

Certain NETGEAR devices are affected by stored XSS. This affects CBR40 before 2.5.0.10, EAX20 before 1.0.0.48, EAX80 before 1.0.1.64, EX6120 before 1.0.0.64, EX6130 before 1.0.0.44, EX7500 before 1.0.0.72, R7960P before 1.4.1.66, RAX200 before 1.0.3.106, RBS40V before 2.6.1.4, RBW30 before 2.6.1.4, EX3700 before 1.0.0.90, MR60 before 1.0.6.110, R8000P before 1.4.1.66, RAX20 before 1.0.2.82, RAX45 before 1.0.2.72, RAX80 before 1.0.3.106, EX3800 before 1.0.0.90, MS60 before 1.0.6.110, R7900P before 1.4.1.66, RAX15 before 1.0.2.82, RAX50 before 1.0.2.72, RAX75 before 1.0.3.106, RBR750 before 3.2.

CVE-2021-31882
Capital Embedded AR Classic 431-422 Web
6.5
MEDIUM
EPSS
1.4%
2021 CWE-119 1 PoC

A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303). The DHCP client application does not validate the length of the Domain Name Server IP option(s) (0x06) when processing DHCP ACK packets. This may lead to Denial-of-Service conditions. (FSMD-2021-0011)

CVE-2021-3728
firefly-iii/firefly-iii Web
6.5
MEDIUM
EPSS
0.1%
2021 CWE-352 1 PoC

firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2021-4445
Premium Addons for Elementor – Powerful Elementor Templates & Widgets Web Windows
6.5
MEDIUM
EPSS
0.1%
2021 CWE-862 1 PoC

The Premium Addons for Elementor plugin for WordPress is vulnerable to Arbitrary Option Updates in versions up to, and including, 4.5.1. This is due to missing capability and nonce checks in the pa_dismiss_admin_notice AJAX action. This makes it possible for authenticated subscriber+ attackers to change arbitrary options with a restricted value of 1 on vulnerable WordPress sites.

CVE-2021-4033
kevinpapst/kimai2 Web
6.5
MEDIUM
EPSS
0.1%
2021 CWE-352 1 PoC

kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2021-43847
humhub Web
6.5
MEDIUM
EPSS
0.3%
2021 CWE-285 1 PoC

HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to become unauthorized members of private Spaces. Versions 1.10.3 and 1.9.3 contain a patch for this issue.

CVE-2021-3853
chaskiq/chaskiq Web
6.5
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

chaskiq is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-36092
((OTRS)) Community Edition Web
6.5
MEDIUM
EPSS
0.4%
2021 CWE-79 1 PoC

It's possible to create an email which contains specially crafted link and it can be used to perform XSS attack. This issue affects: OTRS AG ((OTRS)) Community Edition:6.0.x version 6.0.1 and later versions. OTRS AG OTRS: 7.0.x version 7.0.27 and prior versions; 8.0.x version 8.0.14 and prior versions.

CVE-2021-21816
D-LINK Web ⚡ nuclei
6.5
MEDIUM
EPSS
77.3%
2021 CWE-200 1 PoC

An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to the disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-4121
yetiforcecompany/yetiforcecrm Web
6.4
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-32644
ampache Web
6.4
MEDIUM
EPSS
0.4%
2021 CWE-79 1 PoC

Ampache is an open source web based audio/video streaming application and file manager. Due to a lack of input filtering versions 4.x.y are vulnerable to code injection in random.php. The attack requires user authentication to access the random.php page unless the site is running in demo mode. This issue has been resolved in 4.4.3.

CVE-2021-2366
Primavera P6 Enterprise Project Portfolio Management Web Database
6.4
MEDIUM
EPSS
0.2%
2021 1 PoC

Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 17.12.0-17.12.20, 18.8.0-18.8.23, 19.12.0-19.12.14 and 20.12.0-20.12.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management. While the vulnerability is in Primavera P6 Enterprise Project Portfolio Management, attacks may significantly impact additional products. Successful attacks of this vulnerability c

CVE-2021-4108
snipe/snipe-it Web
6.4
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-27909
Mautic Web ⚡ nuclei
6.3
MEDIUM
EPSS
18.7%
2021 CWE-79 0 PoCs

For Mautic versions prior to 3.3.4/4.0.0, there is an XSS vulnerability on Mautic's password reset page where a vulnerable parameter, "bundle," in the URL could allow an attacker to execute Javascript code. The attacker would be required to convince or trick the target into clicking a password reset URL with the vulnerable parameter utilized.

CVE-2021-3539
EspoCRM Web
6.3
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

EspoCRM 6.1.6 and prior suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar images. This issue was fixed in version 6.1.7 of the product.

CVE-2021-3904
getgrav/grav Web
6.3
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

grav is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-4242
BR270n Web
6.3
MEDIUM
EPSS
10.5%
2021 CWE-707 2 PoCs

A vulnerability was found in Sapido BR270n, BRC76n, GR297 and RB1732 and classified as critical. Affected by this issue is some unknown functionality of the file ip/syscmd.htm. The manipulation leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-214592.

CVE-2021-3983
kevinpapst/kimai2 Web
6.3
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-23400
nodemailer Web
6.3
MEDIUM
EPSS
0.5%
2021 2 PoCs

The package nodemailer before 6.6.1 are vulnerable to HTTP Header Injection if unsanitized user input that may contain newlines and carriage returns is passed into an address object.