3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-2315
HTTP Server Web Database
5.4
MEDIUM
EPSS
0.6%
2021 1 PoC

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HTTP Server accessible data as well as unauthorized read access to a subset of Oracle H

CVE-2021-20350
Rational Quality Manager Web
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194707.

CVE-2021-23387
trailing-slash Web
5.4
MEDIUM
EPSS
0.3%
2021 2 PoCs

The package trailing-slash before 2.0.1 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as https://example.com//attacker.example/). The vulnerable code is in index.js::createTrailing(), as the web server uses relative URLs instead of absolute URLs.

CVE-2021-25977
Piranha Web
5.4
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

In PiranhaCMS, versions 7.0.0 to 9.1.1 are vulnerable to stored XSS due to the page title improperly sanitized. By creating a page with a specially crafted page title, a low privileged user can trigger arbitrary JavaScript execution.

CVE-2021-23648
@braintree/sanitize-url Web
5.4
MEDIUM
EPSS
0.1%
2021 1 PoC

The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.

CVE-2021-35553
PeopleSoft Enterprise CS Student Records Web Database
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Class Search). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Records. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise CS Student Records, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized updat

CVE-2021-25967
ckan Web
5.4
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

In CKAN, versions 2.9.0 to 2.9.3 are affected by a stored XSS vulnerability via SVG file upload of users’ profile picture. This allows low privileged application users to store malicious scripts in their profile picture. These scripts are executed in a victim’s browser when they open the malicious profile picture

CVE-2021-34590
CC612 Web
5.4
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

In Bender/ebee Charge Controllers in multiple versions are prone to Cross-site Scripting. An authenticated attacker could write HTML Code into configuration values. These values are not properly escaped when displayed.

CVE-2021-3768
bookstackapp/bookstack Web
5.4
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-2117
Application Express (APEX) Web Database
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

Vulnerability in the Oracle Application Express Survey Builder component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Survey Builder. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express Survey Builder, attacks may significantly impact additional products. Successful attacks of this vulnerability ca

CVE-2021-25059
Download Plugin Web Windows
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

The Download Plugin WordPress plugin before 2.0.0 does not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download a full copy of the website.

CVE-2021-20340
Rational DOORS Next Generation Web
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194451.

CVE-2021-25988
ifme Web
5.4
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability (notifications section) which can be directly triggered by sending an ally request to the admin.

CVE-2021-2346
Commerce Guided Search / Oracle Commerce Experience Manager Web Database
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Tools and Frameworks). The supported version that is affected is 11.3.1.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact addit

CVE-2021-33600
F-Secure Internet Gatekeeper Web
5.4
MEDIUM
EPSS
0.4%
2021 1 PoC

A denial-of-service (DoS) vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper. The vulnerability occurs because of an attacker can trigger assertion via malformed HTTP packet to web interface. An unauthenticated attacker could exploit this vulnerability by sending a large username parameter. A successful exploitation could lead to a denial-of-service of the product.

CVE-2021-43657
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2021 2 PoCs

A Stored Cross-site scripting (XSS) vulnerability via MAster.php in Sourcecodetester Simple Client Management System (SCMS) 1.0 allows remote attackers to inject arbitrary web script or HTML via the vulnerable input fields.

CVE-2021-25968
opencms-core Web
5.4
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

In “OpenCMS”, versions 10.5.0 to 11.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the Sitemap functionality. These scripts are executed in a victim’s browser when they open the page containing the vulnerable field.

CVE-2021-2116
Application Express (APEX) Web Database
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

Vulnerability in the Oracle Application Express Opportunity Tracker component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Opportunity Tracker. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express Opportunity Tracker, attacks may significantly impact additional products. Successful attacks of this v

CVE-2021-41074
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2021 1 PoC

A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document.

CVE-2021-35571
PeopleSoft Enterprise CS Academic Advisement Web Database
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

Vulnerability in the PeopleSoft Enterprise CS Academic Advisement product of Oracle PeopleSoft (component: Advising Notes). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Academic Advisement. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise CS Academic Advisement accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise CS Academic Advisement accessib