3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-36805
Akaunting Web
5.2
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in the sales invoice processing component of the application. This issue was fixed in version 2.1.13 of the product.

CVE-2021-45677
Software Genérico Web
5.2
MEDIUM
EPSS
0.4%
2021 1 PoC

Certain NETGEAR devices are affected by stored XSS. This affects GS108Tv2 before 5.4.2.36 and GS110TPv2 before 5.4.2.36.

CVE-2021-47843
Tagstoo Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Tagstoo 2.0.1 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious payloads through files or custom tags. Attackers can execute arbitrary JavaScript code to spawn system processes, access files, and perform remote code execution on the victim's computer.

CVE-2021-47873
VestaCP Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

VestaCP versions prior to 0.9.8-25 contain a cross-site scripting vulnerability in the IP interface configuration that allows attackers to inject malicious scripts. Attackers can exploit the 'v_interface' parameter by sending a crafted POST request to the add/ip/ endpoint with a stored XSS payload.

CVE-2021-47842
StudyMD Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 2 PoCs

StudyMD 0.3.2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into markdown files. Attackers can upload crafted markdown files with embedded JavaScript payloads that execute when the file is opened, potentially enabling remote code execution.

CVE-2021-47914
PHP Melody Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

PHP Melody version 3.0 contains a persistent cross-site scripting vulnerability in the edit-video.php submitted parameter that allows remote attackers to inject malicious script code. Attackers can exploit this vulnerability to execute arbitrary JavaScript, potentially leading to session hijacking, persistent phishing, and manipulation of application modules.

CVE-2021-25453
Samsung Mobile Devices Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-20 1 PoC

Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluetooth information.

CVE-2021-47729
Selea Targa IP OCR-ANPR Camera Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 2 PoCs

Selea Targa IP OCR-ANPR Camera contains a stored cross-site scripting vulnerability in the 'files_list' parameter that allows attackers to inject malicious HTML and script code. Attackers can send a POST request to /cgi-bin/get_file.php with crafted payload to execute arbitrary scripts in victim's browser session.

CVE-2021-47743
COMMAX Biometric Access Control System Web
5.1
MEDIUM
EPSS
0.1%
2021 CWE-79 1 PoC

COMMAX Biometric Access Control System 1.0.0 contains an unauthenticated reflected cross-site scripting vulnerability in cookie parameters 'CMX_ADMIN_NM' and 'CMX_COMPLEX_NM'. Attackers can inject malicious HTML and JavaScript code into these cookie values to execute arbitrary scripts in a victim's browser session.

CVE-2021-47885
PayPal PRO Payment Terminal Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Multiple payment terminal versions contain non-persistent cross-site scripting vulnerabilities in billing and payment information input fields. Attackers can inject malicious script code through vulnerable parameters to manipulate client-side requests and potentially execute session hijacking or phishing attacks.

CVE-2021-47844
Xmind Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 2 PoCs

Xmind 2020 contains a cross-site scripting vulnerability that allows attackers to inject malicious payloads into mind mapping files or custom headers. Attackers can craft malicious files with embedded JavaScript that execute system commands when opened, enabling remote code execution through mouse interactions or file opening.

CVE-2021-47839
Marky Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 2 PoCs

Marky 0.0.1 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into markdown files. Attackers can upload crafted markdown files with embedded JavaScript payloads that execute when the file is opened, potentially enabling remote code execution.

CVE-2021-47738
CSZ CMS Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

CSZ CMS 1.2.7 contains a persistent cross-site scripting vulnerability that allows unauthorized users to embed malicious JavaScript in private messages. Attackers can send messages with script payloads in the user-agent header, which will execute when an admin views the message in the backend dashboard.

CVE-2021-47750
YouPHPTube Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

YouPHPTube <= 7.8 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the redirectUri parameter in the signup page. Attackers can craft special signup URLs with embedded script tags to execute arbitrary JavaScript in victims' browsers when they access the signup page.

CVE-2021-47905
MyBB Delete Account Plugin Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

MyBB Delete Account Plugin 1.4 contains a cross-site scripting vulnerability in the account deletion reason input field. Attackers can inject malicious scripts that will execute in the admin interface when viewing delete account reasons.

CVE-2021-47897
PEEL Shopping Web
5.1
MEDIUM
EPSS
0.1%
2021 CWE-79 1 PoC

PEEL Shopping 9.3.0 contains a stored cross-site scripting vulnerability in the address parameter of the change_params.php script. Attackers can inject malicious JavaScript payloads that execute when users interact with the address text box, potentially enabling client-side script execution.

CVE-2021-47841
SnipCommand Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 2 PoCs

SnipCommand 0.1.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious payloads into command snippets. Attackers can execute arbitrary code by embedding malicious JavaScript that triggers remote command execution through file or title inputs.

CVE-2021-47892
PEEL Shopping Web
5.1
MEDIUM
EPSS
0.1%
2021 CWE-79 1 PoC

PEEL Shopping 9.3.0 contains a stored cross-site scripting vulnerability in the 'Comments / Special Instructions' parameter of the purchase page. Attackers can inject malicious JavaScript payloads that will execute when the page is refreshed, potentially allowing client-side script execution.

CVE-2021-47834
Schlix CMS Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Schlix CMS 2.2.6-6 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into category titles. Attackers can create a new contact category with a script payload that will execute when the page is viewed by other users.

CVE-2021-47906
BloofoxCMS Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

BloofoxCMS 0.5.2.1 contains a stored cross-site scripting vulnerability in the articles text parameter that allows authenticated attackers to inject malicious scripts. Attackers can insert malicious javascript payloads in the text field to execute scripts and potentially steal authenticated users' cookies.