3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-2033
WebLogic Server Web Database
4.3
MEDIUM
EPSS
0.3%
2021 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).

CVE-2021-4386
WP Security Question Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The WP Security Question plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-3963
kevinpapst/kimai2 Web
4.3
MEDIUM
EPSS
0.1%
2021 CWE-352 1 PoC

kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2021-2439
Hyperion BI+ Web Database
4.3
MEDIUM
EPSS
0.8%
2021 1 PoC

Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: UI and Visualization). Supported versions that are affected are 11.1.2.4 and 11.2.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion BI+. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion BI+ accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N

CVE-2021-4419
WP-Backgrounds Lite Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The WP-Backgrounds Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3. This is due to missing or incorrect nonce validation on the ino_save_data() function. This makes it possible for unauthenticated attackers to save meta data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4413
Process Steps Template Designer Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to save field icons via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4392
eCommerce Product Catalog Plugin for WordPress Web Windows
4.3
MEDIUM
EPSS
0.1%
2021 CWE-352 7 PoCs

The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.43. This is due to missing or incorrect nonce validation on the implecode_save_products_meta() function. This makes it possible for unauthenticated attackers to save product meta data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4399
Edwiser Bridge – WordPress Moodle Integration Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Edwiser Bridge plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,2.0.6. This is due to missing or incorrect nonce validation on the user_data_synchronization_initiater(), course_synchronization_initiater(), users_link_to_moodle_synchronization(), connection_test_initiater(), admin_menus(), and subscribe_handler() function. This makes it possible for unauthenticated attackers to perform unauthorized actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4405
ElasticPress Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The ElasticPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.3. This is due to missing or incorrect nonce validation on the epio_send_autosuggest_allowed() function. This makes it possible for unauthenticated attackers to send allowed parameters for autosuggest to elasticpress[.]io via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-2343
Workflow Web Database
4.3
MEDIUM
EPSS
0.2%
2021 1 PoC

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Workflow accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVE-2021-4415
Sunshine Photo Cart – Client Photo Gallery & Photo Proofing for Photographers Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Sunshine Photo Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.28 This is due to missing or incorrect nonce validation on the sunshine_products_quicksave_post() function. This makes it possible for unauthenticated attackers to save custom post data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4427
Vuukle Comments, Reactions, Share Bar, Revenue Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Vuukle Comments, Reactions, Share Bar, Revenue plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.31. This is due to missing or incorrect nonce validation in the /admin/partials/free-comments-for-wordpress-vuukle-admin-display.php file. This makes it possible for unauthenticated attackers to edit the plugins settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-37867
Mattermost Boards Web
4.3
MEDIUM
EPSS
0.2%
2021 CWE-200 1 PoC

Mattermost Boards plugin v0.10.0 and earlier fails to protect email addresses of all users via one of the Boards APIs, which allows authenticated and unauthorized users to access this information resulting in sensitive & private information disclosure.

CVE-2021-2153
Internet Expenses Web Database
4.3
MEDIUM
EPSS
0.7%
2021 1 PoC

Vulnerability in the Oracle Internet Expenses product of Oracle E-Business Suite (component: Mobile Expenses). Supported versions that are affected are 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Internet Expenses. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Internet Expenses accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts). CVSS Vector: (CV

CVE-2021-3858
snipe/snipe-it Web
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 1 PoC

snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2021-4409
Etsy Integration For WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The WooCommerce Etsy Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.1. This is due to missing or incorrect nonce validation on the etcpf_delete_feed() function. This makes it possible for unauthenticated attackers to delete an export feed via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4005
firefly-iii/firefly-iii Web
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 1 PoC

firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2021-4412
WP Prayer Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The WP Prayer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.5. This is due to missing or incorrect nonce validation on the save() and export() functions. This makes it possible for unauthenticated attackers to save plugin settings and trigger a data export via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-2155
One-to-One Fulfillment Web Database
4.3
MEDIUM
EPSS
0.7%
2021 1 PoC

Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle One-to-One Fulfillment accessible data. CVSS 3.1 Base Score 4.3 (Integrity

CVE-2021-45785
Software Genérico Web
4.3
MEDIUM
EPSS
0.1%
2021 1 PoC

TruDesk Help Desk/Ticketing Solution v1.1.11 is vulnerable to a Cross-Site Request Forgery (CSRF) attack which would allow an attacker to restart the server, causing a DoS attack. The attacker must craft a webpage that would perform a GET request to the /api/v1/admin/restart endpoint, then the victim (who has sufficient privileges), would visit the page and the server restart would begin. The attacker must know the full URL that TruDesk is on in order to craft the webpage.