3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-2480
HTTP Server Web Database
3.7
LOW
EPSS
0.6%
2021 1 PoC

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affected is 11.1.1.9.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HTTP Server accessible data. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).

CVE-2021-32696
striptags Web
3.7
LOW
EPSS
0.3%
2021 CWE-241 1 PoC

The npm package "striptags" is an implementation of PHP's strip_tags in Typescript. In striptags before version 3.2.0, a type-confusion vulnerability can cause `striptags` to concatenate unsanitized strings when an array-like object is passed in as the `html` parameter. This can be abused by an attacker who can control the shape of their input, e.g. if query parameters are passed directly into the function. This can lead to a XSS.

CVE-2021-2007
MySQL Server Web Database
3.7
LOW
EPSS
0.5%
2021 2 PoCs

Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.47 and prior, 5.7.29 and prior and 8.0.19 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Client accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVE-2021-40339
Software Genérico Web
3.7
LOW
EPSS
0.3%
2021 1 PoC

Configuration vulnerability in Hitachi Energy LinkOne application due to the lack of HTTP Headers, allows an attacker that manages to exploit this vulnerability to retrieve sensitive information. This issue affects: Hitachi Energy LinkOne 3.20; 3.22; 3.23; 3.24; 3.25; 3.26.

CVE-2021-28378
Software Genérico Web
3.7
LOW
EPSS
12.9%
2021 1 PoC

Gitea 1.12.x and 1.13.x before 1.13.4 allows XSS via certain issue data in some situations.

CVE-2021-3901
firefly-iii/firefly-iii Web
3.5
LOW
EPSS
0.1%
2021 CWE-352 1 PoC

firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2021-33597
F-Secure endpoint protection products on Windows, Mac and Linux Security Web Windows
3.5
LOW
EPSS
0.1%
2021 1 PoC

A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the SAVAPI component used in certain F-Secure products can crash while scanning fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine.

CVE-2021-23889
McAfee ePolicy Orchestrator (ePO) Web
3.5
LOW
EPSS
0.2%
2021 1 PoC

Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows ePO administrators to inject arbitrary web script or HTML via multiple parameters where the administrator's entries were not correctly sanitized.

CVE-2021-4232
Zoo Management System Web
3.5
LOW
EPSS
0.2%
2021 CWE-79 1 PoC

A vulnerability classified as problematic has been found in Zoo Management System 1.0. Affected is an unknown function of the file admin/manage-ticket.php. The manipulation with the input <script>alert(1)</script> leads to cross site scripting. It is possible to launch the attack remotely.

CVE-2021-2159
PeopleSoft Enterprise CS Campus Community Web Database
3.5
LOW
EPSS
0.2%
2021 1 PoC

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Frameworks). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 3.5 (Confidentiality impacts

CVE-2021-34563
WHA-GW-F2D2-0-AS- Z2-ETH Web Networking
3.3
LOW
EPSS
0.0%
2021 CWE-1004 1 PoC

In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 and 3.0.9 the HttpOnly attribute is not set on a cookie. This allows the cookie's value to be read or set by client-side JavaScript.

CVE-2021-23163
JFrog Artifactory Web
3.1
LOW
EPSS
0.1%
2021 CWE-352 1 PoC

JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.33.6 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x.

CVE-2021-3944
bookstackapp/bookstack Web
3.1
LOW
EPSS
0.1%
2021 CWE-352 1 PoC

bookstack is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2021-22898
https://github.com/curl/curl Web
3.1
LOW
EPSS
0.1%
2021 CWE-200 4 PoCs

curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol.

CVE-2021-32718
rabbitmq-server DevOps Web
3.1
LOW
EPSS
0.1%
2021 CWE-80 1 PoC

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.17, a new user being added via management UI could lead to the user's bane being rendered in a confirmation message without proper `<script>` tag sanitization, potentially allowing for JavaScript code execution in the context of the page. In order for this to occur, the user must be signed in and have elevated permissions (other user management). The vulnerability is patched in RabbitMQ 3.8.17. As a workaround, disable `rabbitmq_management` plugin and use CLI tools for management operations and Prometheus an

CVE-2021-32719
rabbitmq-server Web
3.1
LOW
EPSS
0.1%
2021 CWE-80 2 PoCs

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper <script> tag sanitization. This potentially allows for JavaScript code execution in the context of the page. The user must be signed in and have elevated permissions (manage federation upstreams and policies) for this to occur. The vulnerability is patched in RabbitMQ 3.8.18. As a workaround, disable the `rabbitmq_federation_management` plugin an

CVE-2021-32792
mod_auth_openidc Web
3.1
LOW
EPSS
0.2%
2021 CWE-79 1 PoC

mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9, there is an XSS vulnerability in when using `OIDCPreservePost On`.

CVE-2021-37864
Mattermost Web
2.6
LOW
EPSS
0.2%
2021 CWE-284 1 PoC

Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view contents of archived channels even when this is denied by system administrators by directly accessing the APIs.

CVE-2021-4240
phpservermon Web Networking
2.6
LOW
EPSS
0.2%
2021 CWE-331 2 PoCs

A vulnerability, which was classified as problematic, was found in phpservermon. This affects the function generatePasswordResetToken of the file src/psm/Service/User.php. The manipulation leads to use of predictable algorithm in random number generator. The exploit has been disclosed to the public and may be used. The name of the patch is 3daa804d5f56c55b3ae13bfac368bb84ec632193. It is recommended to apply a patch to fix this issue. The identifier VDB-213717 was assigned to this vulnerability.

CVE-2021-21320
matrix-react-sdk Web
2.6
LOW
EPSS
0.2%
2021 CWE-345 1 PoC

matrix-react-sdk is an npm package which is a Matrix SDK for React Javascript. In matrix-react-sdk before version 3.15.0, the user content sandbox can be abused to trick users into opening unexpected documents. The content is opened with a `blob` origin that cannot access Matrix user data, so messages and secrets are not at risk. This has been fixed in version 3.15.0.