3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-36563
Software Genérico Web
N/A
UNKNOWN
EPSS
8.0%
2021 1 PoC

The CheckMK management web console (versions 1.5.0 to 2.0.0) does not sanitise user input in various parameters of the WATO module. This allows an attacker to open a backdoor on the device with HTML content and interpreted by the browser (such as JavaScript or other client-side scripts), the XSS payload will be triggered when the user accesses some specific sections of the application. In the same sense a very dangerous potential way would be when an attacker who has the monitor role (not administrator) manages to get a stored XSS to steal the secretAutomation (for the use of the API in admini

CVE-2021-25096
IP2Location Country Blocker Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-639 1 PoC

The IP2Location Country Blocker WordPress plugin before 2.26.5 bans can be bypassed by using a specific parameter in the URL

CVE-2021-40101
Software Genérico Web
N/A
UNKNOWN
EPSS
9.1%
2021 1 PoC

An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password.

CVE-2021-24189
Captchinoo, Google recaptcha for admin login page Web Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-285 1 PoC

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptcha for admin login page WordPress plugin before 2.4, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

CVE-2021-43163
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
2.8%
2021 1 PoC

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the checkNet function in /cgi-bin/luci/api/auth.

CVE-2021-41849
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It sends the following Personally Identifiable Information (PII) in plaintext using HTTP to servers located in China: user's list of installed apps and device International Mobile Equipment Identity (IMEI). This PII is transmitted to log.skyroam.com.cn using HTTP, independent of whether the user uses the Simo software.

CVE-2021-30213
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.3%
2021 0 PoCs

Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in '/servlet/AdapterHTTP' via the 'targetService' parameter.

CVE-2021-32604
Software Genérico Web
N/A
UNKNOWN
EPSS
1.8%
2021 1 PoC

Share/IncomingWizard.htm in SolarWinds Serv-U before 15.2.3 mishandles the user-supplied SenderEmail parameter, aka "Share URL XSS."

CVE-2021-44827
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
44.6%
2021 3 PoCs

There is remote authenticated OS command injection on TP-Link Archer C20i 0.9.1 3.2 v003a.0 Build 170221 Rel.55462n devices vie the X_TP_ExternalIPv6Address HTTP parameter, allowing a remote attacker to run arbitrary commands on the router with root privileges.

CVE-2021-24754
MainWP Child Reports Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 1 PoC

The MainWP Child Reports WordPress plugin before 2.0.8 does not validate or sanitise the order parameter before using it in a SQL statement in the admin dashboard, leading to an SQL injection issue

CVE-2021-23930
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

OX App Suite through 7.10.4 allows XSS via use of the conversion API for a distributedFile.

CVE-2021-33853
X2CRM Web
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

A Cross-Site Scripting (XSS) attack can cause arbitrary code (javascript) to run in a user’s browser while the browser is connected to a trusted website. As the vehicle for the attack, the application targets the users and not the application itself. Additionally, the XSS payload is executed when the user attempts to access any page of the CRM.

CVE-2021-33211
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 2 PoCs

A Directory Traversal vulnerability in the Unzip feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated users to write files to arbitrary directories via relative paths in ZIP archives.

CVE-2021-25084
Advanced Cron Manager Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-862 1 PoC

The Advanced Cron Manager WordPress plugin before 2.4.2 and Advanced Cron Manager Pro WordPress plugin before 2.5.3 do not have authorisation checks in some of their AJAX actions, allowing any authenticated users, such as subscriber to call them and add or remove events as well as schedules for example

CVE-2021-24952
Conversios.io – Google Analytics and Google Shopping plugin for WooCommerce Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2021 CWE-89 1 PoC

The Conversios.io WordPress plugin before 4.6.2 does not sanitise, validate and escape the sync_progressive_data parameter for the tvcajax_product_sync_bantch_wise AJAX action before using it in a SQL statement, allowing any authenticated user to perform SQL injection attacks.

CVE-2021-31862
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
41.3%
2021 2 PoCs

SysAid 20.4.74 allows XSS via the KeepAlive.jsp stamp parameter without any authentication.

CVE-2021-24880
SupportCandy – Helpdesk & Support Ticket System Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The SupportCandy WordPress plugin before 2.2.7 does not validate and escape the page attribute of its shortcode, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks

CVE-2021-24616
AddToAny Share Buttons Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The AddToAny Share Buttons WordPress plugin before 1.7.48 does not escape its Image URL button setting, which could lead allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2021-31762
Software Genérico Web
N/A
UNKNOWN
EPSS
22.7%
2021 4 PoCs

Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse shell through Webmin's running process feature.

CVE-2021-41467
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
7.6%
2021 0 PoCs

Cross-site scripting (XSS) vulnerability in application/controllers/dropbox.php in JustWriting 1.0.0 and below allow remote attackers to inject arbitrary web script or HTML via the challenge parameter.