3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-35506
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Afian FileRun 2021.03.26 allows XSS when an administrator encounters a crafted document during use of the HTML Editor for a preview or edit action.

CVE-2021-27309
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.9%
2021 0 PoCs

Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "module" parameter.

CVE-2021-24248
Business Directory Plugin – Easy Listing Directories for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-434 1 PoC

The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 did not properly check for imported files, forbidding certain extension via a blacklist approach, allowing administrator to import an archive with a .php4 inside for example, leading to RCE

CVE-2021-20152
Trendnet AC2600 TEW-827DRU Web
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

Trendnet AC2600 TEW-827DRU version 2.08B01 lacks proper authentication to the bittorrent functionality. If enabled, anyone is able to visit and modify settings and files via the Bittorent web client by visiting: http://192.168.10.1:9091/transmission/web/

CVE-2021-24664
School Management System – WPSchoolPress Web Windows
N/A
UNKNOWN
EPSS
1.4%
2021 CWE-79 2 PoCs

The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_field() but does not escape them before outputting in attributes, resulting in Stored Cross-Site Scripting issues.

CVE-2021-3188
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.

CVE-2021-24488
Post Grid Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
11.5%
2021 CWE-79 1 PoC

The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading to Reflected Cross-Site Scripting issues

CVE-2021-40868
Software Genérico Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
27.0%
2021 2 PoCs

In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS.

CVE-2021-22056
VMware Workspace ONE Access and Identity Manager Web
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary origins and read the full response.

CVE-2021-28419
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.2%
2021 1 PoC

The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads to the ability to retrieve all databases.

CVE-2021-25078
Affiliates Manager Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.0%
2021 CWE-79 1 PoC

The Affiliates Manager WordPress plugin before 2.9.0 does not validate, sanitise and escape the IP address of requests logged by the click tracking feature, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admin viewing the tracked requests.

CVE-2021-41647
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.7%
2021 3 PoCs

An un-authenticated error-based and time-based blind SQL injection vulnerability exists in Kaushik Jadhav Online Food Ordering Web App 1.0. An attacker can exploit the vulnerable "username" parameter in login.php and retrieve sensitive database information, as well as add an administrative user.

CVE-2021-24546
Gutenberg Block Editor Toolkit – EditorsKit Web Windows
N/A
UNKNOWN
EPSS
1.0%
2021 CWE-94 1 PoC

The Gutenberg Block Editor Toolkit – EditorsKit WordPress plugin before 1.31.6 does not sanitise and validate the Conditional Logic of the Custom Visibility settings, allowing users with a role as low contributor to execute Arbitrary PHP code

CVE-2021-31761
Software Genérico Web
N/A
UNKNOWN
EPSS
82.3%
2021 4 PoCs

Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process feature.

CVE-2021-24822
Stylish Cost Calculator Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and CSRF checks on some of its AJAX actions (available to authenticated users), which could allow any authenticated users, such as subscriber to call them, and perform Stored Cross-Site Scripting attacks against logged in admin, as well as frontend users due to the lack of sanitisation and escaping in some parameters

CVE-2021-24897
Add Subtitle Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Add Subtitle WordPress plugin through 1.1.0 does not sanitise or escape the sub-title field (available only with classic editor) when output in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

CVE-2021-25277
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

FTAPI 4.0 - 4.10 allows XSS via a crafted filename to the alternative text hover box in the file submission component.

CVE-2021-46780
Easy Google Maps Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Easy Google Maps WordPress plugin before 1.9.32 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting

CVE-2021-24864
WP Cloudy, weather plugin Web Database Cloud Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The WP Cloudy, weather plugin WordPress plugin before 4.4.9 does not escape the post_id parameter before using it in a SQL statement in the admin dashboard, leading to a SQL Injection issue