3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-24521
Side Menu Lite – add sticky fixed buttons Web Database Windows
N/A
UNKNOWN
EPSS
0.8%
2021 CWE-89 1 PoC

The Side Menu Lite – add sticky fixed buttons WordPress plugin before 2.2.1 does not properly sanitize input values from the browser when building an SQL statement. Users with the administrator role or permission to manage this plugin could perform an SQL Injection attack.

CVE-2021-25329
Apache Tomcat Web
N/A
UNKNOWN
EPSS
1.0%
2021 4 PoCs

The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.

CVE-2021-42740
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
9.0%
2021 1 PoC

The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metacharacters through a regex designed to support Windows drive letters. If the output of this package is passed to a real shell as a quoted argument to a command with exec(), an attacker can inject arbitrary commands. This is because the Windows drive letter regex character class is {A-z] instead of the correct {A-Za-z]. Several shell metacharacters exist in the space between capital letter Z and lower case letter a, such as the backtick character.

CVE-2021-44263
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Gurock TestRail before 7.2.4 mishandles HTML escaping.

CVE-2021-37372
Software Genérico Web
N/A
UNKNOWN
EPSS
7.9%
2021 3 PoCs

Online Student Admission System 1.0 is affected by an insecure file upload vulnerability. A low privileged user can upload malicious PHP files by updating their profile image to gain remote code execution.

CVE-2021-31643
Software Genérico Web
N/A
UNKNOWN
EPSS
3.8%
2021 2 PoCs

An XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and Webpass due to a lack of sanitization on the component if.cgi - username parameter.

CVE-2021-30039
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Fever" or "Blood Pressure" field on the patients/register-report.php.

CVE-2021-24178
Business Directory Plugin – Easy Listing Directories for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-352 1 PoC

The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 suffered from Cross-Site Request Forgery issues, allowing an attacker to make a logged in administrator add, edit or delete form fields, which could also lead to Stored Cross-Site Scripting issues.

CVE-2021-24729
Logo Showcase with Slick Slider – Logo Carousel, Logo Slider & Logo Grid Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Logo Showcase with Slick Slider WordPress plugin before 1.2.4 does not sanitise the Grid Settings, which could allow users with a role as low as Author to perform stored Cross-Site Scripting attacks via post metadata of Grid logo showcase.

CVE-2021-28146
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

CVE-2021-31935
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

OX App Suite 7.10.4 and earlier allows XSS via a crafted distribution list (payload in the common name) that is mishandled in the scheduling view.

CVE-2021-43195
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains TeamCity before 2021.1.2, some HTTP security headers were missing.

CVE-2021-42644
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file information of the website such as the database configuration file (config / config_database) can be read through this vulnerability.

CVE-2021-24852
MouseWheel Smooth Scroll Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The MouseWheel Smooth Scroll WordPress plugin before 5.7 does not have CSRF check in place on its settings page, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2021-24728
Membership & Content Restriction – Paid Member Subscriptions Web Database Windows
N/A
UNKNOWN
EPSS
1.5%
2021 CWE-89 2 PoCs

The Membership & Content Restriction – Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, validate or escape its order and orderby parameters before using them in SQL statement, leading to Authenticated SQL Injections in the Members and Payments pages.

CVE-2021-24464
YouTube Embed, Playlist and Popup by WpDevArt Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise some of its shortcode options, available to users with a role as low as Contributor, leading to an authenticated Stored Cross-Site Scripting issue.

CVE-2021-24332
Autoptimize Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Autoptimize WordPress plugin before 2.8.4 was missing proper escaping and sanitisation in some of its settings, allowing high privilege users to set XSS payloads in them, leading to stored Cross-Site Scripting issues

CVE-2021-25122
Apache Tomcat Web
N/A
UNKNOWN
EPSS
2.6%
2021 CWE-200 3 PoCs

When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.

CVE-2021-28657
Apache Tika Web
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-835 2 PoCs

A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.

CVE-2021-44280
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2021 4 PoCs

attendance management system 1.0 is affected by a SQL injection vulnerability in admin/incFunctions.php through the makeSafe function.