3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-43728
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Pix-Link MiNi Router 28K.MiniRouter.20190211 was discovered to contain a stored cross-site scripting (XSS) vulnerability due to an unsanitized SSID parameter.

CVE-2021-46068
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.7%
2021 1 PoC

A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the My Account Section in login panel.

CVE-2021-24419
WP YouTube Lyte Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The WP YouTube Lyte WordPress plugin before 1.7.16 did not sanitise or escape its lyte_yt_api_key and lyte_notification settings before outputting them back in the page, allowing high privilege users to set XSS payload on them and leading to stored Cross-Site Scripting issues.

CVE-2021-24821
Cost Calculator Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Cost Calculator WordPress plugin before 1.6 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the Description fields of a Cost Calculator > Price Settings (which gets injected on the edit page as well as any page that embeds the calculator using the shortcode), as well as the Text Preview field of a Project (injected on the edit project page)

CVE-2021-30224
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Cross Site Request Forgery (CSRF) in Rukovoditel v2.8.3 allows attackers to create an admin user with an arbitrary credentials.

CVE-2021-24860
BSK PDF Manager Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 1 PoC

The BSK PDF Manager WordPress plugin before 3.1.2 does not validate and escape the orderby and order parameters before using them in a SQL statement, leading to a SQL injection issue

CVE-2021-24412
Html5 Audio Player – Audio Player for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Html5 Audio Player – Audio Player for WordPress plugin before 2.1.3 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode

CVE-2021-27973
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages.

CVE-2021-24837
Passster Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The Passster WordPress plugin before 3.5.5.8 does not escape the area parameter of its shortcode, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

CVE-2021-25067
Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.1%
2021 CWE-79 1 PoC

The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb_post admin page.

CVE-2021-36766
Software Genérico Web
N/A
UNKNOWN
EPSS
1.5%
2021 1 PoC

Concrete5 through 8.5.5 deserializes Untrusted Data. The vulnerable code is located within the controllers/single_page/dashboard/system/environment/logging.php Logging::update_logging() method. User input passed through the logFile request parameter is not properly sanitized before being used in a call to the file_exists() PHP function. This can be exploited by malicious users to inject arbitrary PHP objects into the application scope (PHP Object Injection via phar:// stream wrapper), allowing them to carry out a variety of attacks, such as executing arbitrary PHP code.

CVE-2021-24508
Smash Balloon Social Post Feed Web Windows
N/A
UNKNOWN
EPSS
15.8%
2021 CWE-79 1 PoC

The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter in its feed_locator AJAX action (available to both authenticated and unauthenticated users) before outputting a truncated version of it in the admin dashboard, leading to an unauthenticated Stored Cross-Site Scripting issue which will be executed in the context of a logged in administrator.

CVE-2021-24314
Goto Web Database Windows
N/A
UNKNOWN
EPSS
1.0%
2021 CWE-89 2 PoCs

The Goto WordPress theme before 2.1 did not sanitise, validate of escape the keywords GET parameter from its listing page before using it in a SQL statement, leading to an Unauthenticated SQL injection issue

CVE-2021-24766
404 to 301 – Redirect, Log and Notify 404 Errors Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The 404 to 301 – Redirect, Log and Notify 404 Errors WordPress plugin before 3.0.9 does not have CSRF check in place when cleaning the logs, which could allow attacker to make a logged in admin delete all of them via a CSRF attack

CVE-2021-24428
RSS for Yandex Turbo Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The RSS for Yandex Turbo WordPress plugin through 1.30 does not sanitise or escape some of its settings before saving and outputing them in the admin dashboard, leading to an Authenticated Stored Cross-Site Scripting issue even when the unfiltered_html capability is disallowed.

CVE-2021-28295
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php, which may lead to database information disclosure.

CVE-2021-24142
301 Redirects - Easy Redirect Manager Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise its "Redirect From" column when importing a CSV file, allowing high privilege users to perform SQL injections.

CVE-2021-28157
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An SQL Injection issue in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows an administrative user to execute arbitrary SQL commands via a username in api/security/userinfo/delete.

CVE-2021-24496
Community Events Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and successimportcount GET parameters before outputting them back in an admin page, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator

CVE-2021-33483
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. The comment posting functionality allows an attacker to add an XSS payload to the JSON request that will execute when users visit the page with the comment.