3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-27308
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to inject JavaScript via the "redirect" parameter.

CVE-2021-24344
Easy Preloader Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The Easy Preloader WordPress plugin through 1.0.0 does not sanitise its setting fields, leading to authenticated (admin+) Stored Cross-Site scripting issues

CVE-2021-38840
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2021 4 PoCs

SQL Injection can occur in Simple Water Refilling Station Management System 1.0 via the water_refilling/classes/Login.php username parameter.

CVE-2021-24635
Visual Link Preview Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-284 1 PoC

The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the CSRF nonce displayed for all authenticated users, allowing any authenticated user (such as subscriber) to call them and 1) Get and search through title and content of Draft post, 2) Get title of a password-protected post as well as 3) Upload an image from an URL

CVE-2021-24197
wpDataTables – Tables & Table Charts Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-284 1 PoC

The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that visits the page where the table is published can tamper the parameters to access the data of another user that are present in the same table by taking over the user permissions on the table through formdata[wdt_ID] parameter. By exploiting this issue an attacker is able to access and manage the data of all users in the same table.

CVE-2021-46076
Software Genérico Web
N/A
UNKNOWN
EPSS
7.6%
2021 1 PoC

Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in multiple endpoints it leading to Code Execution.

CVE-2021-24323
WooCommerce Web
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

When taxes are enabled, the "Additional tax classes" field was not properly sanitised or escaped before being output back in the admin dashboard, allowing high privilege users such as admin to use XSS payloads even when the unfiltered_html is disabled

CVE-2021-24236
Imagements Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
74.1%
2021 CWE-434 1 PoC

The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Content-Type in the request to forbid dangerous files. This allows unauthenticated attackers to upload arbitrary files by using a valid image Content-Type along with a PHP filename and code, leading to RCE.

CVE-2021-24270
DethemeKit For Elementor Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The “DeTheme Kit for Elementor” WordPress Plugin before 1.5.5.5 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

CVE-2021-24691
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it in some pages, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2021-24762
Perfect Survey Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
85.7%
2021 CWE-89 3 PoCs

The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection.

CVE-2021-40373
Software Genérico Web
N/A
UNKNOWN
EPSS
25.5%
2021 1 PoC

playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then executing that code via the index.php?app=main&inc=core_welcome URI.

CVE-2021-26291
Apache Maven Web
N/A
UNKNOWN
EPSS
46.1%
2021 4 PoCs

Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in

CVE-2021-42665
Software Genérico Web Database
N/A
UNKNOWN
EPSS
24.9%
2021 5 PoCs

An SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the login form inside of index.php, which can allow an attacker to bypass authentication.

CVE-2021-24995
HTML5 Responsive FAQ Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The HTML5 Responsive FAQ WordPress plugin through 2.8.5 does not properly sanitise and escape some of its settings, which could allow a high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

CVE-2021-40106
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

An issue was discovered in Concrete CMS through 8.5.5. There is unauthenticated stored XSS in blog comments via the website field.

CVE-2021-31702
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Frontier ichris through 5.18 mishandles making a DNS request for the hostname in the HTTP Host header, as demonstrated by submitting 127.0.0.1 multiple times for DoS.

CVE-2021-33562
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

A reflected cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via the ref parameter to a page about an arbitrary product, e.g., a product/insert-product-name-here.html/ref= URL.

CVE-2021-24753
Rich Reviews by Starfish Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2021 CWE-89 1 PoC

The Rich Reviews by Starfish WordPress plugin before 1.9.6 does not properly validate the orderby GET parameter of the pending reviews page before using it in a SQL statement, leading to an authenticated SQL injection issue

CVE-2021-45835
Software Genérico Web
N/A
UNKNOWN
EPSS
22.2%
2021 1 PoC

The Online Admission System 1.0 allows an unauthenticated attacker to upload or transfer files of dangerous types to the application through documents.php, which may be used to execute malicious code or lead to code execution.