3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-24738
Logo Carousel – Logo Slider, Logo Showcase, and Clients Logo Gallery Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Logo Carousel WordPress plugin before 3.4.2 does not validate and escape the "Logo Margin" carousel option, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks

CVE-2021-41674
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An SQL Injection vulnerability exists in Sourcecodester E-Negosyo System 1.0 via the user_email parameter in /admin/login.php.

CVE-2021-30180
Apache Dubbo Web
N/A
UNKNOWN
EPSS
4.4%
2021 1 PoC

Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When parsing these YAML rules, Dubbo customers may enable calling arbitrary constructors.

CVE-2021-24437
Favicon by RealFaviconGenerator Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Favicon by RealFaviconGenerator WordPress plugin through 1.3.20 does not sanitise or escape one of its parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting (XSS) which is executed in the context of a logged administrator.

CVE-2021-27315
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
31.5%
2021 1 PoC

Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via the comment parameter.

CVE-2021-24731
Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
68.1%
2021 CWE-89 1 PoC

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection.

CVE-2021-25083
Registrations for the Events Calendar – Event Registration Plugin Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outputting it back in an attribute in the settings page, leading to a Reflected Cross-Site Scripting

CVE-2021-24755
myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-89 1 PoC

The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL statement, leading to an SQL injection exploitable by any authenticated user

CVE-2021-24804
Simple JWT Login – Login and Register to WordPress using JWT Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The Simple JWT Login WordPress plugin before 3.2.1 does not have nonce checks when saving its settings, allowing attackers to make a logged in admin changed them. Settings such as HMAC verification secret, account registering and default user roles can be updated, which could result in site takeover.

CVE-2021-45098
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An issue was discovered in Suricata before 6.0.4. It is possible to bypass/evade any HTTP-based signature by faking an RST TCP packet with random TCP options of the md5header from the client side. After the three-way handshake, it's possible to inject an RST ACK with a random TCP md5header option. Then, the client can send an HTTP GET request with a forbidden URL. The server will ignore the RST ACK and send the response HTTP packet for the client's request. These packets will not trigger a Suricata reject action.

CVE-2021-39408
Software Genérico Web
N/A
UNKNOWN
EPSS
1.3%
2021 1 PoC

Cross Site Scripting (XSS) vulnerability exists in Online Student Rate System 1.0 via the page parameter on the index.php file

CVE-2021-24927
My Calendar Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue

CVE-2021-42565
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2021 1 PoC

myfactory.FMS before 7.1-912 allows XSS via the UID parameter.

CVE-2021-24424
WP Reset – Most Advanced WordPress Reset Tool Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The WP Reset – Most Advanced WordPress Reset Tool WordPress plugin before 1.90 did not sanitise or escape its extra_data parameter when creating a snapshot via the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue

CVE-2021-24884
Formidable Form Builder – Contact Form, Survey & Quiz Forms Plugin for WordPress Web Windows
N/A
UNKNOWN
EPSS
19.2%
2021 CWE-79 2 PoCs

The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img>,<a> and<button>.This could allow an unauthenticated, remote attacker to exploit a HTML-injection byinjecting a malicous link. The HTML-injection may trick authenticated users to follow the link. If the Link gets clicked, Javascript code can be executed. The vulnerability is due to insufficient sanitization of the "data-frmverify" tag for links in the web-based entry inspection page of affected systems. A successful exploitation incomibantion with CSRF could allow the attack

CVE-2021-43528
Thunderbird Web
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level privileges, but could be used as a stepping stone to further an attack with other vulnerabilities. This vulnerability affects Thunderbird < 91.4.0.

CVE-2021-24733
WP Post Page Clone Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-863 1 PoC

The WP Post Page Clone WordPress plugin before 1.2 allows users with a role as low as Contributor to clone and view other users' draft and password-protected posts which they cannot view normally.

CVE-2021-24670
CoolClock – a Javascript Analog Clock Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The CoolClock WordPress plugin before 4.3.5 does not escape some shortcode attributes, allowing users with a role as low as Contributor toperform Stored Cross-Site Scripting attacks

CVE-2021-25106
Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages WordPress plugin before 2.7.1 does not check for authorisation and has a flawed CSRF logic when saving its settings, allowing any authenticated users, such as subscriber, to update them. Furthermore, due to the lack of sanitisation and escaping, it could lead to Stored Cross-Site Scripting

CVE-2021-4057
Chrome Web
N/A
UNKNOWN
EPSS
3.0%
2021 1 PoC

Use after free in file API in Google Chrome prior to 96.0.4664.93 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.