3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-44664
Software Genérico Web
N/A
UNKNOWN
EPSS
15.0%
2021 2 PoCs

An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by uploading a maliciously crafted PHP file though the project interface disguised as a language file to bypasses the upload filters. Attackers can manipulate the files destination by abusing path traversal in the 'mediapath' variable.

CVE-2021-45086
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js.

CVE-2021-43544
Firefox Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

When receiving a URL through a SEND intent, Firefox would have searched for the text, but subsequent usages of the address bar might have caused the URL to load unintentionally, which could lead to XSS and spoofing attacks. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 95.

CVE-2021-45268
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading a maliciously add-on with crafted PHP file. NOTE: the vendor disputes this because the attack requires a session cookie of a high-privileged authenticated user who is entitled to install arbitrary add-ons

CVE-2021-32612
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 3 PoCs

The VeryFitPro (com.veryfit2hr.second) application 3.2.8 for Android does all communication with the backend API over cleartext HTTP. This includes logins, registrations, and password change requests. This allows information theft and account takeover via network sniffing.

CVE-2021-35061
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in DRK Odenwaldkreis Testerfassung March-2021 allow remote attackers to inject arbitrary web script or HTML via all parameters to HTML form fields in all components.

CVE-2021-24792
Shiny Buttons – CSS3 Button Generator for WordPress Web Cloud Windows
N/A
UNKNOWN
EPSS
12.1%
2021 CWE-79 1 PoC

The Shiny Buttons WordPress plugin through 1.1.0 does not have any authorisation and CSRF in place when saving a template (wpbtn_save_template function hooked to the init action), nor sanitise and escape them before outputting them in the admin dashboard, which allow unauthenticated users to add a malicious template and lead to Stored Cross-Site Scripting issues.

CVE-2021-41449
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
1.4%
2021 1 PoC

A path traversal attack in web interfaces of Netgear RAX35, RAX38, and RAX40 routers before v1.0.4.102, allows a remote unauthenticated attacker to gain access to sensitive restricted information, such as forbidden files of the web application, via sending a specially crafted HTTP packet.

CVE-2021-24187
SEO Redirection Plugin - 301 Redirect Manager Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The setting page of the SEO Redirection Plugin - 301 Redirect Manager WordPress plugin before 6.4 is vulnerable to reflected Cross-Site Scripting (XSS) as user input is not properly sanitised before being output in an attribute.

CVE-2021-29349
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 2 PoCs

Mahara 20.10 is affected by Cross Site Request Forgery (CSRF) that allows a remote attacker to remove inbox-mail on the server. The application fails to validate the CSRF token for a POST request. An attacker can craft a module/multirecipientnotification/inbox.php pieform_delete_all_notifications request, which leads to removing all messages from a mailbox.

CVE-2021-24293
NextGen Gallery Pro Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

In the eCommerce module of the NextGEN Gallery Pro WordPress plugin before 3.1.11, there is an action to call get_cart_items via photocrati_ajax , after that the settings[shipping_address][name] is able to inject malicious javascript.

CVE-2021-22901
https://github.com/curl/curl Web
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-416 3 PoCs

curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstances to potentially reach remote code execution in the client. When libcurl at run-time sets up support for TLS 1.3 session tickets on a connection using OpenSSL, it stores pointers to the transfer in-memory object for later retrieval when a session ticket arrives. If the connection is used by multiple transfers (like with a reused HTTP/1.1 connection or multiplex

CVE-2021-37412
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The TechRadar app 1.1 for Confluence Server allows XSS via the Title field of a Radar.

CVE-2021-35323
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.0%
2021 1 PoC

Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.

CVE-2021-29953
Firefox Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

A malicious webpage could have forced a Firefox for Android user into executing attacker-controlled JavaScript in the context of another domain, resulting in a Universal Cross-Site Scripting vulnerability. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected. Further details are being temporarily withheld to allow users an opportunity to update.*. This vulnerability affects Firefox < 88.0.1 and Firefox for Android < 88.1.3.

CVE-2021-44224
Apache HTTP Server Web
N/A
UNKNOWN
EPSS
11.0%
2021 CWE-476 2 PoCs

A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included).

CVE-2021-24707
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The Learning Courses WordPress plugin before 5.0 does not sanitise and escape the Email PDT identity token settings, which could allow high privilege users to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2021-38145
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.3%
2021 1 PoC

An issue was discovered in Form Tools through 3.0.20. SQL Injection can occur via the export_group_id field when a low-privileged user (client) tries to export a form with data, e.g., manipulation of modules/export_manager/export.php?export_group_id=1&export_group_1_results=all&export_type_id=1.

CVE-2021-24914
Tawk.To Live Chat Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-862 1 PoC

The Tawk.To Live Chat WordPress plugin before 0.6.0 does not have capability and CSRF checks in the tawkto_setwidget and tawkto_removewidget AJAX actions, available to any authenticated user. The first one allows low-privileged users (including simple subscribers) to change the 'tawkto-embed-widget-page-id' and 'tawkto-embed-widget-widget-id' parameters. Any authenticated user can thus link the vulnerable website to their own Tawk.to instance. Consequently, they will be able to monitor the vulnerable website and interact with its visitors (receive contact messages, answer, ...). They will also

CVE-2021-24947
RVM – Responsive Vector Maps Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
10.2%
2021 CWE-863 1 PoC

The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in the rvm_import_regions AJAX action, allowing any authenticated user, such as subscriber, to read arbitrary files on the web server