3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-24643
WP Map Block – Gutenberg Map Block for Google Map and OpenStreet Map Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The WP Map Block WordPress plugin before 1.2.3 does not escape some attributes of the WP Map Block, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2021-42325
Software Genérico Web Database
N/A
UNKNOWN
EPSS
5.5%
2021 3 PoCs

Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.

CVE-2021-24627
G Auto-Hyperlink Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
25.4%
2021 CWE-89 2 PoCs

The G Auto-Hyperlink WordPress plugin through 1.0.1 does not sanitise or escape an 'id' GET parameter before using it in a SQL statement, to select data to be displayed in the admin dashboard, leading to an authenticated SQL injection

CVE-2021-24723
WP Reactions Lite Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The WP Reactions Lite WordPress plugin before 1.3.6 does not properly sanitize inputs within wp-admin pages, allowing users with sufficient access to inject XSS payloads within /wp-admin/ pages.

CVE-2021-24718
Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Contact Form, Survey & Popup Form Plugin for WordPress plugin before 1.5 does not properly sanitize some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2021-44312
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered in Firmware Analysis and Comparison Tool v3.2. Logged in administrators could be targeted by a CSRF attack through visiting a crafted web page.

CVE-2021-36543
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.UnlockDocument.php in SeedDMS v5.1.x <5.1.23 and v6.0.x <6.0.16 allows a remote attacker to unlock any document without victim's knowledge, by enticing an authenticated user to visit an attacker's web page.

CVE-2021-30149
Software Genérico Web
N/A
UNKNOWN
EPSS
17.4%
2021 2 PoCs

Composr 10.0.36 allows upload and execution of PHP files.

CVE-2021-35458
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2021 3 PoCs

Online Pet Shop We App 1.0 is vulnerable to Union SQL Injection in products.php (aka p=products) via the c or s parameter.

CVE-2021-3003
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Agenzia delle Entrate Desktop Telematico 1.0.0 contacts the jws.agenziaentrate.it server over cleartext HTTP, which allows man-in-the-middle attackers to spoof product updates.

CVE-2021-27023
Puppet Enterprise, Puppet Server, Puppet Agent Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007

CVE-2021-39291
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

Certain NetModule devices allow credentials via GET parameters to CLI-PHP. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, NB2810, NB3700, NB3701, NB3710, NB3711, NB3720, and NB3800.

CVE-2021-24165
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.2%
2021 CWE-601 1 PoC

In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect parameter and no protection in place.

CVE-2021-24272
fitness calculators Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-352 2 PoCs

The fitness calculators WordPress plugin before 1.9.6 add calculators for Water intake, BMI calculator, protein Intake, and Body Fat and was lacking CSRF check, allowing attackers to make logged in users perform unwanted actions, such as change the calculator headers. Due to the lack of sanitisation, this could also lead to a Stored Cross-Site Scripting issue

CVE-2021-3137
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

XWiki 12.10.2 allows XSS via an SVG document to the upload feature of the comment section.

CVE-2021-22008
VMware vCenter Server, VMware Cloud Foundation Web Cloud
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

The vCenter Server contains an information disclosure vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by sending a specially crafted json-rpc message to gain access to sensitive information.

CVE-2021-46889
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

The 10Web Photo Gallery plugin through 1.5.69 for WordPress allows XSS via theme_id for bwg_frontend_data. NOTE: other parameters are covered by CVE-2021-24291, CVE-2021-25041, and CVE-2021-31693.

CVE-2021-44043
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

An issue was discovered in UiPath App Studio 21.4.4. There is a persistent XSS vulnerability in the file-upload functionality for uploading icons when attempting to create new Apps. An attacker with minimal privileges in the application can build their own App and upload a malicious file containing an XSS payload, by uploading an arbitrary file and modifying the MIME type in a subsequent HTTP request. This then allows the file to be stored and retrieved from the server by other users in the same organization.

CVE-2021-3501
kernel Web
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-787 1 PoC

A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this vulnerability is to data integrity and system availability.

CVE-2021-42646
Software Genérico Web
N/A
UNKNOWN
EPSS
1.3%
2021 2 PoCs

XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; and WSO2 IS as Key Manager 5.7.0, 5.9.0, and 5.10.0; and WSO2 Identity Server 5.7.0, 5.8.0, 5.9.0, 5.10.0, and 5.11.0. Allows attackers to gain read access to sensitive information or cause a denial of service via crafted GET requests.