3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-23934
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

OX App Suite through 7.10.4 allows XSS via a contact whose name contains JavaScript code.

CVE-2021-20660
SolarView Compact Web
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

Cross-site scripting vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to inject an arbitrary script via unspecified vectors.

CVE-2021-24361
Location Manager Web Database Windows
N/A
UNKNOWN
EPSS
1.1%
2021 CWE-89 1 PoC

In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its POST parameters, which are then used in a SQL statement, leading to unauthenticated SQL Injection issues.

CVE-2021-20154
Trendnet AC2600 TEW-827DRU Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Trendnet AC2600 TEW-827DRU version 2.08B01 contains an security flaw in the web interface. HTTPS is not enabled on the device by default. This results in cleartext transmission of sensitive information such as passwords.

CVE-2021-24434
Glass Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-79 1 PoC

The Glass WordPress plugin through 1.3.2 does not sanitise or escape its "Glass Pages" setting before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin did not have CSRF check in place when saving its settings, allowing the issue to be exploited via a CSRF attack.

CVE-2021-24191
WP Maintenance Mode & Site Under Construction Web Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-285 1 PoC

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site Under Construction WordPress plugin before 1.8.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

CVE-2021-43186
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS.

CVE-2021-20096
OpenOversight Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Cross-site request forgery in OpenOversight 0.6.4 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.

CVE-2021-24403
WordPress Page Contact Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 2 PoCs

The Orders functionality in the WordPress Page Contact plugin through 1.0 has an order_id parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. The feature is available to low privilege users such as contributors

CVE-2021-43181
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains Hub before 2021.1.13690, stored XSS is possible.

CVE-2021-24945
Like Button Rating ♥ LikeBtn Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-200 1 PoC

The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to get a list of email and IP addresses of people who liked content from the blog.

CVE-2021-25055
FeedWordPress Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.7%
2021 CWE-79 1 PoC

The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" parameter.

CVE-2021-24871
Get Custom Field Values Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-79 1 PoC

The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

CVE-2021-24561
WP SMS Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The WP SMS WordPress plugin before 5.4.13 does not sanitise the "wp_group_name" parameter before outputting it back in the "Groups" page, leading to an Authenticated Stored Cross-Site Scripting issue

CVE-2021-24260
Livemesh Addons for Elementor Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The “Livemesh Addons for Elementor” WordPress Plugin before 6.8 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

CVE-2021-24705
NEX-Forms Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The NEX-Forms WordPress plugin before 8.4.3 does not have CSRF checks in place when editing a form, and does not escape some of its settings as well as form fields before outputting them in attributes. This could allow attackers to make a logged in admin edit arbitrary forms with Cross-Site Scripting payloads in them

CVE-2021-27190
Software Genérico Web
N/A
UNKNOWN
EPSS
3.9%
2021 2 PoCs

A Stored Cross Site Scripting(XSS) Vulnerability was discovered in PEEL SHOPPING 9.3.0 and 9.4.0, which are publicly available. The user supplied input containing polyglot payload is echoed back in javascript code in HTML response. This allows an attacker to input malicious JavaScript which can steal cookie, redirect them to other malicious website, etc.

CVE-2021-45979
Software Genérico Web
N/A
UNKNOWN
EPSS
2.3%
2021 1 PoC

Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via app.launchURL in the JavaScript API.

CVE-2021-33328
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Cross-site scripting (XSS) vulnerability in the Asset module's edit vocabulary page in Liferay Portal 7.0.0 through 7.3.4, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20, and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the (1) _com_liferay_journal_web_portlet_JournalPortlet_name or (2) _com_liferay_document_library_web_portlet_DLAdminPortlet_name parameter.

CVE-2021-24856
Shared Files – Easy Download Manager and File Sharing Plugin with Frontend File Upload Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Shared Files WordPress plugin before 1.6.61 does not sanitise and escape the Download Counter Text settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed