3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-24900
Ninja Tables – Best WP DataTables Plugin for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-79 2 PoCs

The Ninja Tables WordPress plugin before 4.1.8 does not sanitise and escape some of its table fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2021-41731
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Cross Site Scripting (XSS vulnerability exists in )Sourcecodester News247 News Magazine (CMS) PHP 5.6 or higher and MySQL 5.7 or higher via the blog category name field

CVE-2021-24276
Contact Form by Supsystic Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.4%
2021 CWE-79 2 PoCs

The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

CVE-2021-39486
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

A Stored XSS via Malicious File Upload exists in Gila CMS version 2.2.0. An attacker can use this to steal cookies, passwords or to run arbitrary code on a victim's browser.

CVE-2021-25063
Skins for Contact Form 7 Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.2%
2021 CWE-79 1 PoC

The Skins for Contact Form 7 WordPress plugin before 2.5.1 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2021-20187
moodle Web
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-94 1 PoC

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to execute arbitrary PHP scripts via a PHP include used during Shibboleth authentication.

CVE-2021-24678
CM Tooltip Glossary – Better SEO and UEX for your WP site Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The CM Tooltip Glossary WordPress plugin before 3.9.21 does not escape some glossary_tooltip shortcode attributes, which could allow users a role as low as Contributor to perform Stored Cross-Site Scripting attacks

CVE-2021-26599
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
3.9%
2021 1 PoC

ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.

CVE-2021-24919
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

The Wicked Folders WordPress plugin before 2.8.10 does not sanitise and escape the folder_id parameter before using it in a SQL statement in the wicked_folders_save_sort_order AJAX action, available to any authenticated user. leading to an SQL injection

CVE-2021-33215
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The API allows Directory Traversal.

CVE-2021-25068
Sync WooCommerce Product feed to Google Shopping Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 1 PoC

The Sync WooCommerce Product feed to Google Shopping WordPress plugin through 1.2.4 uses the 'feed_id' POST parameter which is not properly sanitized for use in a SQL statement, leading to a SQL injection vulnerability in the admin dashboard

CVE-2021-37402
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via binary data that is mishandled when the legacy dataretrieval endpoint has been enabled.

CVE-2021-42051
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An issue was discovered in AbanteCart before 1.3.2. Any low-privileged user with file-upload permissions can upload a malicious SVG document that contains an XSS payload.

CVE-2021-30129
Apache Mina SSHD Web Networking
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0

CVE-2021-28417
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php and the "search_name" parameter.

CVE-2021-25922
openemr Web
N/A
UNKNOWN
EPSS
1.7%
2021 1 PoC

In OpenEMR, versions 4.2.0 to 6.0.0 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validated properly. An attacker could trick a user to click on a malicious url and execute malicious code.

CVE-2021-24575
School Management System – WPSchoolPress Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-89 1 PoC

The School Management System – WPSchoolPress WordPress plugin before 2.1.10 does not properly sanitize or use prepared statements before using POST variable in SQL queries, leading to SQL injection in multiple actions available to various authenticated users, from simple subscribers/students to teachers and above.

CVE-2021-30044
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Cross Site Scripting (XSS) in Remote Clinic v2.0 via the First Name or Last Name field on staff/register.php.

CVE-2021-24717
AutomatorWP Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-863 1 PoC

The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or perform privilege escalation via Ajax actions.

CVE-2021-24921
Advanced Database Cleaner Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Advanced Database Cleaner WordPress plugin before 3.0.4 does not sanitise and escape $_GET keys and values before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues