3118 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-24199
wpDataTables – Tables & Table Charts Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-89 1 PoC

The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to perform Boolean-based blind SQL Injection in the table list page on the endpoint /wp-admin/admin-ajax.php?action=get_wdtable&table_id=1, on the 'start' HTTP POST parameter. This allows an attacker to access all the data in the database and obtain access to the WordPress application.

CVE-2021-28423
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.7%
2021 3 PoCs

Multiple SQL Injection vulnerabilities in Teachers Record Management System 1.0 thru 2.1 allow remote authenticated users to execute arbitrary SQL commands via the 'editid' GET parameter in edit-subjects-detail.php, edit-teacher-detail.php, or the 'searchdata' POST parameter in search.php.

CVE-2021-24877
MainWP Child - Securely connects sites to the MainWP WordPress Manager Dashboard Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 1 PoC

The MainWP Child WordPress plugin before 4.1.8 does not validate the orderby and order parameter before using them in a SQL statement, leading to an SQL injection exploitable by high privilege users such as admin when the Backup and Staging by WP Time Capsule plugin is installed

CVE-2021-25115
WP Photo Album Plus Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The WP Photo Album Plus WordPress plugin before 8.0.10 was vulnerable to Stored Cross-Site Scripting (XSS). Error log content was handled improperly, therefore any user, even unauthenticated, could cause arbitrary javascript to be executed in the admin panel.

CVE-2021-31911
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains TeamCity before 2020.2.3, reflected XSS was possible on several pages.

CVE-2021-24215
Controlled Admin Access Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
54.6%
2021 CWE-284 1 PoC

An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the website customization functionality and global CMS settings, like /wp-admin/customization.php and /wp-admin/options.php, can lead to a complete compromise of the target resource.

CVE-2021-24454
YOP Poll Web Windows
N/A
UNKNOWN
EPSS
1.7%
2021 CWE-79 1 PoC

In the YOP Poll WordPress plugin before 6.2.8, when a pool is created with the options "Allow other answers", "Display other answers in the result list" and "Show results", it can lead to Stored Cross-Site Scripting issues as the 'Other' answer is not sanitised before being output in the page. The execution of the XSS payload depends on the 'Show results' option selected, which could be before or after sending the vote for example.

CVE-2021-20128
Draytek VigorConnect Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The Profile Name field in the floor plan (Network Menu) page in Draytek VigorConnect 1.6.0-B3 was found to be vulnerable to stored XSS, as user input is not properly sanitized.

CVE-2021-24138
AdRotate Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-89 1 PoC

Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via param "id". This requires an admin privileged user.

CVE-2021-40094
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

A DOM-based XSS vulnerability affects SquaredUp for SCOM 5.2.1.6654. If successfully exploited, this vulnerability may allow attackers to inject malicious code into a user's device.

CVE-2021-29660
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

A Cross-Site Request Forgery (CSRF) vulnerability in en/cfg_setpwd.html in Softing AG OPC Toolbox through 4.10.1.13035 allows attackers to reset the administrative password by inducing the Administrator user to browse a URL controlled by an attacker.

CVE-2021-46361
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2021 2 PoCs

An issue in the Freemark Filter of Magnolia CMS v6.2.11 and below allows attackers to bypass security restrictions and execute arbitrary code via a crafted FreeMarker payload.

CVE-2021-35490
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Thruk before 2.44 allows XSS for a quick command.

CVE-2021-46426
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2021 2 PoCs

phpIPAM 1.4.4 allows Reflected XSS and CSRF via app/admin/subnets/find_free_section_subnets.php of the subnets functionality.

CVE-2021-27885
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.

CVE-2021-46385
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.FormDataAction#queryData. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability through which attacker can get sensitive information from the database.

CVE-2021-24668
MAZ Loader – Preloader Builder for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The MAZ Loader WordPress plugin before 1.4.1 does not enforce nonce checks, which allows attackers to make administrators delete arbitrary loaders via a CSRF attack

CVE-2021-24226
AccessAlly Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
25.4%
2021 CWE-200 1 PoC

In the AccessAlly WordPress plugin before 3.5.7, the file "resource/frontend/product/product-shortcode.php" responsible for the [accessally_order_form] shortcode is dumping serialize($_SERVER), which contains all environment variables. The leakage occurs on all public facing pages containing the [accessally_order_form] shortcode, no login or administrator role is required.

CVE-2021-24362
Photo Gallery by 10Web – Mobile-Friendly Image Gallery Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded SVG files added to a gallery do not contain malicious content. As a result, users allowed to add images to gallery can upload an SVG file containing JavaScript code, which will be executed when accessing the image directly (ie in the /wp-content/uploads/photo-gallery/ folder), leading to a Cross-Site Scripting (XSS) issue

CVE-2021-37805
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

A Stored Cross Site Scripting (XSS) vunerability exists in Sourcecodeste Vehicle Parking Management System affected version 1.0 is via the add-vehicle.php endpoint.