1363 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2021-41349
Microsoft Exchange Server 2013 Cumulative Update 23 Windows ⚡ nuclei
6.5
MEDIUM
EPSS
91.1%
2021 2 PoCs

Microsoft Exchange Server Spoofing Vulnerability

CVE-2021-1115
NVIDIA GPU Display Driver Windows
6.5
MEDIUM
EPSS
0.0%
2021 CWE-476 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for private IOCTLs, where an attacker with local unprivileged system access may cause a NULL pointer dereference, which may lead to denial of service in a component beyond the vulnerable component.

CVE-2021-31195
Microsoft Exchange Server 2016 Cumulative Update 19 Windows ⚡ nuclei
6.5
MEDIUM
EPSS
79.8%
2021 0 PoCs

Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2021-4445
Premium Addons for Elementor – Powerful Elementor Templates & Widgets Web Windows
6.5
MEDIUM
EPSS
0.1%
2021 CWE-862 1 PoC

The Premium Addons for Elementor plugin for WordPress is vulnerable to Arbitrary Option Updates in versions up to, and including, 4.5.1. This is due to missing capability and nonce checks in the pa_dismiss_admin_notice AJAX action. This makes it possible for authenticated subscriber+ attackers to change arbitrary options with a restricted value of 1 on vulnerable WordPress sites.

CVE-2021-24085
Microsoft Exchange Server 2019 Cumulative Update 8 Windows
6.5
MEDIUM
EPSS
13.2%
2021 1 PoC

Microsoft Exchange Server Spoofing Vulnerability

CVE-2021-36917
Hide My WP (WordPress plugin) Web Windows
6.5
MEDIUM
EPSS
1.2%
2021 CWE-284 1 PoC

WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can then be used to deactivate the plugin.

CVE-2021-4377
Doneren met Mollie Web Windows
6.5
MEDIUM
EPSS
0.4%
2021 CWE-200 1 PoC

The Doneren met Mollie plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.8.5 via the dmm_export_donations() function which is called via the admin_post_dmm_export hook due to missing capability checks. This can allow authenticated attackers to extract a CSV file that contains sensitive information about the donors.

CVE-2021-43408
Duplicate Post WordPress Plugin Web Database Windows
6.5
MEDIUM
EPSS
30.6%
2021 CWE-89 1 PoC

The "Duplicate Post" WordPress plugin up to and including version 1.1.9 is vulnerable to SQL Injection. SQL injection vulnerabilities occur when client supplied data is included within an SQL Query insecurely. SQL Injection can typically be exploited to read, modify and delete SQL table data. In many cases it also possible to exploit features of SQL server to execute system commands and/or access the local file system. This particular vulnerability can be exploited by any authenticated user who has been granted access to use the Duplicate Post plugin. By default, this is limited to Administrat

CVE-2021-31959
Windows 10 Version 21H1 Windows
6.4
MEDIUM
EPSS
5.9%
2021 1 PoC

Scripting Engine Memory Corruption Vulnerability

CVE-2021-1093
NVIDIA GPU Display Driver Windows
6.2
MEDIUM
EPSS
0.1%
2021 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in firmware where the driver contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary, and may lead to denial of service or system crash.

CVE-2021-25022
UpdraftPlus WordPress Backup Plugin Web Windows
6.1
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.66 does not sanitise and escape the backup_timestamp and job_id parameter before outputting then back in admin pages, leading to Reflected Cross-Site Scripting issues

CVE-2021-24432
Advanced AJAX Product Filters Web Windows
6.1
MEDIUM
EPSS
0.4%
2021 1 PoC

The Advanced AJAX Product Filters WordPress plugin does not sanitise the 'term_id' POST parameter before outputting it in the page, leading to reflected Cross-Site Scripting issue.

CVE-2021-39322
Easy Social Icons Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
13.9%
2021 CWE-79 1 PoC

The Easy Social Icons plugin <= 3.0.8 for WordPress echoes out the raw value of `$_SERVER['PHP_SELF']` in its main file. On certain configurations including Apache+modPHP this makes it possible to use it to perform a reflected Cross-Site Scripting attack by injecting malicious code in the request path.

CVE-2021-34643
Skaut Bazar Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
7.7%
2021 CWE-79 0 PoCs

The Skaut bazar WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/skaut-bazar.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.3.2.

CVE-2021-24964
LiteSpeed Cache Web Cloud Windows
6.1
MEDIUM
EPSS
14.8%
2021 CWE-79 1 PoC

The LiteSpeed Cache WordPress plugin before 4.4.4 does not properly verify that requests are coming from QUIC.cloud servers, allowing attackers to make requests to certain endpoints by using a specific X-Forwarded-For header value. In addition, one of the endpoint could be used to set CSS code if a setting is enabled, which will then be output in some pages without being sanitised and escaped. Combining those two issues, an unauthenticated attacker could put Cross-Site Scripting payloads in pages visited by users.

CVE-2021-24870
WP Fastest Cache Web Windows
6.1
MEDIUM
EPSS
0.1%
2021 1 PoC

The WP Fastest Cache WordPress plugin before 0.9.5 is lacking a CSRF check in its wpfc_save_cdn_integration AJAX action, and does not sanitise and escape some the options available via the action, which could allow attackers to make logged in high privilege users call it and set a Cross-Site Scripting payload

CVE-2021-39320
underConstruction Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
19.7%
2021 CWE-79 1 PoC

The underConstruction plugin <= 1.18 for WordPress echoes out the raw value of `$GLOBALS['PHP_SELF']` in the ucOptions.php file. On certain configurations including Apache+modPHP, this makes it possible to use it to perform a reflected Cross-Site Scripting attack by injecting malicious code in the request path.

CVE-2021-39350
FV Flowplayer Video Player Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
16.6%
2021 CWE-79 0 PoCs

The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts, in versions 7.5.0.727 - 7.5.2.727.

CVE-2021-1094
NVIDIA GPU Display Driver Windows
6.1
MEDIUM
EPSS
0.1%
2021 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where an out of bounds array access may lead to denial of service or information disclosure.

CVE-2021-34657
TypoFR Web Windows
6.1
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

The 2TypoFR WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the text function found in the ~/vendor/Org_Heigl/Hyphenator/index.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.11.