3431 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-25993
wiki Web
5.4
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

In Requarks wiki.js, versions 2.0.0-beta.147 to 2.5.255 are affected by Stored XSS vulnerability, where a low privileged (editor) user can upload a SVG file that contains malicious JavaScript while uploading assets in the page. That will send the JWT tokens to the attacker’s server and will lead to account takeover when accessed by the victim.

CVE-2021-25921
openemr Web
5.4
MEDIUM
EPSS
30.6%
2021 1 PoC

In OpenEMR, versions 2.7.3-rc1 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly in the `Allergies` section. An attacker could lure an admin to enter a malicious payload and by that initiate the exploit.

CVE-2021-3799
getgrav/grav-plugin-admin General
5.4
MEDIUM
EPSS
0.2%
2021 CWE-1021 1 PoC

grav-plugin-admin is vulnerable to Improper Restriction of Rendered UI Layers or Frames

CVE-2021-23648
@braintree/sanitize-url Web
5.4
MEDIUM
EPSS
0.1%
2021 1 PoC

The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.

CVE-2021-20340
Rational DOORS Next Generation Web
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194451.

CVE-2021-35649
Secure Global Desktop Database
5.4
MEDIUM
EPSS
0.3%
2021 1 PoC

Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Server). The supported version that is affected is 5.6. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Secure Global Desktop. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Secure Global Desktop accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Secure Global Desktop. CVSS 3.1 Base Score 5.4 (Confidentiality and Avai

CVE-2021-2460
Application Express (APEX) Web Database
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server. The supported version that is affected is Prior to 21.1.0.00.04. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Data Reporter. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express Data Reporter, attacks may significantly impact additional products. Successful attacks of this vulnerabili

CVE-2021-29670
Engineering Test Management Web
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199408.

CVE-2021-3862
icecoder/icecoder Web
5.4
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

icecoder is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-37378
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2021 1 PoC

Cross Site Scripting (XSS) vulnerability in Teradek Cube and Cube Pro firmware version 7.3.x and earlier allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to address this issue.

CVE-2021-23673
pekeupload Web
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

This affects all versions of package pekeupload. If an attacker induces a user to upload a file whose name contains javascript code, the javascript code will be executed.

CVE-2021-23385
Flask-Security General
5.4
MEDIUM
EPSS
0.2%
2021 2 PoCs

This affects all versions of package Flask-Security. When using the get_post_logout_redirect and get_post_login_redirect functions, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as \\\evil.com/path. This vulnerability is only exploitable if an alternative WSGI server other than Werkzeug is used, or the default behaviour of Werkzeug is modified using 'autocorrect_location_header=False. **Note:** Flask-Security is not maintained anymore.

CVE-2021-25986
Django-wiki Web
5.4
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

In Django-wiki, versions 0.0.20 to 0.7.8 are vulnerable to Stored Cross-Site Scripting (XSS) in Notifications Section. An attacker who has access to edit pages can inject JavaScript payload in the title field. When a victim gets a notification regarding the changes made in the application, the payload in the notification panel renders and loads external JavaScript.

CVE-2021-41278
app-functions-sdk-go General
5.4
MEDIUM
EPSS
0.1%
2021 CWE-327 1 PoC

Functions SDK for EdgeX is meant to provide all the plumbing necessary for developers to get started in processing/transforming/exporting data out of the EdgeX IoT platform. In affected versions broken encryption in app-functions-sdk “AES” transform in EdgeX Foundry releases prior to Jakarta allows attackers to decrypt messages via unspecified vectors. The app-functions-sdk exports an “aes” transform that user scripts can optionally call to encrypt data in the processing pipeline. No decrypt function is provided. Encryption is not enabled by default, but if used, the level of protection may be

CVE-2021-35616
Transportation Management Web Database
5.4
MEDIUM
EPSS
2.8%
2021 1 PoC

Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: UI Infrastructure). The supported version that is affected is 6.4.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Transportation Management accessible data as well as unauthorized read access to a subset of Oracle Transportation Management accessible data. CVSS 3.1 Base Score 5.4 (Confide

CVE-2021-41074
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2021 1 PoC

A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document.

CVE-2021-2346
Commerce Guided Search / Oracle Commerce Experience Manager Web Database
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Tools and Frameworks). The supported version that is affected is 11.3.1.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact addit

CVE-2021-25059
Download Plugin Web Windows
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

The Download Plugin WordPress plugin before 2.0.0 does not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download a full copy of the website.

CVE-2021-2117
Application Express (APEX) Web Database
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

Vulnerability in the Oracle Application Express Survey Builder component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Survey Builder. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express Survey Builder, attacks may significantly impact additional products. Successful attacks of this vulnerability ca

CVE-2021-3768
bookstackapp/bookstack Web
5.4
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')