3431 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-37374
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

Cross Site Scripting (XSS) vulnerability in Teradek Clip all firmware versions allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to address this issue.

CVE-2021-40303
Software Genérico Web
5.4
MEDIUM
EPSS
0.2%
2021 2 PoCs

perfex crm 1.10 is vulnerable to Cross Site Scripting (XSS) via /clients/profile.

CVE-2021-30140
Software Genérico Web
5.4
MEDIUM
EPSS
1.2%
2021 2 PoCs

LiquidFiles 3.4.15 has stored XSS through the "send email" functionality when sending a file via email to an administrator. When a file has no extension and contains malicious HTML / JavaScript content (such as SVG with HTML content), the payload is executed upon a click. This is fixed in 3.5.

CVE-2021-2220
PeopleSoft Enterprise SCM eProcurement Web Database
5.4
MEDIUM
EPSS
0.3%
2021 1 PoC

Vulnerability in the PeopleSoft Enterprise SCM eProcurement product of Oracle PeopleSoft (component: Manage Requisition Status). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM eProcurement. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise SCM eProcurement accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise SCM eProcurement accessible data. CVSS

CVE-2021-25964
calibreweb Web
5.4
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

In “Calibre-web” application, v0.6.0 to v0.6.12, are vulnerable to Stored XSS in “Metadata”. An attacker that has access to edit the metadata information, can inject JavaScript payload in the description field. When a victim tries to open the file, XSS will be triggered.

CVE-2021-20562
Sterling B2B Integrator Web
5.4
MEDIUM
EPSS
0.7%
2021 2 PoCs

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_3 and 6.1.0.0 through 6.1.0.2 vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199232.

CVE-2021-24366
Admin Columns Web Windows
5.4
MEDIUM
EPSS
0.4%
2021 1 PoC

The Admin Columns WordPress plugin before 4.3 and Admin Columns Pro WordPress plugin before 5.5.1 do not sanitise and escape its Label settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2021-23416
curly-bracket-parser General
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

This affects all versions of package curly-bracket-parser. When used as a template library, it does not properly sanitize the user input.

CVE-2021-20343
Engineering Test Management General
5.4
MEDIUM
EPSS
0.1%
2021 1 PoC

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194593.

CVE-2021-3683
star7th/showdoc Web
5.4
MEDIUM
EPSS
0.1%
2021 CWE-352 1 PoC

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2021-35541
PeopleSoft Enterprise SCM Purchasing Web Database
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

Vulnerability in the PeopleSoft Enterprise SCM product of Oracle PeopleSoft (component: Supplier Portal). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise SCM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Peop

CVE-2021-20345
Rational Rhapsody Model Manager General
5.4
MEDIUM
EPSS
0.1%
2021 1 PoC

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194594.

CVE-2021-20346
Rational Collaborative Lifecycle Management General
5.4
MEDIUM
EPSS
0.1%
2021 1 PoC

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194595.

CVE-2021-25989
ifme Web
5.4
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability in the markdown editor. It can be exploited by making a victim a Leader of a group which triggers the payload for them.

CVE-2021-29252
Software Genérico Web
5.4
MEDIUM
EPSS
0.5%
2021 1 PoC

RSA Archer before 6.9 SP1 P1 (6.9.1.1) contains a stored XSS vulnerability. A remote authenticated malicious Archer user with access to modify link name fields could potentially exploit this vulnerability to execute code in a victim's browser.

CVE-2021-39473
Software Genérico Web
5.4
MEDIUM
EPSS
0.4%
2021 1 PoC

Saibamen HotelManager v1.2 is vulnerable to Cross Site Scripting (XSS) due to improper sanitization of comment and contact fields.

CVE-2021-25975
publify_core Web
5.4
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file.

CVE-2021-29666
Spectrum Scale Web
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199400.

CVE-2021-29668
Engineering Test Management Web
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199406.

CVE-2021-23447
teddy General
5.4
MEDIUM
EPSS
0.3%
2021 1 PoC

This affects the package teddy before 0.5.9. A type confusion vulnerability can be used to bypass input sanitization when the model content is an array (instead of a string).