3431 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-47737
CSZ CMS Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

CSZ CMS 1.2.7 contains an HTML injection vulnerability that allows authenticated users to insert malicious hyperlinks in message titles. Attackers can craft POST requests to the member messaging system with HTML-based links to potentially conduct phishing or social engineering attacks.

CVE-2021-47857
Moodle Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious scripts. Attackers can craft a calendar event with malicious JavaScript in the subtitle track label to execute arbitrary code when users view the event.

CVE-2021-47820
Ubee EVW327 Web Networking
5.1
MEDIUM
EPSS
0.0%
2021 CWE-352 1 PoC

Ubee EVW327 contains a cross-site request forgery vulnerability that allows attackers to enable remote access without user interaction. Attackers can craft a malicious webpage that automatically submits a form to change router remote access settings to port 8080 without the user's consent.

CVE-2021-47856
Easy Cart Shopping Cart Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Easy Cart Shopping Cart 2021 contains a non-persistent cross-site scripting vulnerability in the search module's keyword parameter. Remote attackers can inject malicious script code through the search input to compromise user sessions and manipulate application content.

CVE-2021-47901
dirsearch General
5.1
MEDIUM
EPSS
0.1%
2021 CWE-1236 1 PoC

Dirsearch 0.4.1 contains a CSV injection vulnerability when using the --csv-report flag that allows attackers to inject formulas through redirected endpoints. Attackers can craft malicious server redirects with comma-separated paths containing Excel formulas to manipulate the generated CSV report.

CVE-2021-47808
Cotonti Siena Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Cotonti Siena 0.9.19 contains a stored cross-site scripting vulnerability in the admin configuration panel's site title parameter. Attackers can inject malicious JavaScript code through the 'maintitle' parameter to execute scripts when administrators view the page.

CVE-2021-47908
Software Genérico Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Ultimate POS 4.4 contains a persistent cross-site scripting vulnerability in the product name parameter that allows remote attackers to inject malicious scripts. Attackers can exploit the vulnerability through product add or edit functions to execute arbitrary JavaScript and potentially hijack user sessions.

CVE-2021-47840
Moeditor Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 2 PoCs

Moeditor 0.2.0 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payloads within markdown files. Attackers can upload specially crafted markdown files with embedded JavaScript that execute when opened, potentially enabling remote code execution on the victim's system.

CVE-2021-47716
orangescrum Web
5.1
MEDIUM
EPSS
0.1%
2021 CWE-79 1 PoC

Orangescrum 1.8.0 contains multiple cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts through various input parameters. Attackers can exploit parameters like 'projid', 'CS_message', and 'name' to execute arbitrary JavaScript code in victim's browsers by submitting crafted payloads through application endpoints.

CVE-2021-47732
CMSimple Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

CMSimple 5.2 contains a stored cross-site scripting vulnerability in the Filebrowser External input field that allows attackers to inject malicious JavaScript. Attackers can place unfiltered JavaScript code that executes when users click on Page or Files tabs, enabling persistent script injection.

CVE-2021-47837
Markdownify Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 2 PoCs

Markdownify 1.2.0 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payloads within markdown files. Attackers can upload crafted markdown files with embedded scripts that execute when the file is opened, potentially enabling remote code execution.

CVE-2021-47912
PHP Melody Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

PHP Melody version 3.0 contains multiple non-persistent cross-site scripting vulnerabilities in categories, import, and user import files. Attackers can inject malicious scripts through unvalidated parameters to execute client-side attacks and potentially hijack user sessions.

CVE-2021-47830
My SMTP Contact Plugin Web
5.1
MEDIUM
EPSS
0.1%
2021 CWE-352 2 PoCs

GetSimple CMS My SMTP Contact Plugin 1.1.1 contains a cross-site request forgery (CSRF) vulnerability. Attackers can craft a malicious webpage that, when visited by an authenticated administrator, can change SMTP configuration settings in the plugin. This may allow unauthorized changes but does not directly enable remote code execution.

CVE-2021-47913
PHP Melody Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

PHP Melody 3.0 contains a persistent cross-site scripting vulnerability in the video editor that allows privileged users to inject malicious scripts. Attackers can exploit the WYSIWYG editor to execute persistent scripts, potentially leading to session hijacking and application manipulation.

CVE-2021-47838
Markright Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 2 PoCs

Markright 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to embed malicious payloads in markdown files. Attackers can upload specially crafted markdown files that execute arbitrary JavaScript when opened, potentially enabling remote code execution on the victim's system.

CVE-2021-47906
BloofoxCMS Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

BloofoxCMS 0.5.2.1 contains a stored cross-site scripting vulnerability in the articles text parameter that allows authenticated attackers to inject malicious scripts. Attackers can insert malicious javascript payloads in the text field to execute scripts and potentially steal authenticated users' cookies.

CVE-2021-47841
SnipCommand Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 2 PoCs

SnipCommand 0.1.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious payloads into command snippets. Attackers can execute arbitrary code by embedding malicious JavaScript that triggers remote command execution through file or title inputs.

CVE-2021-47897
PEEL Shopping Web
5.1
MEDIUM
EPSS
0.1%
2021 CWE-79 1 PoC

PEEL Shopping 9.3.0 contains a stored cross-site scripting vulnerability in the address parameter of the change_params.php script. Attackers can inject malicious JavaScript payloads that execute when users interact with the address text box, potentially enabling client-side script execution.

CVE-2021-47750
YouPHPTube Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

YouPHPTube <= 7.8 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the redirectUri parameter in the signup page. Attackers can craft special signup URLs with embedded script tags to execute arbitrary JavaScript in victims' browsers when they access the signup page.

CVE-2021-29253
Software Genérico General
5.1
MEDIUM
EPSS
0.1%
2021 1 PoC

The Tableau integration in RSA Archer 6.4 P1 (6.4.0.1) through 6.9 P2 (6.9.0.2) is affected by an insecure credential storage vulnerability. An malicious attacker with access to the Tableau workbook file may obtain access to credential information to use it in further attacks.