3431 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-47738
CSZ CMS Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

CSZ CMS 1.2.7 contains a persistent cross-site scripting vulnerability that allows unauthorized users to embed malicious JavaScript in private messages. Attackers can send messages with script payloads in the user-agent header, which will execute when an admin views the message in the backend dashboard.

CVE-2021-47839
Marky Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 2 PoCs

Marky 0.0.1 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into markdown files. Attackers can upload crafted markdown files with embedded JavaScript payloads that execute when the file is opened, potentially enabling remote code execution.

CVE-2021-47885
PayPal PRO Payment Terminal Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Multiple payment terminal versions contain non-persistent cross-site scripting vulnerabilities in billing and payment information input fields. Attackers can inject malicious script code through vulnerable parameters to manipulate client-side requests and potentially execute session hijacking or phishing attacks.

CVE-2021-47729
Selea Targa IP OCR-ANPR Camera Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 2 PoCs

Selea Targa IP OCR-ANPR Camera contains a stored cross-site scripting vulnerability in the 'files_list' parameter that allows attackers to inject malicious HTML and script code. Attackers can send a POST request to /cgi-bin/get_file.php with crafted payload to execute arbitrary scripts in victim's browser session.

CVE-2021-25453
Samsung Mobile Devices Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-20 1 PoC

Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluetooth information.

CVE-2021-47914
PHP Melody Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

PHP Melody version 3.0 contains a persistent cross-site scripting vulnerability in the edit-video.php submitted parameter that allows remote attackers to inject malicious script code. Attackers can exploit this vulnerability to execute arbitrary JavaScript, potentially leading to session hijacking, persistent phishing, and manipulation of application modules.

CVE-2021-47873
VestaCP Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

VestaCP versions prior to 0.9.8-25 contain a cross-site scripting vulnerability in the IP interface configuration that allows attackers to inject malicious scripts. Attackers can exploit the 'v_interface' parameter by sending a crafted POST request to the add/ip/ endpoint with a stored XSS payload.

CVE-2021-25340
Samsung Mobile Devices General
5.1
MEDIUM
EPSS
0.0%
2021 CWE-284 2 PoCs

Improper access control vulnerability in Samsung keyboard version prior to SMR Feb-2021 Release 1 allows physically proximate attackers to change in arbitrary settings during Initialization State.

CVE-2021-47743
COMMAX Biometric Access Control System Web
5.1
MEDIUM
EPSS
0.1%
2021 CWE-79 1 PoC

COMMAX Biometric Access Control System 1.0.0 contains an unauthenticated reflected cross-site scripting vulnerability in cookie parameters 'CMX_ADMIN_NM' and 'CMX_COMPLEX_NM'. Attackers can inject malicious HTML and JavaScript code into these cookie values to execute arbitrary scripts in a victim's browser session.

CVE-2021-47834
Schlix CMS Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Schlix CMS 2.2.6-6 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into category titles. Attackers can create a new contact category with a script payload that will execute when the page is viewed by other users.

CVE-2021-47919
Simple CMS Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Simple CMS 2.1 contains a non-persistent cross-site scripting vulnerability in the preview.php file's id parameter. Attackers can inject malicious script code through a GET request to execute arbitrary scripts and potentially hijack user sessions or perform phishing attacks.

CVE-2021-47917
Simple CMS Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Simple CMS 2.1 contains a persistent cross-site scripting vulnerability in user input parameters that allows remote attackers to inject malicious script code. Attackers can exploit the newUser and editUser modules to inject persistent scripts that execute on user list preview, potentially leading to session hijacking and application manipulation.

CVE-2021-47950
Advanced Guestbook Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Advanced Guestbook 2.4.4 contains a persistent cross-site scripting vulnerability in the smilies administration interface that allows authenticated attackers to inject malicious scripts by manipulating the s_emotion parameter. Attackers can submit POST requests to admin.php with JavaScript code in the s_emotion field, which executes when administrators view the smilies tab.

CVE-2021-47924
Ultimate Product Catalog Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Ultimate Product Catalog 5.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the price parameter. Attackers can submit POST requests to post.php with HTML/JavaScript payloads in the price field to execute arbitrary code when the product is viewed.

CVE-2021-47931
Exponent CMS Web
5.1
MEDIUM
EPSS
0.1%
2021 CWE-79 1 PoC

Exponent CMS 2.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the Title and Text Block parameters in the text editing endpoint. Attackers can inject iframe payloads with embedded SVG onload events to execute arbitrary JavaScript, and the application also exposes database credentials in responses and lacks brute-force protection on authentication endpoints.

CVE-2021-47922
Slider by Soliloquy Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Slider by Soliloquy 2.6.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the title parameter. Attackers can add JavaScript payloads in the title field when creating or editing sliders, which executes in the browsers of users viewing the slider on both administrative and frontend pages.

CVE-2021-47907
Rocket LMS Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Rocket LMS 1.1 contains a persistent cross-site scripting vulnerability in the support ticket module that allows authenticated users to inject malicious script code through the title parameter. Attackers can submit support tickets with embedded HTML/JavaScript payloads that execute in the browsers of other users viewing the message history, enabling session hijacking and phishing attacks.

CVE-2021-47957
Cookie Law Bar Web Windows
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Cookie Law Bar 1.2.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting unsanitized input to the Bar Message field. Attackers can inject script payloads through the plugin settings page that execute in the browsers of all WordPress users viewing the site, enabling cookie theft and sensitive data exfiltration.

CVE-2021-47926
Contact Form to Email Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Contact Form to Email 1.3.24 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by creating forms with script tags in the form name field. Attackers can craft form names containing JavaScript code that executes when other logged-in users access the form management page, enabling session hijacking or credential theft.

CVE-2021-32006
GateManager General
5.0
MEDIUM
EPSS
0.1%
2021 CWE-275 1 PoC

This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Permission Issues vulnerability in LinkManager web portal of Secomea GateManager allows logged in LinkManager user to access stored SiteManager backup files.