3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2021-45967
Software Genérico Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
92.6%
2021 1 PoC

An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints.

CVE-2021-24647
Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
85.0%
2021 CWE-287 2 PoCs

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username

CVE-2021-31324
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
80.0%
2021 1 PoC

The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.

CVE-2021-24169
Advanced Order Export For WooCommerce Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2021 CWE-79 2 PoCs

This Advanced Order Export For WooCommerce WordPress plugin before 3.1.8 helps you to easily export WooCommerce order data. The tab parameter in the Admin Panel is vulnerable to reflected XSS.

CVE-2021-24406
wpForo Forum Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.5%
2021 CWE-601 1 PoC

The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect issue after a successful login. Such issue could allow an attacker to induce a user to use a login URL redirecting to a website under their control and being a replica of the legitimate one, asking them to re-enter their credentials (which will then in the attacker hands)

CVE-2021-25033
WordPress Newsletter Plugin – Noptin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2021 CWE-601 1 PoC

The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the user to its given value, leading to an open redirect issue

CVE-2021-25864
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
57.0%
2021 0 PoCs

node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in file hue-magic.js, to fetch an arbitrary file.

CVE-2021-3110
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
71.9%
2021 3 PoCs

The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] parameter.

CVE-2021-31537
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
88.2%
2021 1 PoC

SIS SIS-REWE Go before 7.7 SP17 allows XSS: rewe/prod/web/index.php (affected parameters are config, version, win, db, pwd, and user) and /rewe/prod/web/rewe_go_check.php (version and all other parameters).

CVE-2021-24212
WooCommerce Help Scout Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
74.5%
2021 CWE-434 2 PoCs

The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site which by default will end up in wp-content/uploads/hstmp.

CVE-2021-24472
QT KenthaRadio Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
89.8%
2021 CWE-918 1 PoC

The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will have the web server fetch and display the content from any URI, this would allow for SSRF (Server Side Request Forgery) and RFI (Remote File Inclusion) vulnerabilities on the website.

CVE-2021-24495
Marmoset Viewer Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
32.2%
2021 CWE-79 1 PoC

The Marmoset Viewer WordPress plugin before 1.9.3 does not property sanitize, validate or escape the 'id' parameter before outputting back in the page, leading to a reflected Cross-Site Scripting issue.

CVE-2021-45811
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
63.1%
2021 1 PoC

A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.

CVE-2021-43510
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
67.2%
2021 2 PoCs

SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php.

CVE-2021-24878
SupportCandy – Helpdesk & Support Ticket System Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The SupportCandy WordPress plugin before 2.2.7 does not sanitise and escape the query string before outputting it back in pages with the [wpsc_create_ticket] shortcode embed, leading to a Reflected Cross-Site Scripting issue

CVE-2021-3297
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
80.5%
2021 0 PoCs

On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access.

CVE-2021-41649
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
91.9%
2021 2 PoCs

An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.

CVE-2021-24827
Asgaros Forum Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
67.7%
2021 CWE-89 1 PoC

The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthenticated SQL injection issue

CVE-2021-31682
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
41.1%
2021 1 PoC

The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for reflected XSS attacks due to the operatorlocale GET parameter not being sanitized. This issue impacts versions 6.5 and below. This issue works by passing in a basic XSS payload to a vulnerable GET parameter that is reflected in the output without sanitization.