3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2021-34370
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
8.5%
2021 1 PoC

Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS. NOTE: the vendor states "there are configurable security flags and we are unable to reproduce them with the available information.

CVE-2021-30203
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2021 0 PoCs

A reflected cross-site scripting (XSS) vulnerability in the zero parameter of dzzoffice 2.02.1_SC_UTF8 allows attackers to execute arbitrary web scripts or HTML.

CVE-2021-20086
jquery-bbq General ⚡ nuclei
N/A
UNKNOWN
EPSS
49.6%
2021 0 PoCs

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-bbq 1.2.1 allows a malicious user to inject properties into Object.prototype.

CVE-2021-24681
Duplicate Page Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-79 1 PoC

The Duplicate Page WordPress plugin through 4.4.2 does not sanitise or escape the Duplicate Post Suffix settings before outputting it, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2021-25079
Contact Form Entries – Contact Form 7, WPforms and more Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.4%
2021 CWE-79 1 PoC

The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page

CVE-2021-27850
Apache Tapestry Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.2%
2021 CWE-200 5 PoCs

A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5, 5.5.0, 5.6.2 and 5.7.0. The vulnerability I have found is a bypass of the fix for CVE-2019-0195. Recap: Before the fix of CVE-2019-0195 it was possible to download arbitrary class files from the classpath by providing a crafted asset file URL. An attacker was able to download the file `AppModule.class` by requesting the URL `http://localhost:8080/assets/something/services/AppModule.class` which contains a HMAC secret key. The fix for that bug was

CVE-2021-40856
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
88.1%
2021 3 PoCs

Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring.

CVE-2021-31589
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2021 3 PoCs

A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Software version 6.0.1 and older, which allows the injection of unauthenticated, specially-crafted web requests without proper sanitization.

CVE-2021-41460
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
44.7%
2021 0 PoCs

ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.

CVE-2021-24554
Paytm – Donation Plugin Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
21.0%
2021 CWE-89 2 PoCs

The Paytm – Donation Plugin WordPress plugin through 1.3.2 does not sanitise, validate or escape the id GET parameter before using it in a SQL statement when deleting donations, leading to an authenticated SQL injection issue

CVE-2021-41419
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
77.1%
2021 0 PoCs

QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization.

CVE-2021-24979
Paid Memberships Pro Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.7%
2021 CWE-79 1 PoC

The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2021-24746
Social Sharing Plugin – Sassy Social Share Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.8%
2021 CWE-79 1 PoC

The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back in onclick attributes when the "Enable 'More' icon" option is enabled (which is the default setting), leading to a Reflected Cross-Site Scripting issue.

CVE-2021-24657
Limit Login Attempts Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.8%
2021 CWE-79 1 PoC

The Limit Login Attempts WordPress plugin before 4.0.50 does not escape the IP addresses (which can be controlled by attacker via headers such as X-Forwarded-For) of attempted logins before outputting them in the reports table, leading to an Unauthenticated Stored Cross-Site Scripting issue.

CVE-2021-22053
Spring Cloud Netflix Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
89.6%
2021 CWE-94 2 PoCs

Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within the request URI path during the resolution of view templates. When a request is made at `/hystrix/monitor;[user-provided data]`, the path elements following `hystrix/monitor` are being evaluated as SpringEL expressions, which can lead to code execution.

CVE-2021-3654
openstack-nova General ⚡ nuclei
N/A
UNKNOWN
EPSS
88.4%
2021 CWE-601 0 PoCs

A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL.

CVE-2021-40651
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
76.5%
2021 2 PoCs

OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary file from the server's filesystem as long as the application has access to the file.

CVE-2021-24510
MF Gig Calendar Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
21.1%
2021 1 PoC

The MF Gig Calendar WordPress plugin before 1.2 does not sanitise and escape the id GET parameter before outputting back in the admin dashboard when editing an Event, leading to a reflected Cross-Site Scripting issue

CVE-2021-40542
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
25.3%
2021 0 PoCs

Opensis-Classic Version 8.0 is affected by cross-site scripting (XSS). An unauthenticated user can inject and execute JavaScript code through the link_url parameter in Ajax_url_encode.php.

CVE-2021-43496
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
40.2%
2021 0 PoCs

Clustering master branch as of commit 53e663e259bcfc8cdecb56c0bb255bd70bfcaa70 is affected by a directory traversal vulnerability. This attack can cause the disclosure of critical secrets stored anywhere on the system and can significantly aid in getting remote code access.