3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2021-42887
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
61.3%
2021 0 PoCs

In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.

CVE-2021-22145
Elasticsearch Database ⚡ nuclei
N/A
UNKNOWN
EPSS
67.9%
2021 CWE-200 3 PoCs

A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.

CVE-2021-24286
Redirect 404 to parent Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
52.3%
2021 CWE-79 2 PoCs

The settings page of the Redirect 404 to parent WordPress plugin before 1.3.1 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue

CVE-2021-46371
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
26.1%
2021 0 PoCs

antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the foreground leads to leakage of sensitive information.

CVE-2021-45043
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
81.3%
2021 2 PoCs

HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_Language parameter.

CVE-2021-24214
OpenID Connect Generic Client Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.0%
2021 CWE-79 1 PoC

The OpenID Connect Generic Client WordPress plugin 3.8.0 and 3.8.1 did not sanitise the login error when output back in the login form, leading to a reflected Cross-Site Scripting issue. This issue does not require authentication and can be exploited with the default configuration.

CVE-2021-38156
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
84.0%
2021 1 PoC

In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.

CVE-2021-32478
moodle Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.4%
2021 CWE-79 0 PoCs

The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected.

CVE-2021-29200
Apache OFBiz Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.5%
2021 2 PoCs

Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack

CVE-2021-37598
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
5.7%
2021 0 PoCs

WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character.

CVE-2021-46419
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
88.3%
2021 1 PoC

An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system files and scripts.

CVE-2021-27124
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
22.3%
2021 3 PoCs

SQL injection in the expertise parameter in search_result.php in Doctor Appointment System v1.0 allows an authenticated patient user to dump the database credentials via a SQL injection attack.

CVE-2021-37291
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
57.5%
2021 1 PoC

An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.

CVE-2021-24291
Photo Gallery by 10Web – Mobile-Friendly Image Gallery Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
14.6%
2021 CWE-79 2 PoCs

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cross-Site Scripting (XSS) issues via the gallery_id, tag, album_id and _id GET parameters passed to the bwg_frontend_data AJAX action (available to both unauthenticated and authenticated users)

CVE-2021-33564
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.4%
2021 3 PoCs

An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the verify_url option is disabled. This may lead to code execution. The problem occurs because the generate and process features mishandle use of the ImageMagick convert utility.

CVE-2021-25016
Floating Chat Widget: Contact Icons, Messages, Telegram, Email, SMS, Call Button – Chaty Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
15.7%
2021 CWE-79 1 PoC

The Chaty WordPress plugin before 2.8.3 and Chaty Pro WordPress plugin before 2.8.2 do not sanitise and escape the search parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting

CVE-2021-39433
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
82.5%
2021 1 PoC

A local file inclusion (LFI) vulnerability exists in version BIQS IT Biqs-drive v1.83 and below when sending a specific payload as the file parameter to download/index.php. This allows the attacker to read arbitrary files from the server with the permissions of the configured web-user.

CVE-2021-24358
The Plus Addons for Elementor Page Builder Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.9%
2021 CWE-601 1 PoC

The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.10 did not validate a redirect parameter on a specifically crafted URL before redirecting the user to it, leading to an Open Redirect issue.

CVE-2021-33221
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.2%
2021 2 PoCs

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Unauthenticated API Endpoints.