3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2021-35265
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.3%
2021 0 PoCs

A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attackers to inject arbitrary web script to a page.

CVE-2021-24139
Photo Gallery by 10Web Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
48.4%
2021 CWE-89 1 PoC

Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter.

CVE-2021-44152
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
86.7%
2021 1 PoC

An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or authorization, an unauthenticated user can change the password of any existing user. This allows an attacker to change the password of any known user, thereby preventing valid users from accessing the system and granting the attacker full access to that user's account.

CVE-2021-24155
WordPress Backup and Migrate Plugin – Backup Guard Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
92.8%
2021 CWE-434 4 PoCs

The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high privilege users (admin+) to upload arbitrary files, including PHP ones, leading to RCE.

CVE-2021-24235
Goto Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
43.8%
2021 CWE-79 1 PoC

The Goto WordPress theme before 2.0 does not sanitise the keywords and start_date GET parameter on its Tour List page, leading to an unauthenticated reflected Cross-Site Scripting issue.

CVE-2021-27520
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.8%
2021 1 PoC

A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "author" parameter.

CVE-2021-24239
Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2021 CWE-79 1 PoC

The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin before 3.7.0.1 does not sanitise the invitaion_code GET parameter when outputting it in the Activation Code page, leading to a reflected Cross-Site Scripting issue.

CVE-2021-35488
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
12.8%
2021 1 PoC

Thruk 2.40-2 allows /thruk/#cgi-bin/status.cgi?style=combined&title={TITLE] Reflected XSS via the host or title parameter. An attacker could inject arbitrary JavaScript into status.cgi. The payload would be triggered every time an authenticated user browses the page containing it.

CVE-2021-28937
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
33.8%
2021 1 PoC

The /password.html page of the Web management interface of the Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) contains the administrator account password in plaintext. The page can be intercepted on HTTP.

CVE-2021-26812
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
19.0%
2021 0 PoCs

Cross Site Scripting (XSS) in the Jitsi Meet 2.7 through 2.8.3 plugin for Moodle via the "sessionpriv.php" module. This allows attackers to craft a malicious URL, which when clicked on by users, can inject javascript code to be run by the application.

CVE-2021-24891
Elementor Website Builder Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.3%
2021 CWE-79 2 PoCs

The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue.

CVE-2021-27319
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
31.4%
2021 1 PoC

Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via email parameter.

CVE-2021-27310
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.3%
2021 0 PoCs

Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "language" parameter.

CVE-2021-32172
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
65.5%
2021 2 PoCs

Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin.

CVE-2021-24934
Visual CSS Style Editor Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.8%
2021 CWE-79 1 PoC

The Visual CSS Style Editor WordPress plugin before 7.5.4 does not sanitise and escape the wyp_page_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

CVE-2021-26475
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
49.6%
2021 0 PoCs

EPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI.

CVE-2021-3017
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
80.4%
2021 0 PoCs

The web interface on Intelbras WIN 300 and WRN 342 devices through 2021-01-04 allows remote attackers to discover credentials by reading the def_wirelesspassword line in the HTML source code.

CVE-2021-40822
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.3%
2021 3 PoCs

GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.