515 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2021-42566
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2021 1 PoC

myfactory.FMS before 7.1-912 allows XSS via the Error parameter.

CVE-2021-24274
Ultimate Maps by Supsystic Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.5%
2021 CWE-79 2 PoCs

The Ultimate Maps by Supsystic WordPress plugin before 1.2.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

CVE-2021-45428
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2021 2 PoCs

TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files including HTML and CGI formats.

CVE-2021-22881
https://github.com/rails/rails Web ⚡ nuclei
N/A
UNKNOWN
EPSS
15.5%
2021 CWE-601 0 PoCs

The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Host` headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. Impacted applications will have allowed hosts with a leading dot. When an allowed host contains a leading dot, a specially crafted `Host` header can be used to redirect to a malicious website.

CVE-2021-24342
JNews Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.3%
2021 CWE-79 1 PoC

The JNews WordPress theme before 8.0.6 did not sanitise the cat_id parameter in the POST request /?ajax-request=jnews (with action=jnews_build_mega_category_*), leading to a Reflected Cross-Site Scripting (XSS) issue.

CVE-2021-46073
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.7%
2021 1 PoC

A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the User List Section in login panel.

CVE-2021-20158
Trendnet AC2600 TEW-827DRU General ⚡ nuclei
N/A
UNKNOWN
EPSS
86.4%
2021 1 PoC

Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauthenticated, malicous actor to force the change of the admin password due to a hidden administrative command.

CVE-2021-24176
JH 404 Logger Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
37.0%
2021 CWE-79 2 PoCs

The JH 404 Logger WordPress plugin through 1.1 doesn't sanitise the referer and path of 404 pages, when they are output in the dashboard, which leads to executing arbitrary JavaScript code in the WordPress dashboard.

CVE-2021-20167
Netgear RAX43 Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
84.6%
2021 1 PoC

Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable to command injection in the name parameter.

CVE-2021-40875
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
83.0%
2021 1 PoC

Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat actor can access the /files.md5 file on the client side of a Gurock TestRail application, disclosing a full list of application files and the corresponding file paths. The corresponding file paths can be tested, and in some cases, result in the disclosure of hardcoded credentials, API keys, or other sensitive data.

CVE-2021-31805
Apache Struts Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.8%
2021 CWE-917 10 PoCs

The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.

CVE-2021-37416
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.2%
2021 1 PoC

Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page.

CVE-2021-24387
WP Pro Real Estate 7 Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
42.0%
2021 CWE-79 1 PoC

The WP Pro Real Estate 7 WordPress theme before 3.1.1 did not properly sanitise the ct_community parameter in its search listing page before outputting it back in it, leading to a reflected Cross-Site Scripting which can be triggered in both unauthenticated or authenticated user context

CVE-2021-24150
Like Button Rating ♥ LikeBtn Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
46.3%
2021 CWE-918 1 PoC

The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request Forgery (SSRF).

CVE-2021-36356
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.0%
2021 1 PoC

KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames (even though browseSystemFiles.php is no longer reachable via the GUI). NOTE: this issue exists because of an incomplete fix for CVE-2019-17124.

CVE-2021-24219
Thrive Optimize Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
16.4%
2021 CWE-284 2 PoCs

The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive Apprentice WordPress plugin before 2.3.9.4, Thrive Visual Editor WordPress plugin before 2.6.7.4, Thrive Dashboard WordPress plugin before 2.3.9.3, Thrive Ovation WordPress plugin before 2.4.5, Thrive Clever Widgets WordPress plugin before 1.57.1 and Rise by Thrive Themes WordPres

CVE-2021-21745
MF971R Web ⚡ nuclei
N/A
UNKNOWN
EPSS
36.4%
2021 0 PoCs

ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform illegal authorization operations by sending a request to the user to click.

CVE-2021-24340
WP Statistics Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
83.2%
2021 CWE-89 1 PoC

The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been accessible to administrator only, was also available to any visitor, including unauthenticated ones.

CVE-2021-46424
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
91.5%
2021 1 PoC

Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to delete any file, even system internal files, via a DELETE request.

CVE-2021-45232
Apache APISIX Dashboard Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2021 CWE-306 13 PoCs

In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some API directly use the interface of framework `gin` thus bypassing the authentication.