515 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2021-40150
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
34.2%
2021 0 PoCs

The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapped to a publicly accessible path. In this way an attacker can download the entire NGINX/FastCGI configurations by querying the /conf/nginx.conf or /conf/fastcgi.conf URI.

CVE-2021-45968
Software Genérico Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
86.8%
2021 1 PoC

An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Phone System before 7.20.x (and in other products). An endpoint in the backend Tomcat server of the Pascom allows SSRF, a related issue to CVE-2019-18394.

CVE-2021-24364
Jannah Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.0%
2021 CWE-79 1 PoC

The Jannah WordPress theme before 5.4.4 did not properly sanitize the options JSON parameter in its tie_get_user_weather AJAX action before outputting it back in the page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

CVE-2021-24499
Workreap Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.9%
2021 CWE-434 7 PoCs

The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks, or validate that the request is from a valid user in any other way. The endpoints allowed for uploading arbitrary files to the uploads/workreap-temp directory. Uploaded files were neither sanitized nor validated, allowing an unauthenticated visitor to upload executable code such as php scripts.

CVE-2021-46418
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
63.1%
2021 1 PoC

An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.

CVE-2021-24452
W3 Total Cache Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
7.7%
2021 CWE-79 1 PoC

The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the "extension" parameter in the Extensions dashboard, when the 'Anonymously track usage to improve product quality' setting is enabled, as the parameter is output in a JavaScript context without proper escaping. This could allow an attacker, who can convince an authenticated admin into clicking a link, to run malicious JavaScript within the user's web browser, which could lead to full site compromise.

CVE-2021-24876
Registrations for the Events Calendar – Event Registration Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

CVE-2021-24943
Registrations for the Events Calendar – Event Registration Plugin Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
55.5%
2021 CWE-89 1 PoC

The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.

CVE-2021-24435
Titan Framework Web ⚡ nuclei
N/A
UNKNOWN
EPSS
13.3%
2021 CWE-79 1 PoC

The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET parameters before outputting them back in an href attribute, leading to Reflected Cross-Site Scripting issues

CVE-2021-26294
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.5%
2021 1 PoC

An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal to read files (such as a data/settings/settings.xml file containing admin panel credentials), as demonstrated by dav/server.php/files/personal/%2e%2e when using the caldav_public_user account (with caldav_public_user as its password).

CVE-2021-38147
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
78.7%
2021 1 PoC

Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as reports containing sensitive information, because authentication is not required for API access to processexecution/DownloadExcelFile/Domain_Credential_Report_Excel, processexecution/DownloadExcelFile/User_Report_Excel, processexecution/DownloadExcelFile/Process_Report_Excel, processexecution/DownloadExcelFile/Infrastructure_Report_Excel, or processexecution/DownloadExcelFile/Resolver_Report_Excel.

CVE-2021-25008
Code Snippets Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.4%
2021 CWE-79 1 PoC

The Code Snippets WordPress plugin before 2.14.3 does not escape the snippets-safe-mode parameter before outputting it back in attributes, leading to a Reflected Cross-Site Scripting issue

CVE-2021-24288
Newsletter via SMTP, Sendinblue, Sendgrid, Mailgun - AcyMailing SMTP Newsletter General ⚡ nuclei
N/A
UNKNOWN
EPSS
4.4%
2021 CWE-601 1 PoC

When subscribing using AcyMailing, the 'redirect' parameter isn't properly sanitized. Turning the request from POST to GET, an attacker can craft a link containing a potentially malicious landing page and send it to the victim.

CVE-2021-46072
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.7%
2021 1 PoC

A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service List Section in login panel.

CVE-2021-29156
Software Genérico Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
88.7%
2021 2 PoCs

ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-character retrieval of password hashes, or retrieve a session token or a private key.

CVE-2021-43734
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
77.4%
2021 0 PoCs

kkFileview v4.0.0 has arbitrary file read through a directory traversal vulnerability which may lead to sensitive file leak on related host.

CVE-2021-25099
GiveWP – Donation Plugin and Fundraising Platform Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.4%
2021 CWE-79 1 PoC

The GiveWP WordPress plugin before 2.17.3 does not sanitise and escape the form_id parameter before outputting it back in the response of an unauthenticated request via the give_checkout_login AJAX action, leading to a Reflected Cross-Site Scripting

CVE-2021-43287
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
79.2%
2021 1 PoC

An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets known to the GoCD server to unauthenticated attackers.

CVE-2021-24442
Poll, Survey, Questionnaire and Voting system Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
72.5%
2021 CWE-89 1 PoC

The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to perform SQL Injection attacks

CVE-2021-29006
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
20.6%
2021 2 PoCs

rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any file on the server.