515 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2021-38540
Apache Airflow Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.8%
2021 CWE-269 1 PoC

The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information disclosure or remote code execution. This issue affects Apache Airflow >=2.0.0, <2.1.3.

CVE-2021-28150
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
78.8%
2021 0 PoCs

Hongdian H8922 3.0.5 devices allow the unprivileged guest user to read cli.conf (with the administrator password and other sensitive data) via /backup2.cgi.

CVE-2021-46379
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
52.2%
2021 3 PoCs

DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site.

CVE-2021-20091
Buffalo WSR-2533DHPL2, Buffalo WSR-2533DHP3 General ⚡ nuclei
N/A
UNKNOWN
EPSS
84.7%
2021 1 PoC

The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly sanitize user input. An authenticated remote attacker could leverage this vulnerability to alter device configuration, potentially gaining remote code execution.

CVE-2021-46069
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.7%
2021 1 PoC

A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Mechanic List Section in login panel.

CVE-2021-46071
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.7%
2021 1 PoC

A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Category List Section in login panel.

CVE-2021-20031
SonicOS Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
36.2%
2021 CWE-601 1 PoC

A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domains.

CVE-2021-24956
Blog2Social: Social Media Auto Post & Scheduler Web Networking Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.5%
2021 CWE-79 1 PoC

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sShowByDate parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

CVE-2021-24298
Simple Giveaways – Grow your business, email lists and traffic with contests Web ⚡ nuclei
N/A
UNKNOWN
EPSS
13.9%
2021 CWE-79 2 PoCs

The method and share GET parameters of the Giveaway pages were not sanitised, validated or escaped before being output back in the pages, thus leading to reflected XSS

CVE-2021-33851
WordPress Customize Login Image Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.8%
2021 CWE-79 1 PoC

A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Custom logo link" executes whenever the user opens the Settings Page of the "Customize Login Image" Plugin.

CVE-2021-45422
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
21.5%
2021 4 PoCs

Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability in the /goform/activate_process "count" parameter via GET. No authentication is required.

CVE-2021-24389
WP Foodbakery Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
13.9%
2021 CWE-79 1 PoC

The WP Foodbakery WordPress plugin before 2.2, used in the FoodBakery WordPress theme before 2.2 did not properly sanitize the foodbakery_radius parameter before outputting it back in the response, leading to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability.

CVE-2021-35064
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.5%
2021 3 PoCs

KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits running of multiple dangerous commands, including unzip, systemctl and dpkg.

CVE-2021-24316
Mediumish Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
57.4%
2021 CWE-79 2 PoCs

The search feature of the Mediumish WordPress theme through 1.0.47 does not properly sanitise it's 's' GET parameter before output it back the page, leading to the Cross-SIte Scripting issue.

CVE-2021-36646
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.2%
2021 0 PoCs

A Cross Site Scrtpting (XSS) vulnerability in KodExplorer 4.45 allows remote attackers to run arbitrary code via /index.php page.