7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-43062
Fortinet FortiMail Web Networking ⚡ nuclei
6.1
MEDIUM
EPSS
57.1%
2021 1 PoC

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows attacker to execute unauthorized code or commands via crafted HTTP GET requests to the FortiGuard URI protection service.

CVE-2021-24870
WP Fastest Cache Web Windows
6.1
MEDIUM
EPSS
0.1%
2021 1 PoC

The WP Fastest Cache WordPress plugin before 0.9.5 is lacking a CSRF check in its wpfc_save_cdn_integration AJAX action, and does not sanitise and escape some the options available via the action, which could allow attackers to make logged in high privilege users call it and set a Cross-Site Scripting payload

CVE-2021-35568
PeopleSoft Enterprise PT PeopleTools Web Database
6.1
MEDIUM
EPSS
0.6%
2021 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Rich Text Editor). Supported versions that are affected are 8.57, 8.58 and 8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update

CVE-2021-39322
Easy Social Icons Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
13.9%
2021 CWE-79 1 PoC

The Easy Social Icons plugin <= 3.0.8 for WordPress echoes out the raw value of `$_SERVER['PHP_SELF']` in its main file. On certain configurations including Apache+modPHP this makes it possible to use it to perform a reflected Cross-Site Scripting attack by injecting malicious code in the request path.

CVE-2021-28957
Software Genérico Web
6.1
MEDIUM
EPSS
0.5%
2021 1 PoC

An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in lxml 4.6.3.

CVE-2021-2375
JD Edwards EnterpriseOne Tools Web Database
6.1
MEDIUM
EPSS
0.6%
2021 1 PoC

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime). Supported versions that are affected are 9.2.5.3 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or dele

CVE-2021-33707
SAP NetWeaver (Knowledge Management) General
6.1
MEDIUM
EPSS
0.6%
2021 CWE-601 1 PoC

SAP NetWeaver Knowledge Management allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via a URL stored in a component. This could enable the attacker to compromise the user's confidentiality and integrity.

CVE-2021-43446
Software Genérico Web
6.1
MEDIUM
EPSS
6.4%
2021 1 PoC

ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Cross Site Scripting (XSS). The "macros" feature of the document editor allows malicious cross site scripting payloads to be used.

CVE-2021-42552
ArchivistaBox webclient Web
6.1
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

Cross-site Scripting (XSS) vulnerability in ArchivistaBox webclient allows an attacker to craft a malicious link, executing JavaScript in the context of a victim's browser. This issue affects all ArchivistaBox versions prior to 2022/I.

CVE-2021-46767
2nd Gen EPYC General
6.1
MEDIUM
EPSS
0.1%
2021 1 PoC

Insufficient input validation in the ASP may allow an attacker with physical access, unauthorized write access to memory potentially leading to a loss of integrity or denial of service.

CVE-2021-22141
Kibana General
6.1
MEDIUM
EPSS
0.2%
2021 CWE-601 1 PoC

An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously crafted URL, it could result in Kibana redirecting the user to an arbitrary website.

CVE-2021-25959
opencrx-core-config Web
6.1
MEDIUM
EPSS
0.4%
2021 CWE-79 1 PoC

In OpenCRX, versions v4.0.0 through v5.1.0 are vulnerable to reflected Cross-site Scripting (XSS), due to unsanitized parameters in the password reset functionality. This allows execution of external javascript files on any user of the openCRX instance.

CVE-2021-2192
Solaris Operating System Database
6.1
MEDIUM
EPSS
0.1%
2021 1 PoC

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris as well as unauthorized update, insert or delete access to some of Oracle Solaris accessible data. Note: This vulnerability applies to Oracle Solaris on SPARC

CVE-2021-34643
Skaut Bazar Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
7.7%
2021 CWE-79 0 PoCs

The Skaut bazar WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/skaut-bazar.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.3.2.

CVE-2021-41943
Software Genérico General
6.1
MEDIUM
EPSS
0.2%
2021 1 PoC

Logrhythm Web Console 7.4.9 allows for HTML tag injection through Contextualize Action -> Create a new Contextualize Action -> Inject your HTML tag in the name field.

CVE-2021-45522
Software Genérico General
6.1
MEDIUM
EPSS
0.2%
2021 1 PoC

NETGEAR XR1000 devices before 1.0.0.58 are affected by a hardcoded password.

CVE-2021-25982
Factor Web
6.1
MEDIUM
EPSS
1.5%
2021 CWE-79 1 PoC

In Factor (App Framework & Headless CMS) forum plugin, versions 1.3.5 to 1.8.30, are vulnerable to reflected Cross-Site Scripting (XSS) at the “search” parameter in the URL. An unauthenticated attacker can execute malicious JavaScript code and steal the session cookies.

CVE-2021-30134
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
1.8%
2021 1 PoC

php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php.

CVE-2021-35580
Applications Manager Web Database
6.1
MEDIUM
EPSS
0.6%
2021 1 PoC

Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: View Reports). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Manager, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert o

CVE-2021-25370
🔥 KEV Samsung Mobile Devices General
6.1
MEDIUM
EPSS
0.5%
2021 2 PoCs

An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic.