7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-3767
bookstackapp/bookstack Web
5.4
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-25989
ifme Web
5.4
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability in the markdown editor. It can be exploited by making a victim a Leader of a group which triggers the payload for them.

CVE-2021-29670
Engineering Test Management Web
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199408.

CVE-2021-29668
Engineering Test Management Web
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199406.

CVE-2021-21087
ColdFusion Web ⚡ nuclei
5.4
MEDIUM
EPSS
84.2%
2021 CWE-79 0 PoCs

Adobe Coldfusion versions 2016 (update 16 and earlier), 2018 (update 10 and earlier) and 2021.0.0.323925 are affected by an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An attacker could abuse this vulnerability to execute arbitrary JavaScript code in context of the current user. Exploitation of this issue requires user interaction.

CVE-2021-20346
Rational Collaborative Lifecycle Management General
5.4
MEDIUM
EPSS
0.1%
2021 1 PoC

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194595.

CVE-2021-20345
Rational Rhapsody Model Manager General
5.4
MEDIUM
EPSS
0.1%
2021 1 PoC

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194594.

CVE-2021-3862
icecoder/icecoder Web
5.4
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

icecoder is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-37378
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2021 1 PoC

Cross Site Scripting (XSS) vulnerability in Teradek Cube and Cube Pro firmware version 7.3.x and earlier allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to address this issue.

CVE-2021-4176
livehelperchat/livehelperchat Web
5.4
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-23673
pekeupload Web
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

This affects all versions of package pekeupload. If an attacker induces a user to upload a file whose name contains javascript code, the javascript code will be executed.

CVE-2021-35541
PeopleSoft Enterprise SCM Purchasing Web Database
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

Vulnerability in the PeopleSoft Enterprise SCM product of Oracle PeopleSoft (component: Supplier Portal). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise SCM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Peop

CVE-2021-34590
CC612 Web
5.4
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

In Bender/ebee Charge Controllers in multiple versions are prone to Cross-site Scripting. An authenticated attacker could write HTML Code into configuration values. These values are not properly escaped when displayed.

CVE-2021-23385
Flask-Security General
5.4
MEDIUM
EPSS
0.2%
2021 2 PoCs

This affects all versions of package Flask-Security. When using the get_post_logout_redirect and get_post_login_redirect functions, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as \\\evil.com/path. This vulnerability is only exploitable if an alternative WSGI server other than Werkzeug is used, or the default behaviour of Werkzeug is modified using 'autocorrect_location_header=False. **Note:** Flask-Security is not maintained anymore.

CVE-2021-3683
star7th/showdoc Web
5.4
MEDIUM
EPSS
0.1%
2021 CWE-352 1 PoC

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2021-20343
Engineering Test Management General
5.4
MEDIUM
EPSS
0.1%
2021 1 PoC

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194593.

CVE-2021-37936
Kibana Database
5.4
MEDIUM
EPSS
0.6%
2021 CWE-79 1 PoC

It was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an attacker with the ability to write documents to an elasticsearch index could inject HTML. When the Discover app highlighted a search term containing the HTML, it would be rendered for the user.

CVE-2021-23416
curly-bracket-parser General
5.4
MEDIUM
EPSS
0.2%
2021 1 PoC

This affects all versions of package curly-bracket-parser. When used as a template library, it does not properly sanitize the user input.

CVE-2021-24366
Admin Columns Web Windows
5.4
MEDIUM
EPSS
0.4%
2021 1 PoC

The Admin Columns WordPress plugin before 4.3 and Admin Columns Pro WordPress plugin before 5.5.1 do not sanitise and escape its Label settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2021-37704
phpfastcache Web ⚡ nuclei
5.4
MEDIUM
EPSS
53.1%
2021 CWE-200 0 PoCs

PhpFastCache is a high-performance backend cache system (packagist package phpfastcache/phpfastcache). In versions before 6.1.5, 7.1.2, and 8.0.7 the `phpinfo()` can be exposed if the `/vendor` is not protected from public access. This is a rare situation today since the vendor directory is often located outside the web directory or protected via server rule (.htaccess, etc). Only the v6, v7 and v8 will be patched respectively in 8.0.7, 7.1.2, 6.1.5. Older versions such as v5, v4 are not longer supported and will **NOT** be patched. As a workaround, protect the `/vendor` directory from public