7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-2347
Hyperion Infrastructure Technology Web Database
5.2
MEDIUM
EPSS
0.6%
2021 1 PoC

Vulnerability in the Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). The supported version that is affected is 11.2.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Hyperion Infrastructure Technology accessible data as well as unauthorized update, i

CVE-2021-21264
october Web
5.2
MEDIUM
EPSS
0.0%
2021 CWE-862 1 PoC

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-26231 (fixed in 1.0.470/471 and 1.1.1) was discovered that has the same impact as CVE-2020-26231 & CVE-2020-15247. An authenticated backend user with the `cms.manage_pages`, `cms.manage_layouts`, or `cms.manage_partials` permissions who would **normally** not be permitted to provide PHP code to be executed by the CMS due to `cms.enableSafeMode` being enabled is able to write specific Twig code to escape the Twig sandbox and execute arbitrary PHP. This is not a problem for anyone th

CVE-2021-25635
LibreOffice General
5.2
MEDIUM
EPSS
0.0%
2021 CWE-295 1 PoC

An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to self sign an ODF document, with a signature untrusted by the target, then modify it to change the signature algorithm to an invalid (or unknown to LibreOffice) algorithm and LibreOffice would incorrectly present such a signature with an unknown algorithm as a valid signature issued by a trusted person This issue affects LibreOffice: from 7.0 before 7.0.5, from 7.1 before 7.1.1.

CVE-2021-21440
((OTRS)) Community Edition General
5.2
MEDIUM
EPSS
0.2%
2021 CWE-200 1 PoC

Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.27 and prior versions; 8.0.x version 8.0.14 and prior versions.

CVE-2021-45677
Software Genérico Web
5.2
MEDIUM
EPSS
0.4%
2021 1 PoC

Certain NETGEAR devices are affected by stored XSS. This affects GS108Tv2 before 5.4.2.36 and GS110TPv2 before 5.4.2.36.

CVE-2021-36096
((OTRS)) Community Edition General
5.2
MEDIUM
EPSS
0.2%
2021 CWE-200 1 PoC

Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions; 8.0.x version 8.0.15 and prior versions.

CVE-2021-36805
Akaunting Web
5.2
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in the sales invoice processing component of the application. This issue was fixed in version 2.1.13 of the product.

CVE-2021-32557
apport General
5.2
MEDIUM
EPSS
0.1%
2021 CWE-59 1 PoC

It was discovered that the process_report() function in data/whoopsie-upload-all allowed arbitrary file writes via symlinks.

CVE-2021-47873
VestaCP Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

VestaCP versions prior to 0.9.8-25 contain a cross-site scripting vulnerability in the IP interface configuration that allows attackers to inject malicious scripts. Attackers can exploit the 'v_interface' parameter by sending a crafted POST request to the add/ip/ endpoint with a stored XSS payload.

CVE-2021-47914
PHP Melody Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

PHP Melody version 3.0 contains a persistent cross-site scripting vulnerability in the edit-video.php submitted parameter that allows remote attackers to inject malicious script code. Attackers can exploit this vulnerability to execute arbitrary JavaScript, potentially leading to session hijacking, persistent phishing, and manipulation of application modules.

CVE-2021-47729
Selea Targa IP OCR-ANPR Camera Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 2 PoCs

Selea Targa IP OCR-ANPR Camera contains a stored cross-site scripting vulnerability in the 'files_list' parameter that allows attackers to inject malicious HTML and script code. Attackers can send a POST request to /cgi-bin/get_file.php with crafted payload to execute arbitrary scripts in victim's browser session.

CVE-2021-25453
Samsung Mobile Devices Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-20 1 PoC

Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluetooth information.

CVE-2021-47885
PayPal PRO Payment Terminal Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Multiple payment terminal versions contain non-persistent cross-site scripting vulnerabilities in billing and payment information input fields. Attackers can inject malicious script code through vulnerable parameters to manipulate client-side requests and potentially execute session hijacking or phishing attacks.

CVE-2021-47835
Freeter Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 2 PoCs

Freeter 1.2.1 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payloads in custom widget titles and files. Attackers can craft malicious files with embedded scripts that execute when victims interact with the application, potentially enabling remote code execution.

CVE-2021-47839
Marky Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 2 PoCs

Marky 0.0.1 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into markdown files. Attackers can upload crafted markdown files with embedded JavaScript payloads that execute when the file is opened, potentially enabling remote code execution.

CVE-2021-47843
Tagstoo Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Tagstoo 2.0.1 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious payloads through files or custom tags. Attackers can execute arbitrary JavaScript code to spawn system processes, access files, and perform remote code execution on the victim's computer.

CVE-2021-47738
CSZ CMS Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

CSZ CMS 1.2.7 contains a persistent cross-site scripting vulnerability that allows unauthorized users to embed malicious JavaScript in private messages. Attackers can send messages with script payloads in the user-agent header, which will execute when an admin views the message in the backend dashboard.

CVE-2021-29253
Software Genérico General
5.1
MEDIUM
EPSS
0.1%
2021 1 PoC

The Tableau integration in RSA Archer 6.4 P1 (6.4.0.1) through 6.9 P2 (6.9.0.2) is affected by an insecure credential storage vulnerability. An malicious attacker with access to the Tableau workbook file may obtain access to credential information to use it in further attacks.

CVE-2021-47750
YouPHPTube Web
5.1
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

YouPHPTube <= 7.8 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the redirectUri parameter in the signup page. Attackers can craft special signup URLs with embedded script tags to execute arbitrary JavaScript in victims' browsers when they access the signup page.

CVE-2021-25340
Samsung Mobile Devices General
5.1
MEDIUM
EPSS
0.0%
2021 CWE-284 2 PoCs

Improper access control vulnerability in Samsung keyboard version prior to SMR Feb-2021 Release 1 allows physically proximate attackers to change in arbitrary settings during Initialization State.