7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-28192
BMC firmware for ASMB9-iKVM Windows
4.9
MEDIUM
EPSS
0.9%
2021 CWE-120 1 PoC

The specific function in ASUS BMC’s firmware Web management page (Remote video storage function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

CVE-2021-2160
MySQL Server Database
4.9
MEDIUM
EPSS
0.2%
2021 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.7.30 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVE-2021-21907
Garrett Metal Detectors General
4.9
MEDIUM
EPSS
0.3%
2021 CWE-22 1 PoC

A directory traversal vulnerability exists in the CMA CLI getenv command functionality of Garrett Metal Detectors’ iC Module CMA Version 5.0. A specially-crafted command line argument can lead to local file inclusion. An attacker can provide malicious input to trigger this vulnerability.

CVE-2021-25919
openemr Web
4.8
MEDIUM
EPSS
32.5%
2021 1 PoC

In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly. A highly privileged attacker could inject arbitrary code into input fields when creating a new user.

CVE-2021-4038
McAfee Network Security Manager (NSM) Web
4.8
MEDIUM
EPSS
0.1%
2021 CWE-79 1 PoC

Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) prior to 10.1 Minor 7 allows a remote authenticated administrator to embed a XSS in the administrator interface via specially crafted custom rules containing HTML. NSM did not correctly sanitize custom rule content in all scenarios.

CVE-2021-47920
WebMO Job Manager Web
4.8
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

WebMO Job Manager 20.0 contains a cross-site scripting vulnerability in search parameters that allows remote attackers to inject malicious script code. Attackers can exploit the filterSearch and filterSearchType parameters to perform non-persistent attacks including session hijacking and external redirects.

CVE-2021-3797
hestiacp/hestiacp General
4.8
MEDIUM
EPSS
0.4%
2021 CWE-597 1 PoC

hestiacp is vulnerable to Use of Wrong Operator in String Comparison

CVE-2021-23881
Endpoint Security (ENS) for Windows Windows
4.8
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

A stored cross site scripting vulnerability in ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 February 2021 Update allows an ENS ePO administrator to add a script to a policy event which will trigger the script to be run through a browser block page when a local non-administrator user triggers the policy.

CVE-2021-47911
Affiliate Pro Web
4.8
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

Affiliate Pro 1.7 contains multiple reflected cross-site scripting vulnerabilities in the index module's input fields. Attackers can inject malicious scripts through fullname, username, and email parameters to execute client-side attacks and manipulate browser requests.

CVE-2021-47725
STVS ProVision Web
4.8
MEDIUM
EPSS
0.1%
2021 CWE-79 1 PoC

STVS ProVision 5.9.10 contains a cross-site scripting vulnerability in the 'files' POST parameter that allows authenticated attackers to inject arbitrary HTML code. Attackers can exploit the unvalidated input to execute malicious scripts within a user's browser session in the context of the affected site.

CVE-2021-31835
McAfee ePolicy Orchestrator (ePO) Web
4.8
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 11 allows ePO administrators to inject arbitrary web script or HTML via a specific parameter where the administrator's entries were not correctly sanitized.

CVE-2021-25917
openemr Web
4.8
MEDIUM
EPSS
2.8%
2021 1 PoC

In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly and rendered in the U2F USB Device authentication method page. A highly privileged attacker could inject arbitrary code into input fields when creating a new user.

CVE-2021-25918
openemr Web
4.8
MEDIUM
EPSS
2.8%
2021 1 PoC

In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly and rendered in the TOTP Authentication method page. A highly privileged attacker could inject arbitrary code into input fields when creating a new user.

CVE-2021-26414
Windows 10 Version 1809 Windows
4.8
MEDIUM
EPSS
9.6%
2021 1 PoC

Windows DCOM Server Security Feature Bypass

CVE-2021-34759
Cisco Identity Services Engine Software Web Networking
4.8
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface

CVE-2021-25933
OpenNMS Web
4.8
MEDIUM
EPSS
0.5%
2021 1 PoC

In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to Stored Cross-Site Scripting, since the function `validateFormInput()` performs improper validation checks on the input sent to the `groupName` and `groupComment` parameters. Due to this flaw, an authenticated attacker could inject arbitrary script and trick other admin users into downloading malicious files which can cause severe damage

CVE-2021-25117
WP-PostRatings Web Windows
4.8
MEDIUM
EPSS
0.2%
2021 1 PoC

The WP-PostRatings WordPress plugin before 1.86.1 does not sanitise the postratings_image parameter from its options page (wp-admin/admin.php?page=wp-postratings/postratings-options.php). Even though the page is only accessible to administrators, and protected against CSRF attacks, the issue is still exploitable when the unfiltered_html capability is disabled.

CVE-2021-47870
My SMTP Contact Plugin Web
4.8
MEDIUM
EPSS
0.1%
2021 CWE-79 1 PoC

GetSimple CMS My SMTP Contact Plugin 1.1.2 suffers from a Stored Cross-Site Scripting (XSS) vulnerability. The plugin attempts to sanitize user input using htmlspecialchars(), but this can be bypassed by passing dangerous characters as escaped hex bytes. This allows attackers to inject arbitrary client-side code that executes in the administrator's browser when visiting a malicious page.

CVE-2021-47817
OpenEMR Web
4.8
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

OpenEMR 5.0.2.1 contains a cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript through user profile parameters. Attackers can exploit the vulnerability by crafting a malicious payload to download and execute a web shell, enabling remote command execution on the vulnerable OpenEMR instance.

CVE-2021-1993
Database - Enterprise Edition Database
4.8
MEDIUM
EPSS
0.2%
2021 1 PoC

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Java VM. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java VM accessible data. CVSS 3.1 Base Score 4.8 (Integrity impacts). CVSS Vector: (CV