7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-4130
snipe/snipe-it Web
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 1 PoC

snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2021-21886
Lantronix Web
4.3
MEDIUM
EPSS
0.3%
2021 CWE-22 1 PoC

A directory traversal vulnerability exists in the Web Manager FSBrowsePage functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially crafted HTTP request can lead to information disclosure. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2021-38874
QRadar SIEM General
4.3
MEDIUM
EPSS
0.3%
2021 1 PoC

IBM QRadar SIEM 7.3, 7.4, and 7.5 allows for users to access information across tenant and domain boundaries in some situations. IBM X-Force ID: 208397.

CVE-2021-4393
eCommerce Product Catalog Plugin for WordPress Web Windows
4.3
MEDIUM
EPSS
0.1%
2021 CWE-352 7 PoCs

The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.17. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to save manual digital orders via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4420
Sell Media Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Sell Media plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.5. This is due to missing or incorrect nonce validation on the sell_media_process() function. This makes it possible for unauthenticated attackers to sell media paypal orders via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4092
yetiforcecompany/yetiforcecrm Web
4.3
MEDIUM
EPSS
0.1%
2021 CWE-352 1 PoC

yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2021-3776
star7th/showdoc Web
4.3
MEDIUM
EPSS
0.1%
2021 CWE-352 1 PoC

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2021-4402
Multiple Roles Web Windows
4.3
MEDIUM
EPSS
0.3%
2021 CWE-352 7 PoCs

The Multiple Roles plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.1. This is due to missing or incorrect nonce validation on the mu_add_roles_in_signup_meta() and mu_add_roles_in_signup_meta_recently() functions. This makes it possible for unauthenticated attackers to add additional roles to users via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4410
Qtranslate Slug Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Qtranslate Slug plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.18. This is due to missing or incorrect nonce validation on the save_postdata() function. This makes it possible for unauthenticated attackers to save post data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4162
archivy/archivy Web
4.3
MEDIUM
EPSS
0.1%
2021 CWE-352 1 PoC

archivy is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2021-4177
livehelperchat/livehelperchat General
4.3
MEDIUM
EPSS
0.3%
2021 CWE-209 1 PoC

livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information

CVE-2021-4400
Better Search – Relevant search results for WordPress Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Better Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.2. This is due to missing or incorrect nonce validation on the bsearch_process_settings_import() and bsearch_process_settings_export() functions. This makes it possible for unauthenticated attackers to import and export settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-20468
Cognos Analytics Web
4.3
MEDIUM
EPSS
0.2%
2021 1 PoC

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 196825.

CVE-2021-4390
Contact Form 7 Style Web Windows
4.3
MEDIUM
EPSS
0.1%
2021 CWE-352 7 PoCs

The Contact Form 7 Style plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2. This is due to missing or incorrect nonce validation on the manage_wp_posts_be_qe_save_post() function. This makes it possible for unauthenticated attackers to quick edit templates via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-35611
Sales Offline Web Database
4.3
MEDIUM
EPSS
0.4%
2021 1 PoC

Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Offline Template). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Offline. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Sales Offline. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).

CVE-2021-38535
Software Genérico Web
4.3
MEDIUM
EPSS
0.4%
2021 1 PoC

Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R6080 before 1.0.0.48, R6120 before 1.0.0.76, R6260 before 1.1.0.78, R6700v2 before 1.2.0.76, R6800 before 1.2.0.76, R6900v2 before 1.2.0.76, R6850 before 1.1.0.78, R7200 before 1.2.0.76, R7350 before 1.2.0.76, R7400 before 1.2.0.76, R7450 before 1.2.0.76, AC2100 before 1.2.0.76, AC2400 before 1.2.0.76, AC2600 before 1.2.0.76, RAX35 before 1.0.3.62, and RAX40 before 1.0.3.62.

CVE-2021-2155
One-to-One Fulfillment Web Database
4.3
MEDIUM
EPSS
0.7%
2021 1 PoC

Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle One-to-One Fulfillment accessible data. CVSS 3.1 Base Score 4.3 (Integrity

CVE-2021-4089
snipe/snipe-it General
4.3
MEDIUM
EPSS
0.2%
2021 CWE-284 1 PoC

snipe-it is vulnerable to Improper Access Control

CVE-2021-27596
SAP 3D Visual Enterprise Viewer General
4.3
MEDIUM
EPSS
0.1%
2021 1 PoC

When a user opens manipulated Autodesk 3D Studio for MS-DOS (.3DS) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

CVE-2021-39884
GitLab DevOps
4.3
MEDIUM
EPSS
0.3%
2021 1 PoC

In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.