7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-25265
Sophos Connect Client General
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

A malicious website could execute code remotely in Sophos Connect Client before version 2.1.

CVE-2021-41696
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An authentication bypass (account takeover) vulnerability exists in Premiumdatingscript 4.2.7.7 due to a weak password reset mechanism in requests\user.php.

CVE-2021-24631
Unlimited PopUps Web Database Windows
N/A
UNKNOWN
EPSS
1.0%
2021 CWE-89 2 PoCs

The Unlimited PopUps WordPress plugin through 4.5.3 does not sanitise or escape the did GET parameter before using it in a SQL statement, available to users as low as editor, leading to an authenticated SQL Injection

CVE-2021-24619
Per page add to head Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Per page add to head WordPress plugin through 1.4.4 does not properly sanitise one of its setting, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html capability is disallowed, which could lead to Cross-Site Scripting issues.

CVE-2021-28918
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
85.9%
2021 1 PoC

Improper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attackers to perform indeterminate SSRF, RFI, and LFI attacks on many of the dependent packages. A remote unauthenticated attacker can bypass packages relying on netmask to filter IPs and reach critical VPN or LAN hosts.

CVE-2021-45416
Software Genérico Web
N/A
UNKNOWN
EPSS
23.1%
2021 2 PoCs

Reflected Cross-site scripting (XSS) vulnerability in RosarioSIS 8.2.1 allows attackers to inject arbitrary HTML via the search_term parameter in the modules/Scheduling/Courses.php script.

CVE-2021-25952
just-safe-set General
N/A
UNKNOWN
EPSS
2.9%
2021 1 PoC

Prototype pollution vulnerability in ‘just-safe-set’ versions 1.0.0 through 2.2.1 allows an attacker to cause a denial of service and may lead to remote code execution.

CVE-2021-24585
Timetable and Event Schedule by MotoPress Web Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-200 2 PoCs

The Timetable and Event Schedule WordPress plugin before 2.4.0 outputs the Hashed Password, Username and Email Address (along other less sensitive data) of the user related to the Even Head of the Timeslot in the response when requesting the event Timeslot data with a user with the edit_posts capability. Combined with the other Unauthorised Event Timeslot Modification issue (https://wpscan.com/reports/submissions/4699/) where an arbitrary user ID can be set, this could allow low privilege users with the edit_posts capability (such as author) to retrieve sensitive User data by iterating over th

CVE-2021-3929
QEMU General
N/A
UNKNOWN
EPSS
4.9%
2021 CWE-416 1 PoC

A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021-3750 and, just like it, when the reentrancy write triggers the reset function nvme_ctrl_reset(), data structs will be freed leading to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition or, potentially, executing arbitrary code within the context of the QEMU process on the host.

CVE-2021-42976
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

NoMachine Enterprise Desktop is affected by Buffer Overflow. IOCTL Handler 0x22001B in the NoMachine Enterprise Desktop above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

CVE-2021-25025
EventCalendar Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events

CVE-2021-21123
Chrome Web
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.

CVE-2021-24700
Forminator – Contact Form, Payment Form & Custom Form Builder Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Forminator WordPress plugin before 1.15.4 does not sanitize and escape the email field label, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

CVE-2021-27707
Software Genérico Networking
N/A
UNKNOWN
EPSS
3.1%
2021 1 PoC

Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"portMappingIndex "request. This occurs because the "formDelPortMapping" function directly passes the parameter "portMappingIndex" to strcpy without limit.

CVE-2021-42763
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Couchbase Server before 6.6.3 and 7.x before 7.0.2 stores Sensitive Information in Cleartext. The issue occurs when the cluster manager forwards a HTTP request from the pluggable UI (query workbench etc) to the specific service. In the backtrace, the Basic Auth Header included in the HTTP request, has the "@" user credentials of the node processing the UI request.

CVE-2021-24473
User Profile Picture Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-639 1 PoC

The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_image capability (by default author and above) to change and delete the profile pictures of other users (including those with higher roles).

CVE-2021-45034
CP-8000 MASTER MODULE WITH I/O -25/+70°C General
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-284 2 PoCs

A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP-8022 MASTER MODULE WITH GPRS (All versions < V16.20). The web server of the affected system allows access to logfiles and diagnostic data generated by a privileged user. An unauthenticated attacker could access the files by knowing the corresponding download links.

CVE-2021-22939
Node Web
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-295 3 PoCs

If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.

CVE-2021-40650
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.

CVE-2021-29646
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

An issue was discovered in the Linux kernel before 5.11.11. tipc_nl_retrieve_key in net/tipc/node.c does not properly validate certain data sizes, aka CID-0217ed2848e8.