7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-26572
HPE Apollo 70 System General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgetactivexcfg function.

CVE-2021-24706
Qwizcards – online quizzes and flashcards Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Qwizcards – online quizzes and flashcards WordPress plugin before 3.62 does not properly sanitize and escape some of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2021-43960
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Lorensbergs Connect2 3.13.7647.20190 is affected by an XSS vulnerability. Exploitation requires administrator privileges and is performed through the Wizard editor of the application. The attack requires an administrator to go into the Wizard editor and enter an XSS payload within the Page title, Page Instructions, Text before, Text after, or Text on side box. Once this has been done, the administrator must click save and finally wait until any user of the application performs a booking for rental items in the booking area of the application, where the XSS triggers. NOTE: another perspective i

CVE-2021-24441
Sign-up Sheets Web Windows
N/A
UNKNOWN
EPSS
0.8%
2021 CWE-1236 1 PoC

The Sign-up Sheets WordPress plugin before 1.0.14 does not not sanitise or validate the Sheet title when generating the CSV to export, which could lead to a CSV injection issue

CVE-2021-27309
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.9%
2021 0 PoCs

Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "module" parameter.

CVE-2021-43286
Software Genérico General
N/A
UNKNOWN
EPSS
1.6%
2021 1 PoC

An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker with privileges to create a new pipeline on a GoCD server can abuse a command-line injection in the Git URL "Test Connection" feature to execute arbitrary code.

CVE-2021-42685
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An Integer Overflow vulnerability exists in Accops HyWorks DVM Tools prior to v3.3.1.105 . The IOCTL Handler 0x22005B in the Accops HyWorks DVM Tools prior to v3.3.1.105 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

CVE-2021-0396
Android General
N/A
UNKNOWN
EPSS
6.2%
2021 1 PoC

In Builtins::Generate_ArgumentsAdaptorTrampoline of builtins-arm.cc and related files, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-160610106

CVE-2021-43436
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

MartDevelopers Inc iResturant v1.0 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed.

CVE-2021-25756
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains IntelliJ IDEA before 2020.2, HTTP links were used for several remote repositories instead of HTTPS.

CVE-2021-24920
StatCounter – Free Real Time Visitor Stats Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The StatCounter WordPress plugin before 2.0.7 does not sanitise and escape the Project ID and Secure Code settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2021-29994
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Cloudera Hue 4.6.0 allows XSS.

CVE-2021-44992
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

There is an Assertion ''ecma_object_is_typedarray (obj_p)'' failed at /jerry-core/ecma/operations/ecma-typedarray-object.c in Jerryscript 3.0.0.

CVE-2021-44993
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

There is an Assertion ''ecma_is_value_boolean (base_value)'' failed at /jerry-core/ecma/operations/ecma-get-put-value.c in Jerryscript 3.0.0.

CVE-2021-29055
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Firtstname parameter to the Update Account form in student_profile.php.

CVE-2021-41645
Software Genérico General
N/A
UNKNOWN
EPSS
10.3%
2021 2 PoCs

Remote Code Execution (RCE) vulnerability exists in Sourcecodester Budget and Expense Tracker System 1.0 that allows a remote malicious user to inject arbitrary code via the image upload field. .

CVE-2021-37929
Software Genérico General
N/A
UNKNOWN
EPSS
37.4%
2021 1 PoC

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

CVE-2021-27918
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

encoding/xml in Go before 1.15.9 and 1.16.x before 1.16.1 has an infinite loop if a custom TokenReader (for xml.NewTokenDecoder) returns EOF in the middle of an element. This can occur in the Decode, DecodeElement, or Skip method.

CVE-2021-37188
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may load customized firmware (because the bootloader does not verify that it is authentic), changing the behavior of the gateway.