7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-24611
Keyword Meta Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The Keyword Meta WordPress plugin through 3.0 does not sanitise of escape its settings before outputting them back in the page after they are saved, allowing for Cross-Site Scripting issues. Furthermore, it is also lacking any CSRF check, allowing attacker to make a logged in high privilege user save arbitrary setting via a CSRF attack.

CVE-2021-38841
Software Genérico Web
N/A
UNKNOWN
EPSS
5.3%
2021 3 PoCs

Remote Code Execution can occur in Simple Water Refilling Station Management System 1.0 via the System Logo option on the system_info page in classes/SystemSettings.php with an update_settings action.

CVE-2021-30145
Software Genérico General
N/A
UNKNOWN
EPSS
1.4%
2021 1 PoC

A format string vulnerability in mpv through 0.33.0 allows user-assisted remote attackers to achieve code execution via a crafted m3u playlist file.

CVE-2021-26691
Apache HTTP Server Web
N/A
UNKNOWN
EPSS
47.8%
2021 CWE-122 3 PoCs

In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow

CVE-2021-29964
Thunderbird Windows
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.11, Firefox < 89, and Firefox ESR < 78.11.

CVE-2021-28857
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

TP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 username and password are sent via the cookie.

CVE-2021-41390
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Injection.

CVE-2021-24671
MX Time Zone Clocks Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The MX Time Zone Clocks WordPress plugin before 3.4.1 does not escape the time_zone attribute of the mxmtzc_time_zone_clocks shortcode, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks

CVE-2021-40500
SAP BusinessObjects Business Intelligence Platform (Crystal Reports) General
N/A
UNKNOWN
EPSS
1.2%
2021 CWE-611 1 PoC

SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an unauthenticated attacker to exploit missing XML validations at endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation can enable the attacker to retrieve arbitrary files from the server.

CVE-2021-38203
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the system space_info.

CVE-2021-0705
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In sanitizeSbn of NotificationManagerService.java, there is a possible way to keep service running in foreground and keep granted permissions due to Bypass of Background Service Restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-185388103

CVE-2021-28002
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which allows remote attackers to execute arbitrary code via a crafted payload entered into the URL field. The vulnerability is triggered by users visiting the 'Articles' page.

CVE-2021-27695
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbitrary web script or HTML via any "Add" sections, such as Add Card Building & Floor, or others in the Name and Code Parameters.

CVE-2021-26273
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Agent in NinjaRMM 5.0.909 has Incorrect Access Control.

CVE-2021-41467
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
7.6%
2021 0 PoCs

Cross-site scripting (XSS) vulnerability in application/controllers/dropbox.php in JustWriting 1.0.0 and below allow remote attackers to inject arbitrary web script or HTML via the challenge parameter.

CVE-2021-25423
Watch Active2 PlugIn General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-779 1 PoC

Improper log management vulnerability in Watch Active2 PlugIn prior to 2.2.08.21033151 version allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone via log.

CVE-2021-37540
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains Hub before 2021.1.13262, a potentially insufficient CSP for the Widget deployment feature was used.

CVE-2021-3610
ImageMagick General
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-125 1 PoC

A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault.

CVE-2021-37549
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient.

CVE-2021-3318
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter.