7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-28114
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2021 2 PoCs

Froala WYSIWYG Editor 3.2.6-1 is affected by XSS due to a namespace confusion during parsing.

CVE-2021-42639
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2021 3 PoCs

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to multiple reflected cross site scripting vulnerabilities. Attacker controlled input is reflected back in the page without sanitization.

CVE-2021-20701
CLUSTERPRO X Windows
N/A
UNKNOWN
EPSS
1.6%
2021 1 PoC

Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network.

CVE-2021-33403
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An integer overflow in the transfer function of a smart contract implementation for Lancer Token, an Ethereum ERC20 token, allows the owner to cause unexpected financial losses between two large accounts during a transaction.

CVE-2021-45469
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when an inode has an invalid last xattr entry.

CVE-2021-26303
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the user-profile.php Full Name field.

CVE-2021-42230
Software Genérico Networking
N/A
UNKNOWN
EPSS
25.4%
2021 2 PoCs

Seowon 130-SLC router all versions as of 2021-09-15 is vulnerable to Remote Code Execution via the queriesCnt parameter.

CVE-2021-43421
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
79.5%
2021 0 PoCs

A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary files and execute PHP code.

CVE-2021-31249
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
90.0%
2021 1 PoC

A CRLF injection vulnerability was found on BF-430, BF-431, and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack of validation on the parameter redirect= available on multiple CGI components.

CVE-2021-22146
Software Genérico Web Database Cloud
N/A
UNKNOWN
EPSS
29.9%
2021 2 PoCs

All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting the anonymous user has no permissions and is unable to successfully query any Elasticsearch APIs, an attacker could leverage the anonymous user to gain insight into certain details of a deployed cluster.

CVE-2021-24227
Patreon WordPress Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
38.7%
2021 CWE-200 0 PoCs

The Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon WordPress plugin before 1.7.0 that could be abused by anyone visiting the site. Using this attack vector, an attacker could leak important internal files like wp-config.php, which contains database credentials and cryptographic keys used in the generation of nonces and cookies.

CVE-2021-24576
Easy Accordion – Best Accordion FAQ Plugin for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Easy Accordion WordPress plugin before 2.0.22 does not properly sanitize inputs when adding new items to an accordion.

CVE-2021-45911
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow in the main function. It allows an attacker to write 2 bytes outside the boundaries of the buffer.

CVE-2021-46378
Software Genérico General
N/A
UNKNOWN
EPSS
33.1%
2021 3 PoCs

DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote configuration download.

CVE-2021-39285
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

A XSS vulnerability exists in Versa Director Release: 16.1R2 Build: S8. An attacker can use the administration web interface URL to create a XSS based attack.

CVE-2021-37606
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Meow hash 0.5/calico does not sufficiently thwart key recovery by an attacker who can query whether there's a collision in the bottom bits of the hashes of two messages, as demonstrated by an attack against a long-running web service that allows the attacker to infer collisions by measuring timing differences.

CVE-2021-42662
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.2%
2021 5 PoCs

A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the Holiday reason parameter. An attacker can leverage this vulnerability in order to run javascript commands on the web server surfers behalf, which can lead to cookie stealing and more.

CVE-2021-35492
Software Genérico General
N/A
UNKNOWN
EPSS
13.0%
2021 3 PoCs

Wowza Streaming Engine through 4.8.11+5 could allow an authenticated, remote attacker to exhaust filesystem resources via the /enginemanager/server/vhost/historical.jsdata vhost parameter. This is due to the insufficient management of available filesystem resources. An attacker could exploit this vulnerability through the Virtual Host Monitoring section by requesting random virtual-host historical data and exhausting available filesystem resources. A successful exploit could allow the attacker to cause database errors and cause the device to become unresponsive to web-based management. (Manual

CVE-2021-24661
PostX – Gutenberg Blocks for Post Grid Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-200 1 PoC

The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with Contributor roles or higher to read password-protected or private post contents the user is otherwise unable to read, given the post ID.

CVE-2021-41317
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

XSS Hunter Express before 2021-09-17 does not properly enforce authentication requirements for paths.