7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-44209
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

OX App Suite through 7.10.5 allows XSS via an HTML 5 element such as AUDIO.

CVE-2021-24736
Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files WordPress plugin before 1.6.57 does not sanitise and escape some of its settings before outputting them in attributes, which could lead to Stored Cross-Site Scripting issues.

CVE-2021-3351
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

OpenPLC runtime V3 through 2016-03-14 allows stored XSS via the Device Name to the web server's Add New Device page.

CVE-2021-24045
Hermes Web
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-843 1 PoC

A type confusion vulnerability could be triggered when resolving the "typeof" unary operator in Facebook Hermes prior to v0.10.0. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.

CVE-2021-30522
Chrome General
N/A
UNKNOWN
EPSS
1.0%
2021 1 PoC

Use after free in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-24904
Mortgage Calculators WP Web Windows
N/A
UNKNOWN
EPSS
3.0%
2021 CWE-79 1 PoC

The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the background of a calculator, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2021-22883
Node General
N/A
UNKNOWN
EPSS
89.4%
2021 CWE-400 3 PoCs

Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.

CVE-2021-46354
Software Genérico General
N/A
UNKNOWN
EPSS
39.2%
2021 1 PoC

Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the parameter "Addr" in cmd site. The ability to send requests to other systems can allow the vulnerable server to filtrate the real IP of the web server or increase the attack surface.

CVE-2021-25160
Aruba Instant Access Points General
N/A
UNKNOWN
EPSS
6.2%
2021 1 PoC

A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba Instant 8.7.x: 8.7.1.1 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.

CVE-2021-24822
Stylish Cost Calculator Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and CSRF checks on some of its AJAX actions (available to authenticated users), which could allow any authenticated users, such as subscriber to call them, and perform Stored Cross-Site Scripting attacks against logged in admin, as well as frontend users due to the lack of sanitisation and escaping in some parameters

CVE-2021-46778
AMD Processors General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen 1”, “Zen 2” and “Zen 3” that use simultaneous multithreading (SMT). By measuring the contention level on scheduler queues an attacker may potentially leak sensitive information.

CVE-2021-24771
Inspirational Quote Rotator Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Inspirational Quote Rotator WordPress plugin through 1.0.0 does not sanitize and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting issues when the quote is output in the "Quotes list" even when the unfiltered_html capability is disallowed

CVE-2021-30809
iOS and iPadOS General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

A use after free issue was addressed with improved memory management. This issue is fixed in Safari 15, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing maliciously crafted web content may lead to arbitrary code execution.

CVE-2021-44829
Software Genérico Web
N/A
UNKNOWN
EPSS
2.8%
2021 3 PoCs

Cross Site Scripting (XSS) vulnerability exists in index.html in AFI WebACMS through 2.1.0 via the the ID parameter.

CVE-2021-3152
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
45.2%
2021 0 PoCs

Home Assistant before 2021.1.3 does not have a protection layer that can help to prevent directory-traversal attacks against custom integrations. NOTE: the vendor's perspective is that the vulnerability itself is in custom integrations written by third parties, not in Home Assistant; however, Home Assistant does have a security update that is worthwhile in addressing this situation

CVE-2021-24157
Orbit Fox by ThemeIsle General
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

Orbit Fox by ThemeIsle has a feature to add custom scripts to the header and footer of a page or post. There were no checks to verify that a user had the unfiltered_html capability prior to saving the script tags, thus allowing lower-level users to inject scripts that could potentially be malicious.

CVE-2021-0306
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In addAllPermissions of PermissionManagerService.java, there is a possible permissions bypass when upgrading major Android versions which allows an app to gain the android.permission.ACTIVITY_RECOGNITION permission without user confirmation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11, Android-8.0, Android-8.1, Android-9, Android-10; Android ID: A-154505240.

CVE-2021-40814
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

The Customer Photo Gallery addon before 2.9.4 for PrestaShop is vulnerable to SQL injection.

CVE-2021-25018
PPOM for WooCommerce Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-862 1 PoC

The PPOM for WooCommerce WordPress plugin before 24.0 does not have authorisation and CSRF checks in the ppom_settings_panel_action AJAX action, allowing any authenticated to call it and set arbitrary settings. Furthermore, due to the lack of sanitisation and escaping, it could lead to Stored XSS issues

CVE-2021-31643
Software Genérico Web
N/A
UNKNOWN
EPSS
3.8%
2021 2 PoCs

An XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and Webpass due to a lack of sanitization on the component if.cgi - username parameter.