7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-24931
Secure Copy Content Protection and Content Locking Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
72.2%
2021 CWE-89 2 PoCs

The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an SQL injection.

CVE-2021-25412
Samsung Mobile Devices General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-284 1 PoC

An improper access control vulnerability in genericssoservice prior to SMR JUN-2021 Release 1 allows local attackers to execute protected activity with system privilege via untrusted applications.

CVE-2021-36695
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in the download file feature on a manager profile due to lack of input validation.

CVE-2021-0334
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In onTargetSelected of ResolverActivity.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-163358811

CVE-2021-24544
Responsive WordPress Slider Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 2 PoCs

The Responsive WordPress Slider WordPress plugin through 2.2.0 does not sanitise and escape some of the Slider options, allowing Cross-Site Scripting payloads to be set in them. Furthermore, as by default any authenticated user is allowed to create Sliders (https://wordpress.org/support/topic/slider-can-be-changed-from-any-user-even-subscriber/, such settings can be changed in the plugin's settings), this would allow user with a role as low as subscriber to perform Cross-Site Scripting attacks against logged in admins viewing the slider list and could lead to privilege escalation by creating a

CVE-2021-40865
Apache Storm Web
N/A
UNKNOWN
EPSS
46.2%
2021 CWE-502 1 PoC

An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrade to version 2.1.1. Apache Storm 1.x users should upgrade to version 1.2.4

CVE-2021-3345
Software Genérico General
N/A
UNKNOWN
EPSS
5.7%
2021 3 PoCs

_gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count value. It is recommended to upgrade to 1.9.1 or later.

CVE-2021-38094
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Integer Overflow vulnerability in function filter_sobel in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.

CVE-2021-3524
ceph Web
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-20 1 PoC

A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. In addition, the prior bug fix for CVE-2020-10753 did not account for the use of \r as a header separator, thus a new flaw has been created.

CVE-2021-25434
Tizen wearable devices General
N/A
UNKNOWN
EPSS
1.1%
2021 CWE-20 1 PoC

Improper input validation vulnerability in Tizen bootloader prior to Firmware update JUL-2021 Release allows arbitrary code execution using param partition in wireless firmware download mode.

CVE-2021-24984
WPFront User Role Editor Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The WPFront User Role Editor WordPress plugin before 3.2.1.11184 does not sanitise and escape the changes-saved parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting

CVE-2021-24850
Insert Pages Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Insert Pages WordPress plugin before 3.7.0 adds a shortcode that prints out other pages' content and custom fields. It can be used by users with a role as low as Contributor to perform Cross-Site Scripting attacks by storing the payload/s in another post's custom fields.

CVE-2021-35478
Software Genérico Web
N/A
UNKNOWN
EPSS
49.2%
2021 2 PoCs

Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. All parameters used for filtering are affected. This affects users who open a crafted link or third-party web page.

CVE-2021-24924
Email Log Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Email Log WordPress plugin before 2.4.8 does not escape the d parameter before outputting it back in an attribute in the Log page, leading to a Reflected Cross-Site Scripting issue

CVE-2021-24170
User Profile Picture Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
42.1%
2021 CWE-200 1 PoC

The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functionality to users with the upload_files capability. This included password hashes, hashed user activation keys, usernames, emails, and other less sensitive information.

CVE-2021-41849
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It sends the following Personally Identifiable Information (PII) in plaintext using HTTP to servers located in China: user's list of installed apps and device International Mobile Equipment Identity (IMEI). This PII is transmitted to log.skyroam.com.cn using HTTP, independent of whether the user uses the Simo software.

CVE-2021-25948
expand-hash General
N/A
UNKNOWN
EPSS
2.9%
2021 1 PoC

Prototype pollution vulnerability in 'expand-hash' versions 0.1.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.

CVE-2021-25043
WOOCS – Currency Switcher for WooCommerce. Professional and Free multi currency plugin – Pay in selected currency Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The WOOCS WordPress plugin before 1.3.7.3 does not sanitise and escape the custom_prices parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue

CVE-2021-45380
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.7%
2021 0 PoCs

AppCMS 2.0.101 has a XSS injection vulnerability in \templates\m\inc_head.php

CVE-2021-24600
WP Dialog Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The WP Dialog WordPress plugin through 1.2.5.5 does not sanitise and escape some of its settings before outputting them in pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.