7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-24476
Steam Group Viewer Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The Steam Group Viewer WordPress plugin through 2.1 does not sanitise or escape its "Steam Group Address" settings before outputting it in the page, leading to an authenticated Stored Cross-Site Scripting issue

CVE-2021-34150
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Bluetooth Classic implementation on Bluetrum AB5301A devices with unknown firmware versions does not properly handle the reception of oversized DM1 LMP packets while no other BT connections are active, allowing attackers in radio range to prevent new BT connections (disabling the AB5301A inquiry and page scan procedures) via a crafted LMP packet. The user needs to manually perform a power cycle (restart) of the device to restore BT connectivity.

CVE-2021-31317
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the VDasher constructor of their custom fork of the rlottie library. A remote attacker might be able to access Telegram's heap memory out-of-bounds on a victim device via a malicious animated sticker.

CVE-2021-38603
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2021 2 PoCs

PluXML 5.8.7 allows core/admin/profil.php stored XSS via the Information field.

CVE-2021-46702
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2021 3 PoCs

Tor Browser 9.0.7 on Windows 10 build 10586 is vulnerable to information disclosure. This could allow local attackers to bypass the intended anonymity feature and obtain information regarding the onion services visited by a local user. This can be accomplished by analyzing RAM memory even several hours after the local user used the product. This occurs because the product doesn't properly free memory.

CVE-2021-25040
Booking Calendar Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2021-3374
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
83.3%
2021 0 PoCs

Directory traversal in RStudio Shiny Server before 1.5.16 allows attackers to read the application source code, involving an encoded slash.

CVE-2021-25060
Five Star Business Profile and Schema Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscribers, to call them. Furthermore, due to the lack of sanitisation, it also lead to Stored Cross-Site Scripting issues

CVE-2021-36747
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Blackboard Learn through 9.1 allows XSS by an authenticated user via the Feedback to Learner form.

CVE-2021-46109
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Invalid input sanitizing leads to reflected Cross Site Scripting (XSS) in ASUS RT-AC52U_B1 3.0.0.4.380.10931 can lead to a user session hijack.

CVE-2021-3449
OpenSSL General
N/A
UNKNOWN
EPSS
9.9%
2021 13 PoCs

An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this i

CVE-2021-42990
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

FlexiHub For Windows is affected by Buffer Overflow. IOCTL Handler 0x22001B in the FlexiHub For Windows above 2.0.4340 below 5.3.14268 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

CVE-2021-22963
https://github.com/fastify/fastify-static Web
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-601 1 PoC

A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbitrary websites via a double slash // followed by a domain: http://localhost:3000//google.com/%2e%2e.The issue shows up on all the fastify-static applications that set redirect: true option. By default, it is false.

CVE-2021-26320
1st Gen AMD EPYC™ General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-295 1 PoC

Insufficient validation of the AMD SEV Signing Key (ASK) in the SEND_START command in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP

CVE-2021-27188
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 allows attackers to cause a denial of service (access suspended for five hours) by making five invalid login attempts to a victim's account.

CVE-2021-31738
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Adiscon LogAnalyzer 4.1.10 and 4.1.11 allow login.php XSS.

CVE-2021-24338
Pods – Custom Content Types and Fields Web Windows
N/A
UNKNOWN
EPSS
1.1%
2021 CWE-79 1 PoC

The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability within the 'Singular Label' field parameter.

CVE-2021-41843
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2021 4 PoCs

An authenticated SQL injection issue in the calendar search function of OpenEMR 6.0.0 before patch 3 allows an attacker to read data from all tables of the database via the parameter provider_id, as demonstrated by the /interface/main/calendar/index.php?module=PostCalendar&func=search URI.

CVE-2021-38707
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Persistent cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow low-privileged attackers to introduce arbitrary JavaScript to account parameters. The XSS payloads will execute in the browser of any user who views the relevant content. This can result in account takeover via session token theft.

CVE-2021-24284
Kaswara Modern VC Addons Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
68.0%
2021 CWE-434 2 PoCs

The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'uploadFontIcon' AJAX action. The supplied zipfile being unzipped in the wp-content/uploads/kaswara/fonts_icon directory with no checks for malicious files such as PHP.