7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-24202
Elementor Website Builder Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-79 1 PoC

In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes/widgets/heading.php) accepts a ‘header_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request with this parameter set to ‘script’ and combined with a ‘title’ parameter containing JavaScript, which will then be executed when the saved page is viewed or previewed.

CVE-2021-24158
Orbit Fox by ThemeIsle General
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-269 1 PoC

Orbit Fox by ThemeIsle has a feature to add a registration form to both the Elementor and Beaver Builder page builders functionality. As part of the registration form, administrators can choose which role to set as the default for users upon registration. This field is hidden from view for lower-level users, however, they can still supply the user_role parameter to update the default role for registration.

CVE-2021-3732
kernel General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-200 2 PoCs

A flaw was found in the Linux kernel's OverlayFS subsystem in the way the user mounts the TmpFS filesystem with OverlayFS. This flaw allows a local user to gain access to hidden files that should not be accessible.

CVE-2021-40101
Software Genérico Web
N/A
UNKNOWN
EPSS
9.1%
2021 1 PoC

An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password.

CVE-2021-20253
ansible-tower DevOps
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-552 1 PoC

A flaw was found in ansible-tower. The default installation is vulnerable to Job Isolation escape allowing an attacker to elevate the privilege from a low privileged user to the awx user from outside the isolated environment. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVE-2021-24632
Recipe Card Blocks by WPZOOM Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.1 does not escape the message parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting issue

CVE-2021-30005
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 3 PoCs

In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.

CVE-2021-43969
Software Genérico Database
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

The login.jsp page of Quicklert for Digium 10.0.0 (1043) is affected by both Blind SQL Injection with Out-of-Band Interaction (DNS) and Blind Time-Based SQL Injections. Exploitation can be used to disclose all data within the database (up to and including the administrative accounts' login IDs and passwords) via the login.jsp uname parameter.

CVE-2021-34412
Zoom Client for Meetings for Windows Windows
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

During the installation process for all versions of the Zoom Client for Meetings for Windows before 5.4.0, it is possible to launch Internet Explorer. If the installer was launched with elevated privileges such as by SCCM this can result in a local privilege escalation.

CVE-2021-4037
Kernel General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-284 2 PoCs

A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not. This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS.

CVE-2021-23923
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An issue was discovered in Devolutions Server before 2020.3. There is Broken Authentication with Windows domain users.

CVE-2021-25938
ArangoDB Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

In ArangoDB, versions v2.2.6.2 through v3.7.10 are vulnerable to Cross-Site Scripting (XSS), since there is no validation of the .zip file name and filtering of potential abusive characters which zip files can be named to. There is no X-Frame-Options Header set, which makes it more susceptible for leveraging self XSS by attackers.

CVE-2021-24800
DW Question Answer Pro Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-639 1 PoC

The DW Question & Answer Pro WordPress plugin through 1.3.4 does not check that the comment to edit belongs to the user making the request, allowing any user to edit other comments.

CVE-2021-24970
All-in-One Video Gallery Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.8%
2021 CWE-22 1 PoC

The All-in-One Video Gallery WordPress plugin before 2.5.0 does not sanitise and validate the tab parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue

CVE-2021-24860
BSK PDF Manager Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 1 PoC

The BSK PDF Manager WordPress plugin before 3.1.2 does not validate and escape the orderby and order parameters before using them in a SQL statement, leading to a SQL injection issue

CVE-2021-43163
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
2.8%
2021 1 PoC

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the checkNet function in /cgi-bin/luci/api/auth.

CVE-2021-31226
Software Genérico Web
N/A
UNKNOWN
EPSS
1.7%
2021 2 PoCs

An issue was discovered in HCC embedded InterNiche 4.0.1. A potential heap buffer overflow exists in the code that parses the HTTP POST request, due to lack of size validation. This vulnerability requires the attacker to send a crafted HTTP POST request with a URI longer than 50 bytes. This leads to a heap overflow in wbs_post() via an strcpy() call.

CVE-2021-3337
Software Genérico General
N/A
UNKNOWN
EPSS
17.4%
2021 1 PoC

The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading restrictions by clicking on reply or quote in the postbit.

CVE-2021-20657
SolarView Compact General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Improper access control vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to obtain and/or alter the setting information without the access privilege via unspecified vectors.

CVE-2021-30213
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.3%
2021 0 PoCs

Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in '/servlet/AdapterHTTP' via the 'targetService' parameter.