7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-31674
Software Genérico Web
N/A
UNKNOWN
EPSS
2.2%
2021 1 PoC

Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacker to execute javascript code via undefine enum constant.

CVE-2021-32604
Software Genérico Web
N/A
UNKNOWN
EPSS
1.8%
2021 1 PoC

Share/IncomingWizard.htm in SolarWinds Serv-U before 15.2.3 mishandles the user-supplied SenderEmail parameter, aka "Share URL XSS."

CVE-2021-32238
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 2 PoCs

Epic Games / Psyonix Rocket League <=1.95 is affected by Buffer Overflow. Stack-based buffer overflow occurs when Rocket League handles UPK object files that can result in code execution and denial of service scenario.

CVE-2021-33853
X2CRM Web
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

A Cross-Site Scripting (XSS) attack can cause arbitrary code (javascript) to run in a user’s browser while the browser is connected to a trusted website. As the vehicle for the attack, the application targets the users and not the application itself. Additionally, the XSS payload is executed when the user attempts to access any page of the CRM.

CVE-2021-24269
Sina Extension for Elementor Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The “Sina Extension for Elementor” WordPress Plugin before 3.3.12 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

CVE-2021-25773
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

JetBrains TeamCity before 2020.2 was vulnerable to reflected XSS on several pages.

CVE-2021-33483
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. The comment posting functionality allows an attacker to add an XSS payload to the JSON request that will execute when users visit the page with the comment.

CVE-2021-33833
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAME, RDATA, or RDLENGTH (for A or AAAA).

CVE-2021-24957
Advanced Page Visit Counter – Advanced WordPress Visit Counter Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2021 CWE-89 1 PoC

The Advanced Page Visit Counter WordPress plugin before 6.1.6 does not escape the artID parameter before using it in a SQL statement in the apvc_reset_count_art AJAX action, available to any authenticated user, leading to a SQL injection

CVE-2021-22494
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered in the fingerprint scanner on Samsung Note20 mobile devices with Q(10.0) software. When a screen protector is used, the required image compensation is not present. Consequently, inversion can occur during fingerprint enrollment, and a high False Recognition Rate (FRR) can occur. The Samsung ID is SVE-2020-19216 (January 2021).

CVE-2021-24217
Facebook for WordPress Web Windows
N/A
UNKNOWN
EPSS
6.5%
2021 CWE-502 1 PoC

The run_action function of the Facebook for WordPress plugin before 3.0.0 deserializes user supplied data making it possible for PHP objects to be supplied creating an Object Injection vulnerability. There was also a useable magic method in the plugin that could be used to achieve remote code execution.

CVE-2021-37777
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Gila CMS 2.2.0 is vulnerable to Insecure Direct Object Reference (IDOR). Thumbnails uploaded by one site owner are visible by another site owner just by knowing the other site name and fuzzing for picture names. This leads to sensitive information disclosure.

CVE-2021-41916
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

A Cross-Site Request Forgery (CSRF) vulnerability in webTareas version 2.4 and earlier allows a remote attacker to create a new administrative profile and add a new user to the new profile. without the victim's knowledge, by enticing an authenticated admin user to visit an attacker's web page.

CVE-2021-44500
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of input validation in calls to eb_div in sr_port/eb_muldiv.c allows attackers to crash the application by performing a divide by zero.

CVE-2021-22147
Elasticsearch Database
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-732 1 PoC

Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.

CVE-2021-24580
Side Menu Lite - add sticky fixed buttons Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The Side Menu Lite WordPress plugin before 2.2.6 does not sanitise user input from the List page in the admin dashboard before using it in SQL statement, leading to a SQL Injection issue

CVE-2021-38602
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

PluXML 5.8.7 allows Article Editing stored XSS via Headline or Content.

CVE-2021-31862
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
41.3%
2021 2 PoCs

SysAid 20.4.74 allows XSS via the KeepAlive.jsp stamp parameter without any authentication.

CVE-2021-45085
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often enough to place that page on the Most Visited list.

CVE-2021-37163
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus operated by released versions of software before Nexus Software 7.2.5.7. The device has two user accounts with passwords that are hardcoded.