7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-24682
Cool Tag Cloud Web Cloud Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Cool Tag Cloud WordPress plugin before 2.26 does not escape the style attribute of the cool_tag_cloud shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.

CVE-2021-30635
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Sonatype Nexus Repository Manager 3.x before 3.30.1 allows a remote attacker to get a list of files and directories that exist in a UI-related folder via directory traversal (no customer-specific data is exposed).

CVE-2021-44917
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

A Divide by Zero vulnerability exists in gnuplot 5.4 in the boundary3d function in graph3d.c, which could cause a Arithmetic exception and application crash.

CVE-2021-36609
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /linkedcontent/editfolder.php.

CVE-2021-41637
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configuration file, which includes among other information the unencrypted passwords of all FTP users.

CVE-2021-24195
Login as User or Customer (User Switching) Web Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-285 1 PoC

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

CVE-2021-33492
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 2 PoCs

OX App Suite 7.10.5 allows XSS via an OX Chat room name.

CVE-2021-24548
Mimetic Books Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The Mimetic Books WordPress plugin through 0.2.13 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS) in the "Default Publisher ID" field on the plugin's settings page.

CVE-2021-24553
Timeline Calendar Web Database Windows
N/A
UNKNOWN
EPSS
1.1%
2021 CWE-89 2 PoCs

The Timeline Calendar WordPress plugin through 1.2 does not sanitise, validate or escape the edit GET parameter before using it in a SQL statement when editing events, leading to an authenticated SQL injection issue. Other SQL Injections are also present in the plugin

CVE-2021-39378
Software Genérico Web Database
N/A
UNKNOWN
EPSS
9.3%
2021 1 PoC

A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the NamesList.php str parameter.

CVE-2021-32012
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 1 of 2).

CVE-2021-25053
WP Coder – add custom html, css and js code Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.

CVE-2021-42686
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An Integer Overflow exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x22001B in the Accops HyWorks Windows Client prior to v 3.2.8.200 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

CVE-2021-37333
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Laravel Booking System Booking Core 2.0 is vulnerable to Session Management. A password change at sandbox.bookingcore.org/user/profile/change-password does not invalidate a session that is opened in a different browser.

CVE-2021-37608
Apache OFBiz Web
N/A
UNKNOWN
EPSS
2.6%
2021 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apache OFBiz version 17.12.07 and prior versions. Upgrade to at least 17.12.08 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12297.

CVE-2021-24405
Easy Cookies Policy Web Windows
N/A
UNKNOWN
EPSS
3.8%
2021 CWE-863 2 PoCs

The Easy Cookies Policy WordPress plugin through 1.6.2 is lacking any capability and CSRF check when saving its settings, allowing any authenticated users (such as subscriber) to change them. If users can't register, this can be done through CSRF. Furthermore, the cookie banner setting is not sanitised or validated before being output in all pages of the frontend and the backend settings one, leading to a Stored Cross-Site Scripting issue.

CVE-2021-24753
Rich Reviews by Starfish Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2021 CWE-89 1 PoC

The Rich Reviews by Starfish WordPress plugin before 1.9.6 does not properly validate the orderby GET parameter of the pending reviews page before using it in a SQL statement, leading to an authenticated SQL injection issue

CVE-2021-24461
FAQ Builder AYS Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The get_faqs() function in the FAQ Builder AYS WordPress plugin before 1.3.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

CVE-2021-20158
Trendnet AC2600 TEW-827DRU General ⚡ nuclei
N/A
UNKNOWN
EPSS
86.4%
2021 1 PoC

Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauthenticated, malicous actor to force the change of the admin password due to a hidden administrative command.

CVE-2021-20075
Racom MIDGE Firmware General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for privilege escalation via configd.