7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-41947
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

A SQL injection vulnerability exists in Subrion CMS v4.2.1 in the visual-mode.

CVE-2021-24592
Sitewide Notice WP Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Sitewide Notice WP WordPress plugin before 2.3 does not sanitise some of its settings before outputting them in frontend pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2021-28079
Software Genérico Web
N/A
UNKNOWN
EPSS
2.1%
2021 2 PoCs

Jamovi <=1.6.18 is affected by a cross-site scripting (XSS) vulnerability. The column-name is vulnerable to XSS in the ElectronJS Framework. An attacker can make a .omv (Jamovi) document containing a payload. When opened by victim, the payload is triggered.

CVE-2021-24160
Responsive Menu – Create Mobile-Friendly Menu Web Windows
N/A
UNKNOWN
EPSS
62.5%
2021 CWE-434 2 PoCs

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ directory. These files could then be accessed via the front end of the site to trigger remote code execution and ultimately allow an attacker to execute commands to further infect a WordPress site.

CVE-2021-43517
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

FOSCAM Camera FI9805E with firmware V4.02.R12.00018510.10012.143900.00000 contains a backdoor that opens Telnet port when special command is sent on port 9530.

CVE-2021-44501
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause calls to ZRead to crash due to a NULL pointer dereference.

CVE-2021-33491
Software Genérico General
N/A
UNKNOWN
EPSS
4.4%
2021 2 PoCs

OX App Suite through 7.10.5 allows Directory Traversal via ../ in an OOXML or ODF ZIP archive, because of the mishandling of relative paths in mail addresses in conjunction with auto-configuration DNS records.

CVE-2021-33829
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
48.8%
2021 1 PoC

A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.

CVE-2021-44503
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a call to va_arg on an empty variadic parameter list, most likely causing a memory segmentation fault.

CVE-2021-24685
Flat Preloader Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does not sanitise and escape them, which could allow attackers to a make logged in admin change them with a Cross-Site Scripting payload (triggered either in the frontend or backend depending on the payload)

CVE-2021-45814
Software Genérico Database
N/A
UNKNOWN
EPSS
0.4%
2021 2 PoCs

Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel with an administrative account.

CVE-2021-0326
Android General
N/A
UNKNOWN
EPSS
13.1%
2021 4 PoCs

In p2p_copy_client_info of p2p.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if the target device is performing a Wi-Fi Direct search, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-172937525

CVE-2021-33336
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Cross-site scripting (XSS) vulnerability in the Journal module's add article menu in Liferay Portal 7.3.0 through 7.3.3, and Liferay DXP 7.1 fix pack 18, and 7.2 fix pack 5 through 7, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_journal_web_portlet_JournalPortlet_name parameter.

CVE-2021-24452
W3 Total Cache Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
7.7%
2021 CWE-79 1 PoC

The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the "extension" parameter in the Extensions dashboard, when the 'Anonymously track usage to improve product quality' setting is enabled, as the parameter is output in a JavaScript context without proper escaping. This could allow an attacker, who can convince an authenticated admin into clicking a link, to run malicious JavaScript within the user's web browser, which could lead to full site compromise.

CVE-2021-24257
Premium Addons for Elementor Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The “Premium Addons for Elementor” WordPress Plugin before 4.2.8 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

CVE-2021-33324
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Layout module in Liferay Portal 7.1.0 through 7.3.1, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 5, does not properly check permission of pages, which allows remote authenticated users without view permission of a page to view the page via a site's page administration.

CVE-2021-25790
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 3 PoCs

Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in all text fields except for Phone Number and Alternate Phone Number.

CVE-2021-23835
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.6%
2021 2 PoCs

An issue was discovered in flatCore before 2.0.0 build 139. A local file disclosure vulnerability was identified in the docs_file HTTP request body parameter for the acp interface. This can be exploited with admin access rights. The affected parameter (which retrieves the contents of the specified file) was found to be accepting malicious user input without proper sanitization, thus leading to retrieval of backend server sensitive files, e.g., /etc/passwd, SQLite database files, PHP source code, etc.

CVE-2021-43708
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Labeling tool in Titus Classification Suite 18.8.1910.140 allows users to avoid the generation of a classification label by using Excel's safe mode.

CVE-2021-44495
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause a NULL pointer dereference after calls to ZPrint.