7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-43708
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Labeling tool in Titus Classification Suite 18.8.1910.140 allows users to avoid the generation of a classification label by using Excel's safe mode.

CVE-2021-44495
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause a NULL pointer dereference after calls to ZPrint.

CVE-2021-28294
Software Genérico Web
N/A
UNKNOWN
EPSS
2.6%
2021 1 PoC

Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code execution (RCE).

CVE-2021-32402
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of validation and insecure configurations in inputs and modules.

CVE-2021-34548
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003. An attacker can forge RELAY_END or RELAY_RESOLVED to bypass the intended access control for ending a stream.

CVE-2021-25096
IP2Location Country Blocker Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-639 1 PoC

The IP2Location Country Blocker WordPress plugin before 2.26.5 bans can be bypassed by using a specific parameter in the URL

CVE-2021-26913
Software Genérico General
N/A
UNKNOWN
EPSS
35.4%
2021 3 PoCs

NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in RpcServlet.

CVE-2021-42631
Software Genérico General
N/A
UNKNOWN
EPSS
20.6%
2021 3 PoCs

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below deserializes attacker controlled leading to pre-auth remote code execution.

CVE-2021-35312
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

A vulnerability was found in CIR 2000 / Gestionale Amica Prodigy v1.7. The Amica Prodigy's executable "RemoteBackup.Service.exe" has incorrect permissions, allowing a local unprivileged user to replace it with a malicious file that will be executed with "LocalSystem" privileges.

CVE-2021-31904
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains TeamCity before 2020.2.2, XSS was potentially possible on the test history page.

CVE-2021-25112
WHMCS Bridge Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.2%
2021 CWE-79 1 PoC

The WHMCS Bridge WordPress plugin before 6.4b does not sanitise and escape the error parameter before outputting it back in admin dashboard, leading to a Reflected Cross-Site Scripting

CVE-2021-25070
Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The Block Bad Bots WordPress plugin before 6.88 does not properly sanitise and escape the User Agent before using it in a SQL statement to record logs, leading to an SQL Injection issue

CVE-2021-24189
Captchinoo, Google recaptcha for admin login page Web Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-285 1 PoC

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptcha for admin login page WordPress plugin before 2.4, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

CVE-2021-28925
Software Genérico Web Database
N/A
UNKNOWN
EPSS
47.7%
2021 1 PoC

SQL injection vulnerability in Nagios Network Analyzer before 2.4.3 via the o[col] parameter to api/checks/read/.

CVE-2021-26352
Ryzen™ Series General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Insufficient bound checks in System Management Unit (SMU) PCIe Hot Plug table may result in access/updates from/to invalid address space that could result in denial of service.

CVE-2021-25038
WordPress Multisite User Sync/Unsync Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The WordPress Multisite User Sync/Unsync WordPress plugin before 2.1.2 does not sanitise and escape the wmus_source_blog and wmus_record_per_page parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

CVE-2021-28419
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.2%
2021 1 PoC

The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads to the ability to retrieve all databases.

CVE-2021-24264
Image Hover Effects – Elementor Addon Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The “Image Hover Effects – Elementor Addon” WordPress Plugin before 1.3.4 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

CVE-2021-28960
Software Genérico General
N/A
UNKNOWN
EPSS
6.7%
2021 1 PoC

Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input command in on-demand operations.