7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-43283
Software Genérico General
N/A
UNKNOWN
EPSS
6.6%
2021 1 PoC

An issue was discovered on Victure WR1200 devices through 1.0.3. A command injection vulnerability was found within the web interface of the device, allowing an attacker with valid credentials to inject arbitrary shell commands to be executed by the device with root privileges. This occurs in the ping and traceroute features. An attacker would thus be able to use this vulnerability to open a reverse shell on the device with root privileges.

CVE-2021-24978
OSMapper Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-862 1 PoC

The OSMapper WordPress plugin through 2.1.5 contains an AJAX action to delete a plugin related post type named 'map' and is registered with the wp_ajax_nopriv prefix, making it available to unauthenticated users. There is no authorisation, CSRF and checks in place to ensure that the post to delete is a map one. As a result, unauthenticated user can delete arbitrary posts from the blog

CVE-2021-27707
Software Genérico Networking
N/A
UNKNOWN
EPSS
3.1%
2021 1 PoC

Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"portMappingIndex "request. This occurs because the "formDelPortMapping" function directly passes the parameter "portMappingIndex" to strcpy without limit.

CVE-2021-30039
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Fever" or "Blood Pressure" field on the patients/register-report.php.

CVE-2021-25091
Link Library Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2021-36798
Software Genérico General
N/A
UNKNOWN
EPSS
27.7%
2021 2 PoCs

A Denial-of-Service (DoS) vulnerability was discovered in Team Server in HelpSystems Cobalt Strike 4.2 and 4.3. It allows remote attackers to crash the C2 server thread and block beacons' communication with it.

CVE-2021-38183
SAP NetWeaver Web
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

SAP NetWeaver - versions 700, 701, 702, 730, does not sufficiently encode user-controlled inputs, allowing an attacker to cause a potential victim to supply a malicious content to a vulnerable web application, which is then reflected to the victim and executed by the web browser, resulting in Cross-Site Scripting vulnerability.

CVE-2021-29022
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.

CVE-2021-20162
Trendnet AC2600 TEW-827DRU General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Trendnet AC2600 TEW-827DRU version 2.08B01 stores credentials in plaintext. Usernames and passwords are stored in plaintext in the config files on the device. For example, /etc/config/cameo contains the admin password in plaintext.

CVE-2021-41638
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

The authentication checks of the MELAG FTP Server in version 2.2.0.4 are incomplete, which allows a remote attacker to access local files only by using a valid username.

CVE-2021-34824
Software Genérico General
N/A
UNKNOWN
EPSS
1.8%
2021 1 PoC

Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can be accessed from different namespaces.

CVE-2021-33488
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

chat in OX App Suite 7.10.5 has Improper Input Validation. A user can be redirected to a rogue OX Chat server via a development-related hook.

CVE-2021-45908
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An issue was discovered in gif2apng 1.9. There is a stack-based buffer overflow involving a while loop. An attacker has little influence over the data written to the stack, making it unlikely that the flow of control can be subverted.

CVE-2021-33880
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack.

CVE-2021-35506
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Afian FileRun 2021.03.26 allows XSS when an administrator encounters a crafted document during use of the HTML Editor for a preview or edit action.

CVE-2021-44042
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2021 2 PoCs

An issue was discovered in UiPath Assistant 21.4.4. User-controlled data supplied to the --process-start argument of the URI handler for uipath-assistant:// is not correctly encoded, resulting in attacker-controlled content being injected into the error message displayed (when the injected content does not match an existing process). A determined attacker could leverage this to execute JavaScript in the context of the Electron application.

CVE-2021-42666
Software Genérico Web Database
N/A
UNKNOWN
EPSS
26.8%
2021 4 PoCs

A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to quiz_question.php, which could let a malicious user extract sensitive data from the web server and in some cases use this vulnerability in order to get a remote code execution on the remote web server.

CVE-2021-25848
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Improper validation of the length field of LLDP-MED TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows information disclosure to attackers due to using fixed loop counter variable without checking the actual available length via a crafted lldp packet.

CVE-2021-45411
Software Genérico Database
N/A
UNKNOWN
EPSS
3.2%
2021 2 PoCs

In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution.

CVE-2021-29643
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

PRTG Network Monitor before 21.3.69.1333 allows stored XSS via an unsanitized string imported from a User Object in a connected Active Directory instance.