7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-41638
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

The authentication checks of the MELAG FTP Server in version 2.2.0.4 are incomplete, which allows a remote attacker to access local files only by using a valid username.

CVE-2021-24588
SMS Alert Order Notifications – WooCommerce Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page.

CVE-2021-34824
Software Genérico General
N/A
UNKNOWN
EPSS
1.8%
2021 1 PoC

Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can be accessed from different namespaces.

CVE-2021-33488
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

chat in OX App Suite 7.10.5 has Improper Input Validation. A user can be redirected to a rogue OX Chat server via a development-related hook.

CVE-2021-45908
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An issue was discovered in gif2apng 1.9. There is a stack-based buffer overflow involving a while loop. An attacker has little influence over the data written to the stack, making it unlikely that the flow of control can be subverted.

CVE-2021-33880
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack.

CVE-2021-35506
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Afian FileRun 2021.03.26 allows XSS when an administrator encounters a crafted document during use of the HTML Editor for a preview or edit action.

CVE-2021-44042
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2021 2 PoCs

An issue was discovered in UiPath Assistant 21.4.4. User-controlled data supplied to the --process-start argument of the URI handler for uipath-assistant:// is not correctly encoded, resulting in attacker-controlled content being injected into the error message displayed (when the injected content does not match an existing process). A determined attacker could leverage this to execute JavaScript in the context of the Electron application.

CVE-2021-42666
Software Genérico Web Database
N/A
UNKNOWN
EPSS
26.8%
2021 4 PoCs

A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to quiz_question.php, which could let a malicious user extract sensitive data from the web server and in some cases use this vulnerability in order to get a remote code execution on the remote web server.

CVE-2021-25848
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Improper validation of the length field of LLDP-MED TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows information disclosure to attackers due to using fixed loop counter variable without checking the actual available length via a crafted lldp packet.

CVE-2021-45411
Software Genérico Database
N/A
UNKNOWN
EPSS
3.2%
2021 2 PoCs

In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution.

CVE-2021-29643
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

PRTG Network Monitor before 21.3.69.1333 allows stored XSS via an unsanitized string imported from a User Object in a connected Active Directory instance.

CVE-2021-24664
School Management System – WPSchoolPress Web Windows
N/A
UNKNOWN
EPSS
1.4%
2021 CWE-79 2 PoCs

The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_field() but does not escape them before outputting in attributes, resulting in Stored Cross-Site Scripting issues.

CVE-2021-34416
Zoom On-Premise Meeting Connector Controller, Zoom On-Premise Meeting Connector MMR, Zoom On-Premise Recording Connector, Zoom On-Premise Virtual Room Connector, Zoom On-Premise Virtual Room Connector Load Balancer General
N/A
UNKNOWN
EPSS
1.5%
2021 1 PoC

The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360.20210325, Zoom on-premise Meeting Connector MMR before version 4.6.360.20210325, Zoom on-premise Recording Connector before version 3.8.44.20210326, Zoom on-premise Virtual Room Connector before version 4.4.6752.20210326, and Zoom on-premise Virtual Room Connector Load Balancer before version 2.5.5495.20210326 fails to validate input sent in requests to update the network configuration, which could lead to remote command injection on the on-premise image by the web portal adm

CVE-2021-25087
Download Manager Web Windows
N/A
UNKNOWN
EPSS
1.6%
2021 CWE-862 1 PoC

The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).

CVE-2021-42192
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
23.5%
2021 1 PoC

Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation.

CVE-2021-40868
Software Genérico Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
27.0%
2021 2 PoCs

In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS.

CVE-2021-3294
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2021 3 PoCs

CASAP Automated Enrollment System 1.0 is affected by cross-site scripting (XSS) in users.php. An attacker can steal a cookie to perform user redirection to a malicious website.

CVE-2021-29369
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2021 1 PoC

The gnuplot package prior to version 0.1.0 for Node.js allows code execution via shell metacharacters in Gnuplot commands.