7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-24448
User Registration & User Profile – Profile Builder Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.8 does not sanitise or escape its 'Modify default Redirect Delay timer' setting, allowing high privilege users to use JavaScript code in it, even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue

CVE-2021-39623
Android General
N/A
UNKNOWN
EPSS
2.5%
2021 2 PoCs

In doRead of SimpleDecodingSource.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-194105348

CVE-2021-44263
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Gurock TestRail before 7.2.4 mishandles HTML escaping.

CVE-2021-33813
Software Genérico Web
N/A
UNKNOWN
EPSS
1.4%
2021 2 PoCs

An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.

CVE-2021-4104
Apache Log4j 1.x Web
N/A
UNKNOWN
EPSS
72.2%
2021 CWE-502 5 PoCs

JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from th

CVE-2021-42183
Software Genérico Web
N/A
UNKNOWN
EPSS
44.6%
2021 1 PoC

MasaCMS 7.2.1 is affected by a path traversal vulnerability in /index.cfm/_api/asset/image/.

CVE-2021-24177
File Manager Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint /wp-admin/admin.php?page=wp_file_manager_properties when a payload is submitted on the User-Agent parameter. The payload is then reflected back on the web application response.

CVE-2021-24178
Business Directory Plugin – Easy Listing Directories for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-352 1 PoC

The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 suffered from Cross-Site Request Forgery issues, allowing an attacker to make a logged in administrator add, edit or delete form fields, which could also lead to Stored Cross-Site Scripting issues.

CVE-2021-20837
Movable Type General ⚡ nuclei
N/A
UNKNOWN
EPSS
94.2%
2021 12 PoCs

Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.5002 and earlier (Movable Type Advanced 7 Series), Movable Type Advanced 6.8.2 and earlier (Movable Type Advanced 6 Series), Movable Type Premium 1.46 and earlier, and Movable Type Premium Advanced 1.46 and earlier allow remote attackers to execute arbitrary OS commands via unspecified vectors. Note that all versions of Movable Type 4.0 or later including unsupported (End-of-Life, EOL) versions are also affected by this vulnerability.

CVE-2021-24326
All 404 Redirect to Homepage Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-79 1 PoC

The tab parameter of the settings page of the All 404 Redirect to Homepage WordPress plugin before 1.21 was vulnerable to an authenticated reflected Cross-Site Scripting (XSS) issue as user input was not properly sanitised before being output in an attribute.

CVE-2021-23924
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An issue was discovered in Devolutions Server before 2020.3. There is an exposure of sensitive information in diagnostic files.

CVE-2021-38584
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

The WHM Locale Upload feature in cPanel before 98.0.1 allows XXE attacks (SEC-585).

CVE-2021-36981
Software Genérico General
N/A
UNKNOWN
EPSS
16.5%
2021 1 PoC

In the server in SerNet verinice before 1.22.2, insecure Java deserialization allows remote authenticated attackers to execute arbitrary code.

CVE-2021-3564
kernel General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-415 3 PoCs

A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious HCI TTY Bluetooth device. A local user could use this flaw to crash the system. This flaw affects all the Linux kernel versions starting from 3.13.

CVE-2021-46424
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
91.5%
2021 1 PoC

Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to delete any file, even system internal files, via a DELETE request.

CVE-2021-21992
VMware vCenter Server, VMware Cloud Foundation Cloud
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing. A malicious actor with non-administrative user access to the vCenter Server vSphere Client (HTML5) or vCenter Server vSphere Web Client (FLEX/Flash) may exploit this issue to create a denial-of-service condition on the vCenter Server host.

CVE-2021-42099
Software Genérico General
N/A
UNKNOWN
EPSS
22.4%
2021 1 PoC

Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.

CVE-2021-24696
Simple Download Monitor Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads

CVE-2021-45897
Software Genérico General
N/A
UNKNOWN
EPSS
24.6%
2021 1 PoC

SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution.

CVE-2021-28146
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.