7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-25760
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains Hub before 2020.1.12669, information disclosure via the public API was possible.

CVE-2021-25034
WP User – Custom Registration Forms, Login and User Profile Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The WP User WordPress plugin before 7.0 does not sanitise and escape some parameters in pages where the [wp_user] shortcode is used, leading to Reflected Cross-Site Scripting issues

CVE-2021-26338
2nd Gen AMD EPYC™ General
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-284 1 PoC

Improper access controls in System Management Unit (SMU) may allow for an attacker to override performance control tables located in DRAM resulting in a potential lack of system resources.

CVE-2021-20164
Trendnet AC2600 TEW-827DRU Windows
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses credentials for the smb functionality of the device. Usernames and passwords for all smb users are revealed in plaintext on the smbserver.asp page.

CVE-2021-31159
Software Genérico General
N/A
UNKNOWN
EPSS
24.3%
2021 4 PoCs

Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732.

CVE-2021-36751
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

ENC DataVault 7.2.3 and before, and OEM versions, use an encryption algorithm that is vulnerable to data manipulation (without knowledge of the key). This is called ciphertext malleability. There is no data integrity mechanism to detect this manipulation.

CVE-2021-37605
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

In version 6.5 Microchip MiWi software and all previous versions including legacy products, the stack is validating only two out of four Message Integrity Check (MIC) bytes.

CVE-2021-31915
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible.

CVE-2021-24169
Advanced Order Export For WooCommerce Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2021 CWE-79 2 PoCs

This Advanced Order Export For WooCommerce WordPress plugin before 3.1.8 helps you to easily export WooCommerce order data. The tab parameter in the Admin Panel is vulnerable to reflected XSS.

CVE-2021-46388
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Sin descripción disponible.

CVE-2021-37580
Apache ShenYu Admin Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2021 CWE-287 7 PoCs

A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue affected Apache ShenYu 2.3.0 and 2.4.0

CVE-2021-28242
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2021 2 PoCs

SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by injecting SQL commands into the "cf_name" parameter when creating a new filter under the "Collections" tab.

CVE-2021-20127
Draytek VigorConnect General
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

An arbitrary file deletion vulnerability exists in the file delete functionality of the Html5Servlet endpoint of Draytek VigorConnect 1.6.0-B3. This allows an authenticated user to arbitrarily delete files in any location on the target operating system with root privileges.

CVE-2021-45856
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

Accu-Time Systems MAXIMUS 1.0 telnet service suffers from a remote buffer overflow which causes the telnet service to crash

CVE-2021-29641
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
6.6%
2021 3 PoCs

Directus 8 before 8.8.2 allows remote authenticated users to execute arbitrary code because file-upload permissions include the ability to upload a .php file to the main upload directory and/or upload a .php file and a .htaccess file to a subdirectory. Exploitation succeeds only for certain installations with the Apache HTTP Server and the local-storage driver (e.g., when the product was obtained from hub.docker.com).

CVE-2021-44964
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.

CVE-2021-27114
Software Genérico General
N/A
UNKNOWN
EPSS
2.6%
2021 1 PoC

An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/addassignment route, a very long text entry for the"'s_ip" and "s_mac" fields could lead to a Stack-Based Buffer Overflow and overwrite the return address.

CVE-2021-41965
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

A SQL injection vulnerability exists in ChurchCRM version 2.0.0 to 4.4.5 that allows an authenticated attacker to issue an arbitrary SQL command to the database through the unsanitized EN_tyid, theID and EID fields used when an Edit action on an existing record is being performed.

CVE-2021-24436
W3 Total Cache Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.0%
2021 CWE-79 1 PoC

The W3 Total Cache WordPress plugin before 2.1.4 was vulnerable to a reflected Cross-Site Scripting (XSS) security vulnerability within the "extension" parameter in the Extensions dashboard, which is output in an attribute without being escaped first. This could allow an attacker, who can convince an authenticated admin into clicking a link, to run malicious JavaScript within the user's web browser, which could lead to full site compromise.

CVE-2021-24893
Stars Rating Web Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-400 1 PoC

The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the comments section, or pending comment dashboard depending if the user sent it as unauthenticated or authenticated.