7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-24412
Html5 Audio Player – Audio Player for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Html5 Audio Player – Audio Player for WordPress plugin before 2.1.3 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode

CVE-2021-20152
Trendnet AC2600 TEW-827DRU Web
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

Trendnet AC2600 TEW-827DRU version 2.08B01 lacks proper authentication to the bittorrent functionality. If enabled, anyone is able to visit and modify settings and files via the Bittorent web client by visiting: http://192.168.10.1:9091/transmission/web/

CVE-2021-3188
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.

CVE-2021-44098
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remote attacker to compromise Application SQL database.

CVE-2021-31610
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The Bluetooth Classic implementation on AB32VG1 devices does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service (either restart or deadlock the device) by flooding a device with LMP_AU_rand data.

CVE-2021-24488
Post Grid Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
11.5%
2021 CWE-79 1 PoC

The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading to Reflected Cross-Site Scripting issues

CVE-2021-28042
Software Genérico General
N/A
UNKNOWN
EPSS
3.2%
2021 1 PoC

Deutsche Post Mailoptimizer 4.3 before 2020-11-09 allows Directory Traversal via a crafted ZIP archive to the Upload feature or the MO Connect component. This can lead to remote code execution.

CVE-2021-26707
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2021 1 PoC

The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-pollution attacks against applications using this library.

CVE-2021-22056
VMware Workspace ONE Access and Identity Manager Web
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary origins and read the full response.

CVE-2021-24713
Video Lessons Manager – Best Video Course LMS Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Video Lessons Manager WordPress plugin before 1.7.2 and Video Lessons Manager Pro WordPress plugin before 3.5.9 do not properly sanitize and escape values when updating their settings, which could allow high privilege users to perform Cross-Site Scripting attacks

CVE-2021-41647
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.7%
2021 3 PoCs

An un-authenticated error-based and time-based blind SQL injection vulnerability exists in Kaushik Jadhav Online Food Ordering Web App 1.0. An attacker can exploit the vulnerable "username" parameter in login.php and retrieve sensitive database information, as well as add an administrative user.

CVE-2021-24314
Goto Web Database Windows
N/A
UNKNOWN
EPSS
1.0%
2021 CWE-89 2 PoCs

The Goto WordPress theme before 2.1 did not sanitise, validate of escape the keywords GET parameter from its listing page before using it in a SQL statement, leading to an Unauthenticated SQL injection issue

CVE-2021-24683
Weather Effect – Christmas Santa Snow Falling Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do not validate or escape them, which could lead to Stored Cross-Site Scripting issue.

CVE-2021-31761
Software Genérico Web
N/A
UNKNOWN
EPSS
82.3%
2021 4 PoCs

Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process feature.

CVE-2021-39290
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Certain NetModule devices allow Limited Session Fixation via PHPSESSID. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, NB2810, NB3700, NB3701, NB3710, NB3711, NB3720, and NB3800.

CVE-2021-25277
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

FTAPI 4.0 - 4.10 allows XSS via a crafted filename to the alternative text hover box in the file submission component.

CVE-2021-45421
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Emerson Dixell XWEB-500 products are affected by information disclosure via directory listing. A potential attacker can use this misconfiguration to access all the files in the remote directories. Note: the product has not been supported since 2018 and should be removed or replaced

CVE-2021-46780
Easy Google Maps Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Easy Google Maps WordPress plugin before 1.9.32 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting

CVE-2021-24876
Registrations for the Events Calendar – Event Registration Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

CVE-2021-24864
WP Cloudy, weather plugin Web Database Cloud Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The WP Cloudy, weather plugin WordPress plugin before 4.4.9 does not escape the post_id parameter before using it in a SQL statement in the admin dashboard, leading to a SQL Injection issue