7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-46780
Easy Google Maps Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Easy Google Maps WordPress plugin before 1.9.32 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting

CVE-2021-24876
Registrations for the Events Calendar – Event Registration Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

CVE-2021-24864
WP Cloudy, weather plugin Web Database Cloud Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The WP Cloudy, weather plugin WordPress plugin before 4.4.9 does not escape the post_id parameter before using it in a SQL statement in the admin dashboard, leading to a SQL Injection issue

CVE-2021-42639
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2021 3 PoCs

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to multiple reflected cross site scripting vulnerabilities. Attacker controlled input is reflected back in the page without sanitization.

CVE-2021-43032
Software Genérico Web
N/A
UNKNOWN
EPSS
1.2%
2021 1 PoC

In XenForo through 2.2.7, a threat actor with access to the admin panel can create a new Advertisement via the Advertising function, and save an XSS payload in the body of the HTML document. This payload will execute globally on the client side.

CVE-2021-24521
Side Menu Lite – add sticky fixed buttons Web Database Windows
N/A
UNKNOWN
EPSS
0.8%
2021 CWE-89 1 PoC

The Side Menu Lite – add sticky fixed buttons WordPress plugin before 2.2.1 does not properly sanitize input values from the browser when building an SQL statement. Users with the administrator role or permission to manage this plugin could perform an SQL Injection attack.

CVE-2021-42740
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
9.0%
2021 1 PoC

The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metacharacters through a regex designed to support Windows drive letters. If the output of this package is passed to a real shell as a quoted argument to a command with exec(), an attacker can inject arbitrary commands. This is because the Windows drive letter regex character class is {A-z] instead of the correct {A-Za-z]. Several shell metacharacters exist in the space between capital letter Z and lower case letter a, such as the backtick character.

CVE-2021-33403
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An integer overflow in the transfer function of a smart contract implementation for Lancer Token, an Ethereum ERC20 token, allows the owner to cause unexpected financial losses between two large accounts during a transaction.

CVE-2021-3141
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In Unisys Stealth (core) before 6.0.025.0, the Keycloak password is stored in a recoverable format that might be accessible by a local attacker, who could gain access to the Management Server and change the Stealth configuration.

CVE-2021-36581
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to the server.

CVE-2021-37372
Software Genérico Web
N/A
UNKNOWN
EPSS
7.9%
2021 3 PoCs

Online Student Admission System 1.0 is affected by an insecure file upload vulnerability. A low privileged user can upload malicious PHP files by updating their profile image to gain remote code execution.

CVE-2021-43194
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains TeamCity before 2021.1.2, user enumeration was possible.

CVE-2021-28950
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

An issue was discovered in fs/fuse/fuse_i.h in the Linux kernel before 5.11.8. A "stall on CPU" can occur because a retry loop continually finds the same bad inode, aka CID-775c5033a0d1.

CVE-2021-45025
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage of Sensitive Information in a Cookie.

CVE-2021-29156
Software Genérico Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
88.7%
2021 2 PoCs

ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-character retrieval of password hashes, or retrieve a session token or a private key.

CVE-2021-24790
Contact Form Advanced Database Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-862 1 PoC

The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks in its delete_cf7_data and export_cf7_data AJAX actions, available to any authenticated users, which could allow users with a role as low as subscriber to call them. The delete_cf7_data would lead to arbitrary metadata deletion, as well as PHP Object Injection if a suitable gadget chain is present in another plugin, as user data is passed to the maybe_unserialize() function without being first validated.

CVE-2021-27224
Software Genérico General
N/A
UNKNOWN
EPSS
6.3%
2021 2 PoCs

The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a user-mode write access violation starting at WPG+0x0000000000012ec6, which might allow remote attackers to execute arbitrary code.

CVE-2021-25330
Samsung Mobile Devices General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Calling of non-existent provider in MobileWips application prior to SMR Feb-2021 Release 1 allows unauthorized actions including denial of service attack by hijacking the provider.

CVE-2021-20227
sqlite Database
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-416 3 PoCs

A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.

CVE-2021-42008
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2021 5 PoCs

The decode_data function in drivers/net/hamradio/6pack.c in the Linux kernel before 5.13.13 has a slab out-of-bounds write. Input from a process that has the CAP_NET_ADMIN capability can lead to root access.