7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-24419
WP YouTube Lyte Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The WP YouTube Lyte WordPress plugin before 1.7.16 did not sanitise or escape its lyte_yt_api_key and lyte_notification settings before outputting them back in the page, allowing high privilege users to set XSS payload on them and leading to stored Cross-Site Scripting issues.

CVE-2021-28657
Apache Tika Web
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-835 2 PoCs

A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.

CVE-2021-41649
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
91.9%
2021 2 PoCs

An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.

CVE-2021-31643
Software Genérico Web
N/A
UNKNOWN
EPSS
3.8%
2021 2 PoCs

An XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and Webpass due to a lack of sanitization on the component if.cgi - username parameter.

CVE-2021-44280
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2021 4 PoCs

attendance management system 1.0 is affected by a SQL injection vulnerability in admin/incFunctions.php through the makeSafe function.

CVE-2021-45281
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

QuickBox Pro v2.4.8 contains a cross-site scripting (XSS) vulnerability at "adminuseredit.php?usertoedit=XSS", as the user supplied input for the value of this parameter is not properly sanitized.

CVE-2021-33270
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.9%
2021 1 PoC

D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function FUN_800462c4 in /formAdvFirewall. This vulnerability is triggered via a crafted POST request.

CVE-2021-45886
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered in PONTON X/P Messenger before 3.11.2. Anti-CSRF tokens are globally valid, making the web application vulnerable to a weakened version of CSRF, where an arbitrary token of a low-privileged user (such as operator) can be used to confirm actions of higher-privileged ones (such as xpadmin).

CVE-2021-40326
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, mishandle hidden and incremental data in signed documents. An attacker can write to an arbitrary file, and display controlled contents, during signature verification.

CVE-2021-3224
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

A stored cross-site scripting (XSS) vulnerability in cszcms 1.2.9 exists in /admin/pages/new via the content parameter.

CVE-2021-1053
NVIDIA GPU Display Driver Windows
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape or IOCTL in which improper validation of a user pointer may lead to denial of service.

CVE-2021-27973
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages.

CVE-2021-44496
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can control the size variable and buffer that is passed to a call to memcpy. An attacker can use this to overwrite key data structures and gain control of the flow of execution.

CVE-2021-36748
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
87.3%
2021 2 PoCs

A SQL Injection issue in the list controller of the Prestahome Blog (aka ph_simpleblog) module before 1.7.8 for Prestashop allows a remote attacker to extract data from the database via the sb_category parameter.

CVE-2021-22134
Elasticsearch Database
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-200 1 PoC

A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query against a recently updated document. This affects documents that have been updated and not yet refreshed in the index. This could result in the search disclosing the existence of documents and fields the attacker should not be able to view.

CVE-2021-22960
Node Web
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-444 1 PoC

The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions.

CVE-2021-26317
Ryzen™ Series General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Failure to verify the protocol in SMM may allow an attacker to control the protocol and modify SPI flash resulting in a potential arbitrary code execution.

CVE-2021-33219
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2021 2 PoCs

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded Web Application Administrator Passwords for the admin and nplus1user accounts.

CVE-2021-39244
Software Genérico General
N/A
UNKNOWN
EPSS
5.1%
2021 1 PoC

Authenticated Semi-Blind Command Injection (via Parameter Injection) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via the getlogs.cgi tcpdump feature. This affects Nexto NX3003 1.8.11.0, Nexto NX3004 1.8.11.0, Nexto NX3005 1.8.11.0, Nexto NX3010 1.8.3.0, Nexto NX3020 1.8.3.0, Nexto NX3030 1.8.3.0, Nexto NX5100 1.8.11.0, Nexto NX5101 1.8.11.0, Nexto NX5110 1.1.2.8, Nexto NX5210 1.1.2.8, Nexto Xpress XP300 1.8.11.0, Nexto Xpress XP315 1.8.11.0, Nexto Xpress XP325 1.8.11.0, Nexto Xpress XP340 1.8.11.0, and Hadron Xtorm HX3040 1.7.58.0.

CVE-2021-43546
Thunderbird General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.