7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-3715
kernel General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-416 1 PoC

A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of classification filters, leading to a use-after-free condition. This flaw allows unprivileged local users to escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVE-2021-41324
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Directory traversal in the Copy, Move, and Delete features in Pydio Cells 2.2.9 allows remote authenticated users to enumerate personal files (or Cells files belonging to any user) via the nodes parameter (for Copy and Move) or via the Path parameter (for Delete).

CVE-2021-24142
301 Redirects - Easy Redirect Manager Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise its "Redirect From" column when importing a CSV file, allowing high privilege users to perform SQL injections.

CVE-2021-24529
Grid Gallery – Photo Image Grid Gallery Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-79 1 PoC

The Grid Gallery – Photo Image Grid Gallery WordPress plugin before 1.2.5 does not properly sanitize the title field for image galleries when adding them via the admin dashboard, resulting in an authenticated Stored Cross-Site Scripting vulnerability.

CVE-2021-42063
SAP Knowledge Warehouse Web ⚡ nuclei
N/A
UNKNOWN
EPSS
40.8%
2021 3 PoCs

A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. The usage of one SAP KW component within a Web browser enables unauthorized attackers to conduct XSS attacks, which might lead to disclose sensitive data.

CVE-2021-35943
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password, per RFC4513.

CVE-2021-24539
Coming Soon, Under Construction & Maintenance Mode By Dazzler Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The Coming Soon, Under Construction & Maintenance Mode By Dazzler WordPress plugin before 1.6.7 does not sanitise or escape its description setting when outputting it in the frontend when the Coming Soon mode is enabled, even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue

CVE-2021-42912
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, to send commands to the operating system as the root user via the ping diagnostic tool, bypassing the IP address field, and concatenating OS commands with a semicolon.

CVE-2021-25832
Software Genérico General
N/A
UNKNOWN
EPSS
7.0%
2021 1 PoC

A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v6.0.0. Using this vulnerability, an attacker is able to gain remote code executions on DocumentServer.

CVE-2021-24526
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not escape its Form Title before outputting it in an attribute when editing a form in the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue

CVE-2021-38833
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.9%
2021 1 PoC

SQL injection vulnerability in PHPGurukul Apartment Visitors Management System (AVMS) v. 1.0 allows attackers to execute arbitrary SQL statements and to gain RCE.

CVE-2021-34675
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

Basix NEX-Forms through 7.8.7 allows authentication bypass for stored PDF reports.

CVE-2021-3025
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Invision Community IPS Community Suite before 4.5.4.2 allows SQL Injection via the Downloads REST API (the sortDir parameter in a sortBy=popular action to the GETindex() method in applications/downloads/api/files.php).

CVE-2021-43289
Software Genérico General
N/A
UNKNOWN
EPSS
1.6%
2021 1 PoC

An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into an arbitrary directory of a GoCD server, but does not control the filename.

CVE-2021-29390
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c.

CVE-2021-25949
set-getter General
N/A
UNKNOWN
EPSS
2.3%
2021 1 PoC

Prototype pollution vulnerability in 'set-getter' version 0.1.0 allows an attacker to cause a denial of service and may lead to remote code execution.

CVE-2021-25273
Sophos UTM Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Stored XSS can execute as administrator in quarantined email detail view in Sophos UTM before version 9.706.

CVE-2021-42566
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2021 1 PoC

myfactory.FMS before 7.1-912 allows XSS via the Error parameter.

CVE-2021-44653
Software Genérico Database
N/A
UNKNOWN
EPSS
0.4%
2021 3 PoCs

Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel authentication can be bypassed due to SQL injection vulnerability in the login form allowing attacker to gain access as admin to the application.

CVE-2021-31673
Software Genérico Web
N/A
UNKNOWN
EPSS
2.7%
2021 1 PoC

A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remote attackers to inject arbitrary web script or HTML via the groupId parameter.