7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-24832
WP SEO Redirect 301 Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The WP SEO Redirect 301 WordPress plugin before 2.3.2 does not have CSRF in place when deleting redirects, which could allow attackers to make a logged in admin delete them via a CSRF attack

CVE-2021-46231
Software Genérico General
N/A
UNKNOWN
EPSS
4.3%
2021 1 PoC

D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function urlrd_opt.asp. This vulnerability allows attackers to execute arbitrary commands via the url_en parameter.

CVE-2021-41382
Software Genérico General
N/A
UNKNOWN
EPSS
15.4%
2021 2 PoCs

Plastic SCM before 10.0.16.5622 mishandles the WebAdmin server management interface.

CVE-2021-42990
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

FlexiHub For Windows is affected by Buffer Overflow. IOCTL Handler 0x22001B in the FlexiHub For Windows above 2.0.4340 below 5.3.14268 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

CVE-2021-44249
Software Genérico Database
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Online Motorcycle (Bike) Rental System 1.0 is vulnerable to a Blind Time-Based SQL Injection attack within the login portal. This can lead attackers to remotely dump MySQL database credentials.

CVE-2021-33256
Software Genérico General
N/A
UNKNOWN
EPSS
16.0%
2021 1 PoC

A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulnerable and a reverse shell could be obtained if a privileged user exports "User Attempts Audit Report" as CSV file. Note: The vendor disputes this vulnerability, claiming "This is not a valid vulnerability in our ADSSP product. We don't see this as a security issue at our side.

CVE-2021-24938
WOOCS – Currency Switcher for WooCommerce. Professional and Free multi currency plugin – Pay in selected currency Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_data AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected cross-Site Scripting issue

CVE-2021-45222
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.4%
2021 3 PoCs

An issue was discovered in COINS Construction Cloud 11.12. Due to logical flaws in the human ressources interface, it is vulnerable to privilege escalation by HR personnel.

CVE-2021-26313
All supported processors General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-208 1 PoC

Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution of overwritten instructions, may cause an incorrect speculation and could result in data leakage.

CVE-2021-26337
Ryzen™ Series General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA read from invalid DRAM address to SRAM resulting in SMU not servicing further requests.

CVE-2021-44226
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 7 PoCs

Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any unprivileged user before Synapse is installed. The unprivileged user may have placed Trojan horse DLLs there.

CVE-2021-39375
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the WAdvancedFilter/getDimensionItemsByCode FilterValue parameter.

CVE-2021-25418
Samsung Internet General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-269 1 PoC

Improper component protection vulnerability in Samsung Internet prior to version 14.0.1.62 allows untrusted applications to execute arbitrary activity in specific condition.

CVE-2021-25100
GiveWP – Donation Plugin and Fundraising Platform Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The GiveWP WordPress plugin before 2.17.3 does not escape the s parameter before outputting it back in an attribute in the Donation Forms dashboard, leading to a Reflected Cross-Site Scripting

CVE-2021-29370
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

A UXSS was discovered in the Thanos-Soft Cheetah Browser in Android 1.2.0 due to the inadequate filter of the intent scheme. This resulted in Cross-site scripting on the cheetah browser in any website.

CVE-2021-24933
Dynamic Widgets Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Dynamic Widgets WordPress plugin through 1.5.16 does not escape the prefix parameter before outputting it back in an attribute when using the term_tree AJAX action (available to any authenticated users), leading to a Reflected Cross-Site Scripting issue

CVE-2021-27362
Software Genérico General
N/A
UNKNOWN
EPSS
4.2%
2021 1 PoC

The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a Read Access Violation on Control Flow starting at WPG!ReadWPG_W+0x0000000000000133, which might allow remote attackers to execute arbitrary code.

CVE-2021-24847
SEO Redirection Plugin – 301 Redirect Manager Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-89 1 PoC

The importFromRedirection AJAX action of the SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 8.2, available to any authenticated user, does not properly sanitise the offset parameter before using it in a SQL statement, leading an SQL injection when the redirection plugin is also installed

CVE-2021-43161
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
2.5%
2021 1 PoC

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the doSwitchApi function in /cgi-bin/luci/api/switch.

CVE-2021-3186
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

A Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47_multi allows remote attackers to inject arbitrary web script or HTML via the Wifi Name parameter.