7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-24414
Video Player for YouTube Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Video Player for YouTube WordPress plugin before 1.4 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode

CVE-2021-24249
Business Directory Plugin – Easy Listing Directories for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator export files, which could then be downloaded by the attacker to get access to PII, such as email, home addresses etc

CVE-2021-24515
Video Gallery - Vimeo and YouTube Gallery Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Video Gallery WordPress plugin before 1.1.5 does not escape the Title and Description of the videos in a gallery before outputting them in attributes, leading to Stored Cross-Site Scripting issues

CVE-2021-37416
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.2%
2021 1 PoC

Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page.

CVE-2021-31659
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is vulnerable to Cross Site Request Forgery (CSRF). All configuration information is placed in the URL, without any additional token authentication information. A malicious link opened by the switch administrator may cause the password of the switch to be modified and the configuration file to be tampered with.

CVE-2021-24659
PostX – Gutenberg Blocks for Post Grid Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's block.

CVE-2021-39614
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2021 2 PoCs

D-Link DVX-2000MS contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file. As weak passwords have been used, the plaintext passwords can be recovered from the hash values.

CVE-2021-27962
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.

CVE-2021-44210
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

OX App Suite through 7.10.5 allows XSS via NIFF (Notation Interchange File Format) data.

CVE-2021-24645
Booking.com Product Helper Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Booking.com Product Helper WordPress plugin before 1.0.2 does not sanitize and escape Product Code when creating Product Shortcode, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2021-24459
Survey Maker Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The get_results() and get_items() functions in the Survey Maker WordPress plugin before 1.5.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

CVE-2021-28975
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

WP Mailster 1.6.18.0 allows XSS when a victim opens a mail server's details in the mst_servers page, for a crafted server_host, server_name, or connection_parameter parameter.

CVE-2021-43339
Software Genérico General
N/A
UNKNOWN
EPSS
12.7%
2021 2 PoCs

In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export functionality. For example, a new admin user could be created.

CVE-2021-26274
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

The Agent in NinjaRMM 5.0.909 has Insecure Permissions.

CVE-2021-46709
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

phpLiteAdmin through 1.9.8.2 allows XSS via the index.php newRows parameter (aka num or number).

CVE-2021-24932
Auto Featured Image (Auto Post Thumbnail) Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.3 does not sanitise and escape the post_id parameter before outputting back in an admin page within a JS block, leading to a Reflected Cross-Site Scripting issue.

CVE-2021-37980
Chrome Windows
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Inappropriate implementation in Sandbox in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially bypass site isolation via Windows.

CVE-2021-35523
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT AUTHORITY\SYSTEM. A non-privileged local user can modify the OpenVPN configuration stored under "%APPDATA%\Securepoint SSL VPN" and add a external script file that is executed as privileged user.

CVE-2021-3355
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

A stored-self XSS exists in LightCMS v1.3.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/SensitiveWords.

CVE-2021-26323
3rd Gen AMD EPYC™ General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-20 1 PoC

Failure to validate SEV Commands while SNP is active may result in a potential impact to memory integrity.