7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-43339
Software Genérico General
N/A
UNKNOWN
EPSS
12.7%
2021 2 PoCs

In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export functionality. For example, a new admin user could be created.

CVE-2021-26274
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

The Agent in NinjaRMM 5.0.909 has Insecure Permissions.

CVE-2021-46709
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

phpLiteAdmin through 1.9.8.2 allows XSS via the index.php newRows parameter (aka num or number).

CVE-2021-24932
Auto Featured Image (Auto Post Thumbnail) Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.3 does not sanitise and escape the post_id parameter before outputting back in an admin page within a JS block, leading to a Reflected Cross-Site Scripting issue.

CVE-2021-37980
Chrome Windows
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Inappropriate implementation in Sandbox in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially bypass site isolation via Windows.

CVE-2021-35523
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT AUTHORITY\SYSTEM. A non-privileged local user can modify the OpenVPN configuration stored under "%APPDATA%\Securepoint SSL VPN" and add a external script file that is executed as privileged user.

CVE-2021-3355
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

A stored-self XSS exists in LightCMS v1.3.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/SensitiveWords.

CVE-2021-26323
3rd Gen AMD EPYC™ General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-20 1 PoC

Failure to validate SEV Commands while SNP is active may result in a potential impact to memory integrity.

CVE-2021-43728
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Pix-Link MiNi Router 28K.MiniRouter.20190211 was discovered to contain a stored cross-site scripting (XSS) vulnerability due to an unsanitized SSID parameter.

CVE-2021-40960
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
73.8%
2021 1 PoC

Galera WebTemplate 1.0 is affected by a directory traversal vulnerability that could reveal information from /etc/passwd and /etc/shadow.

CVE-2021-20155
Trendnet AC2600 TEW-827DRU General
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

Trendnet AC2600 TEW-827DRU version 2.08B01 makes use of hardcoded credentials. It is possible to backup and restore device configurations via the management web interface. These devices are encrypted using a hardcoded password of "12345678".

CVE-2021-24821
Cost Calculator Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Cost Calculator WordPress plugin before 1.6 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the Description fields of a Cost Calculator > Price Settings (which gets injected on the edit page as well as any page that embeds the calculator using the shortcode), as well as the Text Preview field of a Project (injected on the edit project page)

CVE-2021-30224
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Cross Site Request Forgery (CSRF) in Rukovoditel v2.8.3 allows attackers to create an admin user with an arbitrary credentials.

CVE-2021-44505
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a NULL pointer dereference after calls to ZPrint.

CVE-2021-45225
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.4%
2021 3 PoCs

An issue was discovered in COINS Construction Cloud 11.12. Due to improper input neutralization, it is vulnerable to reflected cross-site scripting (XSS) via malicious links (affecting the search window and activity view window).

CVE-2021-30641
Apache HTTP Server Web
N/A
UNKNOWN
EPSS
36.4%
2021 2 PoCs

Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'

CVE-2021-25142
HPE Apollo 70 System General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webstartflash function.

CVE-2021-24837
Passster Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The Passster WordPress plugin before 3.5.5.8 does not escape the area parameter of its shortcode, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

CVE-2021-30042
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Clinic Name", "Clinic Address", "Clinic City", or "Clinic Contact" field on clinics/register.php

CVE-2021-3291
Software Genérico General
N/A
UNKNOWN
EPSS
32.6%
2021 2 PoCs

Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting a command.