7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-24496
Community Events Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and successimportcount GET parameters before outputting them back in an admin page, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator

CVE-2021-40180
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.searchContacts.

CVE-2021-24798
WP Header Images Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The WP Header Images WordPress plugin before 2.0.1 does not sanitise and escape the t parameter before outputting it back in the plugin's settings page, leading to a Reflected Cross-Site Scripting issue

CVE-2021-43136
Software Genérico General
N/A
UNKNOWN
EPSS
13.2%
2021 3 PoCs

An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform.

CVE-2021-24339
Pods – Custom Content Types and Fields Web Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-79 1 PoC

The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability within the 'Menu Label' field parameter.

CVE-2021-43517
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

FOSCAM Camera FI9805E with firmware V4.02.R12.00018510.10012.143900.00000 contains a backdoor that opens Telnet port when special command is sent on port 9530.

CVE-2021-43530
Firefox Web
N/A
UNKNOWN
EPSS
6.0%
2021 2 PoCs

A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a URL scanned from a QR code. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94.

CVE-2021-34166
Software Genérico Database
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

A SQL INJECTION vulnerability in Sourcecodester Simple Food Website 1.0 allows a remote attacker to Bypass Authentication and become Admin.

CVE-2021-34410
Zoom Plugin for Microsoft Outlook for Mac General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

A user-writable application bundle unpacked during the install for all versions of the Zoom Plugin for Microsoft Outlook for Mac before 5.0.25611.0521 allows for privilege escalation to root.

CVE-2021-23206
htmldoc General
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-121 1 PoC

A flaw was found in htmldoc in v1.9.12 and prior. A stack buffer overflow in parse_table() in ps-pdf.cxx may lead to execute arbitrary code and denial of service.

CVE-2021-36368
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but without -oLogLevel=verbose, and an attacker has silently modified the server to support the None authentication option, then the user cannot determine whether FIDO authentication is going to confirm that the user wishes to connect to that server, or that the user wishes to allow that server to connect to a different server on the user's behalf. NOTE: the vendor's position is "this is not an authentication bypass, since nothing is being bypassed.

CVE-2021-24535
Light Messages Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-79 1 PoC

The Light Messages WordPress plugin through 1.0 is lacking CSRF check when updating it's settings, and is not sanitising its Message Content in them (even with the unfiltered_html disallowed). As a result, an attacker could make a logged in admin update the settings to arbitrary values, and set a Cross-Site Scripting payload in the Message Content. Depending on the options set, the XSS payload can be triggered either in the backend only (in the plugin's settings), or both frontend and backend.

CVE-2021-20120
Arris SurfBoard SB8200 Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery attacks. This means that an attacker could make configuration changes (such as changing the administrative password) without the consent of the user.

CVE-2021-24274
Ultimate Maps by Supsystic Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.5%
2021 CWE-79 2 PoCs

The Ultimate Maps by Supsystic WordPress plugin before 1.2.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

CVE-2021-3759
kernel General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-400 1 PoC

A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial of service. The highest threat from this vulnerability is to system availability.

CVE-2021-24694
Simple Download Monitor Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attack via 1) "color" or "css_class" argument of sdm_download shortcode, 2) "class" or "placeholder" argument of sdm_search_form shortcode.

CVE-2021-45232
Apache APISIX Dashboard Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2021 CWE-306 13 PoCs

In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some API directly use the interface of framework `gin` thus bypassing the authentication.

CVE-2021-24737
Comments – wpDiscuz Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Comments – wpDiscuz WordPress plugin through 7.3.0 does not properly sanitise or escape the Follow and Unfollow messages before outputting them in the page, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2021-24755
myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-89 1 PoC

The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL statement, leading to an SQL injection exploitable by any authenticated user

CVE-2021-3772
kernel General
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-354 3 PoCs

A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP addresses.