7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-33216
Software Genérico General
N/A
UNKNOWN
EPSS
17.6%
2021 2 PoCs

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowing shell access via a developer account.

CVE-2021-4083
kernel General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-416 2 PoCs

A read-after-free memory flaw was found in the Linux kernel's garbage collection for Unix domain socket file handlers in the way users call close() and fget() simultaneously and can potentially trigger a race condition. This flaw allows a local user to crash the system or escalate their privileges on the system. This flaw affects Linux kernel versions prior to 5.16-rc4.

CVE-2021-25069
Download Manager Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2021 CWE-89 1 PoC

The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue

CVE-2021-29425
Apache Commons IO Web
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-20 6 PoCs

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.

CVE-2021-28294
Software Genérico Web
N/A
UNKNOWN
EPSS
2.6%
2021 1 PoC

Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code execution (RCE).

CVE-2021-25894
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the /magnoliaPublic/travel/members/login.html mgnlUserId parameter.

CVE-2021-24710
Print-O-Matic Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Print-O-Matic WordPress plugin before 2.0.3 does not escape some of its settings before outputting them in attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2021-27231
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Hestia Control Panel 1.3.5 and below, in a shared-hosting environment, sometimes allows remote authenticated users to create a subdomain for a different customer's domain name, leading to spoofing of services or email messages.

CVE-2021-46782
Pricing Table by Supsystic Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Pricing Table by Supsystic WordPress plugin before 1.9.5 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting

CVE-2021-24499
Workreap Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.9%
2021 CWE-434 7 PoCs

The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks, or validate that the request is from a valid user in any other way. The endpoints allowed for uploading arbitrary files to the uploads/workreap-temp directory. Uploaded files were neither sanitized nor validated, allowing an unauthenticated visitor to upload executable code such as php scripts.

CVE-2021-45428
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2021 2 PoCs

TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files including HTML and CGI formats.

CVE-2021-41651
Software Genérico Web Database
N/A
UNKNOWN
EPSS
6.3%
2021 2 PoCs

A blind SQL injection vulnerability exists in the Raymart DG / Ahmed Helal Hotel-mgmt-system. A malicious attacker can retrieve sensitive database information and interact with the database using the vulnerable cid parameter in process_update_profile.php.

CVE-2021-30942
watchOS General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Description: A memory corruption issue in the processing of ICC profiles was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing a maliciously crafted image may lead to arbitrary code execution.

CVE-2021-24505
Forms Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The Forms WordPress plugin before 1.12.3 did not sanitise its input fields, leading to Stored Cross-Site scripting issues. The plugin was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) vulnerability within the Forms "Add new" field.

CVE-2021-24617
GamePress – The Game Database Plugin Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The GamePress WordPress plugin through 1.1.0 does not escape the op_edit POST parameter before outputting it back in multiple Game Option pages, leading to Reflected Cross-Site Scripting issues

CVE-2021-3243
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Wfilter ICF 5.0.117 contains a cross-site scripting (XSS) vulnerability. An attacker in the same LAN can craft a packet with a malicious User-Agent header to inject a payload in its logs, where an attacker can take over the system by through its plugin-running function.

CVE-2021-45041
Software Genérico Database
N/A
UNKNOWN
EPSS
13.3%
2021 1 PoC

SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resource_id and start_date.

CVE-2021-42671
Software Genérico Web
N/A
UNKNOWN
EPSS
6.2%
2021 4 PoCs

An incorrect access control vulnerability exists in Sourcecodester Engineers Online Portal in PHP in nia_munoz_monitoring_system/admin/uploads. An attacker can leverage this vulnerability in order to bypass access controls and access all the files uploaded to the web server without the need of authentication or authorization.

CVE-2021-31606
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.1%
2021 1 PoC

furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect arbitrary clients.

CVE-2021-36560
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2021 2 PoCs

Phone Shop Sales Managements System using PHP with Source Code 1.0 is vulnerable to authentication bypass which leads to account takeover of the admin.