7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-24189
Captchinoo, Google recaptcha for admin login page Web Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-285 1 PoC

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptcha for admin login page WordPress plugin before 2.4, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

CVE-2021-3243
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Wfilter ICF 5.0.117 contains a cross-site scripting (XSS) vulnerability. An attacker in the same LAN can craft a packet with a malicious User-Agent header to inject a payload in its logs, where an attacker can take over the system by through its plugin-running function.

CVE-2021-45041
Software Genérico Database
N/A
UNKNOWN
EPSS
13.3%
2021 1 PoC

SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resource_id and start_date.

CVE-2021-42671
Software Genérico Web
N/A
UNKNOWN
EPSS
6.2%
2021 4 PoCs

An incorrect access control vulnerability exists in Sourcecodester Engineers Online Portal in PHP in nia_munoz_monitoring_system/admin/uploads. An attacker can leverage this vulnerability in order to bypass access controls and access all the files uploaded to the web server without the need of authentication or authorization.

CVE-2021-31606
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.1%
2021 1 PoC

furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect arbitrary clients.

CVE-2021-36560
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2021 2 PoCs

Phone Shop Sales Managements System using PHP with Source Code 1.0 is vulnerable to authentication bypass which leads to account takeover of the admin.

CVE-2021-29393
Software Genérico General
N/A
UNKNOWN
EPSS
14.2%
2021 2 PoCs

Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to inject and execute arbitrary system commands via the unsanitized user-controlled "command" and "commandvalues" parameters.

CVE-2021-25431
Cameralyzer General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-284 1 PoC

Improper access control vulnerability in Cameralyzer prior to versions 3.2.1041 in 3.2.x, 3.3.1040 in 3.3.x, and 3.4.4210 in 3.4.x allows untrusted applications to access some functions of Cameralyzer.

CVE-2021-26352
Ryzen™ Series General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Insufficient bound checks in System Management Unit (SMU) PCIe Hot Plug table may result in access/updates from/to invalid address space that could result in denial of service.

CVE-2021-25014
Ibtana – WordPress Website Builder Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-862 1 PoC

The Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings which could lead to Stored Cross-Site Scripting issue.

CVE-2021-24343
iFlyChat – WordPress Chat Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The iFlyChat WordPress plugin before 4.7.0 does not sanitise its APP ID setting before outputting it back in the page, leading to an authenticated Stored Cross-Site Scripting issue

CVE-2021-37166
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

A buffer overflow issue leading to denial of service was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. When HMI3 starts up, it binds a local service to a TCP port on all interfaces of the device, and takes extensive time for the GUI to connect to the TCP socket, allowing the connection to be hijacked by an external attacker.

CVE-2021-3773
kernel Networking
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-200 2 PoCs

A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network attacks.

CVE-2021-42980
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

NoMachine Cloud Server is affected by Buffer Overflow. IOCTL Handler 0x22001B in the NoMachine Cloud Server above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

CVE-2021-30072
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

An issue was discovered in prog.cgi on D-Link DIR-878 1.30B08 devices. Because strcat is misused, there is a stack-based buffer overflow that does not require authentication.

CVE-2021-31341
Mendix Database Replication Module General
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-209 1 PoC

Uploading a table mapping using a manipulated XML file results in an exception that could expose information about the application-server and the used XML-framework on the Mendix Database Replication Module (All versions prior to v7.0.1).

CVE-2021-43389
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2021 3 PoCs

An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds flaw in the detach_capi_ctr function in drivers/isdn/capi/kcapi.c.

CVE-2021-20069
Racom MIDGE Firmware Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scripting attacks via the regionalSettings.php dialogs.

CVE-2021-38840
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2021 4 PoCs

SQL Injection can occur in Simple Water Refilling Station Management System 1.0 via the water_refilling/classes/Login.php username parameter.

CVE-2021-20050
SonicWall SMA100 Web Networking
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-284 1 PoC

An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, potentially exposing configuration meta-data.