7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-24425
Floating Notification Bar, Sticky Menu on Scroll, and Sticky Header for Any Theme – myStickymenu Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Floating Notification Bar, Sticky Menu on Scroll, and Sticky Header for Any Theme – myStickymenu WordPress plugin before 2.5.2 does not sanitise or escape its Bar Text settings, allowing hight privilege users to use malicious JavaScript in it, leading to a Stored Cross-Site Scripting issue, which will be triggered in the plugin's setting, as well as all front-page of the blog (when the Welcome bar is active)

CVE-2021-25050
Remove Footer Credit Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Remove Footer Credit WordPress plugin before 1.0.11 does properly sanitise its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

CVE-2021-0652
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In VectorDrawable::VectorDrawable of VectorDrawable.java, there is a possible way to introduce a memory corruption due to sharing of not thread-safe objects. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-185178568

CVE-2021-26795
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

A SQL Injection vulnerability in /appliance/shiftmgn.php in TalariaX sendQuick Alert Plus Server Admin 4.3 before 8HF11 allows attackers to obtain sensitive information via a Roster Time to Roster Management.

CVE-2021-45463
Software Genérico General
N/A
UNKNOWN
EPSS
2.1%
2021 1 PoC

load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.

CVE-2021-24234
Ivory Search – WordPress Search Plugin Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-79 1 PoC

The Search Forms page of the Ivory Search WordPress lugin before 4.6.1 did not properly sanitise the tab parameter before output it in the page, leading to a reflected Cross-Site Scripting issue when opening a malicious crafted link as a high privilege user. Knowledge of a form id is required to conduct the attack.

CVE-2021-34824
Software Genérico General
N/A
UNKNOWN
EPSS
1.8%
2021 1 PoC

Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can be accessed from different namespaces.

CVE-2021-26350
EPYC™ Processors General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

A TOCTOU race condition in SMU may allow for the caller to obtain and manipulate the address of a message port register which may result in a potential denial of service.

CVE-2021-24774
Check & Log Email Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 1 PoC

The Check & Log Email WordPress plugin before 1.0.3 does not validate and escape the "order" and "orderby" GET parameters before using them in a SQL statement when viewing logs, leading to SQL injections issues

CVE-2021-24879
SupportCandy – Helpdesk & Support Ticket System Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-352 1 PoC

The SupportCandy WordPress plugin before 2.2.7 does not have CSRF check in the wpsc_tickets AJAX action, nor has any sanitisation or escaping in some of the filter fields which could allow attackers to make a logged in user having access to the ticket lists dashboard set an arbitrary filter (stored in their cookies) with an XSS payload in it.

CVE-2021-38822
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

A Stored Cross Site Scripting vulnerability via Malicious File Upload exists in multiple pages of IceHrm 30.0.0.OS that allows for arbitrary execution of JavaScript commands.

CVE-2021-24846
Ni WooCommerce Custom Order Status Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-89 1 PoC

The get_query() function of the Ni WooCommerce Custom Order Status WordPress plugin before 1.9.7, used by the niwoocos_ajax AJAX action, available to all authenticated users, does not properly sanitise the sort parameter before using it in a SQL statement, leading to an SQL injection, exploitable by any authenticated users, such as subscriber

CVE-2021-31251
Software Genérico General
N/A
UNKNOWN
EPSS
10.8%
2021 1 PoC

An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by supplying a specially malformed request and an attacker may force the remote telnet server to believe that the user has already authenticated.

CVE-2021-31810
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. A malicious FTP server can use the PASV response to trick Net::FTP into connecting back to a given IP address and port. This potentially makes curl extract information about services that are otherwise private and not disclosed (e.g., the attacker can conduct port scans and service banner extractions).

CVE-2021-26577
HPE Apollo 70 System Networking
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so uploadsshkey function.

CVE-2021-37927
Software Genérico General
N/A
UNKNOWN
EPSS
2.1%
2021 1 PoC

Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.

CVE-2021-24804
Simple JWT Login – Login and Register to WordPress using JWT Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The Simple JWT Login WordPress plugin before 3.2.1 does not have nonce checks when saving its settings, allowing attackers to make a logged in admin changed them. Settings such as HMAC verification secret, account registering and default user roles can be updated, which could result in site takeover.

CVE-2021-33217
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2021 2 PoCs

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The Web Application allows Arbitrary Read/Write actions by authenticated users. The API allows an HTTP POST of arbitrary content into any file on the filesystem as root.

CVE-2021-20106
Nessus Agent General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Nessus Agent versions 8.2.5 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus administrator user to upload a specially crafted file that could lead to gaining administrator privileges on the Nessus host.

CVE-2021-26718
Kaspersky Internet Security for Mac General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus protection.