7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-24222
WP-Curriculo Vitae Free Web Windows
N/A
UNKNOWN
EPSS
5.7%
2021 CWE-434 1 PoC

The WP-Curriculo Vitae Free WordPress plugin through 6.3 suffers from an arbitrary file upload issue in page where the [formCadastro] is embed. The form allows unauthenticated user to register and submit files for their profile picture as well as resume, without any file extension restriction, leading to RCE.

CVE-2021-34676
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

Basix NEX-Forms through 7.8.7 allows authentication bypass for Excel report generation.

CVE-2021-45821
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.9%
2021 1 PoC

A blind SQL injection vulnerability exists in Xbtit 3.1 via the sid parameter in ajaxchat/getHistoryChatData.php file that is accessible by a registered user. As a result, a malicious user can extract sensitive data such as usernames and passwords and in some cases use this vulnerability in order to get a remote code execution on the remote web server.

CVE-2021-24897
Add Subtitle Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Add Subtitle WordPress plugin through 1.1.0 does not sanitise or escape the sub-title field (available only with classic editor) when output in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

CVE-2021-43541
Thunderbird General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

CVE-2021-36690
Software Genérico Database
N/A
UNKNOWN
EPSS
1.7%
2021 5 PoCs

A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance of this report because a sqlite3.exe user already has full privileges (e.g., is intentionally allowed to execute commands). This report does NOT imply any problem in the SQLite library.

CVE-2021-42665
Software Genérico Web Database
N/A
UNKNOWN
EPSS
24.9%
2021 5 PoCs

An SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the login form inside of index.php, which can allow an attacker to bypass authentication.

CVE-2021-31805
Apache Struts Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.8%
2021 CWE-917 10 PoCs

The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.

CVE-2021-24387
WP Pro Real Estate 7 Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
42.0%
2021 CWE-79 1 PoC

The WP Pro Real Estate 7 WordPress theme before 3.1.1 did not properly sanitise the ct_community parameter in its search listing page before outputting it back in it, leading to a reflected Cross-Site Scripting which can be triggered in both unauthenticated or authenticated user context

CVE-2021-21983
VMware vRealize Operations Web
N/A
UNKNOWN
EPSS
83.2%
2021 2 PoCs

Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.

CVE-2021-36622
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 2 PoCs

Sourcecodester Online Covid Vaccination Scheduler System 1.0 is affected vulnerable to Arbitrary File Upload. The admin panel has an upload function of profile photo accessible at http://localhost/scheduler/admin/?page=user. An attacker could upload a malicious file such as shell.php with the Content-Type: image/png. Then, the attacker have to visit the uploaded profile photo to access the shell.

CVE-2021-26336
Ryzen™ Series General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Insufficient bounds checking in System Management Unit (SMU) may cause invalid memory accesses/updates that could result in SMU hang and subsequent failure to service any further requests from other components.

CVE-2021-31618
Apache HTTP Server Web
N/A
UNKNOWN
EPSS
11.0%
2021 CWE-476 1 PoC

Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server and used for the HTTP/1 protocol as well. On violation of these restrictions and HTTP response is sent to the client with a status code indicating why the request was rejected. This rejection response was not fully initialised in the HTTP/2 protocol handler if the offending header was the very first one received or appeared in a a footer. This led to a NULL pointer dereference on initialised memory, crashing reliably the child process. Since such

CVE-2021-24972
Pixel Cat – Conversion Pixel Manager Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Pixel Cat WordPress plugin before 2.6.3 does not escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

CVE-2021-38137
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Corero SecureWatch Managed Services 9.7.2.0020 does not correctly check swa-monitor and cns-monitor user’s privileges, allowing a user to perform actions not belonging to his role.

CVE-2021-39289
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Certain NetModule devices have Insecure Password Handling (cleartext or reversible encryption), These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, NB2810, NB3700, NB3701, NB3710, NB3711, NB3720, and NB3800.

CVE-2021-24555
Diary & Availability Calendar Web Database
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-89 2 PoCs

The daac_delete_booking_callback function, hooked to the daac_delete_booking AJAX action, takes the id POST parameter which is passed into the SQL statement without proper sanitisation, validation or escaping, leading to a SQL Injection issue. Furthermore, the ajax action is lacking any CSRF and capability check, making it available to any authenticated user.

CVE-2021-36209
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset.

CVE-2021-44686
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

calibre before 5.32.0 contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service) in html_preprocess_rules in ebooks/conversion/preprocess.py.

CVE-2021-23955
Firefox General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to clickjacking attacks. This vulnerability affects Firefox < 85.